Knowledge Base

Articles, whitepapers and insights into IT audit, information security, compliance and risk management.

Compliance7 min read

ISO 42001 certification: 7 lessons from the field

More organizations pursue ISO 42001 certification for AI governance. But the practice is tougher than the theory. These are the seven things we encounter.

By Kees van der Vlies
Read more
IT-audit5 min read

SOC 2 report explained: everything you need to know

SOC 2 is an essential audit report for service organizations. Learn what a SOC 2 report entails and why it matters for your business.

By Kees van der Vlies
Read more
IT-audit6 min read

ISAE 3402 vs SOC 2: which audit do you need?

ISAE 3402 and SOC 2 are both assurance standards for service organizations. But they differ in scope, audience and application. Here is how to choose.

By Kees van der Vlies
Read more
Security8 min read

ISO 27001 certification: a practical roadmap

Planning your ISO 27001 certification? This step-by-step roadmap covers scoping, risk assessment, implementation and the certification audit itself.

By Kees van der Vlies
Read more
IT-audit6 min read

Continuous auditing: real-time assurance for modern organizations

Traditional audits look back. Continuous auditing looks forward. Learn how real-time monitoring and automated testing are transforming IT audit.

By Kees van der Vlies
Read more
IT-audit5 min read

SOC 2 Type 1 vs Type 2: what is the difference?

SOC 2 Type 1 and Type 2 reports serve different purposes. Understand the key differences to choose the right report for your organization.

By Kees van der Vlies
Read more
IT-audit6 min read

What is ISAE 3402? A complete guide for service organizations

ISAE 3402 is the international standard for assurance reports on controls at service organizations. This guide explains what it means for your business.

By Kees van der Vlies
Read more
Security5 min read

Pentest vs vulnerability scan: what is the difference?

Both pentests and vulnerability scans identify security weaknesses. But they differ fundamentally in approach, depth and value. Here is how to choose.

By Kees van der Vlies
Read more
Compliance7 min read

ISO 9001 quality management for IT service providers

ISO 9001 provides a solid quality management foundation that integrates naturally with ISO 27001 and other standards. Here is why it matters for IT services.

By Kees van der Vlies
Read more
Compliance7 min read

ISO 22301 business continuity: building organizational resilience

ISO 22301 provides the framework for business continuity management. From business impact analysis to continuity testing, here is what you need to know.

By Kees van der Vlies
Read more
Security6 min read

ISO 27017: cloud security controls beyond ISO 27001

ISO 27017 adds cloud-specific security controls to your ISO 27001 framework. Learn about shared responsibility, the seven new controls, and practical implementation.

By Kees van der Vlies
Read more
Compliance6 min read

ISO 27018: protecting personal data in the public cloud

ISO 27018 sets the standard for PII protection in cloud environments. Learn how it connects to GDPR, ISO 27001, and ISO 27017.

By Kees van der Vlies
Read more
Compliance7 min read

ISO 27701: bridging information security and privacy management

ISO 27701 extends ISO 27001 with a Privacy Information Management System. Learn how it supports GDPR compliance and what certification involves.

By Kees van der Vlies
Read more
Compliance8 min read

eIDAS regulation: electronic identification and trust services explained

The eIDAS regulation governs electronic identification and trust services across the EU. With eIDAS 2.0 and the European Digital Identity Wallet on the horizon, understanding this framework is essential.

By Kees van der Vlies
Read more
IT-audit8 min read

Internal audits for ISO certification: requirements and best practices

Internal audits are a mandatory component of every ISO management system. Done well, they drive real improvement. Done poorly, they become a compliance checkbox.

By Kees van der Vlies
Read more
IT-audit7 min read

Preparing for your first SOC 2 audit: a practical checklist

Your first SOC 2 audit does not have to be overwhelming. This practical checklist covers scope definition, control design, gap remediation and evidence collection.

By Kees van der Vlies
Read more
IT-audit7 min read

ISAE 3402 Type II: understanding the observation period

The ISAE 3402 Type II observation period requires a minimum of six months. Learn why this period matters, what auditors test, and how to manage evidence collection.

By Kees van der Vlies
Read more
IT-audit7 min read

DigiD assessment for SaaS providers: scope and requirements

SaaS providers in the DigiD chain face specific assessment requirements. From network segmentation to multi-tenant challenges, here is what you need to know.

By Kees van der Vlies
Read more
Compliance8 min read

DORA compliance for ICT providers: obligations and opportunities

DORA creates new obligations for ICT providers serving financial institutions. Understanding the requirements early turns compliance into a commercial advantage.

By Kees van der Vlies
Read more
IT-audit7 min read

IT audit evidence management: from chaos to control

Good evidence management can make or break an audit engagement. Learn the fundamentals of audit evidence, common pitfalls, and how to organize evidence efficiently.

By Kees van der Vlies
Read more
Compliance9 min read

EU AI Act 2026: high-risk AI classification and conformity assessment guide

The EU AI Act takes full effect for high-risk AI systems in August 2026, with fines up to 35 million euros. How to classify your AI systems, meet compliance requirements, and prepare for conformity assessment.

By Kees van der Vlies
Read more
Security8 min read

Cyber Resilience Act (CRA): cybersecurity requirements for digital products

The Cyber Resilience Act introduces mandatory cybersecurity requirements for all digital products on the EU market. From IoT devices to software: what manufacturers, importers, and distributors need to know.

By Kees van der Vlies
Read more
Compliance8 min read

ISO 27001:2022 transition: what if you are still on the 2013 version?

The transition period to ISO 27001:2022 expired on 31 October 2025. Organizations still certified to the 2013 version need to take action. Here is what changed and how to approach the transition audit.

By Kees van der Vlies
Read more
IT-audit7 min read

Integrated audits: multiple ISO standards in one engagement

More organizations combine ISO 27001, ISO 42001, NEN 7510, or ISO 9001 in a single management system. An integrated audit saves time and cost. But how does it work in practice?

By Kees van der Vlies
Read more
Security8 min read

Supply chain security: auditing and improving your vendor ecosystem

The biggest cyberattacks of recent years came through the supply chain: SolarWinds, Kaseya, MOVEit. NIS2 mandates supply chain management. How do you audit the security of your supply chain?

By Kees van der Vlies
Read more
Security8 min read

Post-quantum cryptography: preparing for the quantum threat

Quantum computers threaten the cryptography that protects virtually all digital communication. NIST has published the first post-quantum standards. What does this mean for your organization?

By Kees van der Vlies
Read more

Stay informed

Get our latest articles and insights on IT audit, compliance and information security.