Skip to content

Knowledge base

Standards and law. In plain language.

What the standards ask of an IT or software provider, in plain language and without quoting the standards themselves.

ISO 27001

7 articles

Start here

ISO 27001 in plain language: what it is and what it asks of a software supplier

ISO 27001 is the international standard for information security, in its current version since October 2022. It consists of requirements for a management system in clauses 4 to 10 and an annex, Annex A, with 93 controls in four themes. Certificates against the 2013 version have not been valid since 31 October 2025.

Read more 6 min read

Internal audit and management review without the theatre

ISO 27001 requires internal audits in clause 9.2 and a management review in clause 9.3, both at planned intervals. For a company of 10 to 100 people, an audit programme that covers the whole scope over a few years and one management review a year is usually enough. Findings are followed up under clause 10.2.

Read more 5 min read

ISO 27001 certification: steps, timeline and who does what

ISO 27001 certification is a two-stage external assessment by a certification body. Stage 1 checks whether you are ready, stage 2 whether your ISMS works. The certificate is valid for three years, with at least one surveillance audit per calendar year. In the Netherlands, the Dutch Accreditation Council (RvA) accredits the bodies that may certify.

Read more 5 min read

ISO 27001 checklist for IT and software companies

This ISO 27001 checklist organises the work for an IT or software company into five phases: foundation, risks, implementation, evaluation and certification. Each point refers to a clause of the 2022 version or to an Annex A control. It does not replace a risk assessment: which controls you implement follows from your own risks.

Read more 5 min read

ISO 27001 controls: the 93 Annex A controls, grouped the way an IT company experiences them

ISO 27001:2022 contains 93 controls in Annex A, split across four themes: 37 organisational, 8 people, 14 physical and 34 technological. Eleven of them are new compared with the 2013 edition. Annex A is a reference list, not a mandatory checklist: which controls you apply follows from your risk assessment and is recorded in the Statement of Applicability.

Read more 6 min read

What ISO 27001 certification costs in the Netherlands

ISO 27001 certification has no fixed price. The external audit costs audit days times a day rate over three years, plus internal hours, consultancy and tooling where used. Audit days follow from ISO/IEC 27006-1 and depend mainly on the number of people in scope. The only fixed amount is the standard itself, 240 euros excluding VAT from NEN.

Read more 5 min read

Statement of Applicability: what goes in it and how to keep it current

The Statement of Applicability is the document ISO 27001 requires in clause 6.1.3 d). For each Annex A control, 93 in the 2022 edition, it states whether the control applies, why or why not, and whether it has been implemented. Together with the risk treatment plan it shows how risks lead to controls.

Read more 5 min read

Law and regulation

3 articles

Start here

The Dutch Cybersecurity Act: what the Dutch NIS2 law means for IT providers

The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) has been in force since 15 August 2026 and applies to more than 8,000 organisations in 18 sectors. They must register with the NCSC, take appropriate security measures, report significant incidents within 24 hours and train their management. IT providers are either in scope themselves or receive the requirements through their customers.

Read more 6 min read