[{"data":1,"prerenderedAt":520},["ShallowReactive",2],{"article-meta:en":3},{"cra-article-13-for-a-software-manufacturer-the-twenty-five-paragraphs-in-order-which-are-yours-which-are-the-commission-s-and-a-checklist-by-role":4,"the-data-act-for-a-saas-company-the-switching-duties-since-12-september-2025-the-nine-contract-terms-the-end-of-switching-charges-and-what-a-data-holder-owes":14,"the-iso-27001-corrective-action-record-what-clause-10-2-asks-for-the-seven-sections-an-auditor-accepts-the-mistakes-that-reopen-a-finding-and-a-page-that-writes-it":22,"the-iso-27001-information-security-policy-what-clause-5-2-asks-for-the-nine-sections-of-a-short-policy-the-mistakes-an-auditor-flags-and-a-page-that-writes-it":30,"the-iso-27001-management-review-the-seven-inputs-of-clause-9-3-as-an-agenda-the-four-trends-the-two-outputs-what-the-minutes-have-to-show-and-a-page-that-writes-them":38,"the-iso-27001-risk-assessment-for-a-software-company-what-clause-6-1-2-asks-for-a-five-point-method-the-starter-risks-and-a-page-that-writes-the-register-and-the-treatment-plan":46,"the-iso-42001-ai-policy-for-a-software-company-what-clause-5-2-asks-for-the-ten-sections-the-ai-act-duties-it-names-the-mistakes-an-auditor-flags-and-a-page-that-writes-it":54,"the-iso-42001-ai-system-impact-assessment-what-clause-6-1-4-asks-for-the-three-levels-where-it-meets-the-ai-act-the-mistakes-an-auditor-flags-and-a-page-that-writes-it":62,"the-nis2-incident-clock-for-a-software-company-24-hours-72-hours-one-month-what-makes-an-incident-significant-for-a-cloud-provider-and-a-page-that-writes-the-three-reports":70,"ai-literacy-under-article-4-of-the-ai-act-as-rewritten-on-27-july-2026-what-take-measures-means-who-it-covers-what-it-does-not-require-and-the-record-to-keep":78,"article-50-of-the-ai-act-the-four-transparency-duties-since-2-august-2026-the-2-december-2026-transition-the-code-of-practice-and-the-eu-icon":83,"does-iso-9001-2015-require-a-quality-manual-what-clause-7-5-asks-for-instead-the-21-places-the-standard-names-documented-information-and-what-a-manual-is-for-today":87,"dora-for-a-software-vendor-the-article-30-contract-clauses-your-bank-customer-will-send-the-register-of-information-and-what-iso-27001-already-answers":95,"dora-ict-service-types-s01-to-s19-which-one-a-saas-product-is-what-the-register-of-information-records-and-why-one-contract-can-be-several-rows":103,"dora-subcontracting-rts-2025-532-the-twelve-contract-terms-when-you-subcontract-a-critical-service-the-ten-conditions-your-customer-checks-and-the-notice-period":107,"dora-vendor-due-diligence-rts-2024-1773-the-six-questions-the-five-sources-of-assurance-the-eight-conditions-for-relying-on-your-certificate-and-the-five-reports":111,"essential-or-important-under-nis2-the-size-rule-the-size-blind-rules-and-the-seven-ways-to-be-essential":115,"gdpr-international-transfers-for-a-software-company-the-17-adequacy-decisions-the-four-scc-modules-what-a-us-uk-or-indian-sub-processor-needs-and-a-page-that-picks-the-mechanism":123,"harmonised-standards-for-the-cra-what-request-m-606-asks-for-when-and-what-a-manufacturer-has-today":131,"how-to-check-an-iso-9001-certificate-is-real-what-a-certificate-must-show-three-checks-that-take-ten-minutes-and-the-27-accreditation-registers":135,"iso-27701-2025-for-a-software-company-the-standalone-privacy-standard-its-78-controls-what-an-iso-27001-system-already-covers-and-the-gdpr-articles-each-control-evidences":139,"iso-9001-for-a-software-company-what-clause-8-means-when-the-product-is-code-sub-clause-by-sub-clause":147,"iso-9001-in-eu-public-tenders-by-country":151,"nis2-article-20-for-the-board-what-the-management-body-must-approve-oversee-and-learn-the-twelve-places-the-implementing-regulation-names-it-and-what-liability-means":155,"nis2-for-a-saas-company-you-are-a-cloud-computing-service-provider-and-this-is-what-follows":159,"nis2-for-managed-service-providers-and-mssps-an-annex-i-entity-by-definition-and-the-supplier-every-customers-due-diligence-lands-on":163,"nis2-for-online-marketplaces-search-engines-and-social-networks-the-annex-ii-digital-providers-and-why-they-are-never-essential-by-size":167,"nis2-registration-the-two-lists-you-may-be-on-what-you-submit-by-when-and-to-whom-article-3-4-and-article-27":171,"nis2-transposition-state-by-state-what-the-commissions-register-shows":175,"the-ai-act-after-the-digital-omnibus-the-dates-that-changed-and-which-iso-42001-controls-produce-the-evidence-for-article-17-and-articles-9-to-15":179,"the-ai-act-for-a-software-company-which-role-you-are-what-applies-to-everyone-what-applies-only-to-a-high-risk-provider-the-sme-provisions-and-the-dates-as-amended":183,"the-eu-declaration-of-conformity-under-the-cra-annex-v-point-by-point-the-simplified-form-and-a-worked-example":191,"the-gdpr-72-hour-breach-clock-for-a-software-company-when-awareness-starts-it-what-the-notification-contains-the-processor-s-own-clock-and-the-nis2-cra-and-dora-clocks-beside-it":195,"the-gdpr-data-subject-request-for-a-software-company-the-month-of-article-12-3-the-eight-contents-of-an-access-answer-the-two-further-months-and-a-page-that-computes-the-deadline":203,"the-gdpr-for-a-software-company-controller-of-your-own-data-processor-for-your-customers-and-the-five-duties-that-turn-on-size-and-data":211,"the-gdpr-impact-assessment-for-a-software-company-the-three-cases-of-article-35-3-the-nine-criteria-behind-them-the-four-elements-of-article-35-7-and-a-page-that-writes-it":219,"the-gdpr-privacy-notice-for-a-software-company-the-twelve-pieces-of-article-13-the-thirteen-of-article-14-the-moment-each-is-given-and-a-page-that-writes-it":227,"the-gdpr-processor-contract-for-a-saas-company-the-eight-terms-of-article-28-3-every-customer-addendum-carries-the-duty-most-of-them-forget-and-what-sits-beside-them-under-dora":235,"the-gdpr-record-of-processing-for-a-software-company-the-seven-fields-of-article-30-1-the-four-of-article-30-2-why-the-250-person-exemption-never-applies-and-a-page-that-writes-it":243,"the-gdpr-representative-of-article-27-for-a-software-company-outside-the-eu-who-must-appoint-one-the-three-conditions-of-the-exemption-and-where-the-name-goes":251,"the-iso-27001-scope-statement-why-a-certificate-that-says-head-office-does-not-cover-your-saas-what-clause-4-3-asks-for-what-a-buyer-under-dora-checks-and-three-that-pass":259,"the-iso-27001-statement-of-applicability-for-a-software-company-the-93-controls-the-four-columns-of-clause-6-1-3-d-the-exclusions-an-auditor-accepts-and-a-page-that-writes-it":267,"the-iso-9001-management-review-the-13-inputs-and-3-outputs-of-clause-9-3-as-an-agenda-where-each-input-comes-from-and-what-the-minutes-have-to-show":275,"the-iso-9001-quality-policy-the-four-things-clause-5-2-says-it-must-contain-the-three-things-that-must-happen-to-it-and-a-one-page-example":283,"the-nine-places-where-your-bank-customers-ict-risk-framework-reaches-into-your-product-rts-2024-1774-support-end-dates-vulnerability-reports-source-code-accounts-and-incidents":287,"the-ten-measures-of-nis2-article-21-2-as-a-checklist-each-point-quoted-the-regulation-sections-behind-it-and-the-iso-27001-controls-that-already-produce-it":291,"threat-led-penetration-testing-under-dora-from-the-vendors-side-when-your-bank-customers-red-team-is-allowed-into-your-production-systems-the-12-week-test-and-the-pooled-test":295,"what-a-deployer-of-a-high-risk-ai-system-owes-under-article-26-of-the-ai-act-the-twelve-paragraphs-the-article-27-impact-assessment-and-when-you-become-the-provider":299,"what-iso-9001-certification-costs-the-audit-days-iaf-md-5-fixes-by-headcount-the-day-rate-the-three-year-total-and-why-it-is-a-third-of-iso-27001":303,"when-your-outage-becomes-your-bank-customers-major-incident-doras-six-criteria-the-two-hour-downtime-threshold-the-four-clocks-and-the-facts-your-customer-needs-from-you":307,"which-gdpr-supervisory-authority-is-yours-the-main-establishment-the-lead-authority-of-article-56-the-local-cases-and-the-30-authorities-of-the-board":311,"cra-annex-i-the-22-essential-requirements-as-a-checklist":319,"cra-final-report-clock-does-not-start-when-you-become-aware":324,"cra-or-nis2-which-one-applies-to-a-software-company":328,"default-important-or-critical-the-26-technical-descriptions-and-the-core-functionality-test":336,"does-software-need-a-ce-mark-under-the-cra":340,"does-the-cra-apply-to-open-source-software":344,"does-the-cra-require-an-sbom":348,"how-long-is-the-cra-support-period":352,"how-to-file-a-cra-notification-on-enisa-s-single-reporting-platform":356,"is-your-open-source-project-commercial-under-the-cra-the-commissions-seven-tests":360,"is-your-product-important-or-critical-under-the-cyber-resilience-act":364,"is-your-product-in-scope-of-the-cyber-resilience-act":368,"nis2-or-cra-which-incident-clock-runs-for-a-software-company-and-what-makes-an-incident-significant":372,"self-assessment-under-the-cra-what-module-a-actually-requires":380,"the-coordinated-vulnerability-disclosure-policy-the-cra-requires":384,"the-cra-cybersecurity-risk-assessment-what-article-13-actually-requires":388,"the-cyber-resilience-act-for-a-small-software-manufacturer-in-twelve-steps":392,"the-eu-s-own-cra-machinery-on-the-day-the-duty-started":400,"what-goes-in-the-cra-technical-file-annex-vii-point-by-point":404,"what-the-cra-asks-of-importers-and-distributors":408,"what-the-cra-asks-of-you-for-your-dependencies-due-diligence-reporting-upstream-and-known-exploitable-vulnerabilities":412,"what-you-have-to-report-under-the-cra-the-two-triggers-defined":416,"when-does-the-cra-24-hour-clock-start-becoming-aware":420,"when-is-software-placed-on-the-market-under-the-cra-and-which-of-your-builds-is-a-product":424,"which-csirt-do-you-report-to-under-cra-article-14":428,"which-parts-of-your-backend-are-inside-the-cra-remote-data-processing":432,"which-update-puts-your-existing-software-under-the-cra-substantial-modifications":436,"who-enforces-the-cyber-resilience-act-in-your-member-state":440,"cyber-resilience-act-penalties":444,"how-to-answer-a-security-questionnaire":449,"iso-27001-in-eu-public-tenders-by-country":454,"best-iso-27001-compliance-software":458,"cheapest-iso-27001-certification":463,"cheapest-way-to-get-iso-27001":467,"how-to-get-iso-27001-certification-for-company":471,"implement-iso-27001-without-the-help-of-consultants":475,"iso-27001-certification-cost-for-company":479,"iso-27001-compliance-checklist":483,"iso-27001-cost-of-implementation":487,"iso-27001-vs-nis2":491,"iso-42001-certification":499,"how-many-auditor-days-iso-27001":503,"iso-27001-or-soc-2-in-europe":512},{"locale":5,"slug":6,"title":7,"description":8,"published":9,"answer":10},"en","cra-article-13-for-a-software-manufacturer-the-twenty-five-paragraphs-in-order-which-are-yours-which-are-the-commission-s-and-a-checklist-by-role","CRA Article 13 for a software manufacturer: the twenty-five paragraphs in order, which are yours, which are the Commission's, and a checklist by role","Article 13 of the Cyber Resilience Act is the manufacturer's article: twenty-five paragraphs from the essential requirements of paragraph 1 to the Commission's powers of paragraph 25. Twenty-one of them are duties a software manufacturer carries, from the product risk assessment and the due diligence on components to the support period, the single point of contact, the technical documentation kept for ten years, the corrective measures and what to do before ceasing operations; two are options, two belong to the Commission and the authorities. Article 14 adds the reporting clocks, Articles 19 and 20 the importer's and distributor's duties, Article 24 the steward's, and Annex I the requirements the product must meet. A free page lists every row that binds your role, in the Official Journal's words in six languages, with a status per row.","2026-09-13",{"who":11,"when":12,"do":13},"A manufacturer of a product with digital elements, which is any software company that places software on the EU market in the course of a commercial activity; and, through Articles 21 and 22, an importer, distributor or modifier that steps into the manufacturer's shoes.","The reporting duties of Article 14 apply from 11 September 2026 to every product in scope whenever it was placed on the market; the rest of Article 13, Annex I, the technical documentation and the CE marking apply from 11 December 2027 to products placed on the market from that day, and to older products once they are substantially modified.","Read the twenty-five paragraphs once as the list below, decide for each whether it is done, in progress or not applicable, put the evidence beside it, and keep the Annex I justifications for anything excluded; the free page holds the eighty-five rows of the Regulation by role and writes the checklist as a document.",{"locale":5,"slug":15,"title":16,"description":17,"published":9,"answer":18},"the-data-act-for-a-saas-company-the-switching-duties-since-12-september-2025-the-nine-contract-terms-the-end-of-switching-charges-and-what-a-data-holder-owes","The Data Act for a SaaS company: the switching duties since 12 September 2025, the nine contract terms, the end of switching charges, and what a data holder owes","Regulation (EU) 2023\u002F2854 has applied since 12 September 2025, and a company that sells hosted software is a provider of a data processing service under it, whatever its size. Chapter VI makes it remove every obstacle to a customer switching provider or moving on-premises: a written contract with the nine terms of Article 25(2), a notice period of at most two months, a transitional period of at most 30 calendar days, a retrieval period of at least 30 calendar days, erasure after it, an online register of the exportable data, open interfaces free of charge, a website statement on the jurisdiction the infrastructure is subject to, and switching charges that are cost-based now and forbidden from 12 January 2027. A company whose product is a connected product or a related service is also a data holder under Chapter II, with access by design for products placed on the market after 12 September 2026. The 96 rows of the Regulation that bind each role are a dataset in six languages.",{"who":19,"when":20,"do":21},"A company that provides hosted software, infrastructure or platform services to customers in the Union (a provider of data processing services under Article 2(8)), and any company whose product is a connected product or a related service that generates data (a data holder under Chapter II); the switching chapter has no small-enterprise exemption.","Chapter VI has applied to every contract since 12 September 2025, the reduced switching charges of Article 29 run until 12 January 2027 and are forbidden after it, the access-by-design duty of Article 3(1) applies to connected products and related services placed on the market after 12 September 2026, and Chapter III to data-sharing obligations under Union law entering into force after 12 September 2025.","Put the nine terms of Article 25(2) in the customer contract, publish the switching procedures and the online register of exportable data, put the