A new rule arrives
Someone reads a long PDF and hopes the right policy gets updated.
You know right away what it means for you
Saga shows what affects you, and a ready-made change is waiting for your approval.
Saga keeps track of the rules that apply to you, finds what’s missing and suggests what to do. You approve, and you always have proof when the auditor, the board or the regulator asks.
New requirements, emails, tickets and files across different tools. No one sees the whole picture, and a lot depends on the right person remembering the right thing.
Every requirement, event and file is pulled in and tied to your business, whichever tool it came from.
Every requirement, action and record lands in its place, and every action gets an owner and a status.
From the requirement, through the action, to the record that shows it is done.
Most companies run compliance out of binders, folders and Excel. It works, until something happens.
Information_Security_Policy_FINAL_v3.docxNobody knows for sure which version is current.
Suppliers_2023.xlsxOnly one person understands it, and that person is on holiday.
Nobody really knows what it means for you.
Someone spends a week searching emails and folders.
Saga brings all of this into one place, and keeps it alive.
A person records a rule change with its source and assigns any follow-up work.
One current version, with changes, review and approval in the same place.
Requirements, gaps, owners and dates stay connected.
Completed training and evidence are linked to the requirement they meet.
Saga keeps the cycle going. When something changes, you know what it means for you and what needs to be done. Recognise the thinking from ISO? It’s the same improvement cycle, only it runs every day.
Saga starts from what you do, where you operate and which suppliers you have, and works out which rules apply to you and why. It all comes together in Company & scope and Vendors & data.
Company & scopeThe rules become your policies. They are written, linked to the requirements they meet and kept current, and when a person records a rule change, affected policies can be reviewed and any update approved in Policies.
Company & scopeThe work reaches the whole organisation. The right people get the right training, checklists and deadlines, and the compliance calendar shows who has done what.
Compliance workThe gap analysis shows whether it works in practice by comparing how you actually work with what the requirements say. Anything missing becomes a finding with an owner, and if something happens an incident is opened straight away.
Compliance workEvidence is collected where the work happens and every decision is approved by a person. Reports for the board, the auditor and the regulator, and the evidence for certification, come straight out of Saga.
Review & proofSaga re-checks work when business facts, evidence or dates change. A person records regulatory changes and reviews their effect on the work.
See the productSomeone reads a long PDF and hopes the right policy gets updated.
Saga shows what affects you, and a ready-made change is waiting for your approval.
Weeks of hunting for evidence in folders, emails and binders.
Evidence has been collected along the way and linked to every requirement. You know what’s missing long before the auditor arrives.
Nobody knows who should do what, or how long you have to report.
Saga opens the case, shows the deadline and who is responsible, and keeps a timestamped history.
Someone builds a presentation on gut feeling, and nobody can answer the follow-up questions.
You produce a report where every figure can be traced back to the record.
Every control, policy and piece of evidence is linked to every requirement it meets. You do the work once, and it counts everywhere it is needed.

In construction, AFS 2023:1 and 2023:3 require risk assessments, a work environment plan and the BAS-P and BAS-U coordinators in every project, subcontractors included. In Saga, every project gets its checklist, its owners and its evidence.

Property owners must have lifts and ventilation (OVK) inspected at set intervals and keep fire protection in order. Miss a lift inspection and the lift may not be used. In Saga, every inspection gets a deadline, an owner and a filed report.

Food producers must work to HACCP and be able to show control points, deviations and traceability to food inspectors and in BRCGS or IFS audits. In Saga, the food safety programme, deviations and audit evidence sit in one place.

Under SOSFS 2011:9, health and social care providers need a management system for systematic quality work, and serious incidents must be reported to IVO under Lex Maria and Lex Sarah. In Saga, deviations, risk analyses and internal checks are followed up with owners and dates.

Since January 2026, energy companies covered by the Cybersecurity Act (NIS2) must register with MCF, take security measures, train their management and report serious incidents. In Saga, measures, incidents and management decisions are linked to the requirements of the law.

Since January 2025, DORA requires financial firms to show how they manage ICT risk, incidents and ICT providers. In Saga, the provider register, incidents and exercises are linked to the requirements they meet.

Manufacturers of home appliances must be able to show that every product is safe, CE marked and meets the energy labelling and ecodesign requirements. Connected products also face new cybersecurity requirements. In Saga the technical documentation and the declaration of conformity are kept together for each product.

