<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyber Compliance — Blog</title>
    <link>https://www.cybercompliance.app/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Fri, 05 Jun 2026 00:51:55 GMT</lastBuildDate>
    <atom:link href="https://www.cybercompliance.app/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>GDPR Article 32 in practice: which security controls actually satisfy it</title>
      <link>https://www.cybercompliance.app/en/blog/gdpr-article-32-security-controls</link>
      <guid isPermaLink="true">https://www.cybercompliance.app/en/blog/gdpr-article-32-security-controls</guid>
      <description