RFC-2350

Established according to RFC-2350.

1. Document Information

1.1. Date of Last Update

This document was last updated 2026-09-15.

1.2. Distribution List for Notifications

None.

1.3. Locations where this Document May Be Found

The current version of this document can be found at: https://www.cert.se/om-cert-se/rfc-2350/

2. Contact Information

2.1. Name of the Team

CERT-SE

2.2. Address

CERT-SE
FRA
171 73 Solna
Sweden

2.3. Time Zone

CET/CEST,
Central European Time/Central European Summer Time,
UTC+0100/UTC+0200

2.4. Telephone Number

+46 10 382 80 00

2.5. Facsimile Number

None.

2.6. Other Telecommunication

None.

2.7. Electronic Mail Address

cert@cert.se

This address can be used to report all security incidents which relate to the CERT-SE constituency.

2.8. Public Keys and Encryption Information

PGP/GnuPG is supported for secure communication. The current CERT-SE team-key can be found at https://www.cert.se/cert_at_cert.se.asc. Please use this key when you want/need to encrypt messages that you send to CERT-SE. When responding, CERT-SE will sign messages using the same key.

2.9. Team Members

No information is provided in public.

2.10. Other Information

2.11. Points of Customer Contact

3. Charter

3.1. Mission Statement

The mission of CERT-SE is stated in Ordinance (2025:237) with Instructions for the FRA, the National Defense Radio Establishment. CERT-SE has been installed to reduce the potential for, and impact of, cyber attacks targeting Sweden and the Swedish society. In brief, the Ordinance states that CERT-SE shall:

  1. respond promptly when IT incidents occur by spreading information, and where needed work with the coordination of measures, and partake in work to remedy or mitigate the incident’s consequences,
  2. report back to relevant actors in connection with an IT incident being reported,
  3. cooperate with authorities that have specific tasks in the field of information security, and
  4. act as Sweden’s point of contact for equivalent services in other countries, and develop cooperation and information exchanges with them.

3.2. Constituency

CERT-SE is the National CERT of Sweden, and the constituency consists of the Swedish society, including but not limited to governmental authorities, regional authorities, municipalities, enterprises and companies. In addition, CERT-SE is the governmental CERT of Sweden and have additional responsibilities within the governmental body.

3.3. Sponsorship and/or Affiliation

CERT-SE is part of FRA, the National Defense Radio Establishment, which is a Swedish governmental agency. CERT-SE is fully financed by FRA.

3.4. Authority

CERT-SE has the authority to issue recommendations regarding vulnerabilities and mitigation of incidents and/or incident handling. Such recommendations can include for example blocking addresses or networks. The authority is limited to non binding recommendations and CERT-SE does not have the authority to issue legally binding regulations, conduct supervision or enforce measures.

4. Policies

4.1. Types of Incidents and Level of Support

All incidents are considered normal priority. CERT-SE itself is the authority that can set and reset the emergency label. An incident can be reported to CERT-SE as emergency, but it is up to CERT-SE to decide whether or not to uphold that status.

4.2. Co-operation, Interaction and Disclosure of Information

CERT-SE is deeply engaged in national, European and international cooperation groups, and supports voluntary cooperation between CSIRT:s at all levels. For that matter, CERT-SE ensures a global presence and networking with its partners through active participation in working groups, international meetings and conferences.

All incoming information related to incidents is handled confidentially by CERT-SE, regardless of its priority. Information that is evidently sensitive in nature is only communicated and stored in a secure environment, using encryption if necessary. When reporting an incident of sensitive nature, please state so explicitly, e.g. by using the label SENSITIVE in the subject field of e-mail and using encryption if possible.

CERT-SE supports the Traffic Light Protocol (TLP) model of information sharing, see https://www.first.org/tlp. Information that comes in with the tags TLP:CLEAR, TLP:GREEN, TLP:AMBER, TLP:AMBER+STRICT or TLP:RED will be handled appropriately.

CERT-SE will use the information you provide to help solve security incidents. This means that by default the information will be distributed further to the appropriate parties, but only on a need-to-know basis, according to present information classification or TLP marking, and in an anonymized fashion unless otherwise agreed upon.

If you object to this default behavior of CERT-SE, please make explicit what CERT-SE can do with the information you provide. CERT-SE will adhere to your policy, but will also point out to you if that means that CERT-SE cannot act on the information provided.

As of October 1, 2022, on behalf of the government, FRA forwards the notifications and completed forms that are reported to FRA (regulation (2022:524), law (2018:1174) and regulation (2018:1175), and which contain descriptions of incidents that can be assumed to have their basis in a criminal act, to the Police Authority.

4.3. Communication and Authentication

See 2.8 Public Keys and Encryption Information. Usage of PGP/GnuPG or other pre-approved cryptographic means in all cases where sensitive information is involved is highly recommended.

5. Services

5.1. Proactive Activities

CERT-SE proactively advises their constituency in regard to recent vulnerabilities and on matters of computer and network security, including but not limited to:

CERT-SE is not responsible for implementation, which is always left at the discretion of the constituents.

5.2. Incident Response (Triage, Coordination and Resolution)

CERT-SE is responsible for the coordination of security incidents somehow involving their constituency, as defined in 3.2. Constituency. CERT-SE therefore handles both the triage and coordination aspects. Incident resolution is left at the discretion of the involved constituents – however CERT-SE will offer support and advice on request.

5.3. Vulnerability Management

CERT-SE supports both mitigation of vulnerabilities and in critical cases patch management on a large scale. This includes:

6. Incident reporting Forms

Clear text e-mail and telephone are considered safe for non-sensitive information. For sensitive information transmission, the use of PGP encryption is recommended. In cases where reporting is required by law, regulation, or other mandate, the reporting method specified by that mandate must be used.

Operators subject to the cyber security law (CSL) must report significant incidents to the NCSC, in accordance with MCFFS 2026:8, Regulations on Incident Reporting and the Duty to Provide Information for Essential and Important Operators.

The incident reporting tool is available on the cyber portal. Incident reports are submitted to the NCSC via CERT-SE, which is Sweden’s national CSIRT (Computer Security Incident Response Team). The incident reports are then forwarded to the relevant supervisory authorities. CERT-SE will never share information sent to us without permission from the sender, unless forced to do so by law or police matters.

7. Disclaimers

CERT-SE is not a law enforcement entity, thus any incident notification to CERT-SE does not replace the lawful communication of security incidents to a law enforcement authority whenever those security incidents are considered a crime that depends on the victim’s complaint for proper prosecution.

While every effort is made to ensure the accuracy of the information, notifications, and alerts provided, CERT-SE accepts no liability for any errors or omissions, nor for any consequences arising from the use of such information. Should you identify any inaccuracies in this document, please inform us via e-mail. We will address the issue as promptly as possible.