Haulage firms must follow the driving and rest time rules, and transporting dangerous goods requires a valid ADR certificate for the driver and a safety adviser in the company. In Saga every driver and vehicle has its certificates and checks, and anything about to expire shows up in good time.
Saga works for every industry with rules to follow. See more examples and what Saga looks like for you.
All industriesAll your compliance in the browser, with Saga doing the heavy lifting in the background.
Pick up where you left off, on your phone or tablet.
Saga collects evidence where the work already happens.
SharePoint
Google Drive
Slack
Claude
ChatGPTIllustrative product view with sample data.
The questions we get in almost every meeting, with straight answers.
More on security and AI →No, fewer. Saga replaces binders, folders and Excel sheets with one place where everything connects.
Less. Saga helps re-check work as facts, evidence or dates change, and suggests next steps. You spend your time on the decisions.
Saga uses AI that runs entirely inside the EU. Your data never leaves the EU, is never used to train models, and no decision is made without a person approving it.
It depends on what you need. We’ll go through it on a short call, with no obligation.
Start with one area, one site or one project. We work from your rules and your day-to-day, and can map the requirements and bring in your policies together with you.
Saga is organised the way compliance work actually happens. Here is what you’ll find in each part of the workspace.
Your starting point every morning, with what matters now and what has changed. Saga ranks what needs attention: new obligations that apply to you, open gaps, approvals waiting for you and the next deadline, without a dashboard you have to configure.
11 of 12 standing reviews within cadence
1 high and 2 medium findings are open
Approved evidence covers 42 of 50 controls
New guidance under DORA Art. 28 changes what your supplier policy has to cover. Saga has drafted three changes to the Supplier Security Policy and linked each one to its source.
What follows today’s recommended action
The material exposure Saga is tracking now
Deadlines and reviews that need attention soon
Decisions, evidence and material updates
Research, decide, draft, or take the next step with this company’s context.
Which suppliers are missing a data processing agreement?
Two: Arkivbolaget and Payfront. I have prepared data collections for both. They go out once you approve.
Illustrative product view with sample data.
First what applies to you, then the work, then the proof and finally what you show others. The same four parts as in Saga, and Home brings the most important things from them together every morning.
Company facts, which rules apply and why, your policies and suppliers.
Priorities, deadlines, findings and follow-up in one ordered view.
Evidence, decisions and approvals, where judgment stays human.
Reports for the board, auditor and regulator, with the record behind them.
Saga answers from your own records and always shows the source. Nothing changes without your explicit approval.
We walk through Saga with your frameworks, your policies and your questions.
The baseline behind every answer Saga gives: your company facts, which rules apply and why, your policies, suppliers and the people responsible. Always current and traceable.
DORAFinancial entity under FI supervisionAppliesGDPRProcesses personal data in the EUAppliesAML ActCovered through its licensed activitiesAppliesISO 27001Voluntary, chosen by youChosenNIS2Question from Maya Lind · todayDORA takes precedence · NIS2 Art. 4To assessDoes not applyDoes NIS2 apply to us?
Reading your company profile and NIS2 Articles 2–4.
Next: compare with DORA’s scope.No, not for ICT risk and incident reporting. As a financial entity you follow DORA, which takes precedence over NIS2.
SourceNIS2 Art. 4Save this assessment to Company & scope?
✓ Approved by Maya Lind · saved
Illustrative product view with sample data.
Policies, agreements and certificates tend to live in folders, emails and copies with names like v7_FINAL. Saga sorts them where they belong: policies under Policies, and agreements and certificates as evidence under Review & proof. Duplicates become one current version, and everything gets an owner, a link to the requirements and a date for review or renewal.
Syftet med policyn är att skydda bolagets information och informationssystem mot obehörig åtkomst, förändring och förlust. Policyn gäller alla medarbetare, konsulter och leverantörer som hanterar information för bolagets räkning.
2. OmfattningInformationssäkerhetsarbetet bedrivs i ett ledningssystem enligt ISO/IEC 27001. Ansvaret för att policyn efterlevs ligger hos respektive chef, och säkerhetsansvarig följer upp arbetet minst en gång per år.
Personuppgiftsbiträdet får endast behandla personuppgifter enligt dokumenterade instruktioner från den personuppgiftsansvarige och ska vidta lämpliga tekniska och organisatoriska åtgärder enligt artikel 32.
2. BehandlingUnderbiträden får endast anlitas efter skriftligt förhandsgodkännande. Biträdet ska utan onödigt dröjsmål underrätta den personuppgiftsansvarige om en personuppgiftsincident.
