Accessibility Directive – digital services, new requirements from June 28, 2025

Accessibility Directive – digital services, new requirements from June 28, 2025.

For the vast majority of private companies, your website, e-commerce or web service will have to meet a number of requirements by June 28, 2025 that previously only applied to authorities. That is when we will get a new law in Sweden based on the Accessibility Directive, which is about making electronic services accessible to everyone. The law is based on The European Accessibility Act, EAA, and means that companies need to ensure that websites, products and services are usable for everyone. Lack of compliance can lead to fines and products being removed from the market.

Approximately 20% of Sweden’s population lives with a physical, mental or intellectual disability. If we include temporary and situational impairments, the figure is even higher. In order for your service to be inclusive and not exclude anyone, it needs to be adapted for people with, for example, impaired vision, hearing, motor skills and concentration.

The Accessibility Directive applies in principle to all companies in the private sector. There are exceptions and these are companies that are referred to as micro-enterprises. A micro-enterprise is a company with fewer than 10 employees and a turnover of less than EUR 2 million. This distinction is made because the effort for these companies is too large in proportion to the size of the companies.

There are a few more exceptions and it depends on the type of service and the size of the effort that the measure requires. For example, map services are not covered as these are considered difficult to adapt to accessibility as they are based on being able to see what you are interacting with. Older content and archived material can also be considered to fall outside the legal requirement. In terms of effort, the work to adapt the product or service to accessibility must not be too much of a benefit for the benefit it would entail, or require too fundamental changes. This is a grey area, there is no right or wrong, but a case-by-case assessment is required.

If you do not adapt your service or product to accessibility, and the shortcomings are considered too great in relation to legal requirements, there may be penalty fees. However, it should be said that you will first receive warnings requesting you to adapt your service or product. If you, despite these warnings, do not take any corrective action, the penalty fees in Sweden range from SEK 10,000 up to SEK 10,000,000 depending on the size of your company and your target group. The Swedish Post and Telecom Agency (PTS) is the coordinating authority with the mission of ensuring compliance with the Accessibility Directive.

In addition to the above, it should also be borne in mind that, as mentioned, there are approximately 20% of the population who are potentially excluded and cannot use your product or service, and this can ultimately affect both your brand and the ability of your company to achieve its full potential.

It is important not to fall into the feeling that there is a long way to go until June 28, 2025. Keep in mind that this is the latest date for implementation. If you have any concerns about how this will affect you, we have the resources you need.

What do you know about DORA?

DORA (Digital Operational Resilience Act) is a comprehensive regulatory framework within the EU for managing digital risks in the financial sector. Through DORA, the scope is expanded from only looking at the financial situation of companies to also include stability in their operations. This takes into account how well they cope with various business-impacting digital incidents, cyber threats and other IT problems. The purpose of DORA is to ensure that financial institutions and market participants are equipped to manage and prevent cyber threats, while maintaining operational stability. This is particularly important given the increasing digitalization of the financial sector and the increasing number of cyber attacks. Companies must broaden their view of identifying resilience for critical functions and underlying processes. They will need to improve their understanding of critical business processes, improve their detection capabilities and incident management routines, expand their testing of critical ICT systems and work closer with their suppliers, who will also have the same obligations. The regulatory framework and its follow-up are under the responsibility of the European Supervisory Authorities (ESAs). ESA will have the power to request information, carry out inspections and issue recommendations, administrative sanctions and remedial measures.

DORA should be seen as a catalyst for strategic improvements in companies’ risk management and increase management awareness of the consequences of serious operational disruptions and increased understanding of the organization’s limitations.

From an EU perspective, nearly 25,000 financial companies and ICT providers are covered by DORA. Those covered include banks and other credit institutions, investment firms, insurance companies, crypto asset providers, data reporting providers and cloud service providers.

The regulations take a cohesive approach to effective risk management, the organization’s ability to manage IT and cybersecurity risks and the management of third-party risks. This is to achieve stability and structure in its entire service delivery. Looking at the regulations, the following points are particularly central:

  • Risk management of ICT services.
  • Reporting of ICT-related incidents.
  • Testing of digital resilience.
  • Risk management of third-party ICT service providers.

