ISO 27001: updating your SoA after scope or cloud changes
New SaaS, merger or outsourcing? Without an up-to-date Statement of Applicability you lose audit credibility fast.
Read article: ISO 27001: updating your SoA after scope or cloud changes →Insights on ISO certification, NIS2, EU regulation and audit readiness in the Netherlands. Practical analysis for leadership, IT and compliance teams, educational, not legal advice.
We cover regulatory changes, audit trends and what organisations can do in practice. Each article links to topics in our knowledge base, from vendor management to processor agreements.
Free tool: Vendor & processor document generator, GDPR, ISO 27001, NIS2, DORA and more; fill in and print as PDF.
For operational ISMS work see ISO Ready. Sources: sources & linking.
Browse the articles below for the latest posts. Combine news with guides on ISO 27001 certification and NIS2 in the knowledge base.
New SaaS, merger or outsourcing? Without an up-to-date Statement of Applicability you lose audit credibility fast.
Read article: ISO 27001: updating your SoA after scope or cloud changes →
Dutch supervisors expect speed and evidence. What belongs in your first internal triage and when do you notify, or not?
Read article: GDPR breach: the 72-hour notification rule in practice (2026) →
DORA sets requirements on the supply chain of banks and insurers. What do supervisors and procurement teams ask Dutch IT vendors in practice?
Read article: DORA 2026: what ICT providers to the financial sector must demonstrate →
National cybersecurity law affects more than vital sectors alone. How to define scope and avoid doubling up with NIS2 programmes.
Read article: Dutch Cybersecurity Act and SMEs: overlap with NIS2 without duplicate work →
Customers and supervisors ask for data sovereignty. What must you prove about regions, logging, support access and subprocessors?
Read article: Data sovereignty in 2026: more than “data is in the EU” →
NIS2 implementation deadlines are here. What do regulators and supply-chain partners expect from Dutch organisations in 2026?
Read article: NIS2 in 2026: what essential and important entities must demonstrate now →
The CRA embeds product security in the EU supply chain. What does that mean for software vendors, integrators and buyers in the Netherlands?
Read article: Cyber Resilience Act: impact on Dutch suppliers and customers →
Threat levels stay high, yet many SMEs gain ground by applying NCSC-style baselines with clear ownership per risk area.
Read article: NCSC and SMEs: baseline controls remain the fastest win in 2026 →
Recertification and surveillance are about proof of operation. These themes show up more often in Dutch audits in 2026.
Read article: ISO 27001 surveillance in 2026: where auditors look harder →
AI governance is becoming a board topic. How to align EU AI Act duties with ISO 42001 and your existing ISMS.
Read article: EU AI Act and ISO 42001: a practical route for Dutch organisations →isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)