Writing
Writing, from our own data
We publish what we can show. Every piece below rests on a dataset we maintain and cite, and where you can re-run the query yourself, we say how.
CRA Article 13 for a software manufacturer: the twenty-five paragraphs in order, which are yours, which are the Commission's, and a checklist by role
Article 13 of the Cyber Resilience Act is the manufacturer's article: twenty-five paragraphs from the essential requirements of paragraph 1 to the Commission's powers of paragraph 25. Twenty-one of them are duties a software manufacturer carries, from the product risk assessment and the due diligence on components to the support period, the single point of contact, the technical documentation kept for ten years, the corrective measures and what to do before ceasing operations; two are options, two belong to the Commission and the authorities. Article 14 adds the reporting clocks, Articles 19 and 20 the importer's and distributor's duties, Article 24 the steward's, and Annex I the requirements the product must meet. A free page lists every row that binds your role, in the Official Journal's words in six languages, with a status per row.
13 September 2026
The Data Act for a SaaS company: the switching duties since 12 September 2025, the nine contract terms, the end of switching charges, and what a data holder owes
Regulation (EU) 2023/2854 has applied since 12 September 2025, and a company that sells hosted software is a provider of a data processing service under it, whatever its size. Chapter VI makes it remove every obstacle to a customer switching provider or moving on-premises: a written contract with the nine terms of Article 25(2), a notice period of at most two months, a transitional period of at most 30 calendar days, a retrieval period of at least 30 calendar days, erasure after it, an online register of the exportable data, open interfaces free of charge, a website statement on the jurisdiction the infrastructure is subject to, and switching charges that are cost-based now and forbidden from 12 January 2027. A company whose product is a connected product or a related service is also a data holder under Chapter II, with access by design for products placed on the market after 12 September 2026. The 96 rows of the Regulation that bind each role are a dataset in six languages.
13 September 2026
The ISO 27001 corrective action record: what Clause 10.2 asks for after a nonconformity, the seven sections an auditor accepts, the mistakes that reopen a finding, and a page that writes it
Clause 10.2 is what happens to a nonconformity once it is found: correct it and deal with what it caused, find the cause, ask whether the same problem exists elsewhere, act so that it does not recur, check that the action worked, change the management system where the cause lived, and keep the nonconformity, the actions and their results as documented information. A record an auditor accepts has seven sections in that order, separates the correction from the corrective action, and stays open until the check shows the action worked. A free page writes the record from the finding, the correction, the cause, the action with its owner and date, and the effectiveness check.
13 September 2026
The ISO 27001 information security policy: what Clause 5.2 asks for, the nine sections of a short policy, the mistakes an auditor flags, and a page that writes it
Clause 5.2 asks top management for one policy that fits the company's purpose, carries the security objectives or the frame for setting them, commits to the requirements that apply and to improving the system, and is documented, communicated and available to the parties that need it. That is seven things, none of them a page count. A good policy for a software company runs to two pages in nine sections: purpose, scope, why security matters here, commitments, objectives, roles, the topic policies under it, compliance, and communication and review. The mistakes an auditor flags are the template with another company's name in it, the thirty pages nobody read, the missing approval, objectives nobody can measure and a policy no new joiner has seen. A free page writes the policy from ten answers in six languages.
13 September 2026
The ISO 27001 management review: the seven inputs of Clause 9.3 as an agenda, the four trends, the two outputs, what the minutes have to show, and a page that writes them
Clause 9.3 has top management review the management system at planned intervals against seven inputs: the actions from the last review, changes in the external and internal issues, changes in what interested parties need and expect, feedback on performance with its four trends (nonconformities and corrective actions, monitoring and measurement, audit results, the objectives), feedback from interested parties, the risk assessment and the treatment plan, and the opportunities to improve. The outputs are two: decisions on continual improvement and any changes the system needs, kept as documented information. The minutes an auditor accepts show each input considered and each decision taken, with an owner and a date on every action. A free page writes the minutes in the clause's order from the meeting facts, the counts and what was said.
13 September 2026
The ISO 27001 risk assessment for a software company: what Clause 6.1.2 asks for, a five-point method, the starter risks, and a page that writes the register and the treatment plan
Clause 6.1.2 does not prescribe a method; it prescribes what the method must produce: criteria for accepting risk and for assessing it, an identification of the information security risks, an analysis of their consequences and likelihood, an evaluation against the criteria, and repeatable, comparable results. Clause 6.1.3 then asks for the treatment options, the controls, the comparison with Annex A, the Statement of Applicability and the plan. For a software company the risks are largely known before the first workshop: credential compromise, a lost laptop, a cloud provider outage, a backup that does not restore, a departing employee with access left open, a vulnerability shipped in its own code. A five-point scale for likelihood and impact, the product as the level, an acceptance threshold, the treatment option and the controls for each risk above it, and a free page that writes the register and the plan in six languages.
13 September 2026
The ISO 42001 AI policy for a software company: what Clause 5.2 asks for, the ten sections, the AI Act duties it names, the mistakes an auditor flags, and a page that writes it
Clause 5.2 of ISO/IEC 42001 asks top management for an AI policy that fits what the company uses AI for, gives the frame for the AI objectives, commits to the requirements that apply and to improving the system, is documented, communicated and available, and says how it sits beside the other policies. Three Annex A controls, A.2.2, A.2.3 and A.2.4, ask for the policy, its alignment with the other policies and its review. A short AI policy for a software company runs to ten sections: purpose, scope, position, the uses ruled out, accountability, objectives, the requirements that apply, the other policies, communication and review. The requirements section is where the AI Act enters: the literacy duty of Article 4, the transparency duties of Article 50 where the company generates content, and a recorded high-risk determination per system that the policy itself never asserts. A free page writes the policy from eleven answers in six languages.
13 September 2026
The ISO 42001 AI system impact assessment: what Clause 6.1.4 asks for, the three levels of consequence, where it meets the AI Act, the mistakes an auditor flags, and a page that writes it
Clause 6.1.4 of ISO/IEC 42001 has the company assess what each AI system could do to the individuals and groups it touches and to society, keep the result as documented information, and act on it through the system's life cycle; Clause 8.4 runs the process and four Annex A controls ask for the process, the retention, the harm to individuals and groups, and the harm beyond the users. It is the record the standard has and ISO 27001 does not. An assessment an auditor accepts names the purpose and the foreseeable misuse, the people, the consequences at the three levels with a likelihood and a severity each, the benefits, the measures, a result and a review date; under the AI Act it is the input to the Article 27 fundamental rights impact assessment and the place the company's own reading of the system is recorded. A free page writes it for one system.
