LEARN
Deep-dive guides to DORA, NIS2, ISO 27001, GDPR, SOC 2 and the EU AI Act: what each one actually requires, article by article, and how to evidence it.

Automated Access Review Software Explained
What actually gets automated in an access review, what has to stay human, and how to tell the difference before you buy. With the scoring model in full.

How to Create a Risk Register
A risk register that survives an audit needs two scores, a named owner and a link to controls. The seven steps, the columns, and the mistakes to avoid.

How to Perform a Third-Party Risk Assessment
Assessing every supplier the same way is why most programmes stall. Tier first, set depth by tier, and the work becomes finishable. Seven steps.

Third-Party Risk Management Process Flow
The flow is simple and it stalls in the same place every time: waiting on the supplier. Where each stage hands off, and how to stop the queue building.

Vendor Security Questionnaires: A Guide
Questionnaires come back late for three fixable reasons. How to size one to the supplier, send it so it gets answered, and stop chasing by hand.

DORA Compliance Cost: A Line-by-Line Model (2026)
Published DORA cost estimates disagree by orders of magnitude. Here is the line-by-line model that produces your number, work item by work item.

NIS2 Fines and Penalties: What You Actually Risk
NIS2 sets minimum ceilings: EUR 10M or 2% of turnover for essential entities, 7M or 1.4% for important ones, plus personal liability for managers.

How Long Does DORA Compliance Take?
DORA has applied since January 2025, so the real question is how long from a standing start. The honest answer, phase by phase, with the long pole named.

NIS2 Compliance Cost: What to Budget
Germany priced NIS2 for its own economy: about 2.1bn one-off and 2.2bn a year across 30,000 entities. Here is what that arithmetic means for your budget.

EU AI Act Policies and Documentation
The EU AI Act asks for a document set rather than a policy. Here is what a high-risk provider has to be able to produce, article by article.

EU AI Act Penalties and Fines Explained
Article 99 sets three tiers, up to 35M EUR or 7% of worldwide turnover. The rule for SMEs inverts the usual formula, and most summaries get it wrong.

NIS2 vs ISO 27001: How They Overlap
ISO 27001 covers much of what NIS2 asks for, and satisfies none of it by itself. Where the overlap is real, and the four gaps certification leaves.

EU AI Act AI Literacy Requirements
Article 4 already applies, it binds providers and deployers alike, and it is the cheapest EU AI Act obligation to satisfy and to evidence.

Bilingual Policies and Evidence for Gulf Regulators
How to run Arabic and English compliance documentation together: which language binds, what needs translating, fixed terminology and per-document language.

NIS2 Solutions for Banks: What Applies vs DORA
NIS2 solutions for banks: why DORA is the operative regime, where NIS2 still applies across the group, and what your platform must do. Reviewed July 2026.

eIDAS Compliance Software: An eIDAS 2.0 Buyer's Guide
eIDAS compliance software compared: the three product categories buyers confuse, and what a real eIDAS 2.0 governance layer must cover before 2027.

What Is NIS2 and Who Must Comply in 2026?
What is NIS2 and who must comply? The 2026 scope guide: sectors, size thresholds, essential vs important, obligations and penalties. Reviewed July 2026.

What Is HIPAA Compliance? Covered Entities and BAAs
HIPAA compliance explained: covered entities, business associates, BAAs, the Privacy, Security and Breach Notification Rules, penalties. Reviewed July 2026.

PCI DSS: Who Must Comply and Which SAQ Applies
PCI DSS applies to any business that stores, processes or transmits cardholder data. Learn who must comply and which SAQ fits your setup. Reviewed July 2026.

What Is SOC 2? Type 1 vs Type 2, Explained
SOC 2 explained: what the AICPA attestation report is, the five Trust Services Criteria, Type 1 vs Type 2, and which SaaS vendors need it. Reviewed July 2026.

ISO 27001 Annex A: The 93 Controls Explained (2022)
ISO 27001 Annex A controls explained: the 93 controls, four themes, the Statement of Applicability, 2022 changes, and who must comply. Reviewed July 2026.

eIDAS 2.0 Scope: Who Must Accept the EUDI Wallet?
Use this role-based decision tree to see when eIDAS 2.0 applies, when EUDI Wallet acceptance is mandatory, and which SME exemptions matter.

The eIDAS 2.0 Deadline: What Happens by 24 December 2027
By 24 December 2027, private relying parties that require strong authentication must accept the EU Digital Identity Wallet. Who it binds, and the timeline.

How to Become Compliant: A Step-by-Step Guide (2026)
How to become compliant without drowning in spreadsheets: find which rules apply, run a gap analysis, remediate, collect evidence once, pass the audit.

Who Must Comply With the Cyber Resilience Act?
CRA scope follows the product, not the sector. The digital-elements test, the three economic operators, Annex III and IV, and the 2026 and 2027 deadlines.

The Cyber Resilience Act Deadlines: 2026 and 2027
CRA reporting obligations start on 11 September 2026 and the regulation applies in full on 11 December 2027. The complete timeline and what binds when.

Solvency II Software: A Pillar 2 Buyer's Guide
Solvency II software compared: the three tool categories, what a Pillar 2 governance platform needs, and how a crosswalk cuts duplicate work.

EU AI Act vs DORA: Comply With Both, One Programme
EU AI Act and DORA overlap in five zones. Run both from one compliance programme instead of two, and see exactly where the requirements meet.