jurisdiction statement of Article 28 on the website, price switching at cost and plan its end on 12 January 2027, open the interfaces the switching needs, and, if the product is a connected product, design the next version to hand its data to the user; the catalogue holds every row by role.",{"locale":5,"slug":23,"title":24,"description":25,"published":9,"answer":26},"the-iso-27001-corrective-action-record-what-clause-10-2-asks-for-the-seven-sections-an-auditor-accepts-the-mistakes-that-reopen-a-finding-and-a-page-that-writes-it","The ISO 27001 corrective action record: what Clause 10.2 asks for after a nonconformity, the seven sections an auditor accepts, the mistakes that reopen a finding, and a page that writes it","Clause 10.2 is what happens to a nonconformity once it is found: correct it and deal with what it caused, find the cause, ask whether the same problem exists elsewhere, act so that it does not recur, check that the action worked, change the management system where the cause lived, and keep the nonconformity, the actions and their results as documented information. A record an auditor accepts has seven sections in that order, separates the correction from the corrective action, and stays open until the check shows the action worked. A free page writes the record from the finding, the correction, the cause, the action with its owner and date, and the effectiveness check.",{"who":27,"when":28,"do":29},"The person who owns the ISO 27001 management system in a company, and whoever is handed a finding to close: an internal audit, a certification audit, an incident or a failed check produces a nonconformity, and Clause 10.2 says what has to happen to it and what has to be written down.","Each time a nonconformity is found, from the day it is raised to the day the check shows the action worked; before the certification audit for every finding of the internal audits, and before the surveillance audit for every finding of the last certification audit, since those are the records the auditor opens first.","Correct it and deal with what it caused, write the nonconformity down as evidence, find the cause with a method, ask whether the same problem exists elsewhere, decide an action in proportion to the effect with an owner and a date, check later that it worked and record the result, change the procedure or the risk register where the cause lived, and keep the record; the free page writes it in the clause's order.",{"locale":5,"slug":31,"title":32,"description":33,"published":9,"answer":34},"the-iso-27001-information-security-policy-what-clause-5-2-asks-for-the-nine-sections-of-a-short-policy-the-mistakes-an-auditor-flags-and-a-page-that-writes-it","The ISO 27001 information security policy: what Clause 5.2 asks for, the nine sections of a short policy, the mistakes an auditor flags, and a page that writes it","Clause 5.2 asks top management for one policy that fits the company's purpose, carries the security objectives or the frame for setting them, commits to the requirements that apply and to improving the system, and is documented, communicated and available to the parties that need it. That is seven things, none of them a page count. A good policy for a software company runs to two pages in nine sections: purpose, scope, why security matters here, commitments, objectives, roles, the topic policies under it, compliance, and communication and review. The mistakes an auditor flags are the template with another company's name in it, the thirty pages nobody read, the missing approval, objectives nobody can measure and a policy no new joiner has seen. A free page writes the policy from ten answers in six languages.",{"who":35,"when":36,"do":37},"Top management of a software company building an ISO 27001 information security management system, and the person who runs the system for them; the policy is the first document a certification auditor asks for and the one every other security policy sits under.","Before the topic policies are written, because they sit under it, and before the first internal audit, because Clause 5.2 is checked against the approval, the date, the communication record and the objectives; then at every management review and whenever the business, its obligations or its risks change.","Write two pages in nine sections in the company's own words, name who approves it and who runs the system, set three to five measurable objectives, publish it where every joiner reads it, date the approval, and review it at least annually; the free page writes the draft from ten answers.",{"locale":5,"slug":39,"title":40,"description":41,"published":9,"answer":42},"the-iso-27001-management-review-the-seven-inputs-of-clause-9-3-as-an-agenda-the-four-trends-the-two-outputs-what-the-minutes-have-to-show-and-a-page-that-writes-them","The ISO 27001 management review: the seven inputs of Clause 9.3 as an agenda, the four trends, the two outputs, what the minutes have to show, and a page that writes them","Clause 9.3 has top management review the management system at planned intervals against seven inputs: the actions from the last review, changes in the external and internal issues, changes in what interested parties need and expect, feedback on performance with its four trends (nonconformities and corrective actions, monitoring and measurement, audit results, the objectives), feedback from interested parties, the risk assessment and the treatment plan, and the opportunities to improve. The outputs are two: decisions on continual improvement and any changes the system needs, kept as documented information. The minutes an auditor accepts show each input considered and each decision taken, with an owner and a date on every action. A free page writes the minutes in the clause's order from the meeting facts, the counts and what was said.",{"who":43,"when":44,"do":45},"Top management of a company running an ISO 27001 information security management system, and the person who prepares the review for them; the review is the one meeting the standard puts on top management personally, and the minutes are what the certification auditor reads to see that it happened.","At planned intervals, which for most companies means once a year and once more before the certification audit, and whenever a change in the business, its obligations or its risks needs a decision at the top; the first review before the first audit, with a previous review's actions to report on by the second.","Put the seven inputs on the agenda in the clause's order, bring a figure for each of the four trends, have someone speak to each input, record a decision on improvement and on changes to the system, give every action an owner and a date, sign and date the minutes, and open the next review with the actions; the free page writes the minutes from the entries.",{"locale":5,"slug":47,"title":48,"description":49,"published":9,"answer":50},"the-iso-27001-risk-assessment-for-a-software-company-what-clause-6-1-2-asks-for-a-five-point-method-the-starter-risks-and-a-page-that-writes-the-register-and-the-treatment-plan","The ISO 27001 risk assessment for a software company: what Clause 6.1.2 asks for, a five-point method, the starter risks, and a page that writes the register and the treatment plan","Clause 6.1.2 does not prescribe a method; it prescribes what the method must produce: criteria for accepting risk and for assessing it, an identification of the information security risks, an analysis of their consequences and likelihood, an evaluation against the criteria, and repeatable, comparable results. Clause 6.1.3 then asks for the treatment options, the controls, the comparison with Annex A, the Statement of Applicability and the plan. For a software company the risks are largely known before the first workshop: credential compromise, a lost laptop, a cloud provider outage, a backup that does not restore, a departing employee with access left open, a vulnerability shipped in its own code. A five-point scale for likelihood and impact, the product as the level, an acceptance threshold, the treatment option and the controls for each risk above it, and a free page that writes the register and the plan in six languages.",{"who":51,"when":52,"do":53},"A software company building an ISO 27001 information security management system, at the first risk assessment before the Statement of Applicability is written, and again at the planned intervals of Clause 8.2 and after a change that Clause 8.1 names.","Before the controls are chosen, because the Statement of Applicability rests on the treatment plan; then at planned intervals and when significant changes occur (Clause 8.2), which for a software company is each new product surface, provider or team; the criteria are kept and the results must be comparable from one assessment to the next.","Write the criteria once, a scale each for likelihood and impact and the level you accept; start from the risks a company like yours carries, score each, name the owner, treat every risk above the threshold with an option and the Annex A controls that treat it, and date the plan; the free page writes the register and the plan from five answers.",{"locale":5,"slug":55,"title":56,"description":57,"published":9,"answer":58},"the-iso-42001-ai-policy-for-a-software-company-what-clause-5-2-asks-for-the-ten-sections-the-ai-act-duties-it-names-the-mistakes-an-auditor-flags-and-a-page-that-writes-it","The ISO 42001 AI policy for a software company: what Clause 5.2 asks for, the ten sections, the AI Act duties it names, the mistakes an auditor flags, and a page that writes it","Clause 5.2 of ISO\u002FIEC 42001 asks top management for an AI policy that fits what the company uses AI for, gives the frame for the AI objectives, commits to the requirements that apply and to improving the system, is documented, communicated and available, and says how it sits beside the other policies. Three Annex A controls, A.2.2, A.2.3 and A.2.4, ask for the policy, its alignment with the other policies and its review. A short AI policy for a software company runs to ten sections: purpose, scope, position, the uses ruled out, accountability, objectives, the requirements that apply, the other policies, communication and review. The requirements section is where the AI Act enters: the literacy duty of Article 4, the transparency duties of Article 50 where the company generates content, and a recorded high-risk determination per system that the policy itself never asserts. A free page writes the policy from eleven answers in six languages.",{"who":59,"when":60,"do":61},"Top management of a software company that builds AI into its product or uses others' AI in its work, and the person who runs the AI management system for them; the AI policy is the first document an ISO 42001 auditor asks for and the one every decision to build, buy or rely on an AI system refers back to.","Before the impact assessments and the inventory are started, because both are promised in it, and before the first internal audit, where Clause 5.2 is checked against the approval, the communication record, the objectives and the alignment with the security and data protection policies; then at every management review and whenever a new AI capability, a changed purpose or a moved regulatory position calls for it.","Write two pages in ten sections in the company's own words, state the position and the uses ruled out, name who approves it and who runs the system, set three to five measurable objectives, name the AI Act duties that apply without classifying any system in the policy, say how it sits beside the security and data protection policies, and publish it where every joiner reads it; the free page writes the draft from eleven answers.",{"locale":5,"slug":63,"title":64,"description":65,"published":9,"answer":66},"the-iso-42001-ai-system-impact-assessment-what-clause-6-1-4-asks-for-the-three-levels-where-it-meets-the-ai-act-the-mistakes-an-auditor-flags-and-a-page-that-writes-it","The ISO 42001 AI system impact assessment: what Clause 6.1.4 asks for, the three levels of consequence, where it meets the AI Act, the mistakes an auditor flags, and a page that writes it","Clause 6.1.4 of ISO\u002FIEC 42001 has the company assess what each AI system could do to the individuals and groups it touches and to society, keep the result as documented information, and act on it through the system's life cycle; Clause 8.4 runs the process and four Annex A controls ask for the process, the retention, the harm to individuals and groups, and the harm beyond the users. It is the record the standard has and ISO 27001 does not. An assessment an auditor accepts names the purpose and the foreseeable misuse, the people, the consequences at the three levels with a likelihood and a severity each, the benefits, the measures, a result and a review date; under the AI Act it is the input to the Article 27 fundamental rights impact assessment and the place the company's own reading of the system is recorded. A free page writes it for one system.",{"who":67,"when":68,"do":69},"A company that builds an AI system into its product or runs someone else's AI system in its work and holds or plans ISO 42001; the impact assessment is the record the certification auditor opens per system, and the one the AI Act's deployer duties reach for first.","Before an AI system is built or first used, again when its purpose, its data, its users or its outputs change, when an incident touches it, and at a review date set in the assessment itself; the first assessments before the first internal audit, since the inventory and the assessments are what the audit reads.","List the systems, and for each write the purpose and the foreseeable misuse, name the people it touches, rate the consequences to individuals, to groups and to society for likelihood and severity and describe them, weigh the benefits, set the measures and the human oversight, record a result and a review date, record the AI Act reading beside it, and keep the record; the free page writes it in that order.",{"locale":5,"slug":71,"title":72,"description":73,"published":9,"answer":74},"the-nis2-incident-clock-for-a-software-company-24-hours-72-hours-one-month-what-makes-an-incident-significant-for-a-cloud-provider-and-a-page-that-writes-the-three-reports","The NIS2 incident clock for a software company: the 24-hour early warning, the 72-hour notification, the one-month final report, what makes an incident significant for a cloud provider, and a page that writes the three reports","Article 23(4) of NIS2 runs three clocks from the moment an essential or important entity becomes aware of a significant incident: an early warning within 24 hours, an incident notification within 72, and a final report within one month of that notification, with an intermediate report on request and a progress report where the incident is still open. For a cloud computing service provider, Implementing Regulation (EU) 2024\u002F2690 says when an incident is significant: a direct financial loss over EUR 500 000 or 5 % of turnover, whichever is lower, a