DORA Requirements in Sweden: What Finansinspektionen Expects

DORA Requirements in Sweden: What Finansinspektionen Expects

Key Takeaways

  • Finansinspektionen’s 2026 supervision priorities commit it to analysing data reported under DORA to identify risks and secure compliance.
  • The Register of Information is due to FI by 28 February each year, covering the position at the end of the previous calendar year.
  • The 28 February filing is not the finish line. FI told firms on 4 March 2026 that each one is responsible for its register being approved at the EBA by 31 March.
  • FI decides which firms must run threat-led penetration testing and how often. The Riksbank coordinates the tests and issues the attestation.
  • In Sweden TIBER-SE is the process used for DORA TLPT, and designated entities test at least every three years unless FI varies the frequency.
  • DORA leaves penalties to national law. Which ceiling applies depends on which Swedish act governs your business.

The Register You Filed in February Is the Inspection

On 5 February 2026 Finansinspektionen published its supervision priorities for the year and on ICT risk it was specific. FI said it would analyse the data reported under DORA to identify risks and secure good compliance. Four weeks later it did exactly that, telling firms the European Banking Authority had found deficiencies in their registers of information.

That sequence is the shape of the DORA requirements Sweden now enforces. If you run security or compliance at a bank, insurer, payment institution, fund manager or crypto-asset service provider under FI’s supervision or at a fintech supplying one, your filings have become your inspection record.

The reason is a shift in where supervision gets its evidence. ICT oversight here used to run on questionnaires, thematic reviews and audit reports and none of that has gone away. What changed is that DORA turned the same subject matter into structured annual data with a fixed template and a validation rule set. FI no longer has to ask what your estate looks like.

What is DORA and Which Swedish Rules Carry It

DORA is Regulation (EU) 2022/2554, the EU framework for digital operational resilience in the financial sector. It has applied since 17 January 2025 and covers ICT risk management, incident reporting, resilience testing, ICT third-party risk and information sharing. As a regulation it applies directly with no national transposition.

Two Swedish instruments turn it into a working obligation. Finansinspektionen is the competent authority under Article 46 confirmed by lag (2024:1278) which also grants FI its supervisory and intervention powers and assigns the threat-led testing roles.

The second is FFFS 2024:20, in force since 17 January 2025 which sets the format and the timing for reporting. FI can issue injunctions and administrative fines against firms that fall short.

The Dates That Actually Matter

17 Jan 2025DORA applies and FFFS 2024:20 enters into force.
8 Jul 2025The TLPT standard 2025/1190 becomes applicable.
1 Jan 2026The Riksbank’s TLPT fee regulations take effect.
28 Feb 2026Register of Information due to FI in Fidac, covering 31 December 2025.
31 Mar 2026Each firm’s register must be approved at the EBA.
30 Apr 2026Corrections from the EBA’s April checks completed.

Who Must Comply and Who Gets Designated for TLPT

DORA reaches nearly every firm already supervised by FI, from credit institutions and insurers to investment firms, fund managers, payment institutions and crypto-asset service providers. It also reaches their ICT third-party providers through the contractual and register requirements.

Threat-led penetration testing is far narrower. Article 26(1) applies to entities other than those on the simplified ICT risk management framework in Article 16(1) and other than microenterprises and only where they have been identified under Article 26(8). Designated entities test at least every three years and the competent authority may vary that frequency.

You do not self-select. Under chapter 2 section 1 of lag (2024:1278) FI decides which entities must test and how often, after giving the Riksbank the chance to comment. The criteria and methodology sit in Delegated Regulation (EU) 2025/1190 applicable since 8 July 2025.

Who Carries Which Duty

  • Every in-scope firm : ICT risk management, incident reporting and an annual Register of Information.
  • Designated entities : Threat-led testing of critical or important functions on live production systems.
  • Finansinspektionen : Receives the reports and decides who tests and how often.
  • The Riksbank : Coordinates the tests, validates scope and testers and issues the attestation.
  • The ESAs : Designate critical ICT third-party providers from the registers collected.

The Register of Information Does Not End on 28 February

Section 4 of FFFS 2024:20 requires annual reporting to FI by 28 February at the latest reflecting the position at the end of the previous calendar year. The 2026 round covered 31 December 2025. Firms use the templates in Implementing Regulation (EU) 2024/2956 and hold the register at entity, sub-consolidated and consolidated level under Article 28(3).

Mechanically it is a Fidac submission in xbrl-csv, with entities identified by LEI code. A group can report one register at the highest consolidated level, or each firm reports at entity level. One route, not both.

The EBA Feedback of 4 March 2026

On 4 March 2026 FI announced that the EBA had reported deficiencies in firms’ register reporting and that it would email firms to correct the errors and resubmit. Most deficiencies carried error code 805 or 807.

The operative point was ownership. Each firm is responsible for its own reporting being approved at the EBA no later than 31 March. From 1 April the EBA ran fresh quality checks and corrections were due by 30 April.

When the European Supervisory Authorities published their first designations of critical ICT third-party providers on 18 November 2025, the process began with the registers financial entities maintain. Your register is an input to EU-level oversight.

How TLPT Works in Sweden When Two Authorities Share It

Sweden split the job. FI designates and sets frequency. The Riksbank supervises and coordinates the tests run under Articles 26 and 27 and under chapter 2 section 2 of lag (2024:1278) it issues the attestation referred to in Article 26(7). That attestation supports mutual recognition across the EU and no other Swedish body can issue it.

