5 guides

NIS2, ISO 27001 & evidence

An auditor does not want to read policy, they want to see evidence that the policy runs. These guides translate NIS2 art. 21, ISO 27001 Annex A and the CRA into concrete server tasks and show how to collect evidence that still holds up six months later. We describe how to collect evidence, not whether you are compliant — that remains a legal assessment.

NIS2, ISO 27001 & evidence
intermediate · 6 min read
2026-09-16

AWS MSP VCL 8.0 gap analysis in one afternoon: from 61 controls to a work list

From 1 January 2027 AWS validates MSP partners only against Validation Checklist 8.0: 24 new and 27 rewritten controls, with GenAI observability, toil measurement and AI governance as new blocks. This is the method to know where you stand in one afternoon: which controls you already cover with existing systems, which need a time series you must start today, and which are purely organisational. With two scripts (AI-dependency inventory and toil baseline) and a fill-in worksheet.

awsmspvcl-8.0compliancegenaiobservabilitytoil
NIS2, ISO 27001 & evidence
intermediate · 5 min read
2026-09-16

Proving ISO 27001 A.8.8 with logs instead of a Word document: managing technical vulnerabilities

Control A.8.8 requires you to identify, assess and address vulnerabilities in a timely way. Most organisations prove that with a policy and a screenshot of a scanner. An auditor wants to see the chain: when the CVE became known, when you saw it, what you decided, when it was closed. This is how to pull those four timestamps automatically from your servers and turn them into a metric — MTTR per severity — you can show every quarter.

iso27001a.8.8cvemttrevidencenis2
NIS2, ISO 27001 & evidence
intermediate · 6 min read
2026-09-16

A quarterly access review in one hour: accounts, sudo, SSH keys and SSO against the staff list — with script

ISO 27001 A.5.18 and NIS2 Art. 21(2)(i) require you to periodically check who has access and whether that's still right. In practice that becomes an afternoon of spreadsheets, or it doesn't happen. This script turns the review into an hour: it lays the technical inventory (servers, sudo, keys, IdP accounts) next to the HR list, flags every deviation, and produces the signed report an auditor accepts.

access-reviewiso27001nis2sudosshidentity
NIS2, ISO 27001 & evidence
intermediate · 6 min read
2026-09-15

What a NIS2 auditor really asks for: twelve pieces of evidence and the script that pulls them from your servers

No policy, no intentions: an auditor wants artefacts with a date. These are the twelve that come up in virtually every CyFun or NIS2 audit, with the command that produces each one, and an evidence-pack.sh that puts everything in one signed archive that can still be verified six months later.

nis2auditevidencecyberfundamentalsiso27001ed25519
NIS2, ISO 27001 & evidence
beginner · 8 min read
2026-09-15

NIS2 checklist for the Belgian SME: the ten measures of Article 21 translated into concrete server tasks

NIS2 Article 21(2) lists ten measures in legal language. This is the translation into what you do on your servers on Monday — per measure the command, the file or the script that produces the evidence. With the Belgian context: the law of 26 April 2024, the CCB, CyberFundamentals and the registration duty.

nis2ccbcyberfundamentalschecklistsmebelgium

← All guides