RFC-2350
Established according to RFC-2350.
1. Document Information
1.1. Date of Last Update
This document was last updated 2026-09-15.
1.2. Distribution List for Notifications
None.
1.3. Locations where this Document May Be Found
The current version of this document can be found at: https://www.cert.se/om-cert-se/rfc-2350/
2. Contact Information
2.1. Name of the Team
CERT-SE
2.2. Address
CERT-SE
FRA
171 73 Solna
Sweden
2.3. Time Zone
CET/CEST,
Central European Time/Central European Summer Time,
UTC+0100/UTC+0200
2.4. Telephone Number
+46 10 382 80 00
2.5. Facsimile Number
None.
2.6. Other Telecommunication
None.
2.7. Electronic Mail Address
cert@cert.se
This address can be used to report all security incidents which relate to the CERT-SE constituency.
2.8. Public Keys and Encryption Information
PGP/GnuPG is supported for secure communication. The current CERT-SE team-key can be found at https://www.cert.se/cert_at_cert.se.asc. Please use this key when you want/need to encrypt messages that you send to CERT-SE. When responding, CERT-SE will sign messages using the same key.
2.9. Team Members
No information is provided in public.
2.10. Other Information
- See the CERT-SE webpages https://www.cert.se
- CERT-SE is certified by the Trusted Introducer for CERT:s, see https://www.trusted-introducer.org/directory/teams/cert-se.html
- CERT-SE is a full member of FIRST, see http://www.first.org/members/teams/cert-se
- CERT-SE is a member of the Swedish CERT-forum, see https://certforum.se/index-en.html
2.11. Points of Customer Contact
- Regular cases: use the CERT-SE e-mail address or phone +46 10 382 80 00
- Regular response hours: Monday-Friday, 8:00-16:20 (except public holidays in Sweden). We aim to respond within two business days.
- In case of an incident outside these hours, the Duty Officer is available at +46 10 382 80 00
3. Charter
3.1. Mission Statement
The mission of CERT-SE is stated in Ordinance (2025:237) with Instructions for the FRA, the National Defense Radio Establishment. CERT-SE has been installed to reduce the potential for, and impact of, cyber attacks targeting Sweden and the Swedish society. In brief, the Ordinance states that CERT-SE shall:
- respond promptly when IT incidents occur by spreading information, and where needed work with the coordination of measures, and partake in work to remedy or mitigate the incident’s consequences,
- report back to relevant actors in connection with an IT incident being reported,
- cooperate with authorities that have specific tasks in the field of information security, and
- act as Sweden’s point of contact for equivalent services in other countries, and develop cooperation and information exchanges with them.
3.2. Constituency
CERT-SE is the National CERT of Sweden, and the constituency consists of the Swedish society, including but not limited to governmental authorities, regional authorities, municipalities, enterprises and companies. In addition, CERT-SE is the governmental CERT of Sweden and have additional responsibilities within the governmental body.
3.3. Sponsorship and/or Affiliation
CERT-SE is part of FRA, the National Defense Radio Establishment, which is a Swedish governmental agency. CERT-SE is fully financed by FRA.
3.4. Authority
CERT-SE has the authority to issue recommendations regarding vulnerabilities and mitigation of incidents and/or incident handling. Such recommendations can include for example blocking addresses or networks. The authority is limited to non binding recommendations and CERT-SE does not have the authority to issue legally binding regulations, conduct supervision or enforce measures.
4. Policies
4.1. Types of Incidents and Level of Support
All incidents are considered normal priority. CERT-SE itself is the authority that can set and reset the emergency label. An incident can be reported to CERT-SE as emergency, but it is up to CERT-SE to decide whether or not to uphold that status.
4.2. Co-operation, Interaction and Disclosure of Information
CERT-SE is deeply engaged in national, European and international cooperation groups, and supports voluntary cooperation between CSIRT:s at all levels. For that matter, CERT-SE ensures a global presence and networking with its partners through active participation in working groups, international meetings and conferences.
