Komplyo blog

Security & compliance, explained

Practical guides on NIST CSF 2.0, ISO 27001, SOC 2, GDPR and NIS2 for European SMEs and scale-ups without the jargon.

European regulations
6 min read

The AI Act on 2 August 2026: what actually applies and what is postponed for SMEs

2 August 2026 is the general application date of Regulation (EU) 2024/1689, but Regulation (EU) 2026/1744, published on 24 July 2026, postpones the Annex III high-risk obligations to 2 December 2027. A verified overview for SMEs: Article 50 transparency, AI content marking, postponed deadlines, penalties.

  • AI Act
  • EU regulation
  • Governance
  • NIST CSF
Read article
Risk, third parties and continuity
4 min read

Your first risk register: a proportionate method aligned with EBIOS RM and ISO 27005

Risk registers for SMEs: what ISO 27001 (clauses 6.1.2 and 8.2) and NIS2 require, how to start with EBIOS RM workshop 1 (scoping and security baseline), which columns to keep and which pitfalls to avoid. An iterative method aligned with ISO/IEC 27005:2022.

  • Risk register
  • EBIOS RM
  • ISO 27005
  • NIST CSF
Read article
Incidents and vulnerabilities
5 min read

CRA: the 24-hour and 72-hour notification obligation applies on 11 September 2026

Article 14 of Regulation (EU) 2024/2847 applies on 11 September 2026, fifteen months ahead of the rest of the CRA. Early warning within 24 hours, notification within 72 hours, final report within 14 days or one month, through ENISA's single reporting platform. What a manufacturer, including an SME software vendor, must have in place.

  • CRA
  • EU regulation
  • Incident response
  • NIST CSF
Read article
Documentation and governance
4 min read

Coordinated vulnerability disclosure (CVD): the policy the CRA requires, in practice

Annex I, Part II of Regulation (EU) 2024/2847 requires manufacturers to have a coordinated vulnerability disclosure policy. What the policy must contain, the ISO/IEC 29147 and 30111 standards that structure it, the French framework (L. 2321-4 and L. 2321-4-1) and a proportionate implementation for an SME.

  • CRA
  • CVD
  • Vulnerability management
  • NIST CSF
Read article
Risk, third parties and continuity
4 min read

Answering a customer security questionnaire without losing a week: a method for SMBs

CAIQ, SIG, 200-row custom spreadsheets: customer security questionnaires have become a fixture of B2B sales. A 5-step method for SMBs: one answer base aligned with NIST CSF 2.0, projection into each framework's vocabulary, and evidence ready before it's requested.

  • Customer questionnaires
  • Compliance
  • NIST CSF
  • Enterprise sales
Read article
European regulations
4 min read

ENISA's SME maturity model and the CRA: what it measures, what it does not

In July 2026 ENISA published a cyber maturity self-assessment model for SMEs that manufacture products with digital elements: 5 domains, 25 questions scored 1 to 5, three profiles, about two hours. Useful for locating your processes, insufficient for a CRA file. How to combine the two.

  • CRA
  • EU regulation
  • ENISA
  • Maturity
Read article
European regulations
3 min read

NIS2: essential or important entity? The classification test explained

How to determine whether your company is an essential or important entity under NIS2: Annex I and II sectors, size thresholds, size-independent special cases, and what classification actually changes (supervision, penalties, reporting).

  • NIS2
  • Compliance
  • Classification
Read article
Documentation and governance
2 min read

30 compliance documents from a single assessment: how it works

Security policy, ISO 27001 SoA, risk register, business continuity plan, DPIA, records of processing, NIS2 scope memo… How one assessment aligned on NIST CSF 2.0 generates 30+ deliverables ready for your customers and auditors.

  • Compliance
  • NIST CSF
  • ISO 27001
  • GDPR
  • NIS2
Read article
European regulations
16 min read

The Cyber Resilience Act for SMEs: manufacturer obligations and timeline

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) applies to products with digital elements placed on the EU market. The product classes, the manufacturer obligations, the 24h/72h/14-day reporting rule and a 24-month compliance roadmap.

  • CRA
  • Compliance
Read article
Documentation and governance
14 min read

NIST CSF 2.0 for SMEs: the six functions and how to implement them

The NIST Cybersecurity Framework 2.0 organizes cyber risk management into six functions: Govern, Identify, Protect, Detect, Respond, Recover. What each function expects from an SME, category by category, and a 90-day implementation sequence based on the NIST SP 1300 guide.

  • NIST CSF
  • Compliance
  • Cybersecurity
Read article
Certification and audit
5 min read

ISO 27001 or SOC 2 for an SME: deliverables, recognition and how to choose

ISO 27001 produces a certificate issued by an accredited body, valid three years with annual surveillance. SOC 2 produces an attestation report issued by a CPA firm, renewed every year. What each framework requires and produces, what it costs under the published rules, and the criteria that determine the choice for an SME.

  • ISO 27001
  • SOC 2
  • Compliance
Read article
Risk, third parties and continuity
9 min read

Business Impact Analysis for SMBs: a five-step method

A Business Impact Analysis (BIA) prioritizes assets by business criticality rather than technical value. A five-step method for SMBs, based on NIST SP 800-34, NIST CSF 2.0, CISA resources and ANSSI's EBIOS Risk Manager.

  • BIA
  • NIST CSF
  • Business continuity
Read article

Get the security policy template

An information security policy template in .docx format, structured around NIST CSF 2.0 and ISO 27001. Delivered by email, usable as a documentation baseline.

No spam. Unsubscribe in one click.