Blog

August 3, 202619 min

Trust, Trustworthiness, and Zero Trust: Why the Future of Trust Must Be Verifiable

Trust should not be maximized. It should be earned, evidenced, and continuously calibrated to actual trustworthiness.

Digital TrustContinuous Assurance
July 28, 20269 min

CMMC Phase 2 is suspended. Phase 1 obligations remain.

Phase 2 is suspended, but CMMC and the underlying DFARS security obligations have not disappeared. Contractors should verify current solicitations, assessment designations, SPRS records, and data flows.

RegulatoryCMMC-Compliance
July 26, 20268 min

Beyond Spreadsheet Crosswalks

OLIR provides mapping content and governance. OSCAL provides the machine-readable structure for using those mappings in gap analysis, evidence reuse, and change-impact workflows.

OSCALCompliance automation
July 19, 20268 min

We counted every constraint in OSCAL 1.2.2. All 348 of them.

Every OSCAL validator claims to validate OSCAL. We enumerated all 348 constraint occurrences in the NIST sources, proved or excluded each one, and then ran the comparison against the Java CLI for real.

OSCALOSCAL-Validierung
July 18, 20266 min

NIS2: Germany's grace period is ending

Only about a third of affected companies registered with the BSI on time. Until the end of July 2026 this can be fixed – after that, it gets expensive.

RegulatoryNIS2-Compliance
July 17, 20267 min

IT-Grundschutz++ meets OSCAL

With the Stand-der-Technik-Bibliothek, IT-Grundschutz leaves the PDF behind: IT-Grundschutz++ ships as an OSCAL catalog – changing how ISMS work is organized.

IT baseline protectionFramework-Migration
July 16, 20266 min

FedRAMP goes machine-readable

With RFC-0024 and the Consolidated Rules 2026, FedRAMP makes structured authorization data mandatory. The deadlines are staggered – the direction is unambiguous.

OSCALAudit-Readiness
July 15, 20268 min

The OSCAL tools landscape

The OSCAL ecosystem is growing fast: viewing and validating are well covered, while authoring and day-to-day workflows remain the biggest gap.

OSCALCompliance automation
July 14, 20267 min

What is OSCAL?

OSCAL turns compliance documents into structured data: eight document models, three formats, and an ecosystem that is becoming the standard for regulation.

OSCALCompliance automation
June 6, 20265 min

Redefining Compliance

Compliance should not be a reporting project at the end. It should be a living system of trust for teams that need structure, speed, and control.

ISMSCompliance workspace
June 6, 20265 min

AI-native Compliance

AI-native compliance means importing existing evidence, understanding context, finding gaps, reviewing outputs, and keeping humans in control where judgment matters.

AI governanceCompliance automation
May 28, 20268 min

Practical IT-Grundschutz

Turn IT-Grundschutz from a documentation project into a traceable working model for security owners, business teams, and auditors.

IT baseline protectionSecurity concept
May 21, 20267 min

Structure audit readiness

Audit readiness does not begin with the next audit. It begins with an evidence model that reflects day-to-day ISMS work.

Audit readinessEvidence management
May 15, 20269 min

Govern AI agents

AI agents become useful when they disclose sources, respect boundaries, and do not hide decisions.

AI governanceCompliance automation
May 8, 20268 min

Connect protection needs and risk

Protection needs and risk analysis belong together. Their connection is what makes security decisions explainable.

Risk analysisDecision documentation
May 2, 20266 min

ISMS metrics

Good ISMS metrics are not report decoration. They show where work is blocked, risk is rising, or decisions are missing.

ISMSManagement reporting