13 September 2026
The NIS2 incident clock for a software company: the 24-hour early warning, the 72-hour notification, the one-month final report, what makes an incident significant for a cloud provider, and a page that writes the three reports
Article 23(4) of NIS2 runs three clocks from the moment an essential or important entity becomes aware of a significant incident: an early warning within 24 hours, an incident notification within 72, and a final report within one month of that notification, with an intermediate report on request and a progress report where the incident is still open. For a cloud computing service provider, Implementing Regulation (EU) 2024/2690 says when an incident is significant: a direct financial loss over EUR 500 000 or 5 % of turnover, whichever is lower, a service completely unavailable for more than 30 minutes, availability limited for more than 5 % or 1 million of its users in the Union for more than an hour, or a suspectedly malicious compromise of data. What each report contains, which CSIRT it goes to, and a free page that computes the deadlines and writes all three in six languages.
13 September 2026
AI literacy under Article 4 of the AI Act, as rewritten on 27 July 2026: what 'take measures' means, who it covers, what it does not require, and the record to keep
Article 4 has applied to every provider and deployer of an AI system since 2 February 2025. The Digital Omnibus rewrote it: measures to support the development of AI literacy, taking account of people's knowledge and the context, and, in terms the Regulation now uses, no duty to guarantee any specific level of literacy of any individual. The Commission is to publish practical examples and the AI Board common objectives. What the article asks, why it has no fine of its own in Article 99, how ISO 42001's competence and awareness clauses produce the record, and a one-page programme.
12 September 2026
Article 50 of the AI Act for a company that ships or uses generative AI: the four transparency duties in force since 2 August 2026, the 2 December 2026 transition, the code of practice and the EU icon
Article 50 is the AI Act obligation that reaches a company whether or not its system is high-risk: tell people they are talking to an AI, mark generated content so machines can detect it, disclose deep fakes and AI-written text on matters of public interest, inform people exposed to emotion recognition. It has applied since 2 August 2026, the Digital Omnibus left it unchanged and gave providers of generative systems already on the market until 2 December 2026 for the marking duty. The four paragraphs read in order, who is provider and who is deployer for each, the Commission's code of practice of 10 June 2026 with its two-layer marking and its AI icon, the fine, and the record an ISO 42001 system keeps.
12 September 2026
Does ISO 9001:2015 require a quality manual? What clause 7.5 asks for instead, the 21 places the standard names documented information, and what a manual is for today
ISO 9001:2008 required a quality manual; ISO 9001:2015 does not, and says so in its Annex A. What it requires is documented information: five things to maintain (the scope, the process information, the quality policy, the objectives, the operational planning) and sixteen kinds of record to retain, each named by clause. What clause 7.5 asks of every document, why a manual is still the right place for the map of the system, and what to put in it. With the count of EU tender notices that asked for ISO 9001 in the last year, 17,076, five times ISO 27001.
12 September 2026
DORA for a software vendor: the Article 30 contract clauses your bank customer will send, the register of information you will appear in, and what ISO 27001 already answers
Since 17 January 2025 every bank, insurer, investment firm and payment institution in the Union manages its software vendors under Regulation (EU) 2022/2554, DORA. The vendor is not regulated; the contract is. Article 30 lists nine clauses every ICT service contract must carry and six more when the service supports a critical or important function: locations, data return, incident assistance at a pre-set cost, cooperation with the customer's authorities, termination notice, audit rights, exit strategies. Each clause read from the Regulation, the register of information the customer files yearly, the three delegated acts behind it, and which of the clauses an ISO 27001 system already produces the evidence for.
12 September 2026
DORA's nineteen types of ICT service, S01 to S19: which one a SaaS product is, what the register of information records about it, and why one contract can be several rows
Every ICT service a bank, insurer or payment institution buys is recorded in its register of information under one of nineteen codes, S01 to S19, from Annex III of Implementing Regulation (EU) 2024/2956. A hosted product is S19, installed software is S13, a managed service S14, a data feed S05, and the customer files one row per service and function, so a single contract can become several. The nineteen types with the Regulation's own descriptions, the column that carries the code, what the customer must record beside it, and why the code you give one customer must match the code you give the next.
12 September 2026
Subcontracting under DORA, RTS 2025/532: the twelve terms your contract carries when you subcontract a critical service, the ten conditions your customer checks first, and the notice period before you change a subcontractor
Since 22 July 2025 a financial entity may let its software vendor subcontract a service supporting a critical or important function only on the conditions of Delegated Regulation (EU) 2025/532. Ten conditions the customer assesses before signing, from your ability to identify every subcontractor to whether the subcontractor grants the same audit rights; twelve terms the contract then carries, from your responsibility for the subcontractor's service to the customer's right to terminate; a notice period during which you may not change a subcontractor until the customer has approved or not objected; and three cases in which the customer may terminate. Read from the Official Journal, with what the register of information records about the chain and what an ISO 27001 supplier register already answers.
12 September 2026
Your bank's DORA vendor policy, RTS 2024/1773: the six due-diligence questions, the five sources of assurance, the eight conditions for accepting your ISO 27001 certificate in place of an audit, and the five reports you will owe
Every financial entity in the Union has a written policy on its contracts for ICT services supporting critical or important functions, and Delegated Regulation (EU) 2024/1773 says what that policy must contain, in force since 15 July 2024. Read from the vendor's side: the six things the customer assesses about you before signing (Article 6), the five sources of assurance it may use and the eight conditions under which it may rely on your certifications or audit reports rather than auditing you itself (Article 8), the key indicators, penalties and five kinds of report the contract will demand (Article 9), and the exit plan it must test (Article 10). With what an ISO 27001 certificate answers, and what it does not.
12 September 2026
Essential or important under NIS2: the size rule, the size-blind rules and the seven ways to be essential
Whether NIS2 reaches a company is Article 2; whether it is essential or important is Article 3; and the difference is ex ante supervision, a higher fine ceiling and a stricter reading of everything else. The two articles quoted, the size classes of Recommendation 2003/361/EC as they are actually counted, the rules that ignore size, and the cases a software company gets wrong: a cloud provider with 40 staff, a large machinery maker, a registrar, a company outside the Union.
