Resources
Make sense of the regulation
Practical, no-fluff guides on DORA, NIS2, ISO 27001 and building an operational-resilience programme. Not sure where you stand? Start with the 5-minute readiness check.
Topic hubs
Start with a hub
The DORA hub
Everything you need to make sense of the EU Digital Operational Resilience Act: the articles, the Register of Information, ICT third-party risk and incident reporting.
Explore the hubThe NIS2 hub
Practical guidance on NIS2: who's in scope, the risk-management measures, and the staged incident-reporting timelines essential and important entities must meet.
Explore the hubThe ISO 27001 hub
Plain-English guidance on ISO/IEC 27001: the move to the 2022 revision, the Statement of Applicability, and running the ISMS as a living management system.
Explore the hubThe ISO 22301 hub
Guidance on ISO 22301 business continuity: the BIA, RTO/RPO, and how one BCMS evidences the tested continuity DORA and NIS2 both expect.
Explore the hubInteractive tools
Get an answer in minutes
DORA tool
Is your incident reportable under DORA?
Answer a few questions about an ICT incident and get an indicative read on whether it's a major incident you'd have to report, following DORA's classification criteria. Runs entirely in your browser.
Check reportabilityReadiness check
Where do you stand on DORA, NIS2 or ISO 27001?
A 5-minute self-assessment that scores your programme and emails you a tailored readiness report. No spreadsheets, no sales call.
Take the readiness checkLatest guides
Fresh from the team

Which compliance framework(s) does your business need? DORA, NIS2, ISO 27001, ISO 22301, SOC 2 and Cyber Essentials compared
DORA, NIS2, ISO 27001, ISO 22301, SOC 2, Cyber Essentials. The honest answer to which you need comes down to three things: where you operate, what sector you're in, and who your customers are.
31 July 2026
What is SOC 2? The Trust Services Criteria and the report, explained
SOC 2 isn't a certificate you pass or fail. It's an independent auditor's report on how well your controls meet the Trust Services Criteria. Here's what that means and what's actually in it.
31 July 2026
What is Cyber Essentials? The five controls and how certification works
Cyber Essentials is the UK's baseline cyber certification: five technical controls that stop the bulk of common attacks. Here's what it covers, how you certify, and when you'll be asked for it.
31 July 2026
What is a Business Impact Analysis (BIA)?
The BIA is the foundation of continuity: it tells you what's critical, how quickly it must come back, and what it relies on. Get it right and the rest of your plan almost writes itself.
31 July 2026
The five Cyber Essentials controls, explained
Cyber Essentials is five technical controls, no more. Here's what each one actually asks for in practice, and the details that most often trip up a first certification.
31 July 2026
SOC 2 Type I vs Type II: which report do you actually need?
A Type I is a snapshot; a Type II is a film. Type II carries the weight with enterprise buyers, but there's a sensible path between the two, plus the bridge letter that covers the gap.
31 July 2026
SOC 1 vs SOC 2 vs SOC 3: which SOC report do you need?
They sound like versions of the same thing. They aren't. SOC 1 is about your customers' financial reporting, SOC 2 is about security and trust, and SOC 3 is the public summary of a SOC 2.
31 July 2026
RTO vs RPO: the two recovery objectives, explained (with MTPD)
One is about time, the other about data, and confusing them is one of the most common mistakes in continuity planning. Here's RTO vs RPO in plain English, plus how MTPD fits.
31 July 2026
ISO 27001 vs SOC 2: which do you need (or do you need both)?
They cover much of the same ground, which is why buyers confuse them. But one is a certificate and the other is a report, and which you need usually comes down to where your customers are.
31 July 2026
How to choose compliance software: a buyer's guide
The pitches all sound identical: automate compliance, save time, get audit-ready. Here's how to tell the tools apart on the things that actually determine whether you succeed.
31 July 2026
Cyber Essentials vs Cyber Essentials Plus: which do you need?
The controls are identical; the assurance isn't. Cyber Essentials is self-assessed and reviewed, Plus is independently tested. Which one you need usually comes down to who's asking.
31 July 2026
Business continuity vs disaster recovery: what's the difference?
They're used interchangeably, but they aren't the same. Disaster recovery is the IT-restoration part of the much broader discipline of business continuity. Here's how they fit together.
31 July 2026
Is your organisation in scope for NIS2? A plain-English scope test
NIS2 comes down to two questions: what sector are you in, and how big are you. Work through both and you'll know whether you're in scope, and whether you're an essential or important entity.
31 July 2026
Is your organisation in scope for DORA? Who the regulation actually covers
DORA's scope is broad within finance but precise about it. Here's how to tell whether you're a covered financial entity, what the exemptions actually cover, and why plenty of technology companies are pulled in as ICT providers.
31 July 2026
ISO 27001:2022 vs 2013: what changed, and the deadline that's now passed
The 2022 revision restructured Annex A to 93 controls in four themes and added 11 new ones. The transition deadline was 31 October 2025; 2013 certificates are no longer valid.
18 June 2026
What is a Statement of Applicability? The ISO 27001 document auditors open first
The SoA lists every Annex A control, whether it applies, why, and its status. It's the map between your risk treatment and your controls, and it's where an auditor starts.
16 June 2026
DORA Article 30 explained: the contractual provisions you actually need
What Article 30 requires in your ICT supplier contracts: the standard provisions, the enhanced set for critical functions, and how to keep them evidenced.
15 June 2026
What is ISO 22301? Business continuity management, explained
ISO 22301 is the international standard for business continuity management. At its heart: a business impact analysis, recovery objectives, tested plans, and a management system that stays current.
14 June 2026
Using one ISO 22301 BCMS to satisfy DORA and NIS2
DORA Article 11 and NIS2 Article 21 both expect tested continuity and recovery. ISO 22301 is the ready-made framework, so you build it once and evidence it against both.
12 June 2026
Building a DORA Register of Information that survives a supervisor
The Register of Information is one of DORA's most concrete deliverables. Here's how to build one that stays accurate and export-ready.
12 June 2026
NIS2 incident reporting: the timelines that catch teams out
NIS2 reporting happens in stages, on the clock. Here's what each stage asks for and how to avoid scrambling when an incident hits.
10 June 2026
DORA vs NIS2: what's the difference, and can one platform cover both?
DORA and NIS2 are often mentioned in the same breath. They overlap, but they're aimed at different things. Here's how they differ, and where they reinforce each other.
8 June 2026Free templates & checklists
Working starters, not blank pages
DORA Register of Information starter
A simplified single-sheet starter to gather the core data the DORA RoI needs: providers (with LEI), contracts, function criticality and data locations. The official RoI is a multi-table xBRL-CSV submission; this helps you collect, not file.
DORA Article 30 contract checklist
A working checklist of the mandatory contractual provisions: the standard set for all ICT services and the enhanced set for critical or important functions.
NIS2 incident-reporting timeline
A one-page reference to the NIS2 Article 23 clock: 24-hour early warning, 72-hour notification, intermediate report on request, and the 1-month final report.
Business impact analysis starter
A starting BIA template aligned to ISO 22301 clause 8.2: process criticality, MTPD, RTO/RPO, dependencies and single points of failure.
Stay in the loop
New DORA, NIS2 and ISO guidance as we publish it
Occasional and practical, no spam. The odd template or checklist too.