Regulatory requirements and compliance
Knowing which regulations apply to you, where you stand against them, and being able to show it – to management, to customers and to the supervisory authority. From scoping and gap analysis to implementation, ongoing compliance and audit readiness.
Compliance is not a project but a state that has to hold over time. We help organisations achieve and maintain compliance with the Swedish Cybersecurity Act and NIS2, the CRA, DORA, the GDPR and ISO 27001 – coordinated where the requirements overlap, so that one document, one risk analysis and one incident routine can answer several regulations at once.
The work starts by establishing which requirements actually apply to you and a gap analysis that shows where you stand. But that is only the beginning. Then come governance and policies, implementation in the business, ongoing follow-up as regulations and the organisation change, and readiness to show all of it when an auditor, a customer or a supervisory authority asks. For the chemical company that is how it began: a gap analysis against NIS2 and ISO 27001 that gave management a prioritised action plan to work from, with our support step by step. Read more about how we work.
We work from our office in Bjärred outside Lomma with organisations in Malmö, Lund, Helsingborg and the rest of Skåne. Advisory engagements in regulation and information security we take on across Sweden.
In brief
- Who
- Organisations affected by one or more regulations who need compliance work that holds, not just a report
- What
- Scoping, baseline and gap analysis, a compliance programme with policies and controls, implementation, ongoing follow-up, audit and supervisory readiness
- How
- Coordinated across regulations, prioritised by risk, with management deciding and the business owning the measures – and independent review of what we built ourselves
- Geography
- Skåne, Sweden, based in Bjärred outside Malmö/Lund. Engagements across Sweden.
Common situations
This is how it usually starts. If you recognise yourselves in one of them, we know roughly where to begin.
You are not sure which regulations apply to you, or in which role
A scoping assessment that answers whether you are affected, by what, and what it means.
Read about scoping →A customer, auditor or supervisory authority asks how you stand against the requirements
A documented baseline, gaps per requirement and a plan you can show.
Read about baseline and gap analysis →You have a gap report, but little has happened since
We pick up where the report ended: policies, controls, implementation and follow-up in the business.
Read about implementation →You finished last year, but the regulations and the business have changed
Ongoing compliance: regulatory monitoring, control follow-up and reporting to management.
Read about ongoing compliance →Offers in compliance
Six ways to start. Each offer can be bought on its own or combined into a coherent compliance programme.
Gap analysis against ISO 27001, NIS2 or DORA
Where do you stand against the requirements today? A documented baseline, identified gaps and a prioritised action plan management can decide on.
You get: documented baseline, gaps per requirement, prioritised action plan and a review with management.
Scope: defined engagement, a few days to about a weekRead more → Data protectionGDPR current-state and gap analysis
Where do you stand against the GDPR today? Records, legal basis, agreements, breach routines and data-subject rights, reviewed against the requirements.
You get: documented baseline, identified gaps and a prioritised plan.
Scope: defined engagement, about a weekRead more → ProductsCRA readiness for product companies
The Cyber Resilience Act for manufacturers, importers and distributors of products with digital elements: classification, secure development, vulnerability handling and reporting.
You get: product classification, gaps against the requirements and a plan up to the application dates.
Scope: defined engagement, a few weeksRead more → Management systemISO 27001 from gap analysis to certification
An information security management system that works in the business: risk work, policies, controls, internal audit and preparation for certification.
You get: an ISMS with policies, risk method, control structure and Statement of Applicability, ready for audit.
Scope: a project over several months, handed over to youRead more → OngoingAnnual DORA review and maintenance
Compliance has to hold year after year. A recurring review of the ICT risk framework, information registers, testing programme and reporting, updated when the requirements or the business change.
You get: an annual review report, updated policies and registers, and a basis for management.
Scope: recurring, once a year or on changeRead more → OngoingSenior GRC advisory
Once the gaps are closed the work has to hold. Ongoing support with governance, risk work, compliance and reporting to management.
You get: a named senior advisor, recurring reviews and work you can show at an audit.
Scope: ongoing, adapted to your needsRead more →Regulations we work with
A closer look at each regulation: who is affected, what is required and how we help.
Swedish Cybersecurity Act and NIS2
The Swedish act implementing NIS2: which organisations are affected, which security measures are required and how to get started.
Read more →Cyber Resilience Act (CRA)
Cybersecurity requirements for products with digital elements: secure development, vulnerability handling and documentation.
Read more →DORA
Digital operational resilience for financial entities and their critical ICT providers: ICT risk, incidents, testing and third-party risk.
Read more →GDPR
The General Data Protection Regulation: records, legal basis, impact assessments, breaches and data-subject rights.
Read more →ISO 27001
The standard for information security management systems: risk work, policies, controls and certification.
Read more →AI Act
The EU regulation on artificial intelligence: risk classification, requirements per role and timeline.
Read more →How we work with compliance, in detail
Six steps that together are the compliance work. Jump to a section in the menu, or read from the top. About 6 minutes of reading
Scoping: which regulations apply to you?