service completely unavailable for more than 30 minutes, availability limited for more than 5 % or 1 million of its users in the Union for more than an hour, or a suspectedly malicious compromise of data. What each report contains, which CSIRT it goes to, and a free page that computes the deadlines and writes all three in six languages.",{"who":75,"when":76,"do":77},"A software company that is an essential or important entity under NIS2, which for a cloud computing service provider, a managed service provider or a managed security service provider is the case by Annex I or II regardless of the state; and the same company as the supplier its customers' own Article 23 reports depend on.","From the moment of awareness of a significant incident: the early warning within 24 hours, the notification within 72, the final report not later than one month after the notification is submitted; the duty has applied since the transposition deadline of 17 October 2024, and Implementing Regulation (EU) 2024\u002F2690 has set the thresholds for the digital providers since 7 November 2024.","Record the moment of awareness and read the incident against Article 23(3) and, for a digital provider, against the Regulation's thresholds; send the early warning within 24 hours with the two flags it asks for, the notification within 72 with the initial assessment, the final report within a month with its four contents; the free page computes the three deadlines, names the CSIRT and writes the reports.",{"locale":5,"slug":79,"title":80,"description":81,"published":82},"ai-literacy-under-article-4-of-the-ai-act-as-rewritten-on-27-july-2026-what-take-measures-means-who-it-covers-what-it-does-not-require-and-the-record-to-keep","AI literacy under Article 4 of the AI Act, as rewritten on 27 July 2026: what 'take measures' means, who it covers, what it does not require, and the record to keep","Article 4 has applied to every provider and deployer of an AI system since 2 February 2025. The Digital Omnibus rewrote it: measures to support the development of AI literacy, taking account of people's knowledge and the context, and, in terms the Regulation now uses, no duty to guarantee any specific level of literacy of any individual. The Commission is to publish practical examples and the AI Board common objectives. What the article asks, why it has no fine of its own in Article 99, how ISO 42001's competence and awareness clauses produce the record, and a one-page programme.","2026-09-12",{"locale":5,"slug":84,"title":85,"description":86,"published":82},"article-50-of-the-ai-act-the-four-transparency-duties-since-2-august-2026-the-2-december-2026-transition-the-code-of-practice-and-the-eu-icon","Article 50 of the AI Act for a company that ships or uses generative AI: the four transparency duties in force since 2 August 2026, the 2 December 2026 transition, the code of practice and the EU icon","Article 50 is the AI Act obligation that reaches a company whether or not its system is high-risk: tell people they are talking to an AI, mark generated content so machines can detect it, disclose deep fakes and AI-written text on matters of public interest, inform people exposed to emotion recognition. It has applied since 2 August 2026, the Digital Omnibus left it unchanged and gave providers of generative systems already on the market until 2 December 2026 for the marking duty. The four paragraphs read in order, who is provider and who is deployer for each, the Commission's code of practice of 10 June 2026 with its two-layer marking and its AI icon, the fine, and the record an ISO 42001 system keeps.",{"locale":5,"slug":88,"title":89,"description":90,"published":82,"answer":91},"does-iso-9001-2015-require-a-quality-manual-what-clause-7-5-asks-for-instead-the-21-places-the-standard-names-documented-information-and-what-a-manual-is-for-today","Does ISO 9001:2015 require a quality manual? What clause 7.5 asks for instead, the 21 places the standard names documented information, and what a manual is for today","ISO 9001:2008 required a quality manual; ISO 9001:2015 does not, and says so in its Annex A. What it requires is documented information: five things to maintain (the scope, the process information, the quality policy, the objectives, the operational planning) and sixteen kinds of record to retain, each named by clause. What clause 7.5 asks of every document, why a manual is still the right place for the map of the system, and what to put in it. With the count of EU tender notices that asked for ISO 9001 in the last year, 17,076, five times ISO 27001.",{"who":92,"when":93,"do":94},"A company certifying to ISO 9001:2015 or keeping a certificate current; the 2015 edition does not require a quality manual, and an auditor who asks for one is asking for the documented information clause 7.5 names.","ISO 9001:2015 has been the only edition in force since the 2008 edition expired in September 2018; the 21 places the standard names documented information apply from the day the scope is set.","Keep the five things to maintain (scope, process information, quality policy, objectives, operational planning) and the sixteen kinds of record to retain, each named by clause; write a manual only as the map of the system, not because the standard asks.",{"locale":5,"slug":96,"title":97,"description":98,"published":82,"answer":99},"dora-for-a-software-vendor-the-article-30-contract-clauses-your-bank-customer-will-send-the-register-of-information-and-what-iso-27001-already-answers","DORA for a software vendor: the Article 30 contract clauses your bank customer will send, the register of information you will appear in, and what ISO 27001 already answers","Since 17 January 2025 every bank, insurer, investment firm and payment institution in the Union manages its software vendors under Regulation (EU) 2022\u002F2554, DORA. The vendor is not regulated; the contract is. Article 30 lists nine clauses every ICT service contract must carry and six more when the service supports a critical or important function: locations, data return, incident assistance at a pre-set cost, cooperation with the customer's authorities, termination notice, audit rights, exit strategies. Each clause read from the Regulation, the register of information the customer files yearly, the three delegated acts behind it, and which of the clauses an ISO 27001 system already produces the evidence for.",{"who":100,"when":101,"do":102},"A software vendor, SaaS provider, managed service or hosted API with a customer that is a bank, insurer, investment firm, payment or e-money institution, crypto-asset service provider or fund manager in the Union; the vendor is not regulated, its contract is.","DORA applies since 17 January 2025; every ICT contract carries the Article 30 clauses at signature or renewal, and the customer reports the register of information you appear in to its authority every year.","Read the addendum against Article 30(2) and (3), nine clauses in every contract and six more where the service supports a critical or important function; the free clause checklist gives the fifteen with what ISO 27001 already answers.",{"locale":5,"slug":104,"title":105,"description":106,"published":82},"dora-ict-service-types-s01-to-s19-which-one-a-saas-product-is-what-the-register-of-information-records-and-why-one-contract-can-be-several-rows","DORA's nineteen types of ICT service, S01 to S19: which one a SaaS product is, what the register of information records about it, and why one contract can be several rows","Every ICT service a bank, insurer or payment institution buys is recorded in its register of information under one of nineteen codes, S01 to S19, from Annex III of Implementing Regulation (EU) 2024\u002F2956. A hosted product is S19, installed software is S13, a managed service S14, a data feed S05, and the customer files one row per service and function, so a single contract can become several. The nineteen types with the Regulation's own descriptions, the column that carries the code, what the customer must record beside it, and why the code you give one customer must match the code you give the next.",{"locale":5,"slug":108,"title":109,"description":110,"published":82},"dora-subcontracting-rts-2025-532-the-twelve-contract-terms-when-you-subcontract-a-critical-service-the-ten-conditions-your-customer-checks-and-the-notice-period","Subcontracting under DORA, RTS 2025\u002F532: the twelve terms your contract carries when you subcontract a critical service, the ten conditions your customer checks first, and the notice period before you change a subcontractor","Since 22 July 2025 a financial entity may let its software vendor subcontract a service supporting a critical or important function only on the conditions of Delegated Regulation (EU) 2025\u002F532. Ten conditions the customer assesses before signing, from your ability to identify every subcontractor to whether the subcontractor grants the same audit rights; twelve terms the contract then carries, from your responsibility for the subcontractor's service to the customer's right to terminate; a notice period during which you may not change a subcontractor until the customer has approved or not objected; and three cases in which the customer may terminate. Read from the Official Journal, with what the register of information records about the chain and what an ISO 27001 supplier register already answers.",{"locale":5,"slug":112,"title":113,"description":114,"published":82},"dora-vendor-due-diligence-rts-2024-1773-the-six-questions-the-five-sources-of-assurance-the-eight-conditions-for-relying-on-your-certificate-and-the-five-reports","Your bank's DORA vendor policy, RTS 2024\u002F1773: the six due-diligence questions, the five sources of assurance, the eight conditions for accepting your ISO 27001 certificate in place of an audit, and the five reports you will owe","Every financial entity in the Union has a written policy on its contracts for ICT services supporting critical or important functions, and Delegated Regulation (EU) 2024\u002F1773 says what that policy must contain, in force since 15 July 2024. Read from the vendor's side: the six things the customer assesses about you before signing (Article 6), the five sources of assurance it may use and the eight conditions under which it may rely on your certifications or audit reports rather than auditing you itself (Article 8), the key indicators, penalties and five kinds of report the contract will demand (Article 9), and the exit plan it must test (Article 10). With what an ISO 27001 certificate answers, and what it does not.",{"locale":5,"slug":116,"title":117,"description":118,"published":82,"answer":119},"essential-or-important-under-nis2-the-size-rule-the-size-blind-rules-and-the-seven-ways-to-be-essential","Essential or important under NIS2: the size rule, the size-blind rules and the seven ways to be essential","Whether NIS2 reaches a company is Article 2; whether it is essential or important is Article 3; and the difference is ex ante supervision, a higher fine ceiling and a stricter reading of everything else. The two articles quoted, the size classes of Recommendation 2003\u002F361\u002FEC as they are actually counted, the rules that ignore size, and the cases a software company gets wrong: a cloud provider with 40 staff, a large machinery maker, a registrar, a company outside the Union.",{"who":120,"when":121,"do":122},"A company of one of the 67 entity types in Annex I or II of NIS2 that is medium-sized or larger (from 50 staff, or above EUR 10 million in both turnover and balance sheet, counted with linked and partner enterprises), plus the size-blind cases of Article 2(2): communications, trust services, DNS and TLD, the sole provider, and the entities a member state names.","NIS2 applies since 18 October 2024 through the national transposition; the member states' lists of essential and important entities were due by 17 April 2025, and the Article 27 registry entry of DNS, cloud, data centre, CDN, managed service, marketplace, search engine and social network providers by 17 January 2025.","Run the scope determination: entity type, size class, the four size-blind questions; the result says essential (Article 32 supervision, a EUR 10 million ceiling) or important (Article 33, EUR 7 million), and it is the first line of the register.",{"locale":5,"slug":124,"title":125,"description":126,"published":82,"answer":127},"gdpr-international-transfers-for-a-software-company-the-17-adequacy-decisions-the-four-scc-modules-what-a-us-uk-or-indian-sub-processor-needs-and-a-page-that-picks-the-mechanism","GDPR international transfers for a software company: the 17 adequacy decisions, the four SCC modules, what a US, UK or Indian sub-processor needs, and a page that picks the mechanism","Every hosting provider, support desk, analytics tool and payroll service outside the EEA is a transfer under Chapter V. The Commission's list of adequacy decisions, read on 12 September 2026, carries 17 entries: 16 countries and territories, from Andorra to Uruguay, and the European Patent Organisation, with the United Kingdom renewed in December 2025, Brazil added in January 2026, and the United States covered only for companies certified under the Data Privacy Framework. Everything else needs the standard contractual clauses of Decision (EU) 2021\u002F914, whose four modules follow the roles of the exporter and the importer, with the local-law assessment of Clause 14 before the first transfer; the derogations of Article 49 are for the single occasion, never for a product in use. Read against the catalogue, with a free page that picks the mechanism and writes it.",{"who":128,"when":129,"do":130},"A software company established in the Union that sends personal data outside the EEA: its own customer data to a CRM, its customers' data to a hosting, support or AI provider, its staff's data to a payroll or HR tool; as controller for the first and processor for the second, and the customers who ask, in the processor terms, where the data go.","From the first transfer; the adequacy list is a snapshot of 12 September 2026, and the Commission reviews and renews its decisions, so the mechanism a recipient rests on is re-read when the list changes; the clauses of Decision (EU) 2021\u002F914 have been the only Commission clauses since the old sets expired in December 2022.","List every recipient outside the EEA on the record of processing with its country; for each, the adequacy decision that carries it or the SCC module signed with its annexes and the Clause 14 assessment; ask a US importer for its Data Privacy Framework certification and a UK or Japanese one for nothing more; the free page picks the mechanism from the destination and the two roles.",{"locale":5,"slug":132,"title":133,"description":134,"published":82},"harmonised-standards-for-the-cra-what-request-m-606-asks-for-when-and-what-a-manufacturer-has-today","Harmonised standards for the CRA: what request M\u002F606 asks for, when, and what a manufacturer has today","Article 27 gives a presumption of conformity