Gap analysis and implementation for NIS2, CRA, GDPR and ISO 27001
A documented baseline, gaps per requirement and an action plan management can decide on – and then help carrying it out. The work does not end with a report.
Kristensson i Skåne AB is a smaller, independent consultancy that carries out gap analyses against the Swedish Cybersecurity Act and NIS2, the CRA, DORA, the GDPR and ISO 27001 – and then helps you implement the measures. You get a documented baseline, gaps per requirement, prioritised risks and an action plan management can decide on.
The most common mistake is that the analysis stops at analysis: the report is finished, the deficiencies are known, and then nothing happens. We stay on through governance, policies, controls, implementation and follow-up – as with the chemical company that went from gap analysis to a working management system. Read more about how we work.
We work from our office in Bjärred outside Lomma with organisations in Malmö, Lund, Helsingborg and the rest of Skåne. Advisory engagements in information security and regulation we take on across Sweden.
In brief
- Who
- Organisations affected by one or more regulations who need to know exactly where the gaps are – and want help closing them
- What
- Gap analysis against the Swedish Cybersecurity Act, NIS2, CRA, DORA, GDPR and ISO 27001, coordinated where requirements overlap, followed by implementation
- How
- Interviews and document review, gaps per requirement, risk-based prioritisation, action plan, then policies, controls and follow-up together with you
- Geography
- Skåne, Sweden, based in Bjärred outside Lomma. Engagements across Sweden.
Common situations
This is how it usually starts. If you recognise yourselves in one of them, we know roughly where to begin.
You are affected by the Cybersecurity Act, DORA or the CRA and do not know where the gaps are
A gap analysis against the regulation that applies to you, with gaps per requirement and a prioritised plan.
Read about the regulations →You are affected by several regulations and treat each requirement as its own project today
One coordinated analysis where shared requirements are handled once and the specifics are added.
Read about coordination →You have a gap report from last year, but little has happened since
We pick up where the report ended: policies, controls, implementation and follow-up.
Read about implementation →A customer, auditor or procurement asks how you stand against ISO 27001 or the GDPR
A documented baseline you can show, and a plan for what is missing.
Read about what is included →Offers in gap analysis and implementation
Six ways to start. Each offer can be bought on its own or combined into a coherent compliance programme.
Gap analysis against ISO 27001, NIS2 or DORA
Where do you stand against the requirements today? A documented baseline, identified gaps and a prioritised action plan management can decide on.
You get: documented baseline, gaps per requirement, prioritised action plan and a review with management.
Scope: defined engagement, a few days to about a weekRead more → Data protectionGDPR current-state and gap analysis
Where do you stand against the GDPR today? Records, legal basis, agreements, breach routines and data-subject rights, reviewed against the requirements.
You get: documented baseline, identified gaps and a prioritised plan.
Scope: defined engagement, about a weekRead more → ProductsCRA readiness for product companies
The Cyber Resilience Act for manufacturers, importers and distributors of products with digital elements: classification, secure development, vulnerability handling and reporting.
You get: product classification, gaps against the requirements and a plan up to the application dates.
Scope: defined engagement, a few weeksRead more → Management systemISO 27001 from gap analysis to certification
An information security management system that works in the business: risk work, policies, controls, internal audit and preparation for certification.
You get: an ISMS with policies, risk method, control structure and Statement of Applicability, ready for audit.
Scope: a project over several months, handed over to youRead more → OngoingSenior GRC advisory
Once the gaps are closed the work has to hold. Ongoing support with governance, risk work, compliance and reporting to management.
You get: a named senior advisor, recurring reviews and work you can show at an audit.
Scope: ongoing, adapted to your needsRead more → LeadershipInterim CISO
A senior security lead who runs and coordinates the work when you need continuity, with handover planned from day one.
You get: a named interim CISO with a deputy, management reporting and a documented handover.
Scope: part-time or full-time, for a defined periodRead more →Regulations we analyse against
A closer look at each regulation: who is affected, what is required and how we help.
Swedish Cybersecurity Act and NIS2
The Swedish act implementing NIS2: which organisations are affected, which security measures are required and how to get started.
Read more →Cyber Resilience Act (CRA)
Cybersecurity requirements for products with digital elements: secure development, vulnerability handling and documentation.
Read more →DORA
Digital operational resilience for financial entities and their critical ICT providers: ICT risk, incidents, testing and third-party risk.
Read more →GDPR
The General Data Protection Regulation: records, legal basis, impact assessments, breaches and data-subject rights.
Read more →ISO 27001
The standard for information security management systems: risk work, policies, controls and certification.
Read more →AI Act
The EU regulation on artificial intelligence: risk classification, requirements per role and timeline – often the next gap analysis after these.
Read more →How we work with gap analysis and implementation, in detail
Six questions we get before almost every engagement, and the answers. Jump to a section in the menu, or read from the top. About 5 minutes of reading
Which regulations do you analyse against?