12 September 2026
GDPR international transfers for a software company: the 17 adequacy decisions, the four SCC modules, what a US, UK or Indian sub-processor needs, and a page that picks the mechanism
Every hosting provider, support desk, analytics tool and payroll service outside the EEA is a transfer under Chapter V. The Commission's list of adequacy decisions, read on 12 September 2026, carries 17 entries: 16 countries and territories, from Andorra to Uruguay, and the European Patent Organisation, with the United Kingdom renewed in December 2025, Brazil added in January 2026, and the United States covered only for companies certified under the Data Privacy Framework. Everything else needs the standard contractual clauses of Decision (EU) 2021/914, whose four modules follow the roles of the exporter and the importer, with the local-law assessment of Clause 14 before the first transfer; the derogations of Article 49 are for the single occasion, never for a product in use. Read against the catalogue, with a free page that picks the mechanism and writes it.
12 September 2026
Harmonised standards for the CRA: what request M/606 asks for, when, and what a manufacturer has today
Article 27 gives a presumption of conformity to products that follow harmonised standards cited in the Official Journal. On 3 February 2025 the Commission asked CEN, CENELEC and ETSI for 41 of them, with deadlines from 30 August 2026 to 30 October 2027; the three accepted on 3 April 2025. On 12 September 2026 the Commission's index of harmonised standards still has no entry for the Regulation, which for a class I product means no self-assessment route under Article 32(2). What was requested, the dates, and what to build against in the meantime.
12 September 2026
How to check an ISO 9001 certificate is real: what a certificate must show, three checks that take ten minutes, and the 27 accreditation registers
ISO does not certify companies and keeps no register of them, so a certificate is only as good as the body that issued it and the accreditation behind that body. What ISO/IEC 17021-1 makes a certificate show, the three checks (the certifier is accredited for ISO 9001, the certificate is current, the scope covers what you are buying), the 27 national accreditation registers with links, why a certifier in another EU state is as good as one in yours, and why the cheap unaccredited certificate costs more in the end.
12 September 2026
ISO/IEC 27701:2025 for a software company: the standalone privacy standard, its 78 controls, what an ISO 27001 system already covers, and the GDPR articles each control evidences
The second edition of ISO/IEC 27701, published in October 2025, is no longer an extension to ISO 27001: it is a management system standard of its own, with clauses 4 to 10 and one Annex A of 78 controls, 31 for PII controllers, 18 for PII processors and 29 information security controls for both. Read row by row for a software company: which of the 103 requirements a running ISO 27001 system already half-covers and what 27701 asks beyond it, the 33 privacy requirements no security control produces, and the 32 GDPR articles the controls evidence, from the record of processing to the 72-hour breach clock. StandardOS's reading, with the standard's text left where it is.
12 September 2026
ISO 9001 for a software company: what clause 8 means when the product is code, sub-clause by sub-clause
Clauses 4 to 7, 9 and 10 of ISO 9001:2015 are the management-system skeleton an ISO 27001 company already runs. Clause 8, Operation, is the one written for factories and service desks, and the one a software company has to translate. What each sub-clause is when the product is software: requirements review before you commit (8.2), the development life cycle as design and development (8.3), cloud providers and dependencies as external providers (8.4), deployment, traceability, customer data and support as production and service provision (8.5), the release gate (8.6), and bugs and incidents as nonconforming outputs (8.7). With where the Cyber Resilience Act asks for the same records.
12 September 2026
Which EU countries name ISO 9001 in public tenders: 4,897 German notices, 4,743 Romanian, and one in ten Romanian notices names it
Over 365 days, ISO 9001 appears in 16,356 TED notices from EU-27 buyers, 1.87% of everything they published and five times the 3,361 that name ISO 27001. Germany and Romania account for 59% of the mentions; Romania names it in 10.48% of its notices, Bulgaria in 7.34%, Hungary in 7.02%; France, Spain and Italy barely name it. And 1,475 notices name both standards, 44% of every ISO 27001 mention. The table by country, the overlap, and the query to re-run them.
12 September 2026
NIS2 Article 20 for the board: what the management body must approve, oversee and learn, the twelve places the Implementing Regulation names it, and what liability means
Article 20 of NIS2 makes the management body of an essential or important entity approve the cybersecurity risk-management measures, oversee their implementation, be liable for the entity's infringements of Article 21, and follow training. Implementing Regulation 2024/2690 then names the management body in twelve places of its Annex: a dated approval of the policy, an annual review, a direct reporting line, acceptance of residual risk, compliance reporting, an awareness programme. Each of the twelve as a record, the ISO 27001 clause that already produces it, and what Article 32 and Article 34 say liability looks like.
12 September 2026
NIS2 for a SaaS company: you are a cloud computing service provider, and this is what follows
Recital 33 of the Directive names Software as a Service as a cloud service model, so a SaaS company of medium size or larger is an entity of NIS2 as a cloud computing service provider: important below the medium ceilings, essential above them. What follows, in the order it arrives: the state of your main establishment, the registry you had to be in by 17 January 2025, the measures of Implementing Regulation 2024/2690, the four incident thresholds of its Article 7 and the Article 23 clocks, and the line between this and the CRA.
12 September 2026
NIS2 for managed service providers and MSSPs: an Annex I entity by definition, and the supplier every customer's due diligence lands on
Article 6(39) makes anyone who installs, manages, operates or maintains ICT for customers, on site or remotely, a managed service provider, and Article 6(40) makes the ones who help with cybersecurity risk management MSSPs. Both are Annex I types: important at medium size, essential above the ceilings, under the law of the main establishment, in ENISA's registry, under Implementing Regulation 2024/2690 directly, with Article 10's four incident thresholds. And recital 86 tells every essential and important customer to exercise increased diligence in choosing you.
12 September 2026
NIS2 for online marketplaces, search engines and social networks: the Annex II digital providers, and why they are never essential by size
Three definitions borrowed from three other acts decide whether a platform is a digital provider under NIS2: a marketplace where consumers conclude distance contracts, a search engine that searches in principle all websites, a platform where end users connect and share. In scope at medium size, important under Article 3(2) however large, under the law of the main establishment, in ENISA's registry, under Implementing Regulation 2024/2690 with its own incident thresholds in Articles 11 to 13: no 30-minute rule, a share of users instead.
12 September 2026
NIS2 registration: the two lists you may be on, what you submit, by when, and to whom (Article 3(4) and Article 27)
NIS2 has two registrations, not one. Every essential and important entity submits four items to its competent authority so that the member state can establish its list by 17 April 2025 (Article 3(3) and (4)), with changes notified within two weeks. Eleven types of digital entity, cloud providers and managed service providers among them, also submit six items by 17 January 2025 for ENISA's registry (Article 27), with changes within three months. Which state receives it (Article 26), what the two lists are for, what registering does not decide, and the record to keep.
