
By regulation
Regulations & frameworks.
New EU regulation is the most common reason organisations come to us. Here’s where the pressure is right now.
NIS2
The EU's updated cybersecurity directive expanded scope across 18 sectors, strict incident reporting, supply-chain security, and personal accountability for management.
EU AI Act
The world's first comprehensive AI regulation — a risk-based framework with obligations that scale from transparency to strict conformity, for organisations that build or use AI.
Cyber Resilience Act (CRA)
EU security requirements for products with digital elements — secure-by-design, vulnerability handling, and lifecycle obligations for anyone making or selling connected hardware and software.
DORA
The EU's digital operational resilience regulation for the financial sector — covering ICT risk management, incident reporting, resilience testing, and third-party oversight.
Frameworks & standards.
Framework
ISO 27001
The international standard for information security management. We design, implement, and run the ISMS — and take you to certification and beyond.
Explore
⟶
Framework
BIO2
The information-security baseline for Dutch government — the successor to the BIO, aligned to ISO 27001/27002 and more strongly risk-based.
Explore
⟶
Framework
NEN 7510
The Dutch standard for information security in healthcare — an ISO 27001-based management system with healthcare-specific controls for protecting patient data.
Explore
⟶