For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/compliance.md.
← Insights

Compliance

Practical analysis of ISO 27001, NIS2, and DORA, the way we deliver them to Nordic organisations.

Compliance
11 Aug 2026 · Articles
How long does ISO 27001 take?

The work takes weeks, the waiting takes months. What an ISO 27001 run consists of, what sets the pace, and how to plan backwards from a tender deadline.

Read more
Compliance
11 Aug 2026 · Articles
How we use AI to get SMBs certification-ready in four to six weeks

AI drafts the documentation, our consultants adapt it with you, and the evidence gathers itself in a GRC tool. That is how the timeline holds up.

Read more
Compliance
11 Aug 2026 · Articles
ISO 27001 or NIS2 first?

A customer wants ISO 27001 and NIS2 is on the way. Build one management system, let the paying deadline set the order, and the same work carries both.

Read more
Compliance
11 Aug 2026 · Articles
What ISO 27001 costs, and what drives the price

The price of ISO 27001 is the sum of consultant hours, tooling, a GRC system, your own people's time and the audit fee. Here is what moves each one.

Read more
Compliance
11 Aug 2026 · Articles
Your customer requires ISO 27001. What do you do now?

Your customer requires ISO 27001. Here is how to read the requirement, what you can answer today, and the realistic route to the certificate.

Read more
6 Aug 2026 · Guides
DORA and recurring penetration testing, what is required

DORA sets two testing duties: a yearly programme every firm in scope runs, and threat-led penetration testing only where the authority designates you.

Read more
3 Aug 2026 · Articles
What DORA software covers, and what stays a board decision

Software can hold your DORA register and your incident evidence. It cannot decide materiality, own the risk, or write your exit plan.

Read more
31 Jul 2026 · Guides
DORA audit requirements and what you report each year

What DORA asks of internal audit, what leaves the building for Finanstilsynet, and what you show an auditor on an ordinary day.

Read more
28 Jul 2026 · Guides
DORA continuity and response plans for Norwegian firms

What DORA makes you write down, what it makes you test, who has to approve it, and how often each of those has to happen.

Read more
5 Jun 2026 · Articles
What the EU Cyber Resilience Act is, and who it covers

The CRA is an EU law that ties cybersecurity rules to CE marking, so a product with digital elements cannot enter the EU market without it.

Read more
3 Jun 2026 · Articles
What ISO 27001 Lead Implementer certification means for your project

An ISO 27001 Lead Implementer builds your ISMS; a Lead Auditor checks it. Hire the wrong role and your certification project stalls.

Read more
11 May 2026 · Articles
From compliance burden to competitive advantage

How leadership teams move from compliance uncertainty to documented control, evidence that holds up under investor, customer, or regulatory due diligence.

Read more
11 May 2026 · Articles
SOC 2 compliance for Norwegian SMBs selling into the US

SOC 2 can win you a US deal or burn six figures you did not need. Here is how to tell which, and how it fits ISO 27001.

Read more
8 May 2026 · Articles
What SOC 2 Type 2 is, and why US customers ask for it

A US prospect asks for your SOC 2 Type 2 report, you do not have one, and the deal stalls. Here is what it is and the decision it forces.

Read more
7 May 2026 · Articles
What Norway's Digital Security Act is, and how it relates to NIS2

If Norway counts your firm as critical, you have had legal digital-security duties since October 2025, and most boards have not noticed.

Read more
6 May 2026 · Articles
What ISO 27001 is, and why you lose tenders without it

Buyers increasingly require ISO 27001 certification to even let you bid, so missing it quietly drops you from shortlists you would have won.

Read more
5 May 2026 · Guides
ISO 27001 checklist for Norwegian SMBs

A practical ISO 27001 checklist that takes a Norwegian small or mid-size business from "we should get certified" to a Stage 2 audit.

Read more
4 May 2026 · Guides
DORA checklist for Norwegian financial firms

A ten-step DORA checklist for Norwegian banks, insurers, payment firms and asset managers, with Finanstilsynet deadlines and what to do this quarter.

Read more
1 May 2026 · Guides
NIS2 checklist for Norwegian SMB leaders

A leader-facing NIS2 checklist for Norwegian SMBs, the scope self-test, who owns what, the reporting clock, what to budget, and the board questions to ask.

Read more
30 Apr 2026 · Articles
What NIS2 is, and which Norwegian businesses fall under it

NIS2 obligations flow down through contracts, so you can be asked to prove security maturity even before the rule reaches Norwegian law.

Read more
22 Apr 2026 · Guides
How Nordic SMBs prepare for NIS2

Practical compliance steps for the new EU directive, what to do this quarter, and what can wait.

Read more
Questions or inquiry? hello@fmcybersecurity.com Contact us →