Bolaget ska identifiera, värdera och hantera risker som kan påverka verksamheten. Riskaptiten fastställs av styrelsen och riskerna rapporteras kvartalsvis till ledningsgruppen.
2. OmfattningInformationssäkerhetsarbetet bedrivs i ett ledningssystem enligt ISO/IEC 27001. Ansvaret för att policyn efterlevs ligger hos respektive chef, och säkerhetsansvarig följer upp arbetet minst en gång per år.
Hej Maya, här kommer det påskrivna biträdesavtalet från Payfront. De har även bifogat sitt ISO-certifikat, men det går ut i oktober. Kan du lägga in det? Mvh Jonas
Vi har granskat beskrivningen av CloudBase AB:s system och utformningen och effektiviteten hos de kontroller som avser säkerhet och tillgänglighet under perioden.
Vi har granskat beskrivningen av CloudBase AB:s system och utformningen och effektiviteten hos de kontroller som avser säkerhet och tillgänglighet under perioden.
Bolaget ska motverka att verksamheten utnyttjas för penningtvätt eller finansiering av terrorism. Kundkännedom ska inhämtas innan en affärsförbindelse etableras och följas upp löpande.
2. OmfattningInformationssäkerhetsarbetet bedrivs i ett ledningssystem enligt ISO/IEC 27001. Ansvaret för att policyn efterlevs ligger hos respektive chef, och säkerhetsansvarig följer upp arbetet minst en gång per år.
Leverantören ska tillhandahålla tjänsten i enlighet med bilaga 1 och de servicenivåer som anges i bilaga 2. Avtalet gäller i 36 månader från tecknandet.
2. BehandlingUnderbiträden får endast anlitas efter skriftligt förhandsgodkännande. Biträdet ska utan onödigt dröjsmål underrätta den personuppgiftsansvarige om en personuppgiftsincident.
Bolaget ska identifiera, värdera och hantera risker som kan påverka verksamheten. Riskaptiten fastställs av styrelsen och riskerna rapporteras kvartalsvis till ledningsgruppen.
2. OmfattningInformationssäkerhetsarbetet bedrivs i ett ledningssystem enligt ISO/IEC 27001. Ansvaret för att policyn efterlevs ligger hos respektive chef, och säkerhetsansvarig följer upp arbetet minst en gång per år.
Testet omfattade externa tjänster och webbportalen. Två brister med medelhög risk identifierades och har åtgärdats.
Leverantören ska tillhandahålla tjänsten i enlighet med bilaga 1 och de servicenivåer som anges i bilaga 2. Avtalet gäller i 36 månader från tecknandet.
Syftet med policyn är att skydda bolagets information och informationssystem mot obehörig åtkomst, förändring och förlust. Policyn gäller alla medarbetare, konsulter och leverantörer som hanterar information för bolagets räkning.
2. OmfattningInformationssäkerhetsarbetet bedrivs i ett ledningssystem enligt ISO/IEC 27001. Ansvaret för att policyn efterlevs ligger hos respektive chef, och säkerhetsansvarig följer upp arbetet minst en gång per år.
DORA · ISO 27001 · AML Act
1 duplicate mergedGDPR Art. 28 · DORA Art. 30
3 signedISO 27001 · SOC 2Saga knows which suppliers handle your data and which documents your policy requires from them. Requests go out through Data collections, the answers land in the right place and you see at once what is missing or about to expire.
Collect documents from suppliers and track who the company depends on, what data they share, which DPA proves it and when contracts renew.
Third parties, data shared, DPA status, renewals and vendor risk.
Illustrative product view with sample data.
What describes the company and what applies to you, gathered in one place.
Saga answers from your own records and always shows the source. Nothing changes without your explicit approval.
We walk through Saga with your frameworks, your policies and your questions.
Every priority, question and deadline in one ordered view, without configuring the machinery behind it. Saga finds the gaps, proposes the fix and keeps the evidence together until it is done.
Run a gap analysis against DORA Art. 28
Comparing your supplier agreements and routines with DORA Articles 28 and 30.
Next: reading 4 agreements and the supplier policy.Two gaps. The CloudBase agreement has no exit clause, and there is no documented exit plan for critical ICT suppliers.
SourceDORA Art. 28(8) · Art. 30Create two actions with suggested owners?
✓ Approved by Maya Lind · 2 actions created
Illustrative product view with sample data.
The calendar gathers everything that has a date: recurring reviews, training, agreements and certificates that expire and actions that need to be done. Saga reminds the owner in good time, and you see at once what is at risk of slipping.
One dated view of regulatory changes, training, incidents, submissions, certification, policies, acknowledgments, deadlines and recurring reviews.
Illustrative product view with sample data.
Every gap gets an owner, a deadline and a proposed fix. Each step is saved in an append-only event history, and once the gap is resolved the evidence is linked to the requirement. You can show it is done, not just say it.
Issues that need a recorded outcome in the selected company.
Illustrative product view with sample data.
The ongoing work, gathered in one place.
Saga answers from your own records and always shows the source. Nothing changes without your explicit approval.
We walk through Saga with your frameworks, your policies and your questions.
