Published
Summary: 20 short questions give a first indication of which of the following regulations and areas of requirements may affect you, and in what role: the GDPR, the Swedish Cybersecurity Act (2025:1506, NIS2), DORA, the Cyber Resilience Act (CRA), the AI Act and security requirements that come through customers and contracts. The test takes about five minutes. The result is shown directly on the page, with one outcome per area, the reasons behind the outcome and what you can do next. The test is a simplified self-assessment. It is not a legal ruling and not a complete inventory of all legislation that may apply to you.
Answer for the legal entity you want to assess, as it is today.
For the size questions in the Cybersecurity Act, it is not always enough to look only at the individual company’s figures. Partner and linked enterprises may have to be counted under the EU rules on enterprise size. Answer Don’t know if you are unsure about the group or ownership structure.
A Don’t know that affects the outcome is shown as Unclear – needs looking into, never as not affected. Some questions are only shown when they are relevant to earlier answers.
Your answers stay in your browser and are not stored. We only count that a test was completed. If you would like to be contacted, you send the result yourselves with the form below the result.
About you
- Does the legal entity you are assessing, after partner and linked enterprises have been counted under the EU rules on enterprise size, have at least 50 annual work units, or an annual turnover and an annual balance sheet total that both exceed EUR 10 million?
Annual work units correspond in principle to full-time work for one year. If you are part of a group or have significant ownership links to other enterprises, more enterprises may have to be counted.
- After the same count, do you have at least 250 annual work units, or an annual turnover above EUR 50 million and an annual balance sheet total above EUR 43 million?
- Are you a municipality, region or municipal federation? Municipal companies answer No here and answer the sector questions instead.
- Are you a government agency?
Sector
- Do you operate in any of the following areas?
- energy
- transport
- banking
- financial market infrastructure
- health care
- drinking water
- waste water
- digital infrastructure, for example internet exchange points, cloud computing services, data centre services or content delivery networks
- management of ICT services for other businesses, for example outsourced operations or security services
- space
Also answer Yes if you are a private education provider authorised to award degrees.
- Do you operate in any of the following areas?
- postal and courier services
- waste management
- manufacture, production or distribution of chemicals
- wholesale distribution, industrial production or processing of food
- manufacture of certain medical devices, computers and electronics, electrical equipment, machinery, motor vehicles or other transport equipment
- online marketplaces, search engines or social networking platforms
- research
- Do you provide any of the following services?
- DNS services
- top-level domain name registry
- domain name registration services
- trust services under eIDAS, for example services for electronic signatures or seals, electronic time stamps, electronic registered delivery or website authentication certificates
- public electronic communications networks
- publicly available electronic communications services
Finance
- Are you a financial entity, for example a credit institution, payment institution, electronic money institution, investment firm, fund or management company, insurance or reinsurance undertaking, institution for occupational retirement provision or crypto-asset service provider?
DORA contains exemptions and special rules, and being supervised by Finansinspektionen (FI) does not automatically mean that DORA applies. If you are unsure whether your type or size of entity is in scope, answer Don’t know.
- Do you supply ICT, operations, security, system or cloud services to banks, insurance companies or other financial entities?
Products
- Do you make available, import or distribute products with digital elements on the EU market, for example connected hardware, equipment with embedded software or software supplied as a product?
Standalone cloud and SaaS services are normally not in scope merely because they are digital services. The CRA may, however, apply to a remote data processing solution that belongs to a product and that the product depends on to work.
- Do you develop or manufacture the product yourselves, do you have someone else develop or manufacture it and sell it under your own name or trademark, or have you made a substantial modification to a product and make it available on the market?
If you look after free and open-source software in the role of open-source software steward, specific CRA rules apply that the test does not fully classify. Answer Don’t know if that is your main role.
AI
- Do you use AI systems or AI features in your organisation, for example Copilot, ChatGPT or AI features built into your business systems?
- Do you use any of the following?
- AI systems intended to interact directly with customers, citizens or the public, for example chatbots
- AI to generate or manipulate image, audio or video content that may constitute a deepfake
- AI-generated or AI-manipulated text published to inform the public on matters of public interest
- Do you use AI in any of the following types of use case?
