The Compliance Convergence: Why 2025–2026 Is the Year Everything Overlaps
NIS2, DORA, and ISO 27001:2022 deadlines land within 12 months. Here's how to treat them as one project, not three.
Read ArticleIWH Original Series
Article Series
Practical implementation guides for ISO 27001:2022, NIS2, DORA, and GDPR. Not regulatory summaries — real-world compliance strategies for organisations navigating 2025-2026's converging deadlines.
8 Articles · 2 Sections
Section I
NIS2, DORA, and ISO 27001:2022 deadlines land within 12 months. Here's how to treat them as one project, not three.
Read ArticleThe October 2025 deadline has passed. What actually changed, what a real transition took, what to do if your 2013 certificate lapsed, and what surveillance audits now find.
Read ArticleLaw 5160/2024, the National Cybersecurity Authority and the May 2025 requirements framework. Scope in three questions and a defensible implementation on your ISO spine.
Read ArticleYou don't have to be a bank to fall under DORA. ICT providers, cloud vendors, and their supply chains face new obligations.
Read ArticleSection II
60% of requirements overlap. Stop implementing the same control four times. Build once, document four times.
Read ArticleBeyond the sales pitch. What you can realistically automate in evidence collection and continuous monitoring.
Read ArticleFrom both sides of the audit table. It is not about perfect documentation. It is about records the auditor chose, from periods they chose, and live systems.
Read ArticleThe cheapest time to build compliance is at design time. Architectural patterns for compliance by design.
Read Article