This report is a qualitative case study that investigates the compliance of NIS2 Article 21(2)(a) within a large Swedish municipality outside the three major metropolitan regions. NIS2 represents a major shift in the Swedish legal landscape regarding cybersecurity since it has increased the number of sectors that are covered by mandated actions. Since NIS2 has recently been implemented in Sweden there are few other studies regarding its implementation. This study aims to investigate its implementation and analyze potential gaps by using a qualitative methodology based on the municipality’s policies and as well as a survey that was used to confirm and close identified gaps. The empirical findings are mapped within an analytical framework created during this study that encompasses three levels spanning through the governance layer, the process layer, and the technical layer. This analytical framework was developed by considering relevant standardization frameworks, such as ISO/IEC 27000 series and CIS Controls. Gaps were identified in all layers while the technical layer contained the most identified gaps. Recommendations for closing the gaps are given based on our analysis. This study enhances the available knowledge of NIS2 implementation in Sweden and gives insight into how NIS2(2)(a) can be implemented into an organization, as well as how potential gaps in the implementation can be identified and corrected.