DORA · Sweden Regulation (EU) 2022/2554

DORA Applies to You.
Is Your ICT Resilience Provable?

Financial entities and their ICT providers are in scope. DORA wants tested resilience, not assumptions.

Five Pillars, Documented Governance

From ICT risk management to third-party oversight and staff training. Every pillar needs board-approved, audit-ready evidence.

Article 19: The 4-Hour Clock

Without 24/7 detection you will miss the window. Initial notification is due within 4 hours of classifying a major incident.

Article 26–27: TLPT Every 3 Years

Entities designated “significant” by Finansinspektionen face Threat-Led Penetration Testing under TIBER-SE, beyond routine annual testing.

Trusted by 100+ Swedish Kommuner, Regions and
EU-Regulated Enterprises Since 2002

Stakes

Why Acting Now Is Not Optional

DORA has applied directly across the EU since 17 January 2025. Finansinspektionen already supervises against it, no phase-in period remains.

Before You Continue

Signs Your DORA Programme Is Not Ready

Read through these. If two or more describe your organisation today, you have material gaps a supervisory review can act on right now.

Your Risk Framework Has No Named Owner

Your ICT risk framework exists as a policy document but no one at board level can say who owns it or when it was last reviewed. Articles 5 - 16 require a documented, board-approved framework with named accountability at management-body level, not a policy that only surfaces for an audit.

No Way to Classify an Incident in Time

You have no documented process for classifying an ICT incident against DORA’s criteria within the first few hours. Article 19 wants that classification made against defined criteria before the 4-hour notification clock even starts so if you only find out reactively the window is already closing.

A Vendor List Is Not a Register of Information

You have a list of ICT vendors but no Register of Information and no clear view of which contracts are missing the mandatory clauses. Articles 28 - 30 require every contract supporting a critical or important function to include audit rights, security requirements and exit provisions, all tracked in a Register of Information you submit annually.

You Do Not Know Your TLPT Status

You are not sure whether your organisation or a supervisor would classify you as “significant” for TLPT purposes. Finansinspektionen decides which entities must run Threat-Led Penetration Testing under Article 26 and not knowing your status means you cannot plan the testing cycle it requires.

Training Is Not on the Compulsory Record

ICT security awareness training happens but it is not documented as a compulsory part of your staff training scheme. Article 13(6) makes ICT security and operational resilience training compulsory for all employees and senior management, not an optional add-on.

Who Falls Under DORA

Banks & Credit Institutions
Insurers & Reinsurers
Investment Firms & Fund Managers
Payment & E-Money Institutions
Crypto-Asset Providers
ICT Third-Party Providers
DORA · Five Pillars

What the Regulation Requires in Practice

Every DORA pillar and the eBuilder Security service that supports it directly.

Art. 17–19

ICT Incident Management & Reporting

Classify major ICT incidents and report in three stages: initial notification within 4 hours, intermediate report within 72 hours, final report within one month.

Managed by MDR / SOC 24/7
Art. 24–25

Ongoing Vulnerability Assessments

Continuous scanning, risk-based prioritisation and remediation tracking, verified by re-scan, feeding the evidence your ICT risk framework rests on.

Art. 24–27

Resilience Testing & TLPT

Annual baseline testing across web, network, cloud, API and Active Directory plus scoping support where Threat-Led Penetration Testing under TIBER-SE may apply.

Managed by Pen Testing
Art. 5–16

ICT Risk Management Governance

A documented, board-owned ICT risk framework with named accountability, built and kept current rather than assembled once a year.

Managed by CISO Advisory
Art. 28–30

ICT Third-Party Risk Management

Assessing ICT vendor relationships, flagging concentration risk and keeping your contractual position aligned so your Register of Information reflects reality.

Managed by CISO Advisory
Art. 13(6)

Staff ICT Security Awareness Training

Role-based training and phishing simulation, scoped to include the ICT-risk-awareness content DORA expects with reporting your board can review.

Managed by Security Awareness
DORA · Free Gap Score

See Exactly Where You Stand Across DORA’s Five Pillars

Maps your current state against DORA’s ICT risk, incident-reporting, testing and third-party requirements. Takes about 20 minutes. The output is board-ready.

  • Your score per DORA pillar, assessed against Finansinspektionen’s expectations, not a generic checklist.
  • Your three highest-priority gaps, ranked by the likelihood a supervisory review or client due-diligence request would flag them.
  • A board-ready summary, written in plain language, not legal text.

No obligation · EU data residency · Results reviewed in a 30-minute call.

DORA Compliance Gap Score

See where you stand across DORA’s five pillars, scored in plain language. The output is board-ready and reflects current Finansinspektionen guidance.

No spam. EU data residency.

Why eBuilder

Sweden-Based Security Built for This Regulation

We are not a global firm that adapted generic content for Sweden. DORA, Finansinspektionen oversight and Lag (2024:1278) are what we design our services around.

See Full DORA Pillar Coverage

Sweden-Based
24/7 SOC

Human analysts watching every signal, every minute, every day. Logs stay in Sweden.

3-minute
Median Response

Industry response times average 1–24 hours. We measure ours in minutes and escalate threats fast enough to matter.