In practice the Riksbank validates which critical or important functions fall inside the scope and checks that the tester meets the Article 27 requirements. Designated firms must supply the information it needs, and the testing is chargeable.

TIBER-SE Is the How and TLPT Is the What

TIBER-EU is the European Central Bank’s framework for standardised cyber resilience testing and its red team tests are deliberately not pass or fail. TIBER-SE is the Swedish implementation and uses the TIBER-EU documents.

The Riksbank puts the relationship plainly. TLPT describes what to do and TIBER-SE describes how to do it, and in Sweden TIBER-SE will be used for DORA TLPT. It has coordinated threat-led tests since 2019. The framework is currently being updated so anyone scoping a test in 2026 should work from the current documents and confirm the process early.

What to Do Before the Window, During It and All Year

Before the window, reconcile contracts to the register rather than the other way round. Every ICT third-party arrangement needs to appear at the right level with counterparty LEI codes and the subcontracting chain behind any critical or important function. Then test-submit and clear the validation errors.

During the window, treat 28 February as the submission date and 31 March as the deadline that matters because that is when your file has to be accepted at the EBA.

All year, the incident clock in Delegated Regulation (EU) 2025/301 starts at classification so the decision to classify an incident as major is the control worth rehearsing.

The Incident Reporting Sequence

Initial notificationWithin four hours of classifying the incident as major and no later than 24 hours after becoming aware of it.
Intermediate reportWithin 72 hours of the initial notification, even if nothing has changed.
Final reportWithin one month of the intermediate or latest updated intermediate report.
Cyber threatsVoluntary notification to FI under Article 19(2).

Where Swedish Firms Are Most Exposed

Concentration is the first exposure. A small number of providers support critical functions across most of the sector, and the ESAs can now see that pattern in aggregate. Expect questions about substitutability and exit arrangements.

Subcontracting chains are the second because a register that stops at your direct supplier fails a standard that reaches further down the chain.

Third, four hours from classification is generous only if classification happens quickly. Fourth, and specific to Sweden, FI states that the financial entity is responsible for keeping security-classified information out of its incident reports.

Penalties for Non-Compliance Under Swedish Law

DORA leaves administrative penalties to national law which in Sweden means chapter 4 of lag (2024:1278) and the sectoral acts. The ceiling that applies depends on which of those governs your business.

For the entities listed in chapter 4 section 1, among them crypto-asset service providers, pension foundations, benchmark administrators and crowdfunding service providers, section 14 caps a fine on a legal person at the highest of the krona equivalent of EUR 1 million as at 16 January 2023, 10 per cent of turnover or three times the profit from the breach. For banks, insurers and investment firms, section 2 points instead to the act regulating that activity.

Under section 9 FI may ban a board member or chief executive for three to ten years and may impose a fine. Both can apply at once but only where the breach is serious and the person caused it intentionally or through gross negligence. Breaches of Articles 26, 27 and 28 are on that list.

The Ceiling Depends on Which Law Governs You

Chapter 4 of lag (2024:1278) sets fine ceilings for a defined list of entities. For banks, insurers and investment firms it points to the sectoral act instead, so quoting chapter 4 figures at a bank is the commonest error in DORA penalty summaries.

How to Keep the Register and the Test Cycle Alive

Make a contract change trigger a register change. If procurement can sign an ICT arrangement without the register owner hearing about it, the February file gets reconstructed from memory and fails validation.

Keep last cycle’s error codes as this cycle’s checklist since FI’s published explanations amount to a free specification of what the EBA will reject. And if you are designated for testing, open the conversation with the Riksbank before scoping because both the scope and the tester have to satisfy it before an attestation can follow.

What Good Looks Like in 2026

FI said in February that it would analyse what firms report under DORA, and in March it acted on what the data showed. Build the register as a record you could defend line by line on any day of the year, not a file you assemble in February.

Frequently Asked Questions

Who must do TLPT under DORA in Sweden?

Only entities Finansinspektionen designates. Under chapter 2 section 1 of lag (2024:1278), FI decides which financial entities must run threat-led penetration testing and how often, after consulting the Riksbank. Firms on DORA’s simplified ICT risk framework and microenterprises fall outside Article 26 and no firm can opt in.

When must the Register of Information be reported to Finansinspektionen?

Annually, by 28 February at the latest, under section 4 of FFFS 2024:20. The version submitted must reflect the position at the end of the previous calendar year so the 2026 submission covered 31 December 2025. It reaches FI through Fidac in xbrl-csv format.

What happens if the EBA rejects a Register of Information submission?

FI emails the firm with the error codes and asks for a corrected resubmission. Each firm is responsible for its own reporting being approved at the EBA by 31 March. On 4 March 2026 FI reported that most deficiencies carried error code 805 or 807.

Does a TIBER-SE test count as a DORA TLPT?

In Sweden TIBER-SE is the process used for DORA threat-led penetration testing. The Riksbank describes TLPT as what to do and TIBER-SE as how to do it. The framework is being updated so confirm the current documents and the scope with the Riksbank before commissioning a test.

What are the DORA incident reporting deadlines in Sweden?

Three steps, all to FI. An initial notification within four hours of classifying an incident as major and no later than 24 hours after becoming aware of it. An intermediate report within 72 hours of that notification. A final report within one month of the intermediate.

eBuilder Security works with financial entities and their suppliers on Penetration Testing and CISO-as-a-Service. For the framework overview see our DORA compliance hub.

This post is also available in: Svenska