SERVICES · CORE PRACTICE
Compliance & risk
Most organisations don't need a full compliance department. They need someone to tell them plainly whether NIS2 or DORA applies, what it actually requires, and what to do about it — without inflating the scope of work to justify a bigger invoice.
What's actually involved
- Scope determination — working out which regulations actually apply to you, based on sector and size, not a guess.
- Risk assessments mapped to your actual environment, not a generic checklist run through unchanged.
- Audit and registration preparation — getting the paperwork and evidence in order before a regulator or auditor asks for it.
- Ongoing advisory as requirements change, or as your business grows into new scope.
Who this is for
- Swedish SMEs who aren't sure if NIS2 or DORA applies to them
- Organisations that got a scope determination elsewhere and want a second opinion before acting on it
- Teams preparing for their first regulatory audit or registration
If you haven't checked your scope yet, that's the right place to start — the scope check on the homepage takes two minutes and points you in the right direction before anything else.
How it starts
Same as anywhere else on this site: a real reply, not a funnel. The first conversation is a scoping conversation, not a pitch. Nothing starts until you've agreed the scope and cost — no surprise invoice, no assumed retainer.
Want to talk through where you stand?