Service area

Regulatory requirements and compliance

Knowing which regulations apply to you, where you stand against them, and being able to show it – to management, to customers and to the supervisory authority. From scoping and gap analysis to implementation, ongoing compliance and audit readiness.

  • Swedish Cybersecurity Act
  • NIS2
  • CRA
  • DORA
  • GDPR
  • ISO 27001

Compliance is not a project but a state that has to hold over time. We help organisations achieve and maintain compliance with the Swedish Cybersecurity Act and NIS2, the CRA, DORA, the GDPR and ISO 27001 – coordinated where the requirements overlap, so that one document, one risk analysis and one incident routine can answer several regulations at once.

The work starts by establishing which requirements actually apply to you and a gap analysis that shows where you stand. But that is only the beginning. Then come governance and policies, implementation in the business, ongoing follow-up as regulations and the organisation change, and readiness to show all of it when an auditor, a customer or a supervisory authority asks. For the chemical company that is how it began: a gap analysis against NIS2 and ISO 27001 that gave management a prioritised action plan to work from, with our support step by step. Read more about how we work.

We work from our office in Bjärred outside Lomma with organisations in Malmö, Lund, Helsingborg and the rest of Skåne. Advisory engagements in regulation and information security we take on across Sweden.

In brief

Who
Organisations affected by one or more regulations who need compliance work that holds, not just a report
What
Scoping, baseline and gap analysis, a compliance programme with policies and controls, implementation, ongoing follow-up, audit and supervisory readiness
How
Coordinated across regulations, prioritised by risk, with management deciding and the business owning the measures – and independent review of what we built ourselves
Geography
Skåne, Sweden, based in Bjärred outside Malmö/Lund. Engagements across Sweden.

Common situations

This is how it usually starts. If you recognise yourselves in one of them, we know roughly where to begin.

Offers in compliance

Six ways to start. Each offer can be bought on its own or combined into a coherent compliance programme.

Baseline

Gap analysis against ISO 27001, NIS2 or DORA

Where do you stand against the requirements today? A documented baseline, identified gaps and a prioritised action plan management can decide on.

You get: documented baseline, gaps per requirement, prioritised action plan and a review with management.

Scope: defined engagement, a few days to about a weekRead more →
Data protection

GDPR current-state and gap analysis

Where do you stand against the GDPR today? Records, legal basis, agreements, breach routines and data-subject rights, reviewed against the requirements.

You get: documented baseline, identified gaps and a prioritised plan.

Scope: defined engagement, about a weekRead more →
Products

CRA readiness for product companies

The Cyber Resilience Act for manufacturers, importers and distributors of products with digital elements: classification, secure development, vulnerability handling and reporting.

You get: product classification, gaps against the requirements and a plan up to the application dates.

Scope: defined engagement, a few weeksRead more →
Management system

ISO 27001 from gap analysis to certification

An information security management system that works in the business: risk work, policies, controls, internal audit and preparation for certification.

You get: an ISMS with policies, risk method, control structure and Statement of Applicability, ready for audit.

Scope: a project over several months, handed over to youRead more →
Ongoing

Annual DORA review and maintenance

Compliance has to hold year after year. A recurring review of the ICT risk framework, information registers, testing programme and reporting, updated when the requirements or the business change.

You get: an annual review report, updated policies and registers, and a basis for management.

Scope: recurring, once a year or on changeRead more →
Ongoing

Senior GRC advisory

Once the gaps are closed the work has to hold. Ongoing support with governance, risk work, compliance and reporting to management.

You get: a named senior advisor, recurring reviews and work you can show at an audit.

Scope: ongoing, adapted to your needsRead more →

See all offers →

Regulations we work with

A closer look at each regulation: who is affected, what is required and how we help.

How we work with compliance, in detail

Six steps that together are the compliance work. Jump to a section in the menu, or read from the top. About 6 minutes of reading

Scoping: which regulations apply to you?

Before anything can be measured it has to be delimited. We go through your organisation, your services and products, your customers and your role in the supply chain, and answer the question that is often the hardest: are you affected, by what, and in which role? The Swedish Cybersecurity Act distinguishes essential from important entities. The CRA distinguishes manufacturers, importers and distributors. DORA reaches both financial entities and their critical ICT providers. The GDPR applies to everyone processing personal data, but the requirements differ for controllers and processors. The result is a documented scoping decision management can stand behind – and the first thing a supervisory authority asks for.

In brief

  • Which regulations apply to you, in which role and for which parts of the business
  • A documented scoping decision management can stand behind
  • The foundation for everything that follows – and the first thing supervision asks for

Baseline and gap analysis

With the scope settled we go through the requirements one by one against reality: interviews with the people who own each area, review of policies, contracts and the technical environment, and spot checks that what the documents say is also what is done. The result is a documented baseline, a gap per requirement with an assessment of severity, prioritised risks and an action plan with owners, order and estimated effort, written so that management can decide on it. If several regulations apply, we analyse the shared requirements once – risk analysis, policies, incident management, continuity, supplier governance – and add the specifics. The gap analysis is a step, not the goal. Read more in the offer and in our insight on how a gap analysis becomes usable.

In brief

  • Interviews, document review and spot checks against every requirement
  • Documented baseline, gaps per requirement, prioritised risks, action plan for decision
  • Shared requirements analysed once when several regulations apply

Governance, policies and controls

Compliance that holds needs a structure to live in. We help you establish a compliance programme: clear accountability in management and the business, policies that say what applies and who does what, and controls that show it is followed. Where you already have an ISO 27001 management system we build the regulations’ requirements into it rather than creating parallel tracks, so that one policy can answer both the Cybersecurity Act and DORA. Management’s role is not to write the documents but to decide on risk appetite, approve the measures and follow them up – something the Cybersecurity Act now requires explicitly.

In brief

  • A compliance programme with accountability, policies and controls
  • Regulatory requirements built into the existing management system, not parallel tracks
  • Management decides and follows up

Implementation in the business

This is where most compliance initiatives stall. We stay on. The measures in the plan are carried out together with the people who own them: an incident process with roles and reporting lines, continuity plans that are tested, supplier requirements written into contracts, a risk register that is filled in and used, training for management and staff. If you want to go all the way to certification we do it as ISO 27001 from gap analysis to certification. If the work needs a leader over time, there is the interim CISO. The person who did the analysis is also the one who can implement – you do not have to explain your situation twice.

In brief

  • Measures carried out with the people who own them, not beside them
  • Incident process, continuity, supplier requirements, risk register, training
  • All the way to certification when that is the goal

Ongoing compliance and regulatory monitoring

Regulations change – the Cybersecurity Act’s regulations, the CRA’s application dates, the supervisory authority’s guidance – and the business changes more often. Ongoing compliance means someone monitors the changes, assesses what they mean for you, updates policies and controls, and reports to management so that decisions are taken in time. We do it as senior GRC advisory, or as an annual DORA review for financial entities, where registers, testing programme and reporting are reviewed ahead of each new year. The goal is that compliance is a state you are in, not a one-off effort you made.

In brief

  • Regulatory monitoring and impact assessment of changes
  • Updated policies, controls and registers
  • Recurring reporting to management

Audit and supervisory readiness

Sooner or later someone asks: a certification auditor, a customer in a procurement, a supervisory authority after an incident. Readiness means the answer exists before the question arrives: collected evidence that the controls work, a pre-audit that finds the non-conformities in advance, and routines for how you respond to security questionnaires and authority requests. Where we have built parts of the management system ourselves, other consultants carry out the internal audit – an auditor may not review their own work, and we say so in every engagement.

In brief

  • Evidence that the controls work, collected before the question arrives
  • Pre-audit and support during external audit, customer review and supervision
  • Independent review of what we built ourselves

Want to know which regulations apply to you, where you stand against them – and have compliance work that holds when someone asks? Contact us, and we start with the scope.

Frequently asked questions

What is the difference between a gap analysis and an audit?

A gap analysis compares your current state with the requirements to show what is missing and what should be done – it is forward-looking and produces an action plan. An audit assesses whether what you say you do is actually done and works, and produces an attestation or a non-conformity report. The gap analysis is one step in the compliance work; the audit comes once the work is in place.

How often does compliance need to be reviewed?

At least once a year, and always when something material changes: new regulations, new operations, new systems or suppliers, an incident. DORA explicitly requires an annual review of the ICT risk framework; the Cybersecurity Act requires management to follow up the work. Ongoing monitoring turns the review into an update rather than a new gap analysis.

Can you coordinate NIS2, CRA, GDPR and ISO 27001?

Yes. The requirements overlap to a large degree – risk analysis, policies, incident management, continuity and supplier governance recur in all of them. We handle the shared requirements once and add what is specific to each regulation, so you get one compliance programme instead of four.

We are a smaller organisation. Do we really need a compliance programme?

Yes, but a proportionate one. The requirements scale with your size and risk, and a compliance programme for a smaller organisation can be a few pages of policy, a risk register that is used and an annual review with management. What does not scale is lacking documented accountability the day someone asks.

What happens when a regulation changes after we are done?

That is what the ongoing work is for. We monitor changes in the regulations that apply to you, assess what they mean for your specific organisation, update policies and controls and report to management. The regulations under the Swedish Cybersecurity Act that apply from 1 October 2026 are a current example.

Want compliance work that holds – not just a report?

Contact us