Regulation archetype
Finnish public-sector software supplier
Finnish public-sector suppliers should expect GDPR, ISO 27001-style security management, NIS2 pressure in relevant sectors, and procurement-specific criteria such as Julkri or Katakri depending on contract sensitivity.
- Likely now
- 4 planning items
- Possible later
- 4 to watch
- Next steps
- 3 to run
- Last reviewed
- May 2026
Company profile
A Finnish or EU software company bidding for public-sector contracts or handling public administration data.
Likely planning items
Framework
Planning weight
- GDPRPlan now
- ISO 27001Plan now
- JulkriPlan now
- NIS2 supply-chain pressurePlan now
Possible additional pressure
Framework
Planning weight
- KatakriWatch
- eIDAS2Watch
- DORAWatch
- Cyber EssentialsWatch
Next steps
- 01Confirm the procurement criteria and information classification level.
- 02Map technical controls, ownership, continuity, and access evidence before tender review.
- 03Keep public-sector evidence reusable across ISO 27001, NIS2, Julkri, and Katakri work.
This page is a practical planning guide, not legal or audit advice. Use it to scope questions before confirming obligations with legal, audit, or regulatory specialists.
Other company profiles
- EU B2B SaaS company with 15-100 employeesLikely now: GDPR, ISO 27001, SOC 2, NIS2 supply-chain pressure.
- EU fintech or software supplier to financial customersLikely now: GDPR, ISO 27001, SOC 2, DORA due diligence.
- EU SaaS company building or embedding AILikely now: GDPR, EU AI Act readiness, ISO 27001, AI governance controls.