All articles

Tag

Articles on Compliance Advisory.

6 posts tagged#Compliance Advisory.

Three colleagues at a dark meeting table reviewing a document in a folder; one holds a pen over the page while another points to a line on it.

Vendor Risk Management·

You've Spent Years Answering Security Questionnaires. Here's the One You Should Be Sending.

A 12-question vendor security questionnaire for SMBs — the red-flag answers and a one-page scoring rule, mapped to NIS2 Article 21(2)(d).

8 min read · Sylvio Sorel

A team reviewing AI governance documentation together at a desk in a bright modern office.

ISO 42001·

ISO 42001, Sized for SMBs: The AI Certificate Your Buyers Will Ask For Before the Regulator Does

ISO 42001 is the first certifiable AI management system standard. What's inside, what it costs an SMB, and why buyers will ask before the regulator does.

5 min read · Sylvio Sorel

An engineer working on a laptop beside a wiring harness assembly rig in an electronics manufacturing facility.

Cyber Resilience Act·

CRA reporting is live. You may be the manufacturer.

CRA reporting went live on 11 September 2026: 24 hours to report an exploited vulnerability in something you sold. Manufacturer is a role, not an industry.

7 min read · Sylvio Sorel

An aerial view of two paths crossing in a green field, a cyclist pausing at the intersection — which regulatory route applies to you.

NIS2·

NIS2 vs DORA vs ISO 27001: which ones apply to you

NIS2, DORA and ISO 27001 are not rival options: two are law, one is a standard. Who each one binds, where they overlap, and which one wins.

7 min read · Sylvio Sorel

A management team in a glass-walled boardroom discussing AI governance and EU AI Act readiness.

AI Act·

AI Omnibus: The 16-Month AI Act Reprieve, and Why Your Real Deadline Just Got Closer

The AI Omnibus is law. It moved the high-risk deadline to December 2027 — and created a new one on 2 December 2026, in the €35M/7% penalty band.

8 min read · Sylvio Sorel

Vendor Risk Management

Vendor Risk Management·

Vendor, Partner, Breach: How Third-Party Relationships Are Your Biggest Security Blind Spot

Most SMBs cannot name their critical suppliers, let alone assess them. Why third-party access is the most common breach path — and how to manage it without enterprise overhead.

8 min read · Sylvio Sorel