to products that follow harmonised standards cited in the Official Journal. On 3 February 2025 the Commission asked CEN, CENELEC and ETSI for 41 of them, with deadlines from 30 August 2026 to 30 October 2027; the three accepted on 3 April 2025. On 12 September 2026 the Commission's index of harmonised standards still has no entry for the Regulation, which for a class I product means no self-assessment route under Article 32(2). What was requested, the dates, and what to build against in the meantime.",{"locale":5,"slug":136,"title":137,"description":138,"published":82},"how-to-check-an-iso-9001-certificate-is-real-what-a-certificate-must-show-three-checks-that-take-ten-minutes-and-the-27-accreditation-registers","How to check an ISO 9001 certificate is real: what a certificate must show, three checks that take ten minutes, and the 27 accreditation registers","ISO does not certify companies and keeps no register of them, so a certificate is only as good as the body that issued it and the accreditation behind that body. What ISO\u002FIEC 17021-1 makes a certificate show, the three checks (the certifier is accredited for ISO 9001, the certificate is current, the scope covers what you are buying), the 27 national accreditation registers with links, why a certifier in another EU state is as good as one in yours, and why the cheap unaccredited certificate costs more in the end.",{"locale":5,"slug":140,"title":141,"description":142,"published":82,"answer":143},"iso-27701-2025-for-a-software-company-the-standalone-privacy-standard-its-78-controls-what-an-iso-27001-system-already-covers-and-the-gdpr-articles-each-control-evidences","ISO\u002FIEC 27701:2025 for a software company: the standalone privacy standard, its 78 controls, what an ISO 27001 system already covers, and the GDPR articles each control evidences","The second edition of ISO\u002FIEC 27701, published in October 2025, is no longer an extension to ISO 27001: it is a management system standard of its own, with clauses 4 to 10 and one Annex A of 78 controls, 31 for PII controllers, 18 for PII processors and 29 information security controls for both. Read row by row for a software company: which of the 103 requirements a running ISO 27001 system already half-covers and what 27701 asks beyond it, the 33 privacy requirements no security control produces, and the 32 GDPR articles the controls evidence, from the record of processing to the 72-hour breach clock. StandardOS's reading, with the standard's text left where it is.",{"who":144,"when":145,"do":146},"A software company that holds or is building an ISO 27001 system and processes personal data for itself and for its customers: the standard has a table for each role, PII controller and PII processor, and a SaaS is both.","The 2025 edition was published in October 2025 and replaces the withdrawn 2019 extension; a certificate to the old edition runs into the transition the accreditation bodies set, and a first certification is to the new one; the GDPR duties the controls evidence apply now, whatever the certificate says.","Start from the 70 rows a 27001 system already half-covers and close the gap each row names; then add the 33 privacy-only controls, the record of processing, the lawful basis, the impact assessment, the rights of PII principals; the free GDPR determination says which of those your product needs first.",{"locale":5,"slug":148,"title":149,"description":150,"published":82},"iso-9001-for-a-software-company-what-clause-8-means-when-the-product-is-code-sub-clause-by-sub-clause","ISO 9001 for a software company: what clause 8 means when the product is code, sub-clause by sub-clause","Clauses 4 to 7, 9 and 10 of ISO 9001:2015 are the management-system skeleton an ISO 27001 company already runs. Clause 8, Operation, is the one written for factories and service desks, and the one a software company has to translate. What each sub-clause is when the product is software: requirements review before you commit (8.2), the development life cycle as design and development (8.3), cloud providers and dependencies as external providers (8.4), deployment, traceability, customer data and support as production and service provision (8.5), the release gate (8.6), and bugs and incidents as nonconforming outputs (8.7). With where the Cyber Resilience Act asks for the same records.",{"locale":5,"slug":152,"title":153,"description":154,"published":82},"iso-9001-in-eu-public-tenders-by-country","Which EU countries name ISO 9001 in public tenders: 4,897 German notices, 4,743 Romanian, and one in ten Romanian notices names it","Over 365 days, ISO 9001 appears in 16,356 TED notices from EU-27 buyers, 1.87% of everything they published and five times the 3,361 that name ISO 27001. Germany and Romania account for 59% of the mentions; Romania names it in 10.48% of its notices, Bulgaria in 7.34%, Hungary in 7.02%; France, Spain and Italy barely name it. And 1,475 notices name both standards, 44% of every ISO 27001 mention. The table by country, the overlap, and the query to re-run them.",{"locale":5,"slug":156,"title":157,"description":158,"published":82},"nis2-article-20-for-the-board-what-the-management-body-must-approve-oversee-and-learn-the-twelve-places-the-implementing-regulation-names-it-and-what-liability-means","NIS2 Article 20 for the board: what the management body must approve, oversee and learn, the twelve places the Implementing Regulation names it, and what liability means","Article 20 of NIS2 makes the management body of an essential or important entity approve the cybersecurity risk-management measures, oversee their implementation, be liable for the entity's infringements of Article 21, and follow training. Implementing Regulation 2024\u002F2690 then names the management body in twelve places of its Annex: a dated approval of the policy, an annual review, a direct reporting line, acceptance of residual risk, compliance reporting, an awareness programme. Each of the twelve as a record, the ISO 27001 clause that already produces it, and what Article 32 and Article 34 say liability looks like.",{"locale":5,"slug":160,"title":161,"description":162,"published":82},"nis2-for-a-saas-company-you-are-a-cloud-computing-service-provider-and-this-is-what-follows","NIS2 for a SaaS company: you are a cloud computing service provider, and this is what follows","Recital 33 of the Directive names Software as a Service as a cloud service model, so a SaaS company of medium size or larger is an entity of NIS2 as a cloud computing service provider: important below the medium ceilings, essential above them. What follows, in the order it arrives: the state of your main establishment, the registry you had to be in by 17 January 2025, the measures of Implementing Regulation 2024\u002F2690, the four incident thresholds of its Article 7 and the Article 23 clocks, and the line between this and the CRA.",{"locale":5,"slug":164,"title":165,"description":166,"published":82},"nis2-for-managed-service-providers-and-mssps-an-annex-i-entity-by-definition-and-the-supplier-every-customers-due-diligence-lands-on","NIS2 for managed service providers and MSSPs: an Annex I entity by definition, and the supplier every customer's due diligence lands on","Article 6(39) makes anyone who installs, manages, operates or maintains ICT for customers, on site or remotely, a managed service provider, and Article 6(40) makes the ones who help with cybersecurity risk management MSSPs. Both are Annex I types: important at medium size, essential above the ceilings, under the law of the main establishment, in ENISA's registry, under Implementing Regulation 2024\u002F2690 directly, with Article 10's four incident thresholds. And recital 86 tells every essential and important customer to exercise increased diligence in choosing you.",{"locale":5,"slug":168,"title":169,"description":170,"published":82},"nis2-for-online-marketplaces-search-engines-and-social-networks-the-annex-ii-digital-providers-and-why-they-are-never-essential-by-size","NIS2 for online marketplaces, search engines and social networks: the Annex II digital providers, and why they are never essential by size","Three definitions borrowed from three other acts decide whether a platform is a digital provider under NIS2: a marketplace where consumers conclude distance contracts, a search engine that searches in principle all websites, a platform where end users connect and share. In scope at medium size, important under Article 3(2) however large, under the law of the main establishment, in ENISA's registry, under Implementing Regulation 2024\u002F2690 with its own incident thresholds in Articles 11 to 13: no 30-minute rule, a share of users instead.",{"locale":5,"slug":172,"title":173,"description":174,"published":82},"nis2-registration-the-two-lists-you-may-be-on-what-you-submit-by-when-and-to-whom-article-3-4-and-article-27","NIS2 registration: the two lists you may be on, what you submit, by when, and to whom (Article 3(4) and Article 27)","NIS2 has two registrations, not one. Every essential and important entity submits four items to its competent authority so that the member state can establish its list by 17 April 2025 (Article 3(3) and (4)), with changes notified within two weeks. Eleven types of digital entity, cloud providers and managed service providers among them, also submit six items by 17 January 2025 for ENISA's registry (Article 27), with changes within three months. Which state receives it (Article 26), what the two lists are for, what registering does not decide, and the record to keep.",{"locale":5,"slug":176,"title":177,"description":178,"published":82},"nis2-transposition-state-by-state-what-the-commissions-register-shows","NIS2 transposition, state by state: what the Commission's own register shows","Not a law firm's tracker: the national measures the member states have communicated to the Commission as transposing Directive (EU) 2022\u002F2555, read from the Publications Office on 12 September 2026. 25 of the 27 states have communicated at least one, 303 measures in all; Spain and Ireland none; France 15 texts, all older than the Directive. The act each state calls its NIS2 law, when it entered into force, and what a software company does with the answer.",{"locale":5,"slug":180,"title":181,"description":182,"published":82},"the-ai-act-after-the-digital-omnibus-the-dates-that-changed-and-which-iso-42001-controls-produce-the-evidence-for-article-17-and-articles-9-to-15","The AI Act after the Digital Omnibus: the dates that changed on 27 July 2026, and which ISO 42001 controls produce the evidence for Article 17's thirteen aspects and Articles 9 to 15","Regulation (EU) 2026\u002F1744, signed 8 July 2026, published 24 July, in force 27 July, moved the AI Act's high-risk dates to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, rewrote AI literacy as a duty to take measures, and made the post-market monitoring plan part of the technical documentation. Most of what ranks still gives the old dates. The dates as amended, what else changed for a provider, and our mapping of Article 17's thirteen quality-management aspects, Articles 9 to 15, 72 and 73, and the operator duties of Articles 4 and 26 to the Annex A controls of ISO\u002FIEC 42001, with what the Regulation asks for that the standard does not produce.",{"locale":5,"slug":184,"title":185,"description":186,"published":82,"answer":187},"the-ai-act-for-a-software-company-which-role-you-are-what-applies-to-everyone-what-applies-only-to-a-high-risk-provider-the-sme-provisions-and-the-dates-as-amended","The AI Act for a software company: which role you are, what applies to everyone, what applies only to a high-risk provider, the SME provisions, and the dates as amended","A software company meets the AI Act in one of six roles, and most of the Regulation only applies to two of them. What counts as an AI system at all, why shipping a vendor's model under your own name makes you the provider, the three duties every company has since 2025 and 2026 (AI literacy, the prohibitions, transparency), the two routes to high-risk and what each role then owes from 2 December 2027, the general-purpose model line, the SME and small mid-cap provisions the Digital Omnibus widened, and one table of who owes what from when. Read from the two Regulations on CELLAR on 12 September 2026.",{"who":188,"when":189,"do":190},"Every software company that develops, sells, integrates or uses an AI system in the Union, in one of six operator roles; most of the Regulation applies only to the provider of a high-risk system, and most companies are the deployer of many systems and the provider of few.","AI literacy and the prohibitions since 2 February 2025; Article 50 transparency since 2 August 2026; the high-risk obligations from 2 December 2027 for an Annex III use case and from 2 August 2028 for a product under Annex I.","Determine your role for each system and whether it is high-risk, in writing, with the free determination; then the literacy record, which every company owes today.",{"locale":5,"slug":192,"title":193,"description":194,"published":82},"the-eu-declaration-of-conformity-under-the-cra-annex-v-point-by-point-the-simplified-form-and-a-worked-example","The EU declaration of conformity under the CRA: Annex V point by point, the simplified form, and a worked example","Article 28 makes the manufacturer draw up an EU declaration of conformity before the product is placed on the market, in the model structure of Annex V, and Article 28(4) makes signing it the act by which the manufacturer assumes responsibility for the product. The eight points of Annex V, the one-sentence simplified form of Annex VI, the rules around it (languages, the single declaration, product families, 10 years of retention), a worked example, and what a missing or incorrect declaration costs under Article 58 and Article 64.",{"locale":5,"slug":196,"title":197,"description":198,"published":82,"answer":199},"the-gdpr-72-hour-breach-clock-for-a-software-company-when-awareness-starts-it-what-the-notification-contains-the-processor-s-own-clock-and-the-nis2-cra-and-dora-clocks-beside-it","The GDPR 72-hour breach clock for a software company: when awareness starts it, what the notification contains, the processor's own clock, and the NIS2, CRA and DORA clocks beside it","Article 33 gives a controller 72 hours from becoming aware of a personal data breach to notify the supervisory authority, and most companies get the start wrong, the content wrong, or the role wrong. When awareness begins under the EDPB guidelines and recital 87, the four contents of Article 33(3), the phases of 33(4), the reasons-for-delay rule, the processor's duty to notify the controller without undue delay, the communication to the data subjects under Article 34 and its three exceptions, and the NIS2, CRA and DORA clocks a software company may be running from the same moment. With the free page that computes the deadline and writes the notification.",{"who":200,"when":201,"do":202},"Every software company that holds personal data: as controller of its own