What is Cybersecurity BAS according to SSF 1101?
  
Cybersecurity BAS according to SSF 1101 is a standard that establishes fundamental guidelines for protecting organizations’ information assets from various cyber threats and security risks. It focuses on identifying, managing, and reducing risks from potential cyberattacks, as well as promoting a culture of security within the organization. By following this standard, companies can improve their ability to handle cybersecurity incidents and minimize potential damage.  
Svensk Certifiering is authorized to certify according to SSF 1101 by the Swedish Theft Prevention Association (SSF) in accordance with requirement standard SSF 1130, edition 1, decision 250123.
 
Benefits of becoming SSF 1101 certified with Svensk Certifiering:
  
With us, added value is included in the form of random audits performed by independent third-party reviewers, ensuring for you and your customers that the requirements are consistently met.
  
By becoming certified according to SSF 1101, organizations demonstrate that they prioritize information security and have established fundamental IT security principles within six main areas.
  
  
- Management of computers and mobile devices
- Secure use of software and applications
- Network protection
- Secure delivery and management of IT services
- Effective management of access rights and controls
- Implementation of training to raise awareness of security practices
- Credibility: Svensk Certifiering is one of the leading certification bodies for fire and security in the Nordic region, ensuring confidence among both customers and stakeholders.
- Market value and trust: Certificates and certification marks from Svensk Certifiering carry high market value and strengthen your organization’s credibility among industry peers and customers. Holding a certificate demonstrates a serious and professional approach to information security.
SSF 1101 – An Alternative to ISO 27001
  
The SSF 1101 certification is an excellent choice for organizations that wish to strengthen their information security without undergoing the more extensive and costly ISO 27001 certification. While ISO 27001 is aimed at companies with advanced security needs and requires significant resources, SSF 1101 offers a more accessible and cost-effective solution for organizations seeking essential cybersecurity protection.
  
Certification Costs
  
Introductory Price
  
  
- Application fee for certification: 4,500 SEK (excl. VAT)
- Annual control fee: 2,200 SEK (excl. VAT)
The certification is valid for three years, with annual follow-up audits to ensure that the organization continues to meet the requirements of the SSF 1101 standard.
  
How to become certified according to SSF 1101 – The 6-step process
  
  
- Application – Apply for certification by submitting an expression of interest via our website or by contacting us directly by phone.
- Self-declaration – To verify compliance, you complete a questionnaire describing your current security level.
- Review and completion – During a mandatory review session, we go through the declaration, perform random checks, and request any necessary additions.
- Formal confirmation – An authorized company signatory confirms the accuracy of your information.
- Issuance of certificate – After a successful review, we issue your certificate, valid for three years.
- Annual follow-up – During the certificate’s validity period, we conduct annual follow-up audits to ensure continued compliance with the SSF 1101 requirements.
Requirements for Cybersecurity BAS according to SSF 1101
  
To meet the SSF 1101 standard, the organization must fulfill the following requirements:
  
Basic requirements:
  
  
- The organization must be a legal entity.
- The company’s self-declaration must be correctly completed and signed by an authorized signatory.
Examples of additional security requirements:
  
To strengthen the organization’s cybersecurity, the following measures are required, among others:
  
  
- Strong passwords: All user accounts on computers and mobile devices must be protected with strong, unique passwords.
- Encryption: When possible, storage on computers and mobile devices should be encrypted to protect sensitive information.
- Backup: The organization must perform regular backups and verify backup data through random checks.
- Protection against malicious code: All devices connected to external networks must have software that detects and prevents malware.
- Use of personal equipment: The organization must have clear guidelines for whether and how personal equipment may be used within operations.
- Firewall protection: At least one network device with firewall functionality must be installed between internal and external networks to protect against unauthorized access.