Security KPIs for ISO 27001 management review in 2026
Leadership wants numbers, not slides. Which KPIs are audit-ready and feasible for SMEs?
Read article: Security KPIs for ISO 27001 management review in 2026 →Insights on ISO certification, NIS2, EU regulation and audit readiness in the Netherlands. Practical analysis for leadership, IT and compliance teams, educational, not legal advice.
We cover regulatory changes, audit trends and what organisations can do in practice. Each article links to topics in our knowledge base, from vendor management to processor agreements.
Free tool: Vendor & processor document generator, GDPR, ISO 27001, NIS2, DORA and more; fill in and print as PDF.
For operational ISMS work see ISO Ready. Sources: sources & linking.
Browse the articles below for the latest posts. Combine news with guides on ISO 27001 certification and NIS2 in the knowledge base.
Leadership wants numbers, not slides. Which KPIs are audit-ready and feasible for SMEs?
Read article: Security KPIs for ISO 27001 management review in 2026 →
Coordinated vulnerability disclosure is a CRA and customer requirement. What belongs in your disclosure policy?
Read article: Responsible disclosure: policy and audit evidence for SMEs →
SaaS chains have multiple subprocessors. How to inventory and assess them without spreadsheet chaos?
Read article: Subprocessors: due diligence under GDPR and NIS2 in 2026 →
Changing certification body? How to maintain continuity and customer trust in 2026.
Read article: Switching ISO 27001 certification body: no audit gap in 2026 →
SMS MFA no longer satisfies enterprise customers. How to migrate to FIDO2/passkeys without chaos?
Read article: Passkeys and phishing-resistant MFA: SME roadmap in 2026 →
Auditors sample CVE follow-up and patch SLAs. How to organise prioritisation and evidence without a SOC?
Read article: Patch and vulnerability management: surveillance favourite in 2026 →
High-risk AI systems face tighter deadlines. What must you document before supervision and due diligence?
Read article: AI Act high-risk: checklist for SMEs with AI applications →
The Cyber Resilience Act requires SBOM and vulnerability disclosure for software. How to prepare your chain and due diligence?
Read article: CRA and SBOM: what software vendors must document in 2026 →
Supervisors and chain partners increasingly ask for NIS2-specific evidence. What belongs in your readiness file?
Read article: NIS2 audit readiness: preparing for supervision and chain reviews →
Insurers and auditors overlap in 2026. MFA, backup, incident response, what must be ready before renewal?
Read article: Cyber insurance and ISO 27001: evidence insurers ask for →
Exit and data migration are DORA themes. How to prepare contracts and runbooks?
Read article: DORA exit planning: what ICT vendors must document →
Collecting evidence does not require a heavy GRC suite. Pragmatic automation for ISO 27001 surveillance.
Read article: Automating audit evidence without GRC overkill for SMEs →isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)