customer and staff data it owes the 72-hour notification itself; as processor of its customers' data inside the product it owes the customer a notice without undue delay, which starts the customer's clock.","The clock runs from the moment of awareness, a reasonable degree of certainty that a breach has occurred, not from the first alert; the notification is due within 72 hours, in phases where necessary, with the reasons for any delay; the data subjects are told without undue delay where the risk to them is high.","Enter the moment of awareness on the free breach clock: it computes the deadline in your time zone, says whether the reasons-for-delay rule applies, and writes the notification with the four contents of Article 33(3) to copy or download.",{"locale":5,"slug":204,"title":205,"description":206,"published":82,"answer":207},"the-gdpr-data-subject-request-for-a-software-company-the-month-of-article-12-3-the-eight-contents-of-an-access-answer-the-two-further-months-and-a-page-that-computes-the-deadline","The GDPR data subject request for a software company: the month of Article 12(3), the eight contents of an access answer, the two further months, and a page that computes the deadline","A request under Articles 15 to 22 is answered without undue delay and in any event within one month of receipt (Article 12(3)); the period ends on the same date of the next month, or the last day of it; two further months are available where the requests are complex or numerous, with the data subject told within the first month; a refusal carries its reasons and the remedies within the same month (12(4)); the answer is free unless the request is manifestly unfounded or excessive, and the company bears the burden of showing that (12(5)). An access request is answered with a copy of the data and the eight pieces of information of Article 15(1), (a) to (h), from the purposes to the automated decision-making. Read against the catalogue, with a free page that computes the deadline and writes the answer in six languages.",{"who":208,"when":209,"do":210},"A software company as controller of its own customer, user and employee data, which receives the request; and as processor of its customers' data, which assists the controller with it under Article 28(3)(e) and never answers the data subject in the controller's place.","The clock starts on the day the request is received, by any channel the company offers, and ends within one month, or three where the extension is taken and notified within the first; the duty has applied since 25 May 2018 and has no size threshold.","Log the day of receipt and compute the deadline; check identity only where there is reasonable doubt; answer from the record of processing, which already holds the purposes, the categories, the recipients and the retention periods; the free page computes the date and writes the access answer to Article 15(1).",{"locale":5,"slug":212,"title":213,"description":214,"published":82,"answer":215},"the-gdpr-for-a-software-company-controller-of-your-own-data-processor-for-your-customers-and-the-five-duties-that-turn-on-size-and-data","The GDPR for a software company: controller of your own data, processor for your customers', and the five duties that turn on size and data","Regulation (EU) 2016\u002F679 reaches every software company, so the question is which duties turn on. The two roles per processing (Article 4), the record of processing that the 250-person exemption never spares a product in use (Article 30), the officer (Article 37), the impact assessment (Article 35), the representative for a company outside the Union (Article 27), the transfer grounds (Chapter V), the 72-hour and one-month clocks, and what ISO 27701 produces for each. Read from the Official Journal, with the free determination that writes it down.",{"who":216,"when":217,"do":218},"Every software company that processes personal data in the Union or offers its product to people in it: controller of its own customer, prospect and staff data, and, for a SaaS, processor of the data its customers put into the product.","Applying since 25 May 2018; the breach clock is 72 hours from becoming aware, a data subject's request is answered within one month, and the record, the officer, the impact assessment and the representative turn on the day the answer that triggers them changes.","Run the free determination: nine answers give the duties as a table with the provision behind each, then keep the record of processing, it is the document every other duty rests on.",{"locale":5,"slug":220,"title":221,"description":222,"published":82,"answer":223},"the-gdpr-impact-assessment-for-a-software-company-the-three-cases-of-article-35-3-the-nine-criteria-behind-them-the-four-elements-of-article-35-7-and-a-page-that-writes-it","The GDPR impact assessment for a software company: the three cases of Article 35(3), the nine criteria behind them, the four elements of Article 35(7), and a page that writes it","Article 35 requires a data protection impact assessment before any processing likely to result in a high risk, and names three cases where it is required in any event. Which product features fall into them, the nine criteria the supervisory authorities apply and the rule that two of them usually mean an assessment, the lists the authorities publish under Article 35(4) and (5), the four elements the assessment must contain, the data protection officer's advice and the data subjects' views, the prior consultation of Article 36 with its eight weeks, and the review when the risk changes. With the free page that decides whether one is due and writes it.",{"who":224,"when":225,"do":226},"Every software company as controller of a processing it designs: a scoring, ranking or screening feature, behavioural analytics, tracking, an AI feature, large-scale special-category data or monitoring of a public area; the processor supports the assessment but does not owe it (Article 28(3)(f)).","Before the processing starts (Article 35(1)), reviewed when the risk changes (Article 35(11)); where a high residual risk remains, the supervisory authority is consulted first and answers within eight weeks, extendable by six (Article 36).","Answer the three questions of Article 35(3) on the free page, then the Article 35(1) question where none applies; if an assessment is due, write its four elements there, element by element, and keep it on the record of processing it belongs to.",{"locale":5,"slug":228,"title":229,"description":230,"published":82,"answer":231},"the-gdpr-privacy-notice-for-a-software-company-the-twelve-pieces-of-article-13-the-thirteen-of-article-14-the-moment-each-is-given-and-a-page-that-writes-it","The GDPR privacy notice for a software company: the twelve pieces of Article 13, the thirteen of Article 14, the moment each is given, and a page that writes it","A privacy notice is not a genre; it is a list. Article 13 names twelve pieces of information a controller gives at the time personal data are obtained from the person, six in every case and six further ones for fair and transparent processing, and Article 14 names thirteen for data obtained elsewhere, given within a reasonable period and at the latest within one month, with four exemptions. For a software company, seven of them are columns of its record of processing already. Every piece as the Official Journal words it, the moment it is given, the two cases where it is not owed, and a free page that writes the notice from the answers in six languages.",{"who":232,"when":233,"do":234},"A software company as controller of the data its own website, product signup, support desk and job applications collect from people, which owes the Article 13 notice at the point of collection; and the same company where it obtains personal data from a partner, a list or a customer's upload, which owes the Article 14 notice within a month.","Article 13 at the time the data are obtained, so on the form, the signup screen and the first email; Article 14 within a reasonable period after obtaining the data and at the latest within one month, at the first communication with the person, or at the first disclosure to another recipient, whichever comes first; a new purpose restarts the duty before the further processing (13(3), 14(4)).","Write the record of processing first, then answer each piece of Articles 13 and 14 from it, the purposes, the legal bases, the recipients, the transfers and the retention periods; put the notice where the data are collected, in clear and plain language; the free page lists every piece as the Regulation words it and writes the notice from the answers.",{"locale":5,"slug":236,"title":237,"description":238,"published":82,"answer":239},"the-gdpr-processor-contract-for-a-saas-company-the-eight-terms-of-article-28-3-every-customer-addendum-carries-the-duty-most-of-them-forget-and-what-sits-beside-them-under-dora","The GDPR processor contract for a SaaS company: the eight terms of Article 28(3) every customer addendum carries, the duty most of them forget, and what sits beside them under DORA","A SaaS company signs the same contract with every customer it processes data for, and Article 28(3) fixes its content: the subject matter and duration, the eight undertakings from documented instructions to audits, and the processor's duty to flag an instruction that infringes the Regulation. What each term means for a software vendor, the sub-processor rule of Article 28(2) and (4), the Commission's 2021 standard clauses, the liability of Article 82 and the fine ceiling of Article 83, and the DORA Article 30 clause a bank customer sends beside each term. With the free checklist that reads the two addenda as one.",{"who":240,"when":241,"do":242},"Every SaaS company, hosted API or managed service that processes personal data for its customers, as their processor under Article 4(8); the terms bind the vendor whether the customer sends its own addendum or signs the vendor's.","The contract is due before the first processing for that customer and is re-read at every change of sub-processor (Article 28(2)); a bank, insurer or payment institution sends the DORA Article 30 clauses in the same addendum, in force since 17 January 2025, and the two sets are negotiated together.","Run the free checklist with the customer's addendum open: mark each of the eight terms agreed, negotiating or missing, note the clause number, and where the customer is a financial entity, continue into the DORA clause checklist with the same document.",{"locale":5,"slug":244,"title":245,"description":246,"published":82,"answer":247},"the-gdpr-record-of-processing-for-a-software-company-the-seven-fields-of-article-30-1-the-four-of-article-30-2-why-the-250-person-exemption-never-applies-and-a-page-that-writes-it","The GDPR record of processing for a software company: the seven fields of Article 30(1), the four of Article 30(2), why the 250-person exemption never applies, and a page that writes it","Article 30 is the one GDPR duty every other duty refers back to, and the one most software companies believe the 250-person exemption spares them. It does not: Article 30(5) lifts the exemption for any processing that is not occasional, and a product in use processes every day. The seven fields of a controller's record and the four of a processor's, read from the Official Journal, what each one is for, the ISO 27701 control that evidences it, and the free page that writes the record one activity at a time.",{"who":248,"when":249,"do":250},"Every software company with a live product: as the controller of its own customer, prospect and staff data (Article 30(1)), and, where it processes data for its customers inside the product, as their processor too (Article 30(2)); at any headcount, because the processing is not occasional.","The record is due from the first processing and is produced to the supervisory authority on request (Article 30(4)); it changes whenever a purpose, a recipient, a transfer or a retention period changes, and its transfers field is where the Chapter V ground for every sub-processor outside the EEA is written down.","Write one record per processing activity with the free page, seven fields for the controller's side and four for the processor's, each labelled with the point of Article 30 it answers, and keep it where the processor contracts and the breach clock are.",{"locale":5,"slug":252,"title":253,"description":254,"published":82,"answer":255},"the-gdpr-representative-of-article-27-for-a-software-company-outside-the-eu-who-must-appoint-one-the-three-conditions-of-the-exemption-and-where-the-name-goes","The GDPR representative of Article 27 for a software company outside the EU: who must appoint one, the three conditions of the exemption, and where the name goes","A software company with no establishment in the Union whose product is used by people in it is under the Regulation by Article 3(2) and must designate a representative in the Union in writing (Article 27(1)), established in a member state where its users are (27(3)), mandated to be addressed by supervisory authorities and data subjects (27(4)), and no shield against action on the company itself (27(5)). The exemption of Article 27(2)(a) has three conditions that must all hold, and a product in use fails the first. Where the representative's name goes: the privacy notice (Article 13(1)(a)), the record of processing (Article 30(1)(a)), and the record the representative keeps itself. The fine tier is Article 83(4). A free page decides it from two questions.",{"who":256,"when":257,"do":258},"A software company with no establishment in the Union, a US, UK, Swiss, Indian or other company, whose product is offered to people in the Union or monitors their behaviour there; and the EU customers that ask it, in the processor terms, who its representative is.","From the first day the product is offered to people in the Union: Article 3(2) attaches the Regulation to the processing, Article 27(1) attaches the representative to the company, and the duty is not phased, tiered by size or delayed; the exemption of Article 27(2)(a) is read at the same moment.","Designate a representative in writing, established in a member state where your users are, mandated to answer authorities and data subjects; put its name and contact details in the privacy notice and the record of processing, and hand the record to it; the free determination says whether Article 27(2)(a) exempts you, from two questions.",{"locale":5,"slug":260,"title":261,"description":262,"published":82,"answer":263},"the-iso-27001-scope-statement-why-a-certificate-that-says-head-office-does-not-cover-your-saas-what-clause-4-3-asks-for-what-a-buyer-under-dora-checks-and-three-that-pass","The ISO 27001 scope statement: why a certificate that says head office does not cover your SaaS, what clause 4.3 asks for, what a buyer under DORA checks, and three scope statements that pass","The scope statement is the certificate's limit, and buyers now read it against a regulation: a financial customer may rely on your ISO 27001 certificate instead of auditing