12 September 2026
NIS2 transposition, state by state: what the Commission's own register shows
Not a law firm's tracker: the national measures the member states have communicated to the Commission as transposing Directive (EU) 2022/2555, read from the Publications Office on 12 September 2026. 25 of the 27 states have communicated at least one, 303 measures in all; Spain and Ireland none; France 15 texts, all older than the Directive. The act each state calls its NIS2 law, when it entered into force, and what a software company does with the answer.
12 September 2026
The AI Act after the Digital Omnibus: the dates that changed on 27 July 2026, and which ISO 42001 controls produce the evidence for Article 17's thirteen aspects and Articles 9 to 15
Regulation (EU) 2026/1744, signed 8 July 2026, published 24 July, in force 27 July, moved the AI Act's high-risk dates to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, rewrote AI literacy as a duty to take measures, and made the post-market monitoring plan part of the technical documentation. Most of what ranks still gives the old dates. The dates as amended, what else changed for a provider, and our mapping of Article 17's thirteen quality-management aspects, Articles 9 to 15, 72 and 73, and the operator duties of Articles 4 and 26 to the Annex A controls of ISO/IEC 42001, with what the Regulation asks for that the standard does not produce.
12 September 2026
The AI Act for a software company: which role you are, what applies to everyone, what applies only to a high-risk provider, the SME provisions, and the dates as amended
A software company meets the AI Act in one of six roles, and most of the Regulation only applies to two of them. What counts as an AI system at all, why shipping a vendor's model under your own name makes you the provider, the three duties every company has since 2025 and 2026 (AI literacy, the prohibitions, transparency), the two routes to high-risk and what each role then owes from 2 December 2027, the general-purpose model line, the SME and small mid-cap provisions the Digital Omnibus widened, and one table of who owes what from when. Read from the two Regulations on CELLAR on 12 September 2026.
12 September 2026
The EU declaration of conformity under the CRA: Annex V point by point, the simplified form, and a worked example
Article 28 makes the manufacturer draw up an EU declaration of conformity before the product is placed on the market, in the model structure of Annex V, and Article 28(4) makes signing it the act by which the manufacturer assumes responsibility for the product. The eight points of Annex V, the one-sentence simplified form of Annex VI, the rules around it (languages, the single declaration, product families, 10 years of retention), a worked example, and what a missing or incorrect declaration costs under Article 58 and Article 64.
12 September 2026
The GDPR 72-hour breach clock for a software company: when awareness starts it, what the notification contains, the processor's own clock, and the NIS2, CRA and DORA clocks beside it
Article 33 gives a controller 72 hours from becoming aware of a personal data breach to notify the supervisory authority, and most companies get the start wrong, the content wrong, or the role wrong. When awareness begins under the EDPB guidelines and recital 87, the four contents of Article 33(3), the phases of 33(4), the reasons-for-delay rule, the processor's duty to notify the controller without undue delay, the communication to the data subjects under Article 34 and its three exceptions, and the NIS2, CRA and DORA clocks a software company may be running from the same moment. With the free page that computes the deadline and writes the notification.
12 September 2026
The GDPR data subject request for a software company: the month of Article 12(3), the eight contents of an access answer, the two further months, and a page that computes the deadline
A request under Articles 15 to 22 is answered without undue delay and in any event within one month of receipt (Article 12(3)); the period ends on the same date of the next month, or the last day of it; two further months are available where the requests are complex or numerous, with the data subject told within the first month; a refusal carries its reasons and the remedies within the same month (12(4)); the answer is free unless the request is manifestly unfounded or excessive, and the company bears the burden of showing that (12(5)). An access request is answered with a copy of the data and the eight pieces of information of Article 15(1), (a) to (h), from the purposes to the automated decision-making. Read against the catalogue, with a free page that computes the deadline and writes the answer in six languages.
12 September 2026
The GDPR for a software company: controller of your own data, processor for your customers', and the five duties that turn on size and data
Regulation (EU) 2016/679 reaches every software company, so the question is which duties turn on. The two roles per processing (Article 4), the record of processing that the 250-person exemption never spares a product in use (Article 30), the officer (Article 37), the impact assessment (Article 35), the representative for a company outside the Union (Article 27), the transfer grounds (Chapter V), the 72-hour and one-month clocks, and what ISO 27701 produces for each. Read from the Official Journal, with the free determination that writes it down.
12 September 2026
The GDPR impact assessment for a software company: the three cases of Article 35(3), the nine criteria behind them, the four elements of Article 35(7), and a page that writes it
Article 35 requires a data protection impact assessment before any processing likely to result in a high risk, and names three cases where it is required in any event. Which product features fall into them, the nine criteria the supervisory authorities apply and the rule that two of them usually mean an assessment, the lists the authorities publish under Article 35(4) and (5), the four elements the assessment must contain, the data protection officer's advice and the data subjects' views, the prior consultation of Article 36 with its eight weeks, and the review when the risk changes. With the free page that decides whether one is due and writes it.
12 September 2026
The GDPR privacy notice for a software company: the twelve pieces of Article 13, the thirteen of Article 14, the moment each is given, and a page that writes it
A privacy notice is not a genre; it is a list. Article 13 names twelve pieces of information a controller gives at the time personal data are obtained from the person, six in every case and six further ones for fair and transparent processing, and Article 14 names thirteen for data obtained elsewhere, given within a reasonable period and at the latest within one month, with four exemptions. For a software company, seven of them are columns of its record of processing already. Every piece as the Official Journal words it, the moment it is given, the two cases where it is not owed, and a free page that writes the notice from the answers in six languages.
12 September 2026
The GDPR processor contract for a SaaS company: the eight terms of Article 28(3) every customer addendum carries, the duty most of them forget, and what sits beside them under DORA
A SaaS company signs the same contract with every customer it processes data for, and Article 28(3) fixes its content: the subject matter and duration, the eight undertakings from documented instructions to audits, and the processor's duty to flag an instruction that infringes the Regulation. What each term means for a software vendor, the sub-processor rule of Article 28(2) and (4), the Commission's 2021 standard clauses, the liability of Article 82 and the fine ceiling of Article 83, and the DORA Article 30 clause a bank customer sends beside each term. With the free checklist that reads the two addenda as one.
