Regulatory Frameworks
Regulatory frameworks give structure to vendor reviews. Articles in this category explain what each framework proves, how to read the reports, and how to use them inside an assessment — from privacy and information security through to sector-specific regulation.
How to Review a SOC 2 Report
What sections actually matter, which exceptions are red flags, and how to handle CUECs and carve-outs.
11 min readReadSOC 2 vs ISO 27001
Audit model, scope, output and the right way to combine them in a vendor assessment.
9 min readReadGDPR Processor Assessments
What Article 28 actually requires, the eight areas to verify, and how to keep the assessment defensible.
9 min readReadNIS2 Supplier Requirements
Scope, personal liability, the seven supplier areas to cover, and what defensible records look like.
8 min readReadDORA ICT Supplier Requirements
The register, the mandatory contract clauses, concentration risk, and what an exit strategy actually contains.
9 min readRead
Other categories
- Vendor Due DiligenceThe structured process of verifying whether a software supplier meets your organisation's security, privacy, legal and operational requirements before approval.
- Third-Party Risk ManagementThe ongoing programme for governing risk across every third-party relationship throughout its lifecycle.
- Security Documentation & EvidenceThe documents suppliers publish or provide that make claims verifiable — and how to read, evaluate and work with them.
- SaaS ProcurementIntegrating due diligence into the SaaS buying process so security and compliance reviews support the business rather than block it.