you only if its scope covers the systems it depends on. What ISO\u002FIEC 27001:2022 clause 4.3 requires, what ISO\u002FIEC 17021-1 makes the certificate show, the surveillance cycle that decides whether it is current, the 2013-edition deadline that has passed, one scope statement that fails and three that pass for a software company, and how the interfaces to your cloud provider stay inside the scope while the provider stays outside.",{"who":264,"when":265,"do":266},"A certified software company whose certificate names an office, a department or a legal entity rather than the product and the systems a customer depends on; the buyer under DORA reads the scope before anything else, and a scope that does not cover the service is a certificate that does not count.","The certificate is current only inside its three-year cycle, with a surveillance audit at least once a calendar year and the first within 12 months of the decision; a certificate to the 2013 edition has been void since 31 October 2025.","Rewrite the scope to name the product, the delivery model, the supporting functions, the locations including the cloud regions and the Statement of Applicability version, and put it to the certification body before the next surveillance audit.",{"locale":5,"slug":268,"title":269,"description":270,"published":82,"answer":271},"the-iso-27001-statement-of-applicability-for-a-software-company-the-93-controls-the-four-columns-of-clause-6-1-3-d-the-exclusions-an-auditor-accepts-and-a-page-that-writes-it","The ISO 27001 Statement of Applicability for a software company: the 93 controls, the four columns of Clause 6.1.3(d), the exclusions an auditor accepts, and a page that writes it","The Statement of Applicability is the one ISO 27001 document an auditor reads before anything else, and Clause 6.1.3(d) makes it four questions per control: is it necessary, why is it included, is it implemented, and why is any Annex A control left out. For a software company with no offices of its own and a hosted stack, the 93 controls of the 2022 edition sort into the ones that apply in full, the handful that are honestly excluded, and the partly implemented ones that decide the audit's findings. What each column means, the exclusions an auditor accepts and the ones they never do, how the Statement follows the risk treatment plan, and a free page that writes it in six languages with the statuses in the address.",{"who":272,"when":273,"do":274},"A software company building or running an ISO 27001 information security management system, at the point where the risk assessment is done and the controls have to be declared, and the same company a year later when the surveillance audit asks what changed.","Before the certification audit, as the output of the risk treatment of Clause 6.1.3, and again whenever a control's status or a scope changes; the 2022 edition's 93 controls are the ones every new certificate and every certificate transitioned by 31 October 2025 is audited against.","Start from all 93 controls applicable and planned; mark a control implemented only when its evidence exists; exclude a control only with a written reason tied to the scope; write the Statement as a table with the four columns and date it; the free page writes it from the statuses and carries them in the address.",{"locale":5,"slug":276,"title":277,"description":278,"published":82,"answer":279},"the-iso-9001-management-review-the-13-inputs-and-3-outputs-of-clause-9-3-as-an-agenda-where-each-input-comes-from-and-what-the-minutes-have-to-show","The ISO 9001 management review: the 13 inputs and 3 outputs of clause 9.3 as an agenda, where each input comes from, and what the minutes have to show","Clause 9.3 of ISO 9001:2015 is the one meeting the standard writes the agenda for. Top management reviews the quality management system at planned intervals for suitability, adequacy, effectiveness and alignment with strategy (9.3.1); considers thirteen inputs, from the status of last time's actions to the performance of external providers (9.3.2); and decides on improvement, changes to the system and resources (9.3.3), with the results retained as documented information. The agenda, the record behind each input, what the minutes must show, and how the same meeting serves ISO 27001 and, for NIS2 entities, the annual policy review the Implementing Regulation requires.",{"who":280,"when":281,"do":282},"Top management of a company running an ISO 9001 quality management system, and the quality manager who prepares the review for them: the standard writes the agenda for this one meeting, and the certification auditor reads the minutes against it line by line.","At planned intervals, once a year for most companies and before the certification audit, and whenever a change in the business or its customers needs a decision at the top; the actions from the previous review open the next one.","Put the thirteen inputs on the agenda in the clause's order with the record each comes from, judge the system on the four words of 9.3.1, decide on improvement, on changes to the system and on resources, give every action an owner and a date, and keep the minutes as documented information.",{"locale":5,"slug":284,"title":285,"description":286,"published":82},"the-iso-9001-quality-policy-the-four-things-clause-5-2-says-it-must-contain-the-three-things-that-must-happen-to-it-and-a-one-page-example","The ISO 9001 quality policy: the four things clause 5.2 says it must contain, the three things that must happen to it, and a one-page example","Clause 5.2 of ISO 9001:2015 is short and precise. Top management establishes a quality policy that fits the organisation's purpose and context and supports its strategy, gives a framework for the quality objectives, and commits to meeting applicable requirements and to continual improvement (5.2.1). The policy is then maintained as documented information, communicated, understood and applied inside the organisation, and available to interested parties (5.2.2). What each of the seven requirements means for a page of text, the mistakes auditors write up, how the same policy serves ISO 27001, and a one-page example in our own words.",{"locale":5,"slug":288,"title":289,"description":290,"published":82},"the-nine-places-where-your-bank-customers-ict-risk-framework-reaches-into-your-product-rts-2024-1774-support-end-dates-vulnerability-reports-source-code-accounts-and-incidents","The nine places where your bank customer's ICT risk framework reaches into your product, RTS 2024\u002F1774: support end dates, vulnerability reports and library tracking, settings you may not let it bypass, source code tested before production, named accounts for your staff, and your incidents as its alarms","Delegated Regulation (EU) 2024\u002F1774, in force since 15 July 2024, specifies the ICT risk management framework every financial entity runs under DORA, and nine of its articles name the ICT third-party service provider. Read from the vendor's side: the asset register that records the end dates of your support (Article 4), the vulnerability procedure that verifies you handle and report vulnerabilities and tracks the third-party libraries in your product (Article 10), the data and system security procedure that allocates roles between you and the customer and asks for measures on your infrastructure (Article 11), encrypted connections over third-party networks (Article 13), source code from providers analysed and tested before production (Article 16), a unique account for each of your staff with access (Article 20), your incident notifications as one of its detection inputs (Article 23), continuity tests that include your service and your insolvency (Articles 25 and 26). With what an ISO 27001 system already answers.",{"locale":5,"slug":292,"title":293,"description":294,"published":82},"the-ten-measures-of-nis2-article-21-2-as-a-checklist-each-point-quoted-the-regulation-sections-behind-it-and-the-iso-27001-controls-that-already-produce-it","The ten measures of NIS2 Article 21(2), as a checklist: each point quoted, the Regulation sections behind it, and the ISO 27001 controls that already produce it","Article 21(2) lists ten measures every essential and important entity must take, from risk analysis policies to multi-factor authentication. For cloud, managed service and the other digital providers, Implementing Regulation 2024\u002F2690 details each in 13 sections written from ISO\u002FIEC 27001 and 27002. One table: the ten points as the Directive words them, the sections that detail each, and the ISO 27001 clauses and Annex A controls that produce the evidence, with the two places an ISMS does not reach.",{"locale":5,"slug":296,"title":297,"description":298,"published":82},"threat-led-penetration-testing-under-dora-from-the-vendors-side-when-your-bank-customers-red-team-is-allowed-into-your-production-systems-the-12-week-test-and-the-pooled-test","Threat-led penetration testing under DORA, from the vendor's side: when your bank customer's red team is allowed into your production systems, the 12-week test of RTS 2025\u002F1190, the pooled test you can run instead, and what the contract already says","Article 26 of DORA makes the largest financial entities run a threat-led penetration test on live production systems at least every 3 years, covering the critical or important functions they have outsourced, and Article 30(3)(d) puts the vendor's participation into the contract. Delegated Regulation (EU) 2025\u002F1190, in force since 8 July 2025, sets the mechanics: a control team that may include your staff, a blue team that must not know, an active red team phase of at least 12 weeks, a replay and purple teaming within 10 weeks of its end, a remediation plan within 8 weeks. Article 26(4) lets a vendor whose other customers would be harmed contract an external tester directly and run one pooled test for several financial entities. What the vendor signs, what it may refuse, and what an ISO 27001 system already holds. Read from the Official Journal.",{"locale":5,"slug":300,"title":301,"description":302,"published":82},"what-a-deployer-of-a-high-risk-ai-system-owes-under-article-26-of-the-ai-act-the-twelve-paragraphs-the-article-27-impact-assessment-and-when-you-become-the-provider","What a deployer of a high-risk AI system owes under Article 26 of the AI Act: the twelve paragraphs in order, the Article 27 impact assessment, when you become the provider, and the records an ISO 42001 system keeps","Most companies will meet the AI Act as deployers: they buy or licence a system someone else built and use it under their own authority. For a high-risk system the duties are in Article 26, twelve paragraphs, unchanged by the Digital Omnibus, applying from 2 December 2027 for Annex III systems. Each paragraph read in order, the Article 27 fundamental rights impact assessment and who carries it, the three ways a deployer becomes the provider under Article 25, the Article 86 right to explanation, the Article 99 ceiling, and the ISO 42001 control that produces each record.",{"locale":5,"slug":304,"title":305,"description":306,"published":82},"what-iso-9001-certification-costs-the-audit-days-iaf-md-5-fixes-by-headcount-the-day-rate-the-three-year-total-and-why-it-is-a-third-of-iso-27001","What ISO 9001 certification costs: the audit days IAF MD 5 fixes by headcount, the day rate, the three-year total, and why it is a third of ISO 27001","Certification bodies do not publish prices, but the audit days are not their opinion: IAF MD 5 sets them by the number of people in scope, 1.5 days for up to five people, 3 for 16 to 25, 7 for 86 to 125, and the accreditation body holds the certifier to the table. Multiply by a day rate of 1,200 to 1,800 euros, add two surveillance audits at about a third each, and you have your number before anyone quotes you. Worked for six company sizes, with the ISO 27001 days beside them, what moves the number up or down, and what else you pay.",{"locale":5,"slug":308,"title":309,"description":310,"published":82},"when-your-outage-becomes-your-bank-customers-major-incident-doras-six-criteria-the-two-hour-downtime-threshold-the-four-clocks-and-the-facts-your-customer-needs-from-you","When your outage becomes your bank customer's major incident: DORA's six criteria, the two-hour downtime threshold of RTS 2024\u002F1772, the four-hour, 24-hour, 72-hour and one-month clocks of RTS 2025\u002F301, and the facts your customer will need from you","A financial entity must report a major ICT-related incident to its supervisor within four hours of classifying it and no later than 24 hours from becoming aware, follow up within 72 hours and close within one month. Whether an outage at its software vendor is major is decided by six criteria and the thresholds of Delegated Regulation (EU) 2024\u002F1772: more than two hours of downtime on a service supporting a critical or important function, more than 24 hours of duration, more than 10 percent of clients, two or more member states, data losses, 100 000 euro. What each report must contain under Delegated Regulation (EU) 2025\u002F301, which of those facts only the vendor holds, and what the Article 30(2)(f) incident assistance clause turns that into. Read from the Official Journal.",{"locale":5,"slug":312,"title":313,"description":314,"published":82,"answer":315},"which-gdpr-supervisory-authority-is-yours-the-main-establishment-the-lead-authority-of-article-56-the-local-cases-and-the-30-authorities-of-the-board","Which GDPR supervisory authority is yours: the main establishment, the lead authority of Article 56, the local cases, and the 30 authorities of the Board","A software company with customers in several member states deals with one supervisory authority for its cross-border processing: the authority of its main establishment, the lead authority of Article 56(1), its sole interlocutor under Article 56(6). Where that is, what the main establishment means for a controller and for a processor (Article 4(16)), when another authority keeps a local case (Article 56(2)), what a company with no establishment in the Union gets instead (Article 27, recital 122), and where the 72-hour breach notification goes (Article 33(1)). With the 27 authorities and the three EEA ones as the European Data Protection Board lists its members, read on 12 September 2026.",{"who":316,"when":317,"do":318},"A software company established in the Union that processes personal data of people in more than one member state, as controller of its own customer and employee data and as processor of the data its customers put in the product; and a company with no establishment in the Union that sells to people in it.","From 25 May 2018, the day the Regulation applied, for every controller and processor in scope; the register of authorities is read from the Board's members page on 12 September 2026.","Write down where your central administration in the Union is and whether decisions on purposes and means are taken anywhere else; that place's authority is your lead authority for cross-border processing, the one your breach