Framework reference
Katakri for EU B2B software companies.
Katakri is relevant when a company handles classified information or bids for Finnish defense, intelligence, ministry, or high-assurance public-sector work. It is not a general SaaS requirement, but it can become decisive for Finnish public-sector contracts.
- Kaamos support
- Information only
- Category
- Public-sector and contractual criteria
- Obligation
- Binding
- Last updated
Who it applies to
- Suppliers handling classified information for Finnish authorities.
- Companies bidding for defense, intelligence, or ministry contracts.
- Teams that need high-assurance physical, administrative, and information security evidence.
What you need to do
- Security management, personnel, physical, and information-security controls.
- Evidence that protected information is handled according to national criteria.
- Audit readiness for public-sector assurance processes.
How to use this entry
- Use this page to understand the buyer or regulatory pressure before it becomes a deadline.
- Run the regulation checker to see whether this area is likely to matter for your company now.
- If it becomes relevant, Kaamos can help you scope the gap and turn it into prioritized security work.
Sources
- Ministry for Foreign Affairs: Katakri, the authorities' information security auditing tool
- Katakri 2020: Information Security Audit Tool for Authorities (NSA Finland, PDF)
- Ulkoministeriö: Katakri 2020 -kriteeristö, PDF (FI)
- Traficom NCSA-FI: assessment and accreditation of classified information systems
- Traficom: information security inspection bodies accredited for Katakri 2020
- Finlex: Laki tietoturvallisuuden arviointilaitoksista 1405/2011 (FI)
Company profiles this applies to
- Finnish public-sector software supplier — watches Katakri as it grows.
Information bank
Katakri is included as an information-bank entry. Use it to understand the pressure, then run the checker to see whether it should enter your roadmap.