Topic
Compliance
7 guides on Compliance — practical, audit-tested, and honest about the hard parts.
Audit Evidence: What Auditors Actually Accept (and Reject)
Most audit pain is evidence pain. Point-in-time vs operating effectiveness, what makes a screenshot admissible, how sampling works, and how to collect evidence continuously.
8 min read · 12 July 2026
One Control, Many Frameworks: How Crosswalk Mapping Cuts Compliance Work
You’re not managing 72 frameworks — you’re managing one control set that 72 frameworks ask about differently. How crosswalk mapping makes evidence count everywhere.
7 min read · 20 June 2026
PCI DSS 4.0: What Changed and How to Prepare
PCI DSS 4.0 is now fully in force. The customised approach, stronger MFA, client-side script protection, targeted risk analyses — what changed from 3.2.1 and how to prepare.
8 min read · 31 May 2026
SOC 2 Type I vs Type II: Which Do You Need?
Type I tests control design at a point in time; Type II tests how controls operate over months. The real difference, which to get first, and how to plan the observation window.
7 min read · 9 May 2026
Continuous Compliance: Moving Beyond Point-in-Time Audits
Annual audits prove you were compliant on one day. Continuous compliance proves you stay compliant every day — here is what it means and how to get there.
8 min read · 24 April 2026
NIS2 Directive: A Complete Compliance Guide for 2026
NIS2 expands cybersecurity obligations to thousands more EU organisations. Understand scope, requirements, penalties, and how to build a compliant security programme.
9 min read · 2 April 2026
SOC 2 Compliance for Startups: A Complete Guide for 2026
Everything you need to know about getting SOC 2 Type II certified — from scoping your first audit to choosing the right tools, without the six-figure consultant bill.
8 min read · 29 March 2026