Knowledge base
Standards and law. In plain language.
What the standards ask of an IT or software provider, in plain language and without quoting the standards themselves.
ISO 27001
7 articles
Start here
ISO 27001 in plain language: what it is and what it asks of a software supplier
ISO 27001 is the international standard for information security, in its current version since October 2022. It consists of requirements for a management system in clauses 4 to 10 and an annex, Annex A, with 93 controls in four themes. Certificates against the 2013 version have not been valid since 31 October 2025.
Read more 6 min read
Internal audit and management review without the theatre
ISO 27001 requires internal audits in clause 9.2 and a management review in clause 9.3, both at planned intervals. For a company of 10 to 100 people, an audit programme that covers the whole scope over a few years and one management review a year is usually enough. Findings are followed up under clause 10.2.
Read more 5 min read
ISO 27001 certification: steps, timeline and who does what
ISO 27001 certification is a two-stage external assessment by a certification body. Stage 1 checks whether you are ready, stage 2 whether your ISMS works. The certificate is valid for three years, with at least one surveillance audit per calendar year. In the Netherlands, the Dutch Accreditation Council (RvA) accredits the bodies that may certify.
Read more 5 min read
ISO 27001 checklist for IT and software companies
This ISO 27001 checklist organises the work for an IT or software company into five phases: foundation, risks, implementation, evaluation and certification. Each point refers to a clause of the 2022 version or to an Annex A control. It does not replace a risk assessment: which controls you implement follows from your own risks.
Read more 5 min read
ISO 27001 controls: the 93 Annex A controls, grouped the way an IT company experiences them
ISO 27001:2022 contains 93 controls in Annex A, split across four themes: 37 organisational, 8 people, 14 physical and 34 technological. Eleven of them are new compared with the 2013 edition. Annex A is a reference list, not a mandatory checklist: which controls you apply follows from your risk assessment and is recorded in the Statement of Applicability.
Read more 6 min read
What ISO 27001 certification costs in the Netherlands
ISO 27001 certification has no fixed price. The external audit costs audit days times a day rate over three years, plus internal hours, consultancy and tooling where used. Audit days follow from ISO/IEC 27006-1 and depend mainly on the number of people in scope. The only fixed amount is the standard itself, 240 euros excluding VAT from NEN.
Read more 5 min read
Statement of Applicability: what goes in it and how to keep it current
The Statement of Applicability is the document ISO 27001 requires in clause 6.1.3 d). For each Annex A control, 93 in the 2022 edition, it states whether the control applies, why or why not, and whether it has been implemented. Together with the risk treatment plan it shows how risks lead to controls.
Read more 5 min read
Law and regulation
3 articles
Start here
The Dutch Cybersecurity Act: what the Dutch NIS2 law means for IT providers
The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) has been in force since 15 August 2026 and applies to more than 8,000 organisations in 18 sectors. They must register with the NCSC, take appropriate security measures, report significant incidents within 24 hours and train their management. IT providers are either in scope themselves or receive the requirements through their customers.
Read more 6 min read
BIO2 for suppliers to Dutch government: what changes and what you will be asked
BIO2 has been the information security framework for Dutch central government, provinces and water authorities since 23 September 2025, and since 15 August 2026 the Dutch Cybersecurity Act makes it legally mandatory for public sector bodies, including municipalities. It requires an ISMS based on ISO 27001 and builds on ISO 27002:2022. Suppliers receive its requirements through procurement and contracts.
Read more 5 min read
NIS2 duty of care and incident reporting: what your customers will ask of you
The NIS2 duty of care requires measures on ten topics, from risk analysis and incident handling to supply chain security and multi-factor authentication. Incident reporting requires an early warning within 24 hours, a notification within 72 hours and a final report within one month. An ISO 27001 ISMS covers most measures, but not the statutory deadlines, registration or management training.
Read more 5 min read