Knowledge on ISMS, NIS2 & Compliance
Concise, practical guides — written by the team behind Flux Platform.
NIS2 risk analysis step by step: from asset inventory to treatment plan
How to set up the risk analysis NIS2 requires, pragmatically: scope and assets, risk identification and assessment, treatment, and management approval — using proven methods such as ISO 27005 and BSI Standard 200-3.
Read moreISO 27001 certification: costs, timeline, and process explained
What ISO 27001 certification costs, how long implementation and audit take, and how Stage 1 and Stage 2 audits work — with realistic market figures for mid-sized companies and levers that cut budget and timeline.
Read moreNIS2 vs. KRITIS: differences, overlapping obligations, and 2026 deadlines
KRITIS regulates operators of critical facilities; NIS2 obliges tens of thousands of companies to manage cyber risk. How the two regimes interact since Germany's NIS2 implementation act and the new CER umbrella law — and who owes which obligations.
Read moreWhat is an ISMS? Definition, components, and how to implement one
An ISMS (information security management system) is the systematic framework organizations use to manage information security. Definition, components, ISO 27001, and implementation steps.
Read moreNIS2 requirements: who is affected and what to do now
The EU's NIS2 directive obliges tens of thousands of companies to manage cyber risk, report incidents, and hold management accountable. Who is affected, what the obligations are, and how to prepare.
Read moreISO 27001 vs. SOC 2: differences and how to choose
ISO 27001 is a certifiable international ISMS standard; SOC 2 is an attestation report against AICPA criteria. The differences in scope, audit, and audience — and when each proof pays off.
Read more