EU AI Act High-Risk Deadline: Why 2 August 2026 Moved to 2027
The August 2026 high-risk deadline moved to December 2027 for standalone systems. What still binds in 2026, and what high-risk providers must build now.

EU AI Act Conformity Assessment for High-Risk AI in Financial Services
Article 43 conformity assessment for high-risk financial AI, covering credit scoring and insurance pricing, and why the deadline moved to December 2027.

DORA vs NIS2: Key Differences and Who's Covered
DORA vs NIS2: two EU cyber regulations with confusingly close names and very different obligations. See which one applies to your organisation, and why.

DORA TLPT: Threat-Led Penetration Testing in 2026
DORA threat-led penetration testing under Articles 26 and 27: who gets designated, the TIBER-EU phases in RTS 2025/1190, and how to plan the engagement.

Key Risk Indicators (KRIs): 14 to Track in 2026
Key Risk Indicators explained for CISOs and CROs, with thresholds, formulas and a 14-KRI starter pack mapped to ISO 27001, NIS2, DORA and NIST CSF.

DORA Key Risk Indicators: Article-by-Article Guide
Fourteen DORA key risk indicators, each mapped to the article of Regulation 2022/2554 it helps evidence, with every article number checked against the text.

ISO 42001 vs EU AI Act: Do You Need Both?
One is voluntary certification, one is binding law. See exactly where they overlap so you build AI governance once, not twice, and what each requires.

VARA CISO Appointment and Staff Competency Rules
VARA's CISO rule sits in the Technology and Information Rulebook. What Part I Sections I and J actually require of your compliance team, and what they do not.

VARA Cybersecurity Policy: The 19 Mandatory Criteria
VARA's rulebook lists 19 minimum cybersecurity policy criteria, not 18. Each in the rulebook's words, plus the two ISO 27001 templates always miss.

VARA Penetration Testing and Smart Contract Audits
Rule I.E.1 has two triggers, not one: at least annually AND before any new system, application or product ships. What VARA binds, and what is only Guidance.

VARA Compliance Guide for Dubai VASPs 2026
What a Dubai VASP licence requires: the four compulsory rulebooks, 19 cybersecurity criteria, the 72 and 24 hour clocks, and the capital floors.

VARA Key and Wallet Management: What the Rules Say
VARA key and wallet duties come in three tiers: four binding Rules in Part I Section D, Schedule 1 Guidance, and custody-only rules. What each one requires.

VARA Incident Reporting: The 72-Hour Clock
VARA's 72-hour notification runs from detection under Rule I.K.1. What triggers it, what the report must contain, and the 24-hour personal data clock.

VARA Data Protection: UAE PDPL Rules for VASPs
VARA binds every VASP to the UAE PDPL, a mandatory DPO, and a notify-VARA step within 24 hours. What the Technology and Information Rulebook requires.

DORA Supervisory Assessments: 2026 Guide
DORA supervision is live. How it is structured across the NCAs and ESAs, what a supervisor can demand, and the evidence to have ready before they ask.

DORA ICT Risk Management Framework: Article-by-Article Guide
What DORA Chapter II and RTS 2024/1774 require an ICT risk management framework to contain, chapter by chapter, with every citation checked.

DORA ICT Third-Party Risk: Build a Compliant Vendor Register
Build a DORA vendor register from scratch: the nine mandatory contract clauses, six more for critical functions, the subcontracting RTS and exit tests.

DORA Major Incident Classification: 7 Criteria
Do you owe your regulator a report in 4 hours? The exact test in Delegated Regulation 2024/1772, every threshold, and the 4h, 72h and 1-month clock.

DORA Operational Resilience Testing: Article 24
What DORA Article 24 really requires of a resilience testing programme, where the board approval duty comes from, and which quoted numbers are invented.

DORA 'Significant': The Critical ICT Provider Test
Will the ESAs designate your firm a critical ICT third-party provider? See the thresholds behind DORA's 'significant' test and where it bites.

DORA Compliance Gap Assessment: EU Banks
Enforcement is live and supervisors keep flagging the same five DORA gaps at EU banks. See where they fail and how to close each before your assessment.

EU AI Act for Healthcare: Which AI Must Comply
Most medical and diagnostic AI is high-risk under the EU AI Act. Which systems fall under Annex I or Annex III, and what each route demands by 2027.

EU AI Act: Who's in Scope and the 2025-28 Deadlines
Does the EU AI Act apply to you? Map your systems to the risk tiers and the 2025 to 2028 deadlines, including high-risk moving to 2 December 2027.

Does the EU AI Act Apply Outside the EU?
Selling AI into the EU from outside it usually puts you in scope. The output-used-in-the-EU trigger, the authorised representative rule and the deadlines.

Why Your DORA Register of Information Gets Rejected
The seven ESA rule codes that actually reject a Register of Information submission, what causes each one, and how to clear the validation cascade.

DORA Register of Information: 15 Official Templates Explained
The DORA Register of Information explained: all 15 templates from Implementing Regulation 2024/2956, how they connect, and how to file one clean submission.

DORA Gap Assessment: Score Your Readiness
Score your DORA readiness across seven domains, each anchored to the article it comes from, then weight the gaps so you know what to fix first.

DORA Register of Information Software Ranked
Your Register of Information is regulatory data, not a spreadsheet. Compare the tools that export clean XBRL OIM-CSV your NCA accepts on the first try.