This is where judgment stays human. Inspect the sources, test the evidence and make the decisions that matter, with the reasoning and owner saved for each one.
Which evidence can I approve today?
Checking the requirement → control → evidence chain for 3 records awaiting review.
Next: comparing the files’ checksums.Two are complete. The restore test and the Nordlys agreement have the full chain and unchanged files. The access review has no link to a control, so it only counts as partially supported.
SourceISO 27001 A.8.13 · DORA Art. 30Approve the two complete records?
✓ Approved by Maya Lind · 2 records
Illustrative product view with sample data.
Saga shows what has changed since the last version, why, and which requirement each change answers. You approve that exact version, and the approval is saved with a name, a time and a fingerprint of the document.
SHA-256 7f3a 91c2 e04b 5d18✓ Approved by Maya Lind · 1 Oct 2026 16:30Judgments that matter are saved in the decision log: what was decided, why, on what basis and by whom. When the auditor asks why NIS2 does not apply, the answer is there, with its sources.
The long-form reasoning record for important choices behind policies, findings, caveats and reports: what was decided, why and when it must be reviewed.
Northstar is a financial entity under DORA, which takes precedence over NIS2 for ICT risk and incident reporting.
The old archive system stays in use until the migration is done. Access is limited to two named people and logged.
Illustrative product view with sample data.
What shows the work is done, gathered in one place.
Saga answers from your own records and always shows the source. Nothing changes without your explicit approval.
We walk through Saga with your frameworks, your policies and your questions.
Turn approved evidence into clear reports for the board, the auditor and the regulator. Everything points back to the record behind it.
Illustrative product view with sample data.
Saga assembles a versioned, approved pack for the auditor in a room of its own: the requirements, the approved evidence and the decisions behind it. You see exactly what is included before you publish, and internal gaps never end up there by mistake.
Prepare a versioned, approved pack for an auditor, customer or regulator. Every room has its own topic, scope, period and recipients.
The default. You choose and preview exact approved material before issuing a frozen publication.
A separate, deliberately authorized working session. Internal gaps are never added to an external room automatically.
Nordic Assurance · certification body
50 requirements · Oct 2025 – Sep 2026
Internal · Maya Lind and Sara Ek
ISO 27001 · 3 open gaps
Finansinspektionen
DORA Art. 28 · 4 suppliers
Nordbank · supplier assurance
ISO 27001 · DORA Art. 30
Illustrative product view with sample data.
Saga turns the work into a summary that can be read in five minutes: where things stand, the risks and the decisions the board needs to take. Every figure can be followed down to its record if anyone asks.
The position is stable. One ISO 27001 deviation is being fixed before the audit in November.
Approve the risk acceptance for the archive system until Q1 2027.
Presented by Maya LindWhat goes on to auditors, the board and regulators, gathered in one place.
Saga answers from your own records and always shows the source. Nothing changes without your explicit approval.
We walk through Saga with your frameworks, your policies and your questions.
Find the right way in through your industry, the rules you must follow, your role or the situation you are in.
Start where it feels closest. It all leads to the same place, with your rules and your records.
Either you run compliance in your own company, or you own several companies and want to know that all of them do. Saga works for both.
You know what applies, do the work and can show it, with owners, deadlines and proof in one place.
How it works for the company9 of 10 standing reviews within cadence
1 high and 1 medium finding are open
Approved evidence covers 34 of 42 controls
The induction for subcontractor Nordfasad AB at Kv. Tärnan was due on 30 September. Saga has prepared the checklist and a reminder to Anna Lund.
You own several companies, in a portfolio or a group, and see at a glance how each one stands, without their records being mixed up.
How it works for the ownerOpen a company to inspect its recorded posture and outstanding work. Refresh reads the latest available records.
You don’t have to start from a blank page. If you want support, we offer onboarding and set Saga up together with you.
We map your activities, jurisdictions and which rules apply, together with you.
Your existing policies, registers and evidence come into Saga and are linked to the rules they cover.
Continuous review re-checks work when facts, evidence or dates change. Your team records regulatory changes and decides the response.
Tell us your frameworks and your structure. We’ll show you the parts that matter to you.
Every industry has rules. Saga starts from yours, not from a fixed template, and shows what applies, who does what and that it is done.
The same Saga, with the requirements and day-to-day of each industry. Here are ten examples.

