Blog

September 9, 20261 Min.

Is cybersecurity consulting being redistributed?

Fewer job postings, restructuring at large consultancies and more visible solo consultants: what the data reveals about the cybersecurity consulting market.

CybersecurityCybersecurity consulting
September 3, 202617 Min.

How to Choose the Best GRC Software

Seven practical questions reveal whether a platform can connect obligations, controls, evidence, risk, and professional judgment in a repeatable system.

GRC softwareCompliance automation
August 30, 202611 Min.

ISO 27001 checklist

ISO 27001 checklists provide orientation but cannot replace knowledge of the standard. A guide to their limits and available resources.

ISO 27001ISMS-Implementierung
August 3, 202619 Min.

Trust, Trustworthiness, and Zero Trust: Why the Future of Trust Must Be Verifiable

Trust should not be maximized. It should be earned, evidenced, and continuously calibrated to actual trustworthiness.

Digital TrustContinuous Assurance
July 28, 20269 Min.

CMMC Phase 2 is suspended. Phase 1 obligations remain.

Phase 2 is suspended, but CMMC and the underlying DFARS security obligations have not disappeared. Contractors should verify current solicitations, assessment designations, SPRS records, and data flows.

RegulatoryCMMC-Compliance
July 26, 20268 Min.

Beyond Spreadsheet Crosswalks

OLIR provides mapping content and governance. OSCAL provides the machine-readable structure for using those mappings in gap analysis, evidence reuse, and change-impact workflows.

OSCALCompliance automation
July 19, 20268 Min.

We counted every constraint in OSCAL 1.2.2. All 348 of them.

Every OSCAL validator claims to validate OSCAL. We enumerated all 348 constraint occurrences in the NIST sources, proved or excluded each one, and then ran the comparison against the Java CLI for real.

OSCALOSCAL-Validierung
July 18, 20266 Min.

NIS2: Germany's grace period is ending

Only about a third of affected companies registered with the BSI on time. Until the end of July 2026 this can be fixed – after that, it gets expensive.

RegulatoryNIS2-Compliance
July 17, 20267 Min.

IT-Grundschutz++ meets OSCAL

With the Stand-der-Technik-Bibliothek, IT-Grundschutz leaves the PDF behind: IT-Grundschutz++ ships as an OSCAL catalog – changing how ISMS work is organized.

IT baseline protectionFramework-Migration
July 16, 20266 Min.

FedRAMP goes machine-readable

With RFC-0024 and the Consolidated Rules 2026, FedRAMP makes structured authorization data mandatory. The deadlines are staggered – the direction is unambiguous.

OSCALAudit-Readiness
July 15, 20268 Min.

The OSCAL tools landscape

The OSCAL ecosystem is growing fast: viewing and validating are well covered, while authoring and day-to-day workflows remain the biggest gap.

OSCALCompliance automation
July 14, 20267 Min.

What is OSCAL?

OSCAL turns compliance documents into structured data: eight document models, three formats, and an ecosystem that is becoming the standard for regulation.

OSCALCompliance automation
June 6, 20265 Min.

Redefining Compliance

Compliance should not be a reporting project at the end. It should be a living system of trust for teams that need structure, speed, and control.

ISMSCompliance workspace
June 6, 20265 Min.

AI-native Compliance

AI-native compliance means importing existing evidence, understanding context, finding gaps, reviewing outputs, and keeping humans in control where judgment matters.

AI governanceCompliance automation
May 28, 20268 Min.

Practical IT-Grundschutz

Turn IT-Grundschutz from a documentation project into a traceable working model for security owners, business teams, and auditors.

IT baseline protectionSecurity concept
May 21, 20267 Min.

Structure audit readiness

Audit readiness does not begin with the next audit. It begins with an evidence model that reflects day-to-day ISMS work.

Audit readinessEvidence management
May 15, 20269 Min.

Govern AI agents

AI agents become useful when they disclose sources, respect boundaries, and do not hide decisions.

AI governanceCompliance automation
May 8, 20268 Min.

Connect protection needs and risk

Protection needs and risk analysis belong together. Their connection is what makes security decisions explainable.

Risk analysisDecision documentation
May 2, 20266 Min.

ISMS metrics

Good ISMS metrics are not report decoration. They show where work is blocked, risk is rising, or decisions are missing.

ISMSManagement reporting