Companies affected by DORA should be prepared for increased supervision. When it comes into force, both Swedish and EU regulators will receive extensive new mandates and powers. Looking at experiences from the UK and their new regulatory framework, the authorities have been “pressure testing” companies and asking affected companies about their recovery plans and processes already the same week the regulations were implemented. In other words, companies should, given the tight timeframes, focus on areas that require review by regulators.

The regulation came into force on 16 January 2023, which means that organisations covered by DORA have until 16 January 2025 to comply with its requirements. That means there is now only one year left.

What should you as a company do?

A GAP analysis based on the requirements of DORA should be initiated immediately to identify the deficiencies that will need to be addressed in 2024.

How can Upgraded help?

We have specialists who can help you understand the regulation and its impact on your business, identify the actions that need to be taken, and have access to the resources to implement the changes required to become DORA compliant.

Upgraded signs a four-year framework agreement with the Swedish National Debt Office

Upgraded has signed a four-year framework agreement with the Swedish Debt Office that covers the provision of specialists in several areas of expertise such as, Management and Governance/Business Development, System Development, Infrastructure, Architects, IT Security, Testing and Service Desk.

“We are pleased to continue to be trusted to support the Swedish National Debt Office in their operations by providing value-creating IT consultants. As account manager, I look forward to being a part of working and further developing their important function in society,” says Hanna Werner, Team Lead at Upgraded People AB.

The Swedish National Debt Office is the central government financial administration and also has assignments that contribute to safeguarding financial stability. The Swedish National Debt Office is a government agency that reports to the Ministry of Finance. It is the Government that appoints the board and the Director of the Swedish National Debt Office, who is the highest-ranking manager of the Swedish National Debt Office. The Swedish National Debt Office was founded in 1789.

“That Upgraded wins this type of framework agreement is clear proof that we create value for our clients. We want to help our clients in their quest to find relevant and sought-after expertise in today’s competitive climate.

These successes are a result of the work and values ​​we work for in the organization with a wonderful drive, quality and helpfulness of all fantastic employees.” says Hanna.

2023 – A record year for Upgraded People AB

The year 2023 has been a record year for Upgraded People AB, which presents a turnover growth of 51% and turnover for the full year of 1,058 million sek (701 million sek). During the year, we have worked intensively to diversify the service offering, strengthen collaborations and improve the customer experience. Looking at the last three years, the turnover growth is 322%.

Going against the grain and being able to present such strong growth in the weaker economic climate that has characterized 2023 feels fantastic and is proof of the competence and driving force that exists in the organization, says Birgitta Hedegård, CEO of Upgraded People AB.

Upgraded’s growth philosophy is based on an organic growth journey. Growing organically is a basic requirement for a service-driven company to develop and maintain its attractiveness for both employees, customers and partners. The culture in the company and the execution power of each individual are what make Upgraded what it is and the results speak for themselves, continues Birgitta.

Upgraded offers the market tailored solutions to meet the unique needs and wishes of its clients. We provide the right resources at the right time to enable our customers’ goals and visions for the benefit of the individual, organizations and society. We have a focus on services that lead the digital transformation in order to sleeplessly take on the challenges and opportunities of the future.

Today, we operate across a large number of industry segments in the Nordic market, such as:

  • Banking, Finance and Insurance
  • Public Sector
  • Manufacturing
  • Retail
  • Transport
  • Energy
  • Telecom

With 15 years of experience from acting as a competence catalyst for forward-thinking companies and organizations in both the private and public sectors, we have a solid network of specialists in a wide range of services such as System Developers, Project Managers, Architects, Testers, Test Managers, Management Consultants, Change Managers, Copywriters, ADs, UX/UI, SEO/SEM, BI, AI, etc. always ready to support our clients.

Important events during the year

  • New CEO Birgitta Hedegård with many years of experience from leading positions in both consulting brokerage and IT and Digital communication.
  • Internationalization in that Upgraded is establishing itself outside Sweden’s borders for the first time through its entry into Norway and Denmark.
  • Several new strategic framework agreements signed in both the public and private sectors.
  • The growth journey is recognized by Dagens Industri through the awarding of DI Gasell 2023.