12 September 2026
The GDPR record of processing for a software company: the seven fields of Article 30(1), the four of Article 30(2), why the 250-person exemption never applies, and a page that writes it
Article 30 is the one GDPR duty every other duty refers back to, and the one most software companies believe the 250-person exemption spares them. It does not: Article 30(5) lifts the exemption for any processing that is not occasional, and a product in use processes every day. The seven fields of a controller's record and the four of a processor's, read from the Official Journal, what each one is for, the ISO 27701 control that evidences it, and the free page that writes the record one activity at a time.
12 September 2026
The GDPR representative of Article 27 for a software company outside the EU: who must appoint one, the three conditions of the exemption, and where the name goes
A software company with no establishment in the Union whose product is used by people in it is under the Regulation by Article 3(2) and must designate a representative in the Union in writing (Article 27(1)), established in a member state where its users are (27(3)), mandated to be addressed by supervisory authorities and data subjects (27(4)), and no shield against action on the company itself (27(5)). The exemption of Article 27(2)(a) has three conditions that must all hold, and a product in use fails the first. Where the representative's name goes: the privacy notice (Article 13(1)(a)), the record of processing (Article 30(1)(a)), and the record the representative keeps itself. The fine tier is Article 83(4). A free page decides it from two questions.
12 September 2026
The ISO 27001 scope statement: why a certificate that says head office does not cover your SaaS, what clause 4.3 asks for, what a buyer under DORA checks, and three scope statements that pass
The scope statement is the certificate's limit, and buyers now read it against a regulation: a financial customer may rely on your ISO 27001 certificate instead of auditing you only if its scope covers the systems it depends on. What ISO/IEC 27001:2022 clause 4.3 requires, what ISO/IEC 17021-1 makes the certificate show, the surveillance cycle that decides whether it is current, the 2013-edition deadline that has passed, one scope statement that fails and three that pass for a software company, and how the interfaces to your cloud provider stay inside the scope while the provider stays outside.
12 September 2026
The ISO 27001 Statement of Applicability for a software company: the 93 controls, the four columns of Clause 6.1.3(d), the exclusions an auditor accepts, and a page that writes it
The Statement of Applicability is the one ISO 27001 document an auditor reads before anything else, and Clause 6.1.3(d) makes it four questions per control: is it necessary, why is it included, is it implemented, and why is any Annex A control left out. For a software company with no offices of its own and a hosted stack, the 93 controls of the 2022 edition sort into the ones that apply in full, the handful that are honestly excluded, and the partly implemented ones that decide the audit's findings. What each column means, the exclusions an auditor accepts and the ones they never do, how the Statement follows the risk treatment plan, and a free page that writes it in six languages with the statuses in the address.
12 September 2026
The ISO 9001 management review: the 13 inputs and 3 outputs of clause 9.3 as an agenda, where each input comes from, and what the minutes have to show
Clause 9.3 of ISO 9001:2015 is the one meeting the standard writes the agenda for. Top management reviews the quality management system at planned intervals for suitability, adequacy, effectiveness and alignment with strategy (9.3.1); considers thirteen inputs, from the status of last time's actions to the performance of external providers (9.3.2); and decides on improvement, changes to the system and resources (9.3.3), with the results retained as documented information. The agenda, the record behind each input, what the minutes must show, and how the same meeting serves ISO 27001 and, for NIS2 entities, the annual policy review the Implementing Regulation requires.
12 September 2026
The ISO 9001 quality policy: the four things clause 5.2 says it must contain, the three things that must happen to it, and a one-page example
Clause 5.2 of ISO 9001:2015 is short and precise. Top management establishes a quality policy that fits the organisation's purpose and context and supports its strategy, gives a framework for the quality objectives, and commits to meeting applicable requirements and to continual improvement (5.2.1). The policy is then maintained as documented information, communicated, understood and applied inside the organisation, and available to interested parties (5.2.2). What each of the seven requirements means for a page of text, the mistakes auditors write up, how the same policy serves ISO 27001, and a one-page example in our own words.
12 September 2026
The nine places where your bank customer's ICT risk framework reaches into your product, RTS 2024/1774: support end dates, vulnerability reports and library tracking, settings you may not let it bypass, source code tested before production, named accounts for your staff, and your incidents as its alarms
Delegated Regulation (EU) 2024/1774, in force since 15 July 2024, specifies the ICT risk management framework every financial entity runs under DORA, and nine of its articles name the ICT third-party service provider. Read from the vendor's side: the asset register that records the end dates of your support (Article 4), the vulnerability procedure that verifies you handle and report vulnerabilities and tracks the third-party libraries in your product (Article 10), the data and system security procedure that allocates roles between you and the customer and asks for measures on your infrastructure (Article 11), encrypted connections over third-party networks (Article 13), source code from providers analysed and tested before production (Article 16), a unique account for each of your staff with access (Article 20), your incident notifications as one of its detection inputs (Article 23), continuity tests that include your service and your insolvency (Articles 25 and 26). With what an ISO 27001 system already answers.
12 September 2026
The ten measures of NIS2 Article 21(2), as a checklist: each point quoted, the Regulation sections behind it, and the ISO 27001 controls that already produce it
Article 21(2) lists ten measures every essential and important entity must take, from risk analysis policies to multi-factor authentication. For cloud, managed service and the other digital providers, Implementing Regulation 2024/2690 details each in 13 sections written from ISO/IEC 27001 and 27002. One table: the ten points as the Directive words them, the sections that detail each, and the ISO 27001 clauses and Annex A controls that produce the evidence, with the two places an ISMS does not reach.
12 September 2026
Threat-led penetration testing under DORA, from the vendor's side: when your bank customer's red team is allowed into your production systems, the 12-week test of RTS 2025/1190, the pooled test you can run instead, and what the contract already says
Article 26 of DORA makes the largest financial entities run a threat-led penetration test on live production systems at least every 3 years, covering the critical or important functions they have outsourced, and Article 30(3)(d) puts the vendor's participation into the contract. Delegated Regulation (EU) 2025/1190, in force since 8 July 2025, sets the mechanics: a control team that may include your staff, a blue team that must not know, an active red team phase of at least 12 weeks, a replay and purple teaming within 10 weeks of its end, a remediation plan within 8 weeks. Article 26(4) lets a vendor whose other customers would be harmed contract an external tester directly and run one pooled test for several financial entities. What the vendor signs, what it may refuse, and what an ISO 27001 system already holds. Read from the Official Journal.
