Practical resources for Nordic and EU teams managing supplier risk under NIS2, ISO 27001, and GDPR.
A practical breakdown of Article 21 supply chain requirements, what evidence auditors expect, and how to build a repeatable programme without a full GRC suite.
What Article 28 actually requires, how to structure your data processor due diligence, and a ready-made assessment template to get you started.
The 2022 revision made supplier risk controls significantly more demanding. Here's what changed and how to demonstrate compliance in your next audit.
When you have 50 suppliers and limited time, you can't assess them all equally. Here's a practical framework for deciding where to start and how to keep moving.
A risk score tells you where you are. Residual risk tracks whether you're actually getting better. Here's the difference and why it matters for management reporting.
Free for up to 3 suppliers. No credit card required.
Get free access