Six regulations account for almost every engagement: the Swedish Cybersecurity Act, which implements NIS2 in Sweden and has applied since 15 January 2026; the CRA for anyone manufacturing, importing or distributing products with digital elements; DORA for financial entities and their critical ICT providers; the GDPR for anyone processing personal data; and ISO 27001 for those who want a management system they can certify or show. We also analyse against the AI Act and against customer requirements in procurements and contracts.
In brief
- The Swedish Cybersecurity Act and NIS2, CRA, DORA, GDPR and ISO 27001
- AI Act and customer requirements when needed
- The same method regardless of regulation: gaps per requirement, risk-based prioritisation
What is included in a gap analysis?
We go through the requirements one by one against your organisation: interviews with the people who own each area, review of policies, contracts and the technical environment, and spot checks that what the documents say is also what is done. The result is a documented baseline, a gap per requirement with an assessment of how serious it is, prioritised risks and an action plan with owners, order and estimated effort. The plan is written so that management can decide on it without first having to translate it. A gap analysis against one regulation usually takes a few days to about a week, depending on the size of the organisation.
In brief
- Interviews, document review and spot checks
- Documented baseline, gaps per requirement, prioritised risks
- Action plan with owners, order and effort – written for decision
Can you do both the analysis and the implementation?
Yes, and that is usually where the value lies. After the analysis we help you write and anchor policies, introduce controls, set up risk work and incident management, train management and staff, and follow up that the measures take effect. If you want to go all the way to certification we do it as ISO 27001 from gap analysis to certification; if you want the support to continue once the gaps are closed we do it as senior GRC advisory. Where we have built parts of the management system ourselves, other consultants carry out the internal audit – an auditor may not review their own work.
In brief
- Policies, controls, risk work, incident management, training, follow-up
- All the way to certification, or ongoing GRC support
- Independent internal audit of what we built ourselves
Can you coordinate NIS2, CRA, GDPR and ISO 27001 in the same analysis?
Yes. The requirements overlap to a large degree: risk analysis, policies, incident management, continuity, supplier governance and management accountability recur in all of them. We analyse the shared requirements once and add what is specific to each regulation – DORA’s testing programme, the CRA’s product documentation, the GDPR’s legal bases. The result is one action plan instead of four, and a management system where one document can answer several regulations at once. It is also how we avoid the organisation doing the same risk analysis three times with three different templates.
In brief
- Shared requirements analysed once, specifics added
- One action plan, one management system
- No duplicated work between regulations
Who does the work?
Senior consultants holding certifications such as CISSP, ISO 27001 Lead Implementer and Lead Auditor, with backgrounds in both governance and technology. The person doing the analysis is also the one who can implement the measures – you do not have to explain your situation twice. If you need someone to lead the work over time, there is the interim CISO. Who we are and what each of us has done is on the page about our team.
In brief
- Senior, certified consultants with governance and technical backgrounds
- The same person analyses and implements
- Interim CISO when the work needs a leader
Where do you work?
We work from our office in Bjärred outside Lomma with organisations in Malmö, Lund, Helsingborg and the rest of Skåne, on site when it helps – for workshops, management reviews and interviews. Advisory engagements in information security and regulation we take on across Sweden, mostly remotely with planned visits.
In brief
- Based in Bjärred outside Lomma
- On site in Malmö, Lund, Helsingborg and the rest of Skåne
- Advisory across Sweden
Want to know where you stand against the Swedish Cybersecurity Act, CRA, DORA, GDPR or ISO 27001 – and get help reaching the finish line? Contact us, and we start with a gap analysis.
Frequently asked questions
What is the difference between a gap analysis and an audit?
A gap analysis compares your current state with the requirements to show what is missing and what should be done – it is forward-looking and produces an action plan. An audit assesses whether what you say you do is actually done and works, and produces an attestation or a non-conformity report. The gap analysis comes first; the audit comes once the work is in place.
How long does a gap analysis take?
Against one regulation usually a few days to about a week, depending on the size of the organisation and how much is already documented. A coordinated analysis against several regulations takes longer, but less than the sum of separate analyses, because the shared requirements are only reviewed once.
Do we need a gap analysis before we start implementing?
No, but it almost always pays off. Without a documented baseline it is hard to prioritise, and organisations tend to start with what is easiest rather than what matters most. If you already have a recent analysis from someone else, we build on it.
Can you coordinate NIS2, CRA, GDPR and ISO 27001?
Yes. The requirements overlap to a large degree – risk analysis, policies, incident management, continuity and supplier governance recur in all of them. We handle the shared requirements once and add what is specific to each regulation, so you get one action plan instead of four.
Do you only work with large organisations?
No. We work with companies and organisations of all sizes, from smaller businesses to municipalities and regulated entities. The approach is scaled to your size and maturity so the work stays proportionate.
Want to know where you stand against the requirements – and get help closing the gaps?
Contact us