12 September 2026
What a deployer of a high-risk AI system owes under Article 26 of the AI Act: the twelve paragraphs in order, the Article 27 impact assessment, when you become the provider, and the records an ISO 42001 system keeps
Most companies will meet the AI Act as deployers: they buy or licence a system someone else built and use it under their own authority. For a high-risk system the duties are in Article 26, twelve paragraphs, unchanged by the Digital Omnibus, applying from 2 December 2027 for Annex III systems. Each paragraph read in order, the Article 27 fundamental rights impact assessment and who carries it, the three ways a deployer becomes the provider under Article 25, the Article 86 right to explanation, the Article 99 ceiling, and the ISO 42001 control that produces each record.
12 September 2026
What ISO 9001 certification costs: the audit days IAF MD 5 fixes by headcount, the day rate, the three-year total, and why it is a third of ISO 27001
Certification bodies do not publish prices, but the audit days are not their opinion: IAF MD 5 sets them by the number of people in scope, 1.5 days for up to five people, 3 for 16 to 25, 7 for 86 to 125, and the accreditation body holds the certifier to the table. Multiply by a day rate of 1,200 to 1,800 euros, add two surveillance audits at about a third each, and you have your number before anyone quotes you. Worked for six company sizes, with the ISO 27001 days beside them, what moves the number up or down, and what else you pay.
12 September 2026
When your outage becomes your bank customer's major incident: DORA's six criteria, the two-hour downtime threshold of RTS 2024/1772, the four-hour, 24-hour, 72-hour and one-month clocks of RTS 2025/301, and the facts your customer will need from you
A financial entity must report a major ICT-related incident to its supervisor within four hours of classifying it and no later than 24 hours from becoming aware, follow up within 72 hours and close within one month. Whether an outage at its software vendor is major is decided by six criteria and the thresholds of Delegated Regulation (EU) 2024/1772: more than two hours of downtime on a service supporting a critical or important function, more than 24 hours of duration, more than 10 percent of clients, two or more member states, data losses, 100 000 euro. What each report must contain under Delegated Regulation (EU) 2025/301, which of those facts only the vendor holds, and what the Article 30(2)(f) incident assistance clause turns that into. Read from the Official Journal.
12 September 2026
Which GDPR supervisory authority is yours: the main establishment, the lead authority of Article 56, the local cases, and the 30 authorities of the Board
A software company with customers in several member states deals with one supervisory authority for its cross-border processing: the authority of its main establishment, the lead authority of Article 56(1), its sole interlocutor under Article 56(6). Where that is, what the main establishment means for a controller and for a processor (Article 4(16)), when another authority keeps a local case (Article 56(2)), what a company with no establishment in the Union gets instead (Article 27, recital 122), and where the 72-hour breach notification goes (Article 33(1)). With the 27 authorities and the three EEA ones as the European Data Protection Board lists its members, read on 12 September 2026.
12 September 2026
CRA Annex I: the 22 essential requirements, as a checklist
Annex I of the Cyber Resilience Act is what your product has to meet from 11 December 2027 and what the technical file has to show. Part I is 14 product requirements, 13 of them 'where applicable' on the basis of your risk assessment; Part II is 8 vulnerability-handling requirements that always apply. Here they are as one table, with what each one asks and whether you may exclude it.
11 September 2026
The CRA final report clock does not start when you become aware
Most write-ups of Cyber Resilience Act Article 14 give three deadlines from one starting point: 24 hours, 72 hours, 14 days. The first two run from awareness. The third does not, and for a vulnerability its anchor is a date that may not exist yet. Here is what the Regulation says, paragraph by paragraph.
11 September 2026
CRA or NIS2: which one applies to a software company, and can it be both?
The Cyber Resilience Act regulates products placed on the market; NIS2 regulates entities that provide services. A software company can be under one, the other, both or neither, and the answer turns on two questions: do you place a product on the market, and are you a medium-sized or larger entity in a listed sector. The dates, the reporting clocks, the fines and the decision table, from the two texts.
11 September 2026
Default, important or critical: the 26 technical descriptions of Implementing Regulation 2025/2392, and the core-functionality test
Annex III and IV of the CRA name 26 product categories in a line each. Commission Implementing Regulation (EU) 2025/2392, in force since 21 December 2025, describes each one technically, and the Commission's guidance of 27 July 2026 says how to classify against them: by the product's core functionality, not by what it also does or what it integrates. All 26 descriptions verbatim, the guidance's six rules with its examples (SOAR is not a SIEM, a log viewer is not a SIEM, a router with a firewall is a router), and what the classification changes.
11 September 2026
Does software need a CE mark under the CRA? Yes, and Article 30 says where it goes
From 11 December 2027, a CE marking is required on every product with digital elements placed on the EU market, software included. For software the mark goes on the EU declaration of conformity or on the website accompanying the product, before it is placed on the market. What the mark asserts, who can affix it, when a notified body's number joins it, and what the declaration behind it must contain.
11 September 2026
Does the CRA apply to open-source software? Three cases, and the light regime for stewards
The Cyber Resilience Act reaches free and open-source software only when it is supplied in the course of a commercial activity. A non-monetised project is out. A company that ships a product built on open-source components is a manufacturer of that product. And foundations and companies that sustain open-source products intended for commercial use are 'open-source software stewards' under Article 24: a cybersecurity policy, cooperation with authorities, and a narrowed reporting duty, with no CE mark and no technical file. The recitals and the article, quoted.
11 September 2026
Does the CRA require an SBOM? Yes, and here is exactly what it says
Annex I, Part II, point 1 of the Cyber Resilience Act requires a software bill of materials in a commonly used, machine-readable format covering at least the top-level dependencies. It goes in the technical file, it is not published, and a market surveillance authority can ask for it on a reasoned request. The three sentences that decide it, and what they leave open.
11 September 2026
How long is the CRA support period? At least five years, and three other clocks attached to it
Article 13(8) of the Cyber Resilience Act requires a support period of at least five years, or the expected time in use if shorter, during which vulnerabilities are handled. Its end date must be shown at purchase, at least the month and year. Security updates must stay available for ten years or the support period. And the technical file, declaration and user information are kept for the same. The four clocks, from the text.
11 September 2026
How to file a CRA notification on ENISA's single reporting platform, from its own manual
The platform opened on 11 September 2026 at portal.cra-srp.enisa.europa.eu. Who can log in, which coordinator to pick, what each of the three submissions asks for, what the platform's own counter gets wrong, and when you may ask for dissemination to be delayed. Read from ENISA's guidance, FAQ, glossary and terms, not from a summary of them.