notification goes to; enter the state on the breach clock and the authority is named with its address.",{"locale":5,"slug":320,"title":321,"description":322,"published":323},"cra-annex-i-the-22-essential-requirements-as-a-checklist","CRA Annex I: the 22 essential requirements, as a checklist","Annex I of the Cyber Resilience Act is what your product has to meet from 11 December 2027 and what the technical file has to show. Part I is 14 product requirements, 13 of them 'where applicable' on the basis of your risk assessment; Part II is 8 vulnerability-handling requirements that always apply. Here they are as one table, with what each one asks and whether you may exclude it.","2026-09-11",{"locale":5,"slug":325,"title":326,"description":327,"published":323},"cra-final-report-clock-does-not-start-when-you-become-aware","The CRA final report clock does not start when you become aware","Most write-ups of Cyber Resilience Act Article 14 give three deadlines from one starting point: 24 hours, 72 hours, 14 days. The first two run from awareness. The third does not, and for a vulnerability its anchor is a date that may not exist yet. Here is what the Regulation says, paragraph by paragraph.",{"locale":5,"slug":329,"title":330,"description":331,"published":323,"answer":332},"cra-or-nis2-which-one-applies-to-a-software-company","CRA or NIS2: which one applies to a software company, and can it be both?","The Cyber Resilience Act regulates products placed on the market; NIS2 regulates entities that provide services. A software company can be under one, the other, both or neither, and the answer turns on two questions: do you place a product on the market, and are you a medium-sized or larger entity in a listed sector. The dates, the reporting clocks, the fines and the decision table, from the two texts.",{"who":333,"when":334,"do":335},"A software company in the Union, under one, the other, both or neither: the CRA reaches you if you place a product with digital elements on the market; NIS2 reaches you if you are a medium-sized or larger entity in a listed sector, cloud and managed services included.","The CRA's reporting duty applies since 11 September 2026 and its full obligations from 11 December 2027; NIS2 has applied since 18 October 2024 through the national transposition.","Answer the two questions in writing, do you place a product on the market and are you a listed entity of 50 staff or EUR 10 million, and read the decision table below for what each answer brings: the clock, the recipient, the fine ceiling.",{"locale":5,"slug":337,"title":338,"description":339,"published":323},"default-important-or-critical-the-26-technical-descriptions-and-the-core-functionality-test","Default, important or critical: the 26 technical descriptions of Implementing Regulation 2025\u002F2392, and the core-functionality test","Annex III and IV of the CRA name 26 product categories in a line each. Commission Implementing Regulation (EU) 2025\u002F2392, in force since 21 December 2025, describes each one technically, and the Commission's guidance of 27 July 2026 says how to classify against them: by the product's core functionality, not by what it also does or what it integrates. All 26 descriptions verbatim, the guidance's six rules with its examples (SOAR is not a SIEM, a log viewer is not a SIEM, a router with a firewall is a router), and what the classification changes.",{"locale":5,"slug":341,"title":342,"description":343,"published":323},"does-software-need-a-ce-mark-under-the-cra","Does software need a CE mark under the CRA? Yes, and Article 30 says where it goes","From 11 December 2027, a CE marking is required on every product with digital elements placed on the EU market, software included. For software the mark goes on the EU declaration of conformity or on the website accompanying the product, before it is placed on the market. What the mark asserts, who can affix it, when a notified body's number joins it, and what the declaration behind it must contain.",{"locale":5,"slug":345,"title":346,"description":347,"published":323},"does-the-cra-apply-to-open-source-software","Does the CRA apply to open-source software? Three cases, and the light regime for stewards","The Cyber Resilience Act reaches free and open-source software only when it is supplied in the course of a commercial activity. A non-monetised project is out. A company that ships a product built on open-source components is a manufacturer of that product. And foundations and companies that sustain open-source products intended for commercial use are 'open-source software stewards' under Article 24: a cybersecurity policy, cooperation with authorities, and a narrowed reporting duty, with no CE mark and no technical file. The recitals and the article, quoted.",{"locale":5,"slug":349,"title":350,"description":351,"published":323},"does-the-cra-require-an-sbom","Does the CRA require an SBOM? Yes, and here is exactly what it says","Annex I, Part II, point 1 of the Cyber Resilience Act requires a software bill of materials in a commonly used, machine-readable format covering at least the top-level dependencies. It goes in the technical file, it is not published, and a market surveillance authority can ask for it on a reasoned request. The three sentences that decide it, and what they leave open.",{"locale":5,"slug":353,"title":354,"description":355,"published":323},"how-long-is-the-cra-support-period","How long is the CRA support period? At least five years, and three other clocks attached to it","Article 13(8) of the Cyber Resilience Act requires a support period of at least five years, or the expected time in use if shorter, during which vulnerabilities are handled. Its end date must be shown at purchase, at least the month and year. Security updates must stay available for ten years or the support period. And the technical file, declaration and user information are kept for the same. The four clocks, from the text.",{"locale":5,"slug":357,"title":358,"description":359,"published":323},"how-to-file-a-cra-notification-on-enisa-s-single-reporting-platform","How to file a CRA notification on ENISA's single reporting platform, from its own manual","The platform opened on 11 September 2026 at portal.cra-srp.enisa.europa.eu. Who can log in, which coordinator to pick, what each of the three submissions asks for, what the platform's own counter gets wrong, and when you may ask for dissemination to be delayed. Read from ENISA's guidance, FAQ, glossary and terms, not from a summary of them.",{"locale":5,"slug":361,"title":362,"description":363,"published":323},"is-your-open-source-project-commercial-under-the-cra-the-commissions-seven-tests","Is your open-source project 'commercial' under the CRA? The Commission's seven tests, with its examples","The CRA reaches free and open-source software only where it is supplied in the course of a commercial activity, and the Regulation leaves 'commercial' to two recitals. The Commission's guidance of 27 July 2026, section 3, turns them into seven tests: a price, a paid edition or open core, monetising other services or personal data, support services, donations, sponsorship, and not-for-profit status, with 22 examples. Where a maintainer, an open-core company and a foundation each land, and what a pull request makes you.",{"locale":5,"slug":365,"title":366,"description":367,"published":323},"is-your-product-important-or-critical-under-the-cyber-resilience-act","Is your product important or critical under the Cyber Resilience Act? Annex III and IV in full","Once a product is in scope of the CRA it is default, important (class I or II) or critical, and the tier decides whether you can self-assess or need a notified body. Here are the 19, 4 and 3 categories verbatim from the Official Journal, what each tier changes under Article 32, and the one thing the tier does not change.",{"locale":5,"slug":369,"title":370,"description":371,"published":323},"is-your-product-in-scope-of-the-cyber-resilience-act","Is your product in scope of the Cyber Resilience Act? Where SaaS sits","The most-asked CRA question is not how to report, it is whether the Regulation applies to you at all. Pure software as a service is out and inside NIS2; installed and downloadable software is in; remote processing a product cannot work without is back in. The determination is yours to make and record. Here is the text that decides it.",{"locale":5,"slug":373,"title":374,"description":375,"published":323,"answer":376},"nis2-or-cra-which-incident-clock-runs-for-a-software-company-and-what-makes-an-incident-significant","NIS2 or CRA: which incident clock runs for a software company, and what makes an incident 'significant'","Both laws give you 24 hours, 72 hours and a month, and both start the clock when you 'become aware'. Almost everything else differs: what triggers it, who receives it, on which platform, and what counts. NIS2 Article 23 and Implementing Regulation 2024\u002F2690 for the company that runs a cloud service; CRA Article 14 for the company that ships a product; both for the company that does both. The thresholds, criterion by criterion, and one procedure that satisfies the two.",{"who":377,"when":378,"do":379},"A software company that runs a cloud or managed service under NIS2, ships a product under the CRA, or both; each law gives 24 hours, 72 hours and a month from becoming aware, but the trigger, the recipient, the platform and the thresholds differ.","The CRA clock has run since 11 September 2026 for an actively exploited vulnerability or a severe incident in a product; the NIS2 clock runs since the national transposition for a significant incident in the service, with Implementing Regulation 2024\u002F2690 setting the thresholds for cloud and managed services.","Write one procedure with two triggers and two recipients, the CSIRT for the CRA and the national authority for NIS2, and the same reasonable-degree-of-certainty test for becoming aware; the thresholds below say which incident starts which clock.",{"locale":5,"slug":381,"title":382,"description":383,"published":323},"self-assessment-under-the-cra-what-module-a-actually-requires","Self-assessment under the CRA: what module A actually requires, from Annex VIII and the Commission's FAQ","Most software products will never see a notified body. They use module A, the internal control procedure of Annex VIII, and 'self-assessment' is the word everyone uses for it without saying what it contains. Annex VIII Part I is five points; the Commission's FAQ adds the list of activities, the fact that no test methodology is mandated, where a software product carries its CE mark, the two forms of the declaration of conformity, and the harmonised standards timeline that decides when self-assessment stops meaning 'against Annex I directly'.",{"locale":5,"slug":385,"title":386,"description":387,"published":323},"the-coordinated-vulnerability-disclosure-policy-the-cra-requires","The coordinated vulnerability disclosure policy the CRA requires: three provisions, and a one-page policy that meets them","Annex I, Part II, point 5 of the Cyber Resilience Act requires every manufacturer in scope to put in place and enforce a coordinated vulnerability disclosure policy. Article 13(17) requires a single point of contact for reporting that is easy to find and not limited to automated tools; Annex II, point 2 requires the contact and the policy's location in the user information; Annex VII, point 2(b) puts both in the technical file. What each provision asks, what a policy must say, and what it must not promise.",{"locale":5,"slug":389,"title":390,"description":391,"published":323},"the-cra-cybersecurity-risk-assessment-what-article-13-actually-requires","The CRA cybersecurity risk assessment: what Article 13 actually requires, and the one output it must produce","Article 13(2) to (4) of the Cyber Resilience Act make the risk assessment the document every other CRA obligation hangs off. It must analyse risks from the intended purpose, foreseeable use and conditions of use over the expected time in use; state whether and how each Part I, point 2 requirement applies; say how Part I, point 1 and Part II are applied; be documented, kept updated over the support period, and included in the technical file, with a clear justification for every requirement left out. The four paragraphs, and a one-page structure that satisfies them.",{"locale":5,"slug":393,"title":394,"description":395,"published":323,"answer":396},"the-cyber-resilience-act-for-a-small-software-manufacturer-in-twelve-steps","The Cyber Resilience Act for a small software manufacturer, in twelve steps","Everything a ten-person company that ships installed software or a device has to do under the CRA, in the order to do it: the scope determination, the tier, the CSIRT and the enforcer, the reporting procedure that has applied since 11 September 2026, then the technical file, the 22 requirements, the SBOM, the support period, the CE mark and the declaration due by 11 December 2027. Each step with its article and the piece that explains it.",{"who":397,"when":398,"do":399},"A manufacturer of a product with digital elements placed on the EU market: installed or downloadable software, apps, libraries, firmware and devices. Pure software as a service is out and under NIS2; remote processing a product cannot work without is in.","Article 14 reporting applies since 11 September 2026, for products already on the market too; the essential requirements, the technical file, the CE mark and the declaration are due by 11 December 2027.","Write down the scope determination and set up the 24-hour reporting procedure now; the other ten steps follow in the order below.",{"locale":5,"slug":401,"title":402,"description":403,"published":323},"the-eu-s-own-cra-machinery-on-the-day-the-duty-started","The EU's own CRA machinery, on the day the duty started: 0 notified bodies, 0 harmonised standards, 7 of 27 enforcers","The Cyber Resilience Act asks manufacturers to be ready. Here is how ready the institutions it depends on were on 11 and 12 September 2026, read from the Commission's own registers: no conformity assessment body notified under the CRA, no harmonised standard published in the Official Journal, seven member states with a registered market surveillance authority, thirteen with a notifying authority, and the coordinator CSIRT list published the day before, with two states naming a body other than their national CSIRT. What that means for a manufacturer with a class I product, and what to record.",{"locale":5,"slug":405,"title":406,"description":407,"published":323},"what-goes-in-the-cra-technical-file-annex-vii-point-by-point","What goes in the CRA technical file: Annex VII, point by point","From 11 December 2027 every product with digital elements placed on the EU market needs technical documentation before it is placed, kept for ten years or the support period, whichever is longer. Annex VII says what it contains in eight points. Here they are, what each one actually asks for, the four documents Part II of Annex I presumes