Under AFS 2023:1 and 2023:3, construction companies need risk assessments, a work environment plan and appointed BAS-P and BAS-U coordinators in every project, also when subcontractors are on site. In Saga every project gets its checklist with owners and proof, and what is missing shows before it becomes a problem.

Property owners must have elevators and ventilation inspected at regular intervals and keep fire safety in order. Miss an elevator inspection and the elevator cannot be used. In Saga every property gets its calendar, and every inspection a deadline, an owner and a saved protocol.

Food businesses must work to HACCP and be able to show critical control points, deviations and traceability, both to food inspectors and at BRCGS or IFS audits. In Saga every deviation leads to an action with an owner, and the record for the audit is already in place.

Grocery retail must keep the cold chain unbroken, label allergens correctly and be able to trace every product if something has to be recalled. The stores’ own checks are inspected by the municipal food control. In Saga every store has its own checks with temperature logs and deviations, and in a recall you see at once which stores are affected.

Health and social care providers need a management system for systematic quality work under SOSFS 2011:9, and serious events must be reported to IVO under lex Maria and lex Sarah. In Saga every event is investigated with an owner and a date, and the assessment of whether to report it is saved with the reasons.

Since January 2026, energy companies covered by the Cybersecurity Act must register with MCF, take security measures, train management and report serious incidents. In Saga every measure, incident and management decision is linked to the law’s requirements, so you can show where you stand.

Telecom operators fall under the Electronic Communications Act and the Cybersecurity Act, and outages, security incidents and personal data breaches must be reported within short deadlines. In Saga security measures, incidents and reports stay together, with owners and clocks that show how much time is left.

Since January 2025, financial entities must be able to show under DORA how they manage ICT risk, incidents and ICT providers. In Saga the register of information stays current, and every contract, exit plan and exercise is linked to the requirements it meets.

Logistics companies must follow the rules on driving and rest times, the carriage of dangerous goods under ADR and the work environment at the terminal. In Saga every driver and vehicle has its certificates and checks with deadlines, and whatever is about to expire shows in good time.