11 September 2026
Is your open-source project 'commercial' under the CRA? The Commission's seven tests, with its examples
The CRA reaches free and open-source software only where it is supplied in the course of a commercial activity, and the Regulation leaves 'commercial' to two recitals. The Commission's guidance of 27 July 2026, section 3, turns them into seven tests: a price, a paid edition or open core, monetising other services or personal data, support services, donations, sponsorship, and not-for-profit status, with 22 examples. Where a maintainer, an open-core company and a foundation each land, and what a pull request makes you.
11 September 2026
Is your product important or critical under the Cyber Resilience Act? Annex III and IV in full
Once a product is in scope of the CRA it is default, important (class I or II) or critical, and the tier decides whether you can self-assess or need a notified body. Here are the 19, 4 and 3 categories verbatim from the Official Journal, what each tier changes under Article 32, and the one thing the tier does not change.
11 September 2026
Is your product in scope of the Cyber Resilience Act? Where SaaS sits
The most-asked CRA question is not how to report, it is whether the Regulation applies to you at all. Pure software as a service is out and inside NIS2; installed and downloadable software is in; remote processing a product cannot work without is back in. The determination is yours to make and record. Here is the text that decides it.
11 September 2026
NIS2 or CRA: which incident clock runs for a software company, and what makes an incident 'significant'
Both laws give you 24 hours, 72 hours and a month, and both start the clock when you 'become aware'. Almost everything else differs: what triggers it, who receives it, on which platform, and what counts. NIS2 Article 23 and Implementing Regulation 2024/2690 for the company that runs a cloud service; CRA Article 14 for the company that ships a product; both for the company that does both. The thresholds, criterion by criterion, and one procedure that satisfies the two.
11 September 2026
Self-assessment under the CRA: what module A actually requires, from Annex VIII and the Commission's FAQ
Most software products will never see a notified body. They use module A, the internal control procedure of Annex VIII, and 'self-assessment' is the word everyone uses for it without saying what it contains. Annex VIII Part I is five points; the Commission's FAQ adds the list of activities, the fact that no test methodology is mandated, where a software product carries its CE mark, the two forms of the declaration of conformity, and the harmonised standards timeline that decides when self-assessment stops meaning 'against Annex I directly'.
11 September 2026
The coordinated vulnerability disclosure policy the CRA requires: three provisions, and a one-page policy that meets them
Annex I, Part II, point 5 of the Cyber Resilience Act requires every manufacturer in scope to put in place and enforce a coordinated vulnerability disclosure policy. Article 13(17) requires a single point of contact for reporting that is easy to find and not limited to automated tools; Annex II, point 2 requires the contact and the policy's location in the user information; Annex VII, point 2(b) puts both in the technical file. What each provision asks, what a policy must say, and what it must not promise.
11 September 2026
The CRA cybersecurity risk assessment: what Article 13 actually requires, and the one output it must produce
Article 13(2) to (4) of the Cyber Resilience Act make the risk assessment the document every other CRA obligation hangs off. It must analyse risks from the intended purpose, foreseeable use and conditions of use over the expected time in use; state whether and how each Part I, point 2 requirement applies; say how Part I, point 1 and Part II are applied; be documented, kept updated over the support period, and included in the technical file, with a clear justification for every requirement left out. The four paragraphs, and a one-page structure that satisfies them.
11 September 2026
The Cyber Resilience Act for a small software manufacturer, in twelve steps
Everything a ten-person company that ships installed software or a device has to do under the CRA, in the order to do it: the scope determination, the tier, the CSIRT and the enforcer, the reporting procedure that has applied since 11 September 2026, then the technical file, the 22 requirements, the SBOM, the support period, the CE mark and the declaration due by 11 December 2027. Each step with its article and the piece that explains it.
11 September 2026
The EU's own CRA machinery, on the day the duty started: 0 notified bodies, 0 harmonised standards, 7 of 27 enforcers
The Cyber Resilience Act asks manufacturers to be ready. Here is how ready the institutions it depends on were on 11 and 12 September 2026, read from the Commission's own registers: no conformity assessment body notified under the CRA, no harmonised standard published in the Official Journal, seven member states with a registered market surveillance authority, thirteen with a notifying authority, and the coordinator CSIRT list published the day before, with two states naming a body other than their national CSIRT. What that means for a manufacturer with a class I product, and what to record.
11 September 2026
What goes in the CRA technical file: Annex VII, point by point
From 11 December 2027 every product with digital elements placed on the EU market needs technical documentation before it is placed, kept for ten years or the support period, whichever is longer. Annex VII says what it contains in eight points. Here they are, what each one actually asks for, the four documents Part II of Annex I presumes exist, and how long you keep it.
11 September 2026
What the CRA asks of importers and distributors, and when it makes them the manufacturer
If you resell software or devices into the EU rather than build them, Articles 19 and 20 of the Cyber Resilience Act give you a checklist to run before the product goes on sale, a duty to pass vulnerabilities to the manufacturer, a duty to tell authorities about significant risks, and ten years of record-keeping. Article 21 turns you into the manufacturer the moment you sell under your own brand or substantially modify the product. The obligations, from the text.
11 September 2026
What the CRA asks of you for your dependencies: due diligence, reporting upstream, and known exploitable vulnerabilities, from the Commission's guidance
A software product is mostly other people's code. The CRA makes the manufacturer responsible for the product as a whole and gives it three duties towards the components inside it: due diligence under Article 13(5), reporting vulnerabilities upstream and sharing fixes under Article 13(6), and placing the product on the market without known exploitable vulnerabilities. The Commission's guidance of 27 July 2026, sections 3.4, 7.3 and 9.2, says what each one takes and what it does not: no duplicate reports, no obligation to get your fix merged, and a definition of 'known' that includes the CVE database and the news.
11 September 2026
What you have to report under the CRA: the two triggers, as the Regulation defines them
Article 14 has two triggers and both are defined in the text. An actively exploited vulnerability is one with reliable evidence that a malicious actor has exploited it in a system without the owner's permission (Article 3(42)). A severe incident is one that affects, or can affect, the product's ability to protect sensitive data or functions, or that leads, or can lead, to malicious code in the product or a user's systems (Article 14(5)). What is in, what is out, and the duty to tell users that comes with both.