exist, and how long you keep it.",{"locale":5,"slug":409,"title":410,"description":411,"published":323},"what-the-cra-asks-of-importers-and-distributors","What the CRA asks of importers and distributors, and when it makes them the manufacturer","If you resell software or devices into the EU rather than build them, Articles 19 and 20 of the Cyber Resilience Act give you a checklist to run before the product goes on sale, a duty to pass vulnerabilities to the manufacturer, a duty to tell authorities about significant risks, and ten years of record-keeping. Article 21 turns you into the manufacturer the moment you sell under your own brand or substantially modify the product. The obligations, from the text.",{"locale":5,"slug":413,"title":414,"description":415,"published":323},"what-the-cra-asks-of-you-for-your-dependencies-due-diligence-reporting-upstream-and-known-exploitable-vulnerabilities","What the CRA asks of you for your dependencies: due diligence, reporting upstream, and known exploitable vulnerabilities, from the Commission's guidance","A software product is mostly other people's code. The CRA makes the manufacturer responsible for the product as a whole and gives it three duties towards the components inside it: due diligence under Article 13(5), reporting vulnerabilities upstream and sharing fixes under Article 13(6), and placing the product on the market without known exploitable vulnerabilities. The Commission's guidance of 27 July 2026, sections 3.4, 7.3 and 9.2, says what each one takes and what it does not: no duplicate reports, no obligation to get your fix merged, and a definition of 'known' that includes the CVE database and the news.",{"locale":5,"slug":417,"title":418,"description":419,"published":323},"what-you-have-to-report-under-the-cra-the-two-triggers-defined","What you have to report under the CRA: the two triggers, as the Regulation defines them","Article 14 has two triggers and both are defined in the text. An actively exploited vulnerability is one with reliable evidence that a malicious actor has exploited it in a system without the owner's permission (Article 3(42)). A severe incident is one that affects, or can affect, the product's ability to protect sensitive data or functions, or that leads, or can lead, to malicious code in the product or a user's systems (Article 14(5)). What is in, what is out, and the duty to tell users that comes with both.",{"locale":5,"slug":421,"title":422,"description":423,"published":323},"when-does-the-cra-24-hour-clock-start-becoming-aware","When does the CRA's 24-hour clock start? 'Becoming aware', from the Commission's guidance","The 24 and 72 hours run from the moment the manufacturer 'becomes aware', and the Regulation never says what that means. The Commission's guidance of 27 July 2026 does, in paragraphs 211 to 218: a reasonable degree of certainty, after an initial assessment, borrowed word for word from the NIS2 implementing regulation and the GDPR breach guidelines. What that makes of a customer email, a scanner alert, a listed CVE in a component, a bug-bounty zero-day, and a vulnerability you knew about before 11 September.",{"locale":5,"slug":425,"title":426,"description":427,"published":323},"when-is-software-placed-on-the-market-under-the-cra-and-which-of-your-builds-is-a-product","When is software 'placed on the market' under the CRA, and which of your builds is a product? The guidance's rule for standalone software","Everything in the CRA hangs on a date and a noun: the date a product is placed on the market, and whether what you ship is a product at all. For standalone software the Commission's guidance of 27 July 2026 answers both in paragraphs 13 to 21: a version is placed on the market once, when first offered, and every later download of it counts from that day; per-OS builds and feature bundles are separate products; a web app used in a browser is not a product, a browser extension or an installed client is. What that means for 11 December 2027, for betas, and for old versions you keep online.",{"locale":5,"slug":429,"title":430,"description":431,"published":323},"which-csirt-do-you-report-to-under-cra-article-14","Which CSIRT do you report to under CRA Article 14? All 27 coordinators, as ENISA lists them","Every guide to the Cyber Resilience Act's reporting duty says 'notify your national CSIRT' and stops. Since 10 September 2026 ENISA publishes the CSIRT designated as coordinator for each of the 27 member states. Here is that list, the rule that picks the state, and the two states where the coordinator is not the national CSIRT.",{"locale":5,"slug":433,"title":434,"description":435,"published":323},"which-parts-of-your-backend-are-inside-the-cra-remote-data-processing","Which parts of your backend are inside the CRA? Remote data processing, from the Commission's guidance","A product with digital elements includes its remote data processing solutions, and the Regulation defines them in one sentence. The Commission's guidance of 27 July 2026 turns that sentence into two cumulative tests, a boundary rule, a list of what is never in (CI\u002FCD, HR, CRM, telemetry, websites), the SaaS, PaaS and IaaS cases, and a worked mobile banking example. For a software company with an app and a cloud, this is the line.",{"locale":5,"slug":437,"title":438,"description":439,"published":323},"which-update-puts-your-existing-software-under-the-cra-substantial-modifications","Which update puts your existing software under the CRA? Substantial modifications, from the Commission's guidance","Software placed on the market before 11 December 2027 stays outside the CRA's design and conformity duties until it is substantially modified. The Commission's guidance of 27 July 2026 says what that means for a software update in paragraphs 103 to 113 and 122 to 124, with eleven worked examples: a risk not in your risk assessment, not the size of the diff. Security updates are generally out; a 'remember me' checkbox can be in. What to write into every release, and what the first substantial modification does and does not trigger.",{"locale":5,"slug":441,"title":442,"description":443,"published":323},"who-enforces-the-cyber-resilience-act-in-your-member-state","Who enforces the Cyber Resilience Act in your member state? 7 of 27 have said","The CRA is enforced nationally, by a market surveillance authority each member state designates and registers with the Commission. On 11 September 2026, the day the reporting duty applied, seven states had registered one. Here is the register, state by state, including the twenty that have not, and what that means for a small manufacturer asking who will come knocking.",{"locale":5,"slug":445,"title":446,"description":447,"published":448},"cyber-resilience-act-penalties","Cyber Resilience Act penalties: what a small manufacturer is actually exposed to","The CRA sets three fine tiers, up to EUR 15 million or 2.5% of worldwide turnover. Here is which obligations sit in which tier, who does the enforcing, and the two places the Regulation writes small manufacturers into the text by name.","2026-09-08",{"locale":5,"slug":450,"title":451,"description":452,"published":453},"how-to-answer-a-security-questionnaire","How to answer a security questionnaire from your ISO 27001 ISMS: 30 question topics mapped to the Annex A controls that answer them","Nearly every security questionnaire a European company receives asks about the same 30 topics. Here is the map from each topic to the ISO 27001 Annex A controls it is really about, and the four records that answer any of them.","2026-09-03",{"locale":5,"slug":455,"title":456,"description":457,"published":453},"iso-27001-in-eu-public-tenders-by-country","Which EU countries name ISO 27001 in public tenders: 1,548 German notices, 829 Polish, and Greece has the highest share","Over 365 days, ISO 27001 appears in 3,415 TED notices. Germany and Poland account for 70% of them, Greece names it in 2% of everything it buys, and France, Spain and Italy barely name it at all. The numbers by country, and the query to re-run them.",{"locale":5,"slug":459,"title":460,"description":461,"published":462},"best-iso-27001-compliance-software","Best ISO 27001 compliance software: what to ask before you compare features","Integration counts are easy to compare and rarely decide an audit. Here are the questions that do, including the one most vendors will not answer in writing.","2026-08-20",{"locale":5,"slug":464,"title":465,"description":466,"published":462},"cheapest-iso-27001-certification","Cheapest ISO 27001 certification: how to compare quotes without buying a worthless certificate","Certification body quotes vary, but the auditor days behind them are set by ISO\u002FIEC 27006 Annex B. Here is how to read a quote, and the one check that matters more than price.",{"locale":5,"slug":468,"title":469,"description":470,"published":462},"cheapest-way-to-get-iso-27001","The cheapest way to get ISO 27001, and the part you cannot make cheaper","Most of an ISO 27001 budget is auditor days, and those are set by a published chart rather than by negotiation. Here is what actually moves the number, and what does not.",{"locale":5,"slug":472,"title":473,"description":474,"published":462},"how-to-get-iso-27001-certification-for-company","How to get ISO 27001 certification for a company, in the order it actually happens","The path from nothing to a certificate, what happens at Stage 1 and Stage 2, and the records an auditor asks for at each point.",{"locale":5,"slug":476,"title":477,"description":478,"published":462},"implement-iso-27001-without-the-help-of-consultants","Implementing ISO 27001 without consultants: what you take on, and what they were doing for the money","It is entirely possible to certify without a consultant. It is worth knowing what you are absorbing first, and which parts genuinely benefit from someone who has sat on the other side of an audit.",{"locale":5,"slug":480,"title":481,"description":482,"published":462},"iso-27001-certification-cost-for-company","ISO 27001 certification cost for a company, by headcount","Auditor days come from the ISO\u002FIEC 27006 Annex B chart, so certification cost tracks headcount more than industry. Here is the arithmetic, and the lines people forget.",{"locale":5,"slug":484,"title":485,"description":486,"published":462},"iso-27001-compliance-checklist","ISO 27001 compliance checklist, by clause","A checklist that follows the standard's own structure: clauses 4 to 10 and what each one asks you to be able to show, plus what Annex A adds.",{"locale":5,"slug":488,"title":489,"description":490,"published":462},"iso-27001-cost-of-implementation","ISO 27001 cost of implementation: the three-year number, not the first invoice","Certification runs on a three-year cycle with surveillance audits each year. Budgeting only for the first audit is the most common way the total surprises people.",{"locale":5,"slug":492,"title":493,"description":494,"published":462,"answer":495},"iso-27001-vs-nis2","ISO 27001 vs NIS2: what the certificate covers and what it does not","NIS2 is law and ISO 27001 is a certifiable standard, so they are not alternatives. Here is where an existing ISMS satisfies the directive's requirements, and the two places it does not.",{"who":496,"when":497,"do":498},"A company that holds or plans ISO 27001 and is, or may be, an essential or important entity under NIS2: the certificate is a choice and the directive is law, one does not stand in for the other, and the same management system answers most of what the directive asks for technically.","The moment NIS2 reaches you through a national transposition, a supervisory authority's register or a customer's contract; the incident clocks run from awareness, not from certification, and an existing management system shortens the gap analysis but does not replace it.","Keep one management system mapped to both, read the published mapping of the implementing regulation's sections against the Annex A controls, close the two gaps by adding the incident reporting procedure with its clocks and the management body's approval and training, and never present the certificate as NIS2 compliance.",{"locale":5,"slug":500,"title":501,"description":502,"published":462},"iso-42001-certification","ISO 42001 certification: what it is, and whether it is early","ISO\u002FIEC 42001 is the AI management system standard. Here is what it asks for, how it relates to an existing ISO 27001, and an honest read of current demand.",{"locale":5,"slug":504,"title":505,"description":506,"published":507,"answer":508},"how-many-auditor-days-iso-27001","How many auditor days an ISO 27001 certification takes, by headcount","Certification bodies do not publish prices, but the audit days are fixed by ISO\u002FIEC 27006 Annex B. Here is the arithmetic that turns your headcount into a number before anyone quotes you.","2026-08-11",{"who":509,"when":510,"do":511},"A company budgeting an ISO 27001 certification before any certification body has quoted: the auditor days are fixed by ISO\u002FIEC 27006 Annex B from the headcount inside the scope, contractors included, so the largest term of the fee can be worked out at the desk.","Before asking for quotes, so that a quote can be read against the published day count; again when the headcount crosses a band, since the next band means more days at the next audit; and before signing with any body that quotes far below the band.","Count everyone working under your control inside the scope, read the days off the annex (about 5 for up to 10 people, 7 for 16 to 25, 10 for 46 to 65, 12 for 86 to 125), multiply by a day rate of roughly 1,200 to 1,800 EUR, add a third of that for each surveillance year and at least two thirds for recertification, and get three quotes on the same brief from accredited bodies only.",{"locale":5,"slug":513,"title":514,"description":515,"published":507,"answer":516},"iso-27001-or-soc-2-in-europe","ISO 27001 vs SOC 2 in Europe: which one buyers actually ask for","Selling into Europe, get ISO 27001: EU public tenders named it 3,408 times in a year against 104 for SOC 2. Selling to US customers, it runs the other way. The numbers, the public TED query to re-run them, and when you need both.",{"who":517,"when":518,"do":519},"A software company deciding which attestation to get first: selling into Europe, ISO 27001 is the one buyers name; selling mainly to US customers, SOC 2 is the shape their procurement expects; selling to both, the ISO management system comes first, since it produces the evidence a later SOC 2 reads.","Before the first deal or tender that asks for one, and early enough that the audit is booked before the buyer's deadline, since neither attestation can be produced in the month a questionnaire arrives.","Count what your own buyers ask for, re-run the public TED query for the European share, get ISO 27001 if Europe is the market, add SOC 2 when a US customer's procurement requires the report, and build the management system first so that the second attestation reads the evidence the first one produces.",1789306946577]