Appliance makers must be able to show that their products are safe and CE marked, meet the energy labelling and ecodesign requirements and are taken care of when they become waste. In Saga every product is linked to the requirements it falls under, with technical documentation and a declaration of conformity.
The catalogue shows which regulations exist. Which of them apply to your company, and what they require of you, Saga works out from your business and where you operate.
Every business has rules to follow. Saga starts with yours and builds the work around them, whatever the industry.
Logistics and transportRetailManufacturingTelecomIT and servicesPharma and life scienceAutomotiveChemicalsEducationPublic sectorInsuranceHotels and restaurantsWaste and recyclingMediaFarming and forestrySecurity servicesConsulting and advisoryFintech
Tell us about your businessTell us what you do and where you operate, and we will show you the parts that matter to you.
A catalogue of the regulations Saga helps you with. Do the work once, and it counts towards every one that applies to you.
No regulations match your search.
Is your regulation missing? Let us know, and Saga will add it for you
The catalogue is an overview and does not replace legal advice.
Tell us your frameworks and your structure. We’ll show you the parts that matter to you.
Saga is used in two ways: by the company that runs its own compliance, and by the owner who wants to know every company does. The same Saga, from one company to a whole portfolio.
Strukta AB runs its own compliance in Saga. Everyone knows what applies and who does what, and everyone works from the same record: the people doing the work see their actions and deadlines, the CEO sees the status and the risks, and the board gets a report where every figure can be traced to its evidence.
84Strukta ABConstructionStrukta AB owns three subsidiaries. The parent company writes shared policies and routines once and shares them with all of them. Each subsidiary does the work in its own day-to-day, with its own owners and its own evidence, and the parent sees how they all stand in one place.
84Strukta ABParent company · 3 subsidiaries
79Strukta Infrastructure ABInfrastructure
86Strukta Industrial Solutions ABIndustry
88Strukta Fastighetsförvaltning ABProperty managementNorthstar Kapital owns five companies in different industries. The owner doesn’t do the work, but sees readiness, gaps and trends across the whole portfolio. In an acquisition the target is mapped quickly, and the material for the investment committee and the board is already there.
84Northstar Kapital ABInvestment company · 5 portfolio companies
84Strukta ABConstruction
77AXD LogisticsLogistics
88MatFolkGrocery retail
81NordiqHome appliances
90TelioTelecomAdd your companies and Saga shows where each one stands, what’s missing and what to do first. We’ll show you what it looks like for you in a demo.
Tell us your frameworks and your structure. We’ll show you the parts that matter to you.
When something is on the line, you need to know where you stand, what to do and be able to show it afterwards.
Saga runs the gap analysis against Annex A, assigns owners and collects evidence while the work gets done. When the auditor arrives the material is already there, and nobody has to search their inbox.
“We’re going for ISO 27001.”
Saga maps which requirements of the Cybersecurity Act apply to you, flags the policies they affect and sets up the incident reporting deadlines. You see at once what is done and what is left.
“NIS2 now applies to us.”
Saga maps the target’s requirements and gaps before the deal is done, so the risks are part of the decision. After closing the company joins the portfolio and the work carries on there.
“We’re buying a company.”
Saga produces a report with readiness, top risks and decisions, where every figure can be traced to its evidence. After the meeting the decisions are kept with the reasons behind them.
“The board wants to know where we stand.”
Saga opens the case, starts the right notification clock and keeps a timestamped history of everything that is done. You see how much time is left and who owns the next step.
“We’ve had an incident.”
Saga assembles the response from approved evidence and records exactly what was sent, and when. If the regulator asks again, you know exactly what you submitted.
“The regulator got in touch.”
Saga has a way of working for every situation, with steps, owners, templates and deadlines, fitted to the regulations that apply to you. We’re happy to show it in a demo.
Tell us your frameworks and your structure. We’ll show you the parts that matter to you.
Compliance work touches contracts, incidents and personal data. This page sets out how Saga protects them: where your data lives, who can access it and how AI is used.
Last updated October 2026
Saga runs with an established cloud provider in a data centre in Frankfurt, Germany. All customer data is stored and processed there, and your data does not leave the EU. The database is backed up every night, and uploaded files are backed up separately.
All traffic between you and Saga is encrypted with HTTPS and TLS. Stored data sits on disks that are encrypted at rest.
Only the people you invite can access your workspace. Each company has its own bounded workspace with its own permissions, including when several companies belong to the same group or portfolio. Sign-in with your company’s Microsoft account (Entra ID) and automatic user provisioning with SCIM are on the way.
Saga uses AI to read, summarise and draft, and the AI runs entirely within the EU. Your data is never used to train models. Every answer cites its source, meaning the regulation, the policy or the evidence behind it, and every consequential decision is approved by a named person on your side. Saga does not turn missing records into a confident “compliant”.
Saga processes your personal data as a processor under the GDPR, and you get a data processing agreement. Saga is not certified under ISO 27001 or SOC 2 today. Work towards certification is under way.
Before a purchase or a review we share what your security team needs.
Have you found something that looks like a vulnerability or a security issue in Saga? Get in touch right away and we’ll come back to you as soon as we can.