Onboard in Days,
Not Quarters

Signed Monday. MDR live Thursday. Complorer rolled out by Wednesday.

20+ Years in SaaS

Cybersecurity practice within eBuilder, a Swedish enterprise-software company operating since 2002.

ISO 27001 Certified

Independently audited and certified to the ISO 27001 information-security standard for our SOC.

ISO 27001 certification mark

DORA Aligned

All services mapped to DORA’s five pillars from incident reporting to third-party risk oversight.

GDPR & Schrems II
Compliant

Human-led monitoring, secure data handling and infrastructure aligned with GDPR and Schrems II requirements.

Questions

DORA Compliance, Answered

Real questions a board or compliance lead asks before engaging on DORA, answered in two to three sentences.

Is DORA a directive that Sweden had to transpose into law?

No. DORA is an EU regulation, not a directive, so it has applied directly in Sweden since 17 January 2025 without needing a separate transposition law. Lag (2024:1278) supplements it with Sweden-specific supervision and penalty detail but does not create the underlying obligations.

We’re a small fintech. Does DORA still apply to us?

Likely yes. DORA’s scope is broad and covers most regulated financial entities regardless of size. Microenterprises (fewer than 10 staff, turnover or balance sheet under €2 million) get reduced obligations in several places – a lighter risk-framework review cycle, no mandatory TLPT, more flexible testing – but incident reporting and third-party contract requirements still apply in full. The gap score includes a scope determination.

We supply cloud or SaaS services to a bank. Does DORA apply to us?

Yes, potentially. If you support a critical or important function for a financial entity, DORA reaches you through the mandatory contract clauses your customer must now put in place. Providers judged systemically important can also be designated Critical ICT Third-Party Providers under direct EU-level oversight.

What does Articles 5–16 governance actually require from our board?

A documented, board-approved ICT risk management framework with clear accountability at management-body level: an ICT risk appetite, ongoing asset identification and protection and a strategy for detection, response and recovery. The management body carries ultimate responsibility and must maintain up-to-date knowledge of ICT risk.

What happens if we report an ICT incident late?

Late reporting is a compliance failure in its own right. Article 19 requires an initial notification within 4 hours of classification (24-hour backstop from detection), an intermediate report within 72 hours and a final report within one month. eBuilder’s SOC timestamps incidents from first detection to help your team meet all three.

What does ICT third-party risk management mean in practice?

Every contract supporting a critical or important function needs audit rights, security requirements, incident-notification obligations and exit provisions. You also need a Register of Information covering all ICT third-party arrangements, submitted to Finansinspektionen annually. eBuilder’s CISO Advisory helps keep that register current.

Do we need to run Threat-Led Penetration Testing?

Only if Finansinspektionen designates your organisation “significant.” If so, TLPT is required at least every three years under the TIBER-SE framework by testers meeting Article 27’s qualifications. Every in-scope entity still needs an annual baseline testing programme regardless.

Can individuals at our company be personally fined or banned?

Yes. Under Lag (2024:1278), individuals can face a sanction fee up to €500,000 or three times their personal profit from the breach and for serious, intentional or grossly negligent breaches, a 3 - 10 year ban from board or CEO roles at a financial entity.

How large can the fine be for our company?

Finansinspektionen can impose a sanction fee up to the highest of roughly €1 million, 10% of your prior-year turnover or three times the profit gained from the breach for a legal-person financial entity under Lag (2024:1278).

Is Finansinspektionen already supervising DORA in Sweden?

Yes. DORA has applied directly since 17 January 2025 and Finansinspektionen is Sweden’s competent authority for it, supplemented by Lag (2024:1278). Supervision is active now, not at a future date.

We already comply with NIS2 or GDPR. Are we automatically DORA-compliant?

Not automatically. DORA takes precedence over NIS2 for financial entities and adds requirements neither NIS2 nor GDPR cover: a Register of Information, TLPT for significant entities and DORA-specific incident-classification thresholds. A cybersecurity incident involving personal data can still trigger a separate GDPR notification duty at the same time.

Does DORA or NIS2 apply to us if we’re a financial company?

DORA takes precedence over NIS2 for financial entities; it is sector-specific legislation covering the same ICT-risk ground in more detail. Our CISO Advisory service can address both through a combined programme where a group also has non-financial entities in scope of NIS2.

How quickly can eBuilder get us DORA-aligned?

Our CISO Advisory service helped a Stockholm-based fintech complete DORA scope mapping, define incident-classification thresholds and design its reporting workflow within a single working week. Full alignment timelines depend on your starting point. The gap score gives you a specific starting point before you commit to anything.

Can eBuilder work alongside our existing compliance or IT team?

Yes. eBuilder’s MDR/SOC and CISO Advisory extend your existing team’s capability rather than replacing it, integrating with your current tooling and providing the always-on monitoring and governance support DORA expects.

Act Now

DORA Has Applied Since January 2025.
Let’s Close the Gaps First.

Book a free 30-minute compliance briefing with a Sweden-based advisor. We will show you exactly where you stand against DORA’s five pillars, with no obligation.

Book a 30-Minute Security Briefing
No commitment required