- recruitment, selection of candidates or decisions affecting employees’ terms of work, promotion, termination, task allocation or performance evaluation
- creditworthiness assessment or credit scoring of natural persons
- risk assessment or pricing in life or health insurance
- admission, placement or assessment in education
- as a safety component in the management or operation of critical digital infrastructure, road traffic or the supply of water, gas, heating or electricity
- Do you develop AI systems yourselves, or have AI systems developed and place them on the market or put them into service under your own name or trademark?
For high-risk AI systems you may in some cases also take on provider responsibility if you put your own name or trademark on an existing system, make a substantial modification or change the system’s intended purpose (Article 25).
Personal data
- Do you process personal data about employees, customers or other people? Almost every organisation does, for example through payroll, customer records, contact details or email.
- Do you process personal data on behalf of other organisations, for example as an IT, payroll, cloud or system provider?
- Does your core activity consist of any of the following?
- large-scale processing of sensitive personal data, for example health data
- large-scale processing of data relating to criminal convictions or offences
- regular and systematic monitoring of individuals on a large scale
Customers and contracts
- Do your customers set information security requirements in contracts, procurements or security questionnaires, for example ISO 27001 or requirements that refer to NIS2, the Cybersecurity Act or DORA?
- Do you carry out security-sensitive activities, or do you have a protective security agreement?
Would you like to go through the result with us?
Fill in your details and we will be in touch. The result in the box below is sent with the form, exactly as it reads there. We use the details only to contact you about the result and keep them for one year. Read more in our privacy notice.
Reading your answers
If you are reading without the buttons, you can go through your answers like this. A Don’t know that decides the outcome always means Unclear – needs looking into.
- GDPR: likely affected if you answered Yes to question 16. Yes to question 17 means you may also be a processor. Yes to question 3, 4 or 18 means a data protection officer is likely needed.
- The Cybersecurity Act: likely affected with Yes to question 7, Yes to question 3, or Yes to question 5 or 6 together with Yes to question 1. Unclear with Yes to question 4, with Yes to question 5 or 6 but No or Don’t know to question 1, and with Don’t know to questions 3–7. Otherwise you are likely affected indirectly if you answered Yes to question 19. Yes or Don’t know to question 20 adds a reservation on protective security, since the Act has exemptions for security-sensitive activities.
- DORA: likely affected with Yes to question 8. Likely affected indirectly with Yes to question 9.
- CRA: likely affected as a manufacturer with Yes to questions 10 and 11, and as an importer or distributor with Yes to question 10 and No to question 11.
- AI Act: likely affected with Yes to question 12 or 15. Yes to question 13 points to transparency requirements, Yes to question 14 to a possible high-risk area.
- Customer requirements and supply chain: likely affected indirectly with Yes to question 19.
- Notes: with Yes to question 3, 4 or 5 a note is shown on the proposed Swedish act on the resilience of critical entities (CER), and with Yes to question 6 a note that CER may be relevant if the answer refers to food. With Yes or Don’t know to question 20 a note on the Protective Security Act is shown.
Next steps
Several regulations, or answers that need looking into? In a regulatory scope assessment we go through your organisation and document which rules are likely to apply, in what role and what should be done first.
Sources: the Swedish Cybersecurity Act (2025:1506) and Cybersecurity Ordinance (2025:1507); the regulations MCFFS 2026:1, 2026:8, 2026:11 and 2026:12; Commission Implementing Regulation (EU) 2024/2690; Directive (EU) 2022/2555 (NIS2); Regulation (EU) No 910/2014 (eIDAS); Commission Recommendation 2003/361/EC; Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2024/2847 (CRA); Regulation (EU) 2024/1689 (the AI Act) as amended by Regulation (EU) 2026/1744; Regulation (EU) 2016/679 (GDPR); Government Bill 2025/26:303; the Protective Security Act (2018:585). Fact-checked on 10 October 2026.
This text is general information and does not constitute legal advice in an individual case.