Contact usIn a data centre in Frankfurt, Germany. Your data does not leave the EU.
No. Customer data is never used to train AI models.
Only the people you invite. Each company’s workspace runs inside its own boundary and permissions, including within a fund portfolio.
No. Saga organises the work, drafts and flags. Conclusions are approved by your people and can be traced to the record behind them.
Not today. Saga is not certified under ISO 27001 or SOC 2, and work towards certification is under way.
Sign-in with Microsoft Entra ID and user provisioning with SCIM are on the way.
Yes. Contact us and we’ll share our documentation and answer your questionnaire.
We’ll walk your security team through hosting, access and how Saga uses AI.
What is on the way, and guides to the rules that take the most time.
Dates when new rules start to apply, taken from the regulations catalogue and checked in October 2026.
20264
20275
Short walk-throughs of what most often causes trouble, written for the people doing the work.
Sweden’s Cybersecurity Act has applied since 15 January 2026. It implements the EU’s NIS2 Directive and affects far more companies than the law it replaced. Here is what matters, in five minutes.
The Act applies to organisations in 18 designated sectors, including energy, transport, health, drinking water, digital infrastructure, food and manufacturing. As a main rule you are covered if you have at least 50 employees or an annual turnover above EUR 10 million. Some organisations are covered regardless of size, and their suppliers feel the requirements too, through their contracts.
Organisations are classed as essential or important, mainly by sector and size. The security requirements are broadly the same, but supervision is stricter for essential entities. Fines can reach 2 per cent of global turnover or EUR 10 million for essential entities, and 1.4 per cent or EUR 7 million for important ones.
You must register with the supervisory authority for your sector and run systematic, risk-based security work. It covers, among other things, risk analysis, incident handling, continuity and backups, supply chain security, training and access control. Management must approve the measures, follow them up and take training itself.
A significant incident must be reported to the Swedish authority MCF (Myndigheten för civilt försvar) in three steps: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. The clock starts when you detect the incident, so it has to be decided in advance who assesses and who reports.
Start by working out whether you are covered and in which category. Then register with the supervisory authority, run a gap analysis against the requirements and assign an owner to every measure. Make sure management gets its training early, and rehearse incident reporting before you need it.
This guide is an overview and does not replace legal advice.
When something goes wrong several clocks start at once, and they run for different lengths. Here are the most common deadlines side by side, so you know what applies before it happens.
| Regulations | What is reported | Deadlines |
|---|---|---|
| Cybersecurity Act (NIS2) | Significant incident, to MCF | 24 hours, 72 hours and one month |
| GDPR | Personal data breach, to the Swedish Authority for Privacy Protection (IMY) | 72 hours |
| DORA | Major ICT incident, to Finansinspektionen | 4 hours after classification and at most 24 hours after detection, then 72 hours and one month |
A significant incident is reported to MCF. First an early warning within 24 hours, then an incident notification within 72 hours with an initial assessment, and last a final report within one month of the notification.
A personal data breach must be notified to the Swedish Authority for Privacy Protection (IMY) within 72 hours of you becoming aware of it, unless it is unlikely to result in a risk to the people concerned. If the risk is high, they must also be told, without undue delay. Every breach must be documented, including those that are not notified.
Financial entities must report major ICT incidents to Finansinspektionen. The initial notification is due within four hours of the incident being classified as major, and at most 24 hours after it was detected. An intermediate report follows within 72 hours and a final report within one month.
One and the same event can trigger several reports. A breach at an energy company where customer data leaks may require both an early warning under the Cybersecurity Act and a notification under the GDPR. So decide in advance who classifies the event, and keep a timestamped log from the first minute.
This guide is an overview and does not replace legal advice.
ISO 27001 is the international standard for information security management systems. A certificate shows customers and owners that your security is in order. This is what the path there looks like.
The standard has two parts. One is the requirements on the management system itself, such as scope, risk assessment, objectives, internal audit and management review. The other is Annex A with 93 controls in four groups: organisational, people, physical and technological. You choose which controls are relevant and justify the choice.
First decide what the certificate should cover: the whole company, a service or a business unit. Then run a gap analysis that compares where you are with the requirements and shows what is missing. That becomes your work plan.
Assess the risks to your information and decide how each one is to be treated. The result is summarised in a statement of applicability, which shows which Annex A controls you apply and why. It is the document the auditor reads first.
Certification is not about having policies but about being able to show they are followed. Collect evidence as you go: logs, minutes, training records and completed checks. Before the audit you carry out an internal audit and a management review.
The certification audit has two stages. In stage 1 the auditor reviews the documentation, and in stage 2 that the management system works in practice. The certificate is valid for three years, with a surveillance audit every year.
This guide is an overview and does not replace legal advice.