11 September 2026
When does the CRA's 24-hour clock start? 'Becoming aware', from the Commission's guidance
The 24 and 72 hours run from the moment the manufacturer 'becomes aware', and the Regulation never says what that means. The Commission's guidance of 27 July 2026 does, in paragraphs 211 to 218: a reasonable degree of certainty, after an initial assessment, borrowed word for word from the NIS2 implementing regulation and the GDPR breach guidelines. What that makes of a customer email, a scanner alert, a listed CVE in a component, a bug-bounty zero-day, and a vulnerability you knew about before 11 September.
11 September 2026
When is software 'placed on the market' under the CRA, and which of your builds is a product? The guidance's rule for standalone software
Everything in the CRA hangs on a date and a noun: the date a product is placed on the market, and whether what you ship is a product at all. For standalone software the Commission's guidance of 27 July 2026 answers both in paragraphs 13 to 21: a version is placed on the market once, when first offered, and every later download of it counts from that day; per-OS builds and feature bundles are separate products; a web app used in a browser is not a product, a browser extension or an installed client is. What that means for 11 December 2027, for betas, and for old versions you keep online.
11 September 2026
Which CSIRT do you report to under CRA Article 14? All 27 coordinators, as ENISA lists them
Every guide to the Cyber Resilience Act's reporting duty says 'notify your national CSIRT' and stops. Since 10 September 2026 ENISA publishes the CSIRT designated as coordinator for each of the 27 member states. Here is that list, the rule that picks the state, and the two states where the coordinator is not the national CSIRT.
11 September 2026
Which parts of your backend are inside the CRA? Remote data processing, from the Commission's guidance
A product with digital elements includes its remote data processing solutions, and the Regulation defines them in one sentence. The Commission's guidance of 27 July 2026 turns that sentence into two cumulative tests, a boundary rule, a list of what is never in (CI/CD, HR, CRM, telemetry, websites), the SaaS, PaaS and IaaS cases, and a worked mobile banking example. For a software company with an app and a cloud, this is the line.
11 September 2026
Which update puts your existing software under the CRA? Substantial modifications, from the Commission's guidance
Software placed on the market before 11 December 2027 stays outside the CRA's design and conformity duties until it is substantially modified. The Commission's guidance of 27 July 2026 says what that means for a software update in paragraphs 103 to 113 and 122 to 124, with eleven worked examples: a risk not in your risk assessment, not the size of the diff. Security updates are generally out; a 'remember me' checkbox can be in. What to write into every release, and what the first substantial modification does and does not trigger.
11 September 2026
Who enforces the Cyber Resilience Act in your member state? 7 of 27 have said
The CRA is enforced nationally, by a market surveillance authority each member state designates and registers with the Commission. On 11 September 2026, the day the reporting duty applied, seven states had registered one. Here is the register, state by state, including the twenty that have not, and what that means for a small manufacturer asking who will come knocking.
11 September 2026
Cyber Resilience Act penalties: what a small manufacturer is actually exposed to
The CRA sets three fine tiers, up to EUR 15 million or 2.5% of worldwide turnover. Here is which obligations sit in which tier, who does the enforcing, and the two places the Regulation writes small manufacturers into the text by name.
8 September 2026
How to answer a security questionnaire from your ISO 27001 ISMS: 30 question topics mapped to the Annex A controls that answer them
Nearly every security questionnaire a European company receives asks about the same 30 topics. Here is the map from each topic to the ISO 27001 Annex A controls it is really about, and the four records that answer any of them.
3 September 2026
Which EU countries name ISO 27001 in public tenders: 1,548 German notices, 829 Polish, and Greece has the highest share
Over 365 days, ISO 27001 appears in 3,415 TED notices. Germany and Poland account for 70% of them, Greece names it in 2% of everything it buys, and France, Spain and Italy barely name it at all. The numbers by country, and the query to re-run them.
3 September 2026
Best ISO 27001 compliance software: what to ask before you compare features
Integration counts are easy to compare and rarely decide an audit. Here are the questions that do, including the one most vendors will not answer in writing.
20 August 2026
Cheapest ISO 27001 certification: how to compare quotes without buying a worthless certificate
Certification body quotes vary, but the auditor days behind them are set by ISO/IEC 27006 Annex B. Here is how to read a quote, and the one check that matters more than price.
20 August 2026
The cheapest way to get ISO 27001, and the part you cannot make cheaper
Most of an ISO 27001 budget is auditor days, and those are set by a published chart rather than by negotiation. Here is what actually moves the number, and what does not.
20 August 2026
How to get ISO 27001 certification for a company, in the order it actually happens
The path from nothing to a certificate, what happens at Stage 1 and Stage 2, and the records an auditor asks for at each point.
20 August 2026
Implementing ISO 27001 without consultants: what you take on, and what they were doing for the money
It is entirely possible to certify without a consultant. It is worth knowing what you are absorbing first, and which parts genuinely benefit from someone who has sat on the other side of an audit.
20 August 2026
ISO 27001 certification cost for a company, by headcount
Auditor days come from the ISO/IEC 27006 Annex B chart, so certification cost tracks headcount more than industry. Here is the arithmetic, and the lines people forget.
20 August 2026
ISO 27001 compliance checklist, by clause
A checklist that follows the standard's own structure: clauses 4 to 10 and what each one asks you to be able to show, plus what Annex A adds.
20 August 2026
ISO 27001 cost of implementation: the three-year number, not the first invoice
Certification runs on a three-year cycle with surveillance audits each year. Budgeting only for the first audit is the most common way the total surprises people.
20 August 2026
ISO 27001 vs NIS2: what the certificate covers and what it does not
NIS2 is law and ISO 27001 is a certifiable standard, so they are not alternatives. Here is where an existing ISMS satisfies the directive's requirements, and the two places it does not.
20 August 2026
ISO 42001 certification: what it is, and whether it is early
ISO/IEC 42001 is the AI management system standard. Here is what it asks for, how it relates to an existing ISO 27001, and an honest read of current demand.
20 August 2026
How many auditor days an ISO 27001 certification takes, by headcount
Certification bodies do not publish prices, but the audit days are fixed by ISO/IEC 27006 Annex B. Here is the arithmetic that turns your headcount into a number before anyone quotes you.
11 August 2026
ISO 27001 vs SOC 2 in Europe: which one buyers actually ask for
Selling into Europe, get ISO 27001: EU public tenders named it 3,408 times in a year against 104 for SOC 2. Selling to US customers, it runs the other way. The numbers, the public TED query to re-run them, and when you need both.
11 August 2026