Secure SDLC: development controls for ISO 27001 and CRA
Software teams face audit questions on CI/CD, secrets and code review. What is minimum viable SSDLC?
Read article: Secure SDLC: development controls for ISO 27001 and CRA →Insights on ISO certification, NIS2, EU regulation and audit readiness in the Netherlands. Practical analysis for leadership, IT and compliance teams — educational, not legal advice.
We cover regulatory changes, audit trends and what organisations can do in practice. Each article links to topics in our knowledge base — from vendor management to processor agreements.
Free tool: Vendor & processor document generator — GDPR, ISO 27001, NIS2, DORA and more; fill in and print as PDF.
For operational ISMS work see ISO Ready. Sources: sources & linking.
Browse the articles below for the latest posts. Combine news with guides on ISO 27001 certification and NIS2 in the knowledge base.
Software teams face audit questions on CI/CD, secrets and code review. What is minimum viable SSDLC?
Read article: Secure SDLC: development controls for ISO 27001 and CRA →
Supervisors and auditors ask for evidence of exercised scenarios. How to plan tabletop without consultant overkill?
Read article: Tabletop cyber exercise: NIS2 and ISO evidence in 2026 →
Classification often stays on paper. How to make labels workable for SaaS, email and audit?
Read article: Data classification in the ISMS: from policy to daily use →Since the 2022 revision, Data Loss Prevention (DLP) is an explicit control in ISO 27001 (control 8.12). Yet many SMEs struggle with it: DLP sounds like expensive enterprise software, while auditors mainly want to see that you actually control data leakage through everyday channels. This article shows how to implement DLP pragmatically and make it […]
Read article: Data Loss Prevention (DLP) for SMEs: practical under ISO 27001 (2026) →
Laptops and mobile are the weak point in hybrid work. How do you prove MDM compliance to auditors?
Read article: MDM and endpoint security: ISO 27001 evidence in 2026 →
Leadership wants numbers, not slides. Which KPIs are audit-ready and feasible for SMEs?
Read article: Security KPIs for ISO 27001 management review in 2026 →
Coordinated vulnerability disclosure is a CRA and customer requirement. What belongs in your disclosure policy?
Read article: Responsible disclosure: policy and audit evidence for SMEs →
SaaS chains have multiple subprocessors. How to inventory and assess them without spreadsheet chaos?
Read article: Subprocessors: due diligence under GDPR and NIS2 in 2026 →
Changing certification body? How to maintain continuity and customer trust in 2026.
Read article: Switching ISO 27001 certification body: no audit gap in 2026 →
SMS MFA no longer satisfies enterprise customers. How to migrate to FIDO2/passkeys without chaos?
Read article: Passkeys and phishing-resistant MFA: SME roadmap in 2026 →
Auditors sample CVE follow-up and patch SLAs. How to organise prioritisation and evidence without a SOC?
Read article: Patch and vulnerability management: surveillance favourite in 2026 →
High-risk AI systems face tighter deadlines. What must you document before supervision and due diligence?
Read article: AI Act high-risk: checklist for SMEs with AI applications →