Regulatory scope assessment – which regulations apply to you?
We go through your organisation and document our assessment of which of the regulations in question are relevant to you, in what role and for which companies, products or parts of the organisation. You get a clear basis for management’s decisions and a prioritised plan for the next steps. Where the legal position is unclear, a legal interpretation is needed or the competent authority needs to take a position, the report says so explicitly.
Who it is for and when
The scope assessment suits you if you
- do not know for certain whether the Swedish Cybersecurity Act (2025:1506), DORA, the CRA or the AI Act applies to you;
- need to assess GDPR roles or questions about a data protection officer as part of a broader regulatory analysis;
- have received security requirements from customers and want to separate legal requirements from contractual ones;
- are part of a group where different companies may be affected in different ways;
- have several products, services or roles that make the scope hard to determine;
- have taken the regulations self-test and got one or more Unclear – needs looking into.
How it works
- Kick-off meeting. We go through:
- legal entities and group structure;
- size and ownership links;
- areas of activity;
- authorisations and registrations;
- customers and contractual requirements;
- products and digital services;
- supplier roles;
- how personal data is processed;
- how AI is used or developed.
- Documentation. Depending on the engagement, we may for example read:
- the annual report;
- the group and ownership structure;
- relevant authorisations and registrations;
- a list of products and services;
- major customer contracts and security schedules;
- a description of IT and cloud services;
- existing records, policies and governing documents.
- Assessment. We assess each regulation agreed against the actual circumstances and document:
- why it is assessed to apply or not;
- which role you likely have;
- which parts of the organisation are affected;
- which questions remain uncertain.
- Review. We go through the report with management or other relevant decision-makers and prioritise the next steps.
What you get
- a documented scope assessment per regulation analysed, with the reasons for our assessment;
- an assessment of your likely role, for example:
- controller, joint controller or processor;
- essential or important entity;
- financial entity or ICT third-party service provider;
- manufacturer, importer, distributor or other CRA role;
- provider or deployer under the AI Act;
- an assessment of which legal entities, products, services and parts of the organisation are affected;
- relevant dates, authorities and obligations that already apply;
- clearly identified borderline cases and questions that need legal confirmation or a position from an authority;
- a prioritised plan for the next steps;
- a review with management.
Scope and price
A defined engagement, normally a few days depending on complexity. We give a fixed price once the scope has been set and before work starts.
Our standard hourly rate is between SEK 800 and 1,600 excluding VAT, depending on the service, the scope and the consultant’s role and experience.
The engagement covers the regulations and areas of requirements stated in the proposal. The assessment is not a complete legal review of all legislation that may apply to the organisation.
Borderline cases
Some questions cannot be settled with certainty by a consultant’s assessment alone. They may require, for example:
- legal interpretation;
- analysis of unclear boundaries;
- sector-specific specialist expertise;
- a position from the competent authority.
In that case we describe the question, our preliminary assessment and what needs to be confirmed.
After the assessment
The scope assessment can be the first step before, for example:
- a gap analysis against ISO 27001, the Cybersecurity Act or DORA;
- a GDPR current state and gap analysis;
- CRA readiness;
- AI inventory and AI Act readiness;
- a supplier and third-party review.
That way, the next step builds on a documented scope instead of on assumptions.
Frequently asked questions
Isn’t the regulations self-test enough?
The self-test gives a first indication based on 20 questions. The scope assessment builds on actual information about your organisation, group structure, products, contracts, roles and authorisations. The result is a documented assessment that management can use in its decision and that shows how you reasoned. It is not a decision by an authority and does not replace legal advice where such advice is needed.
What does it cost?
We give a fixed price by scope before we start. Our standard hourly rate is between SEK 800 and 1,600 excluding VAT. Where an engagement lands depends on the service, the scope and the consultant’s role and experience.
Is it legal advice?
No. We make an operational and regulatory assessment based on the regulations, guidance from authorities and our experience of information security, IT, risk and compliance. When a question requires legal interpretation or a legal position, we say so and recommend legal advice or contact with the competent authority.
Does the assessment include all legislation that may apply to us?
No. The engagement is limited to the regulations and areas of requirements stated in the proposal. Other rules, authorisations, sector requirements and contractual requirements may also be relevant.
Do you want to know which of these regulations are relevant to you, and get a documented assessment of why? Contact us, and we will start with a short kick-off meeting.
Contact us