NIS2; An Updated NIS Directive – How Does It Affect Your Business?

On 18 October 2024, the NIS2 Directive will enter into force in the EU, replacing the original NIS Directive. The upgraded directive aims to improve collective cybersecurity within member states. This means that more organisations will have to meet stricter cybersecurity requirements. In this article, we will give you a summary of NIS2, find out what it is about, whether the directive affects your organisation and what you should do if so. What new security requirements are placed on these organisations and what is required to meet the new requirements? How do you get started with NIS compliance?

What are the major changes in NIS2?

  • More sectors of organizations will be affected.
  • Minimum requirements for actions will be introduced.
  • More precise reporting requirements will be implemented.

Is your organization covered by the new NIS Directive?

The NIS Directive was created to increase the Union’s level of security within network and information systems for essential services. The NIS Directive covered the following sectors, which are unchanged in NIS2:

Essential units:

  • Energy
  • Transport
  • Banking
  • Financial Market Infrastructure
  • Healthcare
  • Drinking Water Supply and Distribution
  • Digital Infrastructure

However, from the first directive it has been identified that even more sectors need to be included and therefore it has been expanded to also include:

Other important devices:

  • Wastewater
  • ICT service management
  • Public administration
  • Space services
  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacture of certain essential products such as pharmaceuticals
  • Digital providers such as social networking platforms
  • Research

Organizations are also divided into essential and important entities, based on their importance to the sector they belong to, as well as their size.

What happens if the NIS2 Directive does not apply to me?

It is not entirely clear which activities actually fall into each sector and even if your organisation will not have to comply with the NIS2 Directive you may still want to consider building your security work to comply with the Directive. The organisations covered by NIS2 are many and these organisations must ensure that their suppliers are also secure. This means that many companies will ultimately have to comply with the NIS2 Directive because the companies they work with do. This makes NIS2 a directive that most of us should be aware of.

Ten basic security measures required by NIS2

According to NIS2, organizations must take appropriate and proportionate risk management measures to prevent security incidents and minimize their impact. NIS2 includes a list of 10 basic measures that all organizations must take:

  1. Information systems risk analysis and security guidelines
  2. Incident management
  3. Business continuity, such as backup and disaster recovery, and crisis management.
  4. Supply chain security, including security-related issues related to the relationship between each business and its direct suppliers or service providers.
  5. Security in the acquisition, development, and maintenance of networks and information systems, including vulnerability management and disclosure.
  6. Policies and processes for assessing the effectiveness of cybersecurity risk management measures.
  7. Secure cybersecurity fundamentals and cybersecurity training
  8. Policies and procedures for the use of cryptography and, where applicable, encryption
  9. Human resource security, access control policies, and asset management
  10. Use of multi-factor authentication or continuous authentication solutions, secure voice, video, and text communications, and secure emergency communication systems within the organization, where applicable.

Upgraded People AB signs agreement with Landskrona City and Eslöv Municipality for an estimated value of 90 million SEK

Upgraded People AB has signed an agreement with the City of Landskrona and the Municipality of Eslöv for comprehensive IT consultancy services with an estimated value of 90 million sek.

By acting as a broker of expertise in the IT sector, Upgraded People AB has established itself as a reliable partner for companies, authorities and organizations that strive to improve their technical infrastructure. The agreement with the City of Landskrona and the Municipality of Eslöv means that Upgraded People AB will bring together competent IT experts with the cities’ needs for qualified services within Business Development and Strategy, Management and Governance, System Development and System Management, Data & Analysis, Information and IT Security, Usability, Infrastructure and Technology, and IT Support and Training.

“We always strive to offer our clients tailor-made solutions through a careful matching of qualified consultants with each client’s unique requirements and needs. We are very proud to have received this trust from Landskrona City and Eslöv Municipality and look forward to a stimulating and developing collaboration for all parties,” says Birgitta Hedegård, CEO of Upgraded People AB.

Upgraded People AB are experts in the placement of consultants with a specialization in the IT area. Upgraded was started in 2010 and is today established in 5 locations and has over 1000 consultants engaged in assignments across the Nordic market. Turnover for 2023 amounted to just under 1.1 billion.