Processor agreement 2026: checklist for security and privacy teams
DPAs must align with ISMS and NIS2 chain. Which clauses and evidence belong inside?
Read article: Processor agreement 2026: checklist for security and privacy teams →Insights on ISO certification, NIS2, EU regulation and audit readiness in the Netherlands. Practical analysis for leadership, IT and compliance teams, educational, not legal advice.
We cover regulatory changes, audit trends and what organisations can do in practice. Each article links to topics in our knowledge base, from vendor management to processor agreements.
Free tool: Vendor & processor document generator, GDPR, ISO 27001, NIS2, DORA and more; fill in and print as PDF.
For operational ISMS work see ISO Ready. Sources: sources & linking.
Browse the articles below for the latest posts. Combine news with guides on ISO 27001 certification and NIS2 in the knowledge base.
DPAs must align with ISMS and NIS2 chain. Which clauses and evidence belong inside?
Read article: Processor agreement 2026: checklist for security and privacy teams →
Remote work remains standard. How to fit it in scope, SoA and audit evidence?
Read article: ISO 27001 and hybrid work: scope, devices and logging in 2026 →
Directors and chain partners are held accountable for cyber risk in the supply chain. Practical governance without legal panic.
Read article: NIS2 chain liability: what boards must ensure in 2026 →
AI systems need governance on top of security. How to start ISO 42001 without a parallel universe?
Read article: ISO 42001 roadmap: AI governance alongside your ISMS in 2026 →
The European digital identity wallet is approaching. What impact on login, contracts and ISMS should you expect in 2026?
Read article: eIDAS 2.0 and EUDI wallet: what Dutch businesses should prepare →
Joiner-mover-leaver processes are surveillance favourites. How to link HR, IdP and SaaS with an auditable trail?
Read article: Identity lifecycle: HR to offboarding without orphaned accounts →
Data Protection Impact Assessments are not one-off documents. When must you do a DPIA, and how do you keep evidence for supervisors and audit?
Read article: DPIA in practice: when mandatory and how to link to the ISMS →
AWS, Azure and SaaS do not deliver compliance automatically. Which controls stay yours, and how do you prove it in ISO 27001?
Read article: Cloud shared responsibility: SoA and audit without gaps →
Management review is not a meeting without minutes. Which input, decisions and KPIs belong, and what must not be missing?
Read article: ISO 27001 management review: content auditors expect in 2026 →
Supply-chain risk is not a forgotten spreadsheet. How to prioritise vendors, contracts and evidence for supervisors and enterprise customers?
Read article: Vendor risk under NIS2 and DORA: one register, two frameworks →
Backup alone is not enough, restore must be tested and ransomware must not encrypt backups. Practical SME approach.
Read article: Immutable backups in 2026: what auditors and insurers require →
US customers ask for SOC 2; European chains ISO 27001. How to choose, or combine, without duplicate audit work?
Read article: SOC 2 vs ISO 27001 in 2026: what SME customers really ask for →isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)