Up to €1M or 10% of Turnover
Under Lag (2024:1278), Finansinspektionen can fine a financial entity the highest of roughly €1M, 10% of prior-year turnover or three times the profit gained from the breach.
Financial entities and their ICT providers are in scope. DORA wants tested resilience, not assumptions.
From ICT risk management to third-party oversight and staff training. Every pillar needs board-approved, audit-ready evidence.
Without 24/7 detection you will miss the window. Initial notification is due within 4 hours of classifying a major incident.
Entities designated “significant” by Finansinspektionen face Threat-Led Penetration Testing under TIBER-SE, beyond routine annual testing.
Trusted by 100+ Swedish Kommuner, Regions and
EU-Regulated Enterprises Since 2002








DORA has applied directly across the EU since 17 January 2025. Finansinspektionen already supervises against it, no phase-in period remains.
Under Lag (2024:1278), Finansinspektionen can fine a financial entity the highest of roughly €1M, 10% of prior-year turnover or three times the profit gained from the breach.
Initial notification is due within 4 hours of classifying a major ICT incident with a 24-hour backstop from first detection. Intermediate and final reports follow at 72 hours and one month.
DORA requires a board-approved ICT risk framework with named accountability. Individuals can face fines up to €500,000 or a 3 - 10 year ban from board and CEO roles for serious breaches.
Entities Finansinspektionen designates “significant” must run Threat-Led Penetration Testing under TIBER-SE, on top of the annual testing programme every entity needs.
The fine is only part of the cost. Recovery, downtime, legal fees and reputational damage typically exceed the regulatory penalty itself. IBM Cost of a Data Breach Report 2025.
Without active 24/7 monitoring, most organisations discover incidents months after they occur, long after DORA’s 4-hour classification clock has already run out. IBM Cost of a Data Breach Report 2025.
Read through these. If two or more describe your organisation today, you have material gaps a supervisory review can act on right now.
Your ICT risk framework exists as a policy document but no one at board level can say who owns it or when it was last reviewed. Articles 5 - 16 require a documented, board-approved framework with named accountability at management-body level, not a policy that only surfaces for an audit.
You have no documented process for classifying an ICT incident against DORA’s criteria within the first few hours. Article 19 wants that classification made against defined criteria before the 4-hour notification clock even starts so if you only find out reactively the window is already closing.
You have a list of ICT vendors but no Register of Information and no clear view of which contracts are missing the mandatory clauses. Articles 28 - 30 require every contract supporting a critical or important function to include audit rights, security requirements and exit provisions, all tracked in a Register of Information you submit annually.
You are not sure whether your organisation or a supervisor would classify you as “significant” for TLPT purposes. Finansinspektionen decides which entities must run Threat-Led Penetration Testing under Article 26 and not knowing your status means you cannot plan the testing cycle it requires.
ICT security awareness training happens but it is not documented as a compulsory part of your staff training scheme. Article 13(6) makes ICT security and operational resilience training compulsory for all employees and senior management, not an optional add-on.
Every DORA pillar and the eBuilder Security service that supports it directly.
Classify major ICT incidents and report in three stages: initial notification within 4 hours, intermediate report within 72 hours, final report within one month.
Continuous scanning, risk-based prioritisation and remediation tracking, verified by re-scan, feeding the evidence your ICT risk framework rests on.
Annual baseline testing across web, network, cloud, API and Active Directory plus scoping support where Threat-Led Penetration Testing under TIBER-SE may apply.
A documented, board-owned ICT risk framework with named accountability, built and kept current rather than assembled once a year.
Assessing ICT vendor relationships, flagging concentration risk and keeping your contractual position aligned so your Register of Information reflects reality.
Role-based training and phishing simulation, scoped to include the ICT-risk-awareness content DORA expects with reporting your board can review.
Maps your current state against DORA’s ICT risk, incident-reporting, testing and third-party requirements. Takes about 20 minutes. The output is board-ready.
No obligation · EU data residency · Results reviewed in a 30-minute call.
See where you stand across DORA’s five pillars, scored in plain language. The output is board-ready and reflects current Finansinspektionen guidance.
No spam. EU data residency.
We are not a global firm that adapted generic content for Sweden. DORA, Finansinspektionen oversight and Lag (2024:1278) are what we design our services around.
