For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/compliance.md.
← Insights

Compliance

Practical analysis of ISO 27001, NIS2, and DORA, the way we deliver them to Nordic organisations.

11 Aug 2026 · Articles
How long does ISO 27001 take?

The ISO 27001 timeline depends on your starting point, the controls you need to implement and the certification body's audit schedule.

Read more
11 Aug 2026 · Articles
Where AI can help with ISO 27001 preparation

AI can help draft policies and organise evidence. People still need to make risk decisions, implement controls and verify that the records describe reality.

Read more
11 Aug 2026 · Articles
ISO 27001 or NIS2 first?

Build shared security processes, but track legal duties and certification separately. Applicable legal deadlines take priority over commercial preferences.

Read more
11 Aug 2026 · Articles
What ISO 27001 costs, and what drives the price

Compare ISO 27001 proposals on implementation, internal time, tools, audit fees and ongoing maintenance. Scope matters more than an unsupported headline price.

Read more
11 Aug 2026 · Articles
Your customer requires ISO 27001. What do you do now?

Clarify the certificate scope, deadline and acceptable evidence before promising a date. Then assess the gaps and agree a credible plan.

Read more
6 Aug 2026 · Guides
DORA testing: the annual programme and threat-led penetration tests

DORA distinguishes general resilience testing from designated TLPT. Choose methods against risk, document coverage and verify remediation.

Read more
3 Aug 2026 · Articles
Choosing tools for DORA work

Software can organise registers, evidence and technical findings. Choose it around the decisions, data and responsibilities in your DORA programme.

Read more
31 Jul 2026 · Guides
DORA reporting and audit: keep the obligations separate

The ICT agreement register, planned-contract notices, incident reports and internal audit have different purposes. Assign owners and use the current submission rules.

Read more
28 Jul 2026 · Guides
DORA continuity planning: functions, recovery and exercises

Continuity plans should follow the services the firm must sustain. Map dependencies, set recovery objectives and exercise the decisions as well as the technology.

Read more
5 Jun 2026 · Articles
The Cyber Resilience Act: reporting has started

CRA manufacturer reporting began on 11 September 2026. The main product requirements follow in December 2027. Check product scope and your role now.

Read more
3 Jun 2026 · Articles
What an ISO 27001 Lead Implementer credential tells you

Implementation and audit are different assignments. Check the credential issuer, level and current status, then assess the consultant against the work you need.

Read more
11 May 2026 · Articles
Make security evidence useful to the business

Clear security records help answer customer and investor questions. Build evidence around the controls you operate, with owners and an honest view of gaps.

Read more
11 May 2026 · Articles
Planning SOC 2 for a Norwegian business selling to the US

Let actual customer requirements define the SOC 2 scope, report type and timing. Reuse existing security evidence, but assess the gaps before budgeting.

Read more
8 May 2026 · Articles
What a SOC 2 Type 2 report tells a customer

SOC 2 Type 2 reports on controls over a defined period. Read the system scope, opinion, testing results and customer responsibilities, not just the report title.

Read more
7 May 2026 · Articles
Norway's Digital Security Act: scope and reporting

The Digital Security Act has applied since October 2025. Check the service definitions, exceptions and reporting rules for your category of provider.

Read more
6 May 2026 · Articles
What ISO 27001 is, and why buyers ask for it

ISO 27001 certification gives buyers independent evidence about a defined information security management system. Its scope and the tender wording matter.

Read more
5 May 2026 · Guides
ISO 27001 checklist for Norwegian SMBs

Define scope, assess risk, implement controls and gather evidence. A practical checklist for preparing a Norwegian SMB for ISO 27001 assessment.

Read more
4 May 2026 · Guides
DORA checklist for Norwegian financial firms

Confirm the applicable regime, map critical functions and connect the evidence. Updated for Norway's September 2026 extension of DORA-based rules.

Read more
1 May 2026 · Guides
NIS2 checklist for Norwegian SMB leaders

A NIS2 preparation checklist for management: scope, accountable owners, risk measures, supplier oversight and a reporting process matched to applicable law.

Read more
30 Apr 2026 · Articles
What NIS2 means for Norwegian businesses

NIS2 scope depends on service, size, jurisdiction and exceptions. Distinguish direct legal duties from customer requirements and Norway's existing NIS1-based law.

Read more
22 Apr 2026 · Guides
How Nordic SMBs prepare for NIS2

Turn NIS2 preparation into a practical work plan: confirm applicable rules, assess controls, exercise reporting and track corrective actions.

Read more
Questions or inquiry? [email protected] Contact us →