Before anything can be measured it has to be delimited. We go through your organisation, your services and products, your customers and your role in the supply chain, and answer the question that is often the hardest: are you affected, by what, and in which role? The Swedish Cybersecurity Act distinguishes essential from important entities. The CRA distinguishes manufacturers, importers and distributors. DORA reaches both financial entities and their critical ICT providers. The GDPR applies to everyone processing personal data, but the requirements differ for controllers and processors. The result is a documented scoping decision management can stand behind – and the first thing a supervisory authority asks for.
In brief
- Which regulations apply to you, in which role and for which parts of the business
- A documented scoping decision management can stand behind
- The foundation for everything that follows – and the first thing supervision asks for
Baseline and gap analysis
With the scope settled we go through the requirements one by one against reality: interviews with the people who own each area, review of policies, contracts and the technical environment, and spot checks that what the documents say is also what is done. The result is a documented baseline, a gap per requirement with an assessment of severity, prioritised risks and an action plan with owners, order and estimated effort, written so that management can decide on it. If several regulations apply, we analyse the shared requirements once – risk analysis, policies, incident management, continuity, supplier governance – and add the specifics. The gap analysis is a step, not the goal. Read more in the offer and in our insight on how a gap analysis becomes usable.
In brief
- Interviews, document review and spot checks against every requirement
- Documented baseline, gaps per requirement, prioritised risks, action plan for decision
- Shared requirements analysed once when several regulations apply
Governance, policies and controls
Compliance that holds needs a structure to live in. We help you establish a compliance programme: clear accountability in management and the business, policies that say what applies and who does what, and controls that show it is followed. Where you already have an ISO 27001 management system we build the regulations’ requirements into it rather than creating parallel tracks, so that one policy can answer both the Cybersecurity Act and DORA. Management’s role is not to write the documents but to decide on risk appetite, approve the measures and follow them up – something the Cybersecurity Act now requires explicitly.
In brief
- A compliance programme with accountability, policies and controls
- Regulatory requirements built into the existing management system, not parallel tracks
- Management decides and follows up
Implementation in the business
This is where most compliance initiatives stall. We stay on. The measures in the plan are carried out together with the people who own them: an incident process with roles and reporting lines, continuity plans that are tested, supplier requirements written into contracts, a risk register that is filled in and used, training for management and staff. If you want to go all the way to certification we do it as ISO 27001 from gap analysis to certification. If the work needs a leader over time, there is the interim CISO. The person who did the analysis is also the one who can implement – you do not have to explain your situation twice.
In brief
- Measures carried out with the people who own them, not beside them
- Incident process, continuity, supplier requirements, risk register, training
- All the way to certification when that is the goal
Ongoing compliance and regulatory monitoring
Regulations change – the Cybersecurity Act’s regulations, the CRA’s application dates, the supervisory authority’s guidance – and the business changes more often. Ongoing compliance means someone monitors the changes, assesses what they mean for you, updates policies and controls, and reports to management so that decisions are taken in time. We do it as senior GRC advisory, or as an annual DORA review for financial entities, where registers, testing programme and reporting are reviewed ahead of each new year. The goal is that compliance is a state you are in, not a one-off effort you made.
In brief
- Regulatory monitoring and impact assessment of changes
- Updated policies, controls and registers
- Recurring reporting to management
Audit and supervisory readiness
Sooner or later someone asks: a certification auditor, a customer in a procurement, a supervisory authority after an incident. Readiness means the answer exists before the question arrives: collected evidence that the controls work, a pre-audit that finds the non-conformities in advance, and routines for how you respond to security questionnaires and authority requests. Where we have built parts of the management system ourselves, other consultants carry out the internal audit – an auditor may not review their own work, and we say so in every engagement.
In brief
- Evidence that the controls work, collected before the question arrives
- Pre-audit and support during external audit, customer review and supervision
- Independent review of what we built ourselves
Want to know which regulations apply to you, where you stand against them – and have compliance work that holds when someone asks? Contact us, and we start with the scope.
Frequently asked questions
What is the difference between a gap analysis and an audit?
A gap analysis compares your current state with the requirements to show what is missing and what should be done – it is forward-looking and produces an action plan. An audit assesses whether what you say you do is actually done and works, and produces an attestation or a non-conformity report. The gap analysis is one step in the compliance work; the audit comes once the work is in place.
How often does compliance need to be reviewed?
At least once a year, and always when something material changes: new regulations, new operations, new systems or suppliers, an incident. DORA explicitly requires an annual review of the ICT risk framework; the Cybersecurity Act requires management to follow up the work. Ongoing monitoring turns the review into an update rather than a new gap analysis.
Can you coordinate NIS2, CRA, GDPR and ISO 27001?
Yes. The requirements overlap to a large degree – risk analysis, policies, incident management, continuity and supplier governance recur in all of them. We handle the shared requirements once and add what is specific to each regulation, so you get one compliance programme instead of four.
We are a smaller organisation. Do we really need a compliance programme?
Yes, but a proportionate one. The requirements scale with your size and risk, and a compliance programme for a smaller organisation can be a few pages of policy, a risk register that is used and an annual review with management. What does not scale is lacking documented accountability the day someone asks.
What happens when a regulation changes after we are done?
That is what the ongoing work is for. We monitor changes in the regulations that apply to you, assess what they mean for your specific organisation, update policies and controls and report to management. The regulations under the Swedish Cybersecurity Act that apply from 1 October 2026 are a current example.
Want compliance work that holds – not just a report?
Contact us