About Us Contact Blog
Governance DocsGovernance Docs
Which Toolkit?SoA GeneratorFree TemplatesAboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account

CART

No products in the cart.

Category: Articles

ISO 31000 risk management — principles, framework and process

ISO 31000 Risk Management: The 3 Components Explained

Governance Docs15th August 2026

ISO 31000:2018 explained — the three components, why there is no certification, and the third edition now at…
Read More
The CIS Controls v8.1 framework and its three Implementation Groups

CIS Controls v8.1: The 18 Controls and 3 Implementation Groups

Governance Docs15th August 2026

A practical guide to CIS Controls v8.1 — the 18 Controls, the 153 Safeguards, and how the three…
Read More
Cyber Essentials certification — the five technical controls

Cyber Essentials Certification: The Five Controls

Governance Docs15th August 2026

Cyber Essentials certification explained: the five technical controls, why scope decides the outcome, and the four failures that…
Read More
FedRAMP authorization — what FedRAMP 20x changed

FedRAMP Authorization: What FedRAMP 20x Changed

Governance Docs15th August 2026

FedRAMP authorization has changed. 20x is past the pilots and in wide-scale adoption, Key Security Indicators replaced yearly…
Read More
CMMC compliance — the four-phase rollout under 32 CFR Part 170

CMMC Compliance: The Four-Phase Rollout Explained

Governance Docs15th August 2026

CMMC compliance explained: the three levels, the four phases, and why Phase 2 on 10 November 2026 is…
Read More
CRA product classification — Annex III and Annex IV

CRA Product Classification: Default, Class I, Class II, Critical

Governance Docs15th August 2026

Classification decides whether you need a notified body. Article 7(1) contains the two rules that settle most cases,…
Read More
CRA conformity assessment — notified body routes

CRA Conformity Assessment: Do You Need a Notified Body?

Governance Docs15th August 2026

No harmonised standard has been cited under the CRA, so Article 32(2) currently sends every Annex III product…
Read More
CRA reporting deadline — 11 September 2026

The CRA Reporting Deadline: 11 September 2026

Governance Docs15th August 2026

Article 14 applies from 11 September 2026, and Article 69(3) reaches products you placed on the market years…
Read More
EU Cyber Resilience Act — Regulation (EU) 2024/2847 guide

EU CRA: The Cyber Resilience Act Explained

Governance Docs15th August 2026

What Regulation (EU) 2024/2847 requires, the four dates that matter, and the provisions manufacturers reliably get wrong.
Read More
ISO 42001 vs EU AI Act — guide from Governance Docs

ISO 42001 vs the EU AI Act: Standard, Regulation, and How They Fit

Governance Docs13th August 2026

ISO 42001 vs the EU AI Act: one is a voluntary certifiable standard, the other binding law. What…
Read More
GDPR vs HIPAA — guide from Governance Docs

GDPR vs HIPAA: The Differences That Actually Matter

Governance Docs13th August 2026

GDPR vs HIPAA compared: scope, who they bind, consent and lawful basis, breach deadlines and penalties — and…
Read More
ISO 27001 vs ISO 22301 — guide from Governance Docs

ISO 27001 vs ISO 22301: Which One Do You Actually Need?

Governance Docs13th August 2026

ISO 27001 vs ISO 22301 compared: information security versus business continuity, where the two overlap, and why 27001's…
Read More
    ←
  • 1
  • …
  • 5
  • 6
  • 7
  • 8
  • 9
  • …
  • 21
  • →

Recent Posts

ISO 27001 risk treatment plan diagram showing the six steps of clause 6.1.3
ISO 27001 Risk Treatment Plan: The Complete 2026 Guide

August 23, 2026

ISO 27001 nonconformity classification chart comparing major and minor audit findings
ISO 27001 Nonconformity: The Complete 2026 Guide to Major vs Minor Findings

August 22, 2026

ISO 27001 recertification audit timeline showing the three-year certification cycle from Stage 1 and Stage 2 through surveillance audits to year three reassessment
ISO 27001 Recertification Audit: The Complete 2026 Guide

August 21, 2026

Phishing-resistant MFA methods compared against NIST SP 800-63B-4 assurance levels
Phishing-Resistant MFA: The Complete 2026 Guide

August 20, 2026

Cybersecurity governance obligations under NIS2, DORA, ISO 27001 and NIST CSF 2.0
Cybersecurity Governance: The Definitive 2026 Board Guide

August 20, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?
  • Free templates
  • SoA generator
  • RSS feeds

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
Browse by topicISO 27001ISO 42001 & AI governanceGDPRSOC 2HIPAANIS2DORAISO 9001Management systemsSecurity frameworks
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA