
Vendor Risk Management·
You've Spent Years Answering Security Questionnaires. Here's the One You Should Be Sending.
A 12-question vendor security questionnaire for SMBs — the red-flag answers and a one-page scoring rule, mapped to NIS2 Article 21(2)(d).

ISO 42001·
ISO 42001, Sized for SMBs: The AI Certificate Your Buyers Will Ask For Before the Regulator Does
ISO 42001 is the first certifiable AI management system standard. What's inside, what it costs an SMB, and why buyers will ask before the regulator does.

Cyber Resilience Act·
CRA reporting is live. You may be the manufacturer.
CRA reporting went live on 11 September 2026: 24 hours to report an exploited vulnerability in something you sold. Manufacturer is a role, not an industry.

NIS2·
NIS2 vs DORA vs ISO 27001: which ones apply to you
NIS2, DORA and ISO 27001 are not rival options: two are law, one is a standard. Who each one binds, where they overlap, and which one wins.

AI Act·
AI Omnibus: The 16-Month AI Act Reprieve, and Why Your Real Deadline Just Got Closer
The AI Omnibus is law. It moved the high-risk deadline to December 2027 — and created a new one on 2 December 2026, in the €35M/7% penalty band.
Vendor Risk Management·
Vendor, Partner, Breach: How Third-Party Relationships Are Your Biggest Security Blind Spot
Most SMBs cannot name their critical suppliers, let alone assess them. Why third-party access is the most common breach path — and how to manage it without enterprise overhead.