Skip to content
deveca GRC

GRC Blog – Knowledge for people who own the risk.

Practical articles on ISMS, ISO 27001, TISAX, NIS2, GDPR, risk management and GRC implementation – from the deveca editorial team.

All articles

  1. Risk management4 min read

    ERM in practice: ISO 31000, AktG and KonTraG

    ISO 31000, the AktG and KonTraG sound like a pile of duties. Day to day the questions are simple: which risks do we know, who owns them, are we inside appetite, and what must management see?

    • ERM
    • ISO 31000
    • KonTraG
    • AktG
    • Business risks
    Read more
  2. Compliance and standards9 min read

    SOC 1, 2, 3 and Type 1 vs Type 2

    SOC 2 is not a certification. It is an examination report. Here is the difference between SOC 1, 2 and 3, Type 1 versus Type 2, and how a service provider becomes audit-ready.

    • SOC 2
    • SOC 1
    • SOC 3
    • Trust Services Criteria
    • Audit
    Read more
  3. Compliance and standards7 min read

    CRA deadlines 2026/2027

    The Cyber Resilience Act sounds like 2027. It is not: the first fine-backed reporting duty starts in September 2026. Here is the timeline and a practical checklist.

    • CRA
    • Cyber Resilience Act
    • Reporting duties
    • SBOM
    Read more
  4. Compliance and standards6 min read

    NIS2 registration: grace period until 31 July

    Only about two thirds of in-scope organisations were registered with the BSI by the end of May. The BSI is now applying a practical grace period until the end of July.

    • NIS2
    • BSI
    • Registration
    • Reporting duties
    Read more

GRC in practice

See how deveca supports your ISMS and compliance programme.