
ISO 27001·
One ISMS, three regulators: the same nine documents
NIS2, DORA and your ISO auditor ask for the same nine documents — and reject them for three different reasons. Here is the pack, mapped.

Vendor Risk Management·
You've Spent Years Answering Security Questionnaires. Here's the One You Should Be Sending.
A 12-question vendor security questionnaire for SMBs — the red-flag answers and a one-page scoring rule, mapped to NIS2 Article 21(2)(d).

Incident Response·
One Incident, Three Regulators: Why Your Real Deadline Is Four Hours, Not 72
Everyone learned 72 hours from GDPR. DORA's first filing is due in four hours and NIS2's early warning at 24. One incident, three clocks, three start times.

AI Act·
On 2 August, Your Chatbot Must Say It's a Bot. The AI Deadline the Omnibus Didn't Move.
Everyone heard the AI Act was delayed sixteen months. Article 50 wasn't. From 2 August 2026, your chatbot must say it's a bot — fines up to €15M or 3%.

NIS2·
NIS2 vs DORA vs ISO 27001: which ones apply to you
NIS2, DORA and ISO 27001 are not rival options: two are law, one is a standard. Who each one binds, where they overlap, and which one wins.