All incoming information related to incidents is handled confidentially by CERT-SE, regardless of its priority. Information that is evidently sensitive in nature is only communicated and stored in a secure environment, using encryption if necessary. When reporting an incident of sensitive nature, please state so explicitly, e.g. by using the label SENSITIVE in the subject field of e-mail and using encryption if possible.
CERT-SE supports the Traffic Light Protocol (TLP) model of information sharing, see https://www.first.org/tlp. Information that comes in with the tags TLP:CLEAR, TLP:GREEN, TLP:AMBER, TLP:AMBER+STRICT or TLP:RED will be handled appropriately.
CERT-SE will use the information you provide to help solve security incidents. This means that by default the information will be distributed further to the appropriate parties, but only on a need-to-know basis, according to present information classification or TLP marking, and in an anonymized fashion unless otherwise agreed upon.
If you object to this default behavior of CERT-SE, please make explicit what CERT-SE can do with the information you provide. CERT-SE will adhere to your policy, but will also point out to you if that means that CERT-SE cannot act on the information provided.
As of October 1, 2022, on behalf of the government, FRA forwards the notifications and completed forms that are reported to FRA (regulation (2022:524), law (2018:1174) and regulation (2018:1175), and which contain descriptions of incidents that can be assumed to have their basis in a criminal act, to the Police Authority.
4.3. Communication and Authentication
See 2.8 Public Keys and Encryption Information. Usage of PGP/GnuPG or other pre-approved cryptographic means in all cases where sensitive information is involved is highly recommended.
5. Services
5.1. Proactive Activities
CERT-SE proactively advises their constituency in regard to recent vulnerabilities and on matters of computer and network security, including but not limited to:
- weekly newsletter,
- urgent security advisories,
- training and education of CSIRT personnel according to TF-CSIRT TRANSITS I,
- early warning system (ANTS),
- a National Malware Information Sharing Platform (MISP-SE), and
- cyber security guidance and support.
CERT-SE is not responsible for implementation, which is always left at the discretion of the constituents.
5.2. Incident Response (Triage, Coordination and Resolution)
CERT-SE is responsible for the coordination of security incidents somehow involving their constituency, as defined in 3.2. Constituency. CERT-SE therefore handles both the triage and coordination aspects. Incident resolution is left at the discretion of the involved constituents – however CERT-SE will offer support and advice on request.
5.3. Vulnerability Management
CERT-SE supports both mitigation of vulnerabilities and in critical cases patch management on a large scale. This includes:
- vulnerability report intake,
- vulnerability coordination, supporting reporters and vendors through the CVD process, and
- vulnerability response.
6. Incident reporting Forms
Clear text e-mail and telephone are considered safe for non-sensitive information. For sensitive information transmission, the use of PGP encryption is recommended. In cases where reporting is required by law, regulation, or other mandate, the reporting method specified by that mandate must be used.
Operators subject to the cyber security law (CSL) must report significant incidents to the NCSC, in accordance with MCFFS 2026:8, Regulations on Incident Reporting and the Duty to Provide Information for Essential and Important Operators.
The incident reporting tool is available on the cyber portal. Incident reports are submitted to the NCSC via CERT-SE, which is Sweden’s national CSIRT (Computer Security Incident Response Team). The incident reports are then forwarded to the relevant supervisory authorities. CERT-SE will never share information sent to us without permission from the sender, unless forced to do so by law or police matters.
7. Disclaimers
CERT-SE is not a law enforcement entity, thus any incident notification to CERT-SE does not replace the lawful communication of security incidents to a law enforcement authority whenever those security incidents are considered a crime that depends on the victim’s complaint for proper prosecution.
While every effort is made to ensure the accuracy of the information, notifications, and alerts provided, CERT-SE accepts no liability for any errors or omissions, nor for any consequences arising from the use of such information. Should you identify any inaccuracies in this document, please inform us via e-mail. We will address the issue as promptly as possible.