Service area

Gap analysis and implementation for NIS2, CRA, GDPR and ISO 27001

A documented baseline, gaps per requirement and an action plan management can decide on – and then help carrying it out. The work does not end with a report.

  • Swedish Cybersecurity Act
  • NIS2
  • CRA
  • DORA
  • GDPR
  • ISO 27001

Kristensson i Skåne AB is a smaller, independent consultancy that carries out gap analyses against the Swedish Cybersecurity Act and NIS2, the CRA, DORA, the GDPR and ISO 27001 – and then helps you implement the measures. You get a documented baseline, gaps per requirement, prioritised risks and an action plan management can decide on.

The most common mistake is that the analysis stops at analysis: the report is finished, the deficiencies are known, and then nothing happens. We stay on through governance, policies, controls, implementation and follow-up – as with the chemical company that went from gap analysis to a working management system. Read more about how we work.

We work from our office in Bjärred outside Lomma with organisations in Malmö, Lund, Helsingborg and the rest of Skåne. Advisory engagements in information security and regulation we take on across Sweden.

In brief

Who
Organisations affected by one or more regulations who need to know exactly where the gaps are – and want help closing them
What
Gap analysis against the Swedish Cybersecurity Act, NIS2, CRA, DORA, GDPR and ISO 27001, coordinated where requirements overlap, followed by implementation
How
Interviews and document review, gaps per requirement, risk-based prioritisation, action plan, then policies, controls and follow-up together with you
Geography
Skåne, Sweden, based in Bjärred outside Lomma. Engagements across Sweden.

Common situations

This is how it usually starts. If you recognise yourselves in one of them, we know roughly where to begin.

Offers in gap analysis and implementation

Six ways to start. Each offer can be bought on its own or combined into a coherent compliance programme.

Baseline

Gap analysis against ISO 27001, NIS2 or DORA

Where do you stand against the requirements today? A documented baseline, identified gaps and a prioritised action plan management can decide on.

You get: documented baseline, gaps per requirement, prioritised action plan and a review with management.

Scope: defined engagement, a few days to about a weekRead more →
Data protection

GDPR current-state and gap analysis

Where do you stand against the GDPR today? Records, legal basis, agreements, breach routines and data-subject rights, reviewed against the requirements.

You get: documented baseline, identified gaps and a prioritised plan.

Scope: defined engagement, about a weekRead more →
Products

CRA readiness for product companies

The Cyber Resilience Act for manufacturers, importers and distributors of products with digital elements: classification, secure development, vulnerability handling and reporting.

You get: product classification, gaps against the requirements and a plan up to the application dates.

Scope: defined engagement, a few weeksRead more →
Management system

ISO 27001 from gap analysis to certification

An information security management system that works in the business: risk work, policies, controls, internal audit and preparation for certification.

You get: an ISMS with policies, risk method, control structure and Statement of Applicability, ready for audit.

Scope: a project over several months, handed over to youRead more →
Ongoing

Senior GRC advisory

Once the gaps are closed the work has to hold. Ongoing support with governance, risk work, compliance and reporting to management.

You get: a named senior advisor, recurring reviews and work you can show at an audit.

Scope: ongoing, adapted to your needsRead more →
Leadership

Interim CISO

A senior security lead who runs and coordinates the work when you need continuity, with handover planned from day one.

You get: a named interim CISO with a deputy, management reporting and a documented handover.

Scope: part-time or full-time, for a defined periodRead more →

See all offers →

Regulations we analyse against

A closer look at each regulation: who is affected, what is required and how we help.

How we work with gap analysis and implementation, in detail

Six questions we get before almost every engagement, and the answers. Jump to a section in the menu, or read from the top. About 5 minutes of reading

Which regulations do you analyse against?

Six regulations account for almost every engagement: the Swedish Cybersecurity Act, which implements NIS2 in Sweden and has applied since 15 January 2026; the CRA for anyone manufacturing, importing or distributing products with digital elements; DORA for financial entities and their critical ICT providers; the GDPR for anyone processing personal data; and ISO 27001 for those who want a management system they can certify or show. We also analyse against the AI Act and against customer requirements in procurements and contracts.

In brief

  • The Swedish Cybersecurity Act and NIS2, CRA, DORA, GDPR and ISO 27001
  • AI Act and customer requirements when needed
  • The same method regardless of regulation: gaps per requirement, risk-based prioritisation

What is included in a gap analysis?