See Full DORA Pillar CoverageHuman analysts watching every signal, every minute, every day. Logs stay in Sweden.
Industry response times average 1–24 hours. We measure ours in minutes and escalate threats fast enough to matter.
Signed Monday. MDR live Thursday. Complorer rolled out by Wednesday.
Cybersecurity practice within eBuilder, a Swedish enterprise-software company operating since 2002.
Independently audited and certified to the ISO 27001 information-security standard for our SOC.
All services mapped to DORA’s five pillars from incident reporting to third-party risk oversight.
Human-led monitoring, secure data handling and infrastructure aligned with GDPR and Schrems II requirements.
Real questions a board or compliance lead asks before engaging on DORA, answered in two to three sentences.
No. DORA is an EU regulation, not a directive, so it has applied directly in Sweden since 17 January 2025 without needing a separate transposition law. Lag (2024:1278) supplements it with Sweden-specific supervision and penalty detail but does not create the underlying obligations.
Likely yes. DORA’s scope is broad and covers most regulated financial entities regardless of size. Microenterprises (fewer than 10 staff, turnover or balance sheet under €2 million) get reduced obligations in several places – a lighter risk-framework review cycle, no mandatory TLPT, more flexible testing – but incident reporting and third-party contract requirements still apply in full. The gap score includes a scope determination.
Yes, potentially. If you support a critical or important function for a financial entity, DORA reaches you through the mandatory contract clauses your customer must now put in place. Providers judged systemically important can also be designated Critical ICT Third-Party Providers under direct EU-level oversight.
A documented, board-approved ICT risk management framework with clear accountability at management-body level: an ICT risk appetite, ongoing asset identification and protection and a strategy for detection, response and recovery. The management body carries ultimate responsibility and must maintain up-to-date knowledge of ICT risk.
Late reporting is a compliance failure in its own right. Article 19 requires an initial notification within 4 hours of classification (24-hour backstop from detection), an intermediate report within 72 hours and a final report within one month. eBuilder’s SOC timestamps incidents from first detection to help your team meet all three.
Every contract supporting a critical or important function needs audit rights, security requirements, incident-notification obligations and exit provisions. You also need a Register of Information covering all ICT third-party arrangements, submitted to Finansinspektionen annually. eBuilder’s CISO Advisory helps keep that register current.
Only if Finansinspektionen designates your organisation “significant.” If so, TLPT is required at least every three years under the TIBER-SE framework by testers meeting Article 27’s qualifications. Every in-scope entity still needs an annual baseline testing programme regardless.
Yes. Under Lag (2024:1278), individuals can face a sanction fee up to €500,000 or three times their personal profit from the breach and for serious, intentional or grossly negligent breaches, a 3 - 10 year ban from board or CEO roles at a financial entity.
Finansinspektionen can impose a sanction fee up to the highest of roughly €1 million, 10% of your prior-year turnover or three times the profit gained from the breach for a legal-person financial entity under Lag (2024:1278).
Yes. DORA has applied directly since 17 January 2025 and Finansinspektionen is Sweden’s competent authority for it, supplemented by Lag (2024:1278). Supervision is active now, not at a future date.
Not automatically. DORA takes precedence over NIS2 for financial entities and adds requirements neither NIS2 nor GDPR cover: a Register of Information, TLPT for significant entities and DORA-specific incident-classification thresholds. A cybersecurity incident involving personal data can still trigger a separate GDPR notification duty at the same time.
DORA takes precedence over NIS2 for financial entities; it is sector-specific legislation covering the same ICT-risk ground in more detail. Our CISO Advisory service can address both through a combined programme where a group also has non-financial entities in scope of NIS2.
Our CISO Advisory service helped a Stockholm-based fintech complete DORA scope mapping, define incident-classification thresholds and design its reporting workflow within a single working week. Full alignment timelines depend on your starting point. The gap score gives you a specific starting point before you commit to anything.
Yes. eBuilder’s MDR/SOC and CISO Advisory extend your existing team’s capability rather than replacing it, integrating with your current tooling and providing the always-on monitoring and governance support DORA expects.
Book a free 30-minute compliance briefing with a Sweden-based advisor. We will show you exactly where you stand against DORA’s five pillars, with no obligation.
Book a 30-Minute Security Briefing