
Critical ICT Third-Party Providers: A Clear DORA Guide for 2026
Critical ICT third-party providers under DORA: the 4 designation criteria, how a Lead Overseer is chosen, and the…
CART
No products in the cart.

Critical ICT third-party providers under DORA: the 4 designation criteria, how a Lead Overseer is chosen, and the…

DORA incident reporting has 3 deadlines: 4 hours from classification, 72 hours for the intermediate report, one month…

A cybersecurity risk register in 10 elements, from NIST IR 8286 Revision 1 – what each field is…

The NIST RMF in 7 steps, from Prepare to Monitor, with the publication behind each – and how…

OPRP vs CCP under ISO 22000: a CCP has a measurable critical limit, an OPRP an action criterion.…

QHSE documentation works when the tiers are decided first: manual, procedures, work instructions, records. What belongs in each…

The COSO 17 principles listed by component, plus the present-and-functioning test, what counts as a major deficiency, and…

A HACCP plan is built from the 12 Codex steps – 5 preliminary steps then the 7 principles.…

An ISO 45001 assessment can mean 4 things: self-assessment, gap analysis, internal audit or certification audit. What each…

CIS Benchmarks are configuration guides; CIS Controls are a prioritized program. What each covers, the 3 profile levels,…

A crypto-asset white paper under MiCA: when it is required, the 9 Annex I parts, the mandatory statements,…

A BSI C5 attestation is an assurance report, not a certificate. Type 1 vs type 2, what the…
September 8, 2026
September 8, 2026
September 8, 2026
September 8, 2026
September 8, 2026