We go through the requirements one by one against your organisation: interviews with the people who own each area, review of policies, contracts and the technical environment, and spot checks that what the documents say is also what is done. The result is a documented baseline, a gap per requirement with an assessment of how serious it is, prioritised risks and an action plan with owners, order and estimated effort. The plan is written so that management can decide on it without first having to translate it. A gap analysis against one regulation usually takes a few days to about a week, depending on the size of the organisation.

In brief

  • Interviews, document review and spot checks
  • Documented baseline, gaps per requirement, prioritised risks
  • Action plan with owners, order and effort – written for decision

Can you do both the analysis and the implementation?

Yes, and that is usually where the value lies. After the analysis we help you write and anchor policies, introduce controls, set up risk work and incident management, train management and staff, and follow up that the measures take effect. If you want to go all the way to certification we do it as ISO 27001 from gap analysis to certification; if you want the support to continue once the gaps are closed we do it as senior GRC advisory. Where we have built parts of the management system ourselves, other consultants carry out the internal audit – an auditor may not review their own work.

In brief

  • Policies, controls, risk work, incident management, training, follow-up
  • All the way to certification, or ongoing GRC support
  • Independent internal audit of what we built ourselves

Can you coordinate NIS2, CRA, GDPR and ISO 27001 in the same analysis?

Yes. The requirements overlap to a large degree: risk analysis, policies, incident management, continuity, supplier governance and management accountability recur in all of them. We analyse the shared requirements once and add what is specific to each regulation – DORA’s testing programme, the CRA’s product documentation, the GDPR’s legal bases. The result is one action plan instead of four, and a management system where one document can answer several regulations at once. It is also how we avoid the organisation doing the same risk analysis three times with three different templates.

In brief

  • Shared requirements analysed once, specifics added
  • One action plan, one management system
  • No duplicated work between regulations

Who does the work?

Senior consultants holding certifications such as CISSP, ISO 27001 Lead Implementer and Lead Auditor, with backgrounds in both governance and technology. The person doing the analysis is also the one who can implement the measures – you do not have to explain your situation twice. If you need someone to lead the work over time, there is the interim CISO. Who we are and what each of us has done is on the page about our team.

In brief

  • Senior, certified consultants with governance and technical backgrounds
  • The same person analyses and implements
  • Interim CISO when the work needs a leader

Where do you work?

We work from our office in Bjärred outside Lomma with organisations in Malmö, Lund, Helsingborg and the rest of Skåne, on site when it helps – for workshops, management reviews and interviews. Advisory engagements in information security and regulation we take on across Sweden, mostly remotely with planned visits.

In brief

  • Based in Bjärred outside Lomma
  • On site in Malmö, Lund, Helsingborg and the rest of Skåne
  • Advisory across Sweden

Want to know where you stand against the Swedish Cybersecurity Act, CRA, DORA, GDPR or ISO 27001 – and get help reaching the finish line? Contact us, and we start with a gap analysis.

Frequently asked questions

What is the difference between a gap analysis and an audit?

A gap analysis compares your current state with the requirements to show what is missing and what should be done – it is forward-looking and produces an action plan. An audit assesses whether what you say you do is actually done and works, and produces an attestation or a non-conformity report. The gap analysis comes first; the audit comes once the work is in place.

How long does a gap analysis take?

Against one regulation usually a few days to about a week, depending on the size of the organisation and how much is already documented. A coordinated analysis against several regulations takes longer, but less than the sum of separate analyses, because the shared requirements are only reviewed once.

Do we need a gap analysis before we start implementing?

No, but it almost always pays off. Without a documented baseline it is hard to prioritise, and organisations tend to start with what is easiest rather than what matters most. If you already have a recent analysis from someone else, we build on it.

Can you coordinate NIS2, CRA, GDPR and ISO 27001?

Yes. The requirements overlap to a large degree – risk analysis, policies, incident management, continuity and supplier governance recur in all of them. We handle the shared requirements once and add what is specific to each regulation, so you get one action plan instead of four.

Do you only work with large organisations?

No. We work with companies and organisations of all sizes, from smaller businesses to municipalities and regulated entities. The approach is scaled to your size and maturity so the work stays proportionate.

Want to know where you stand against the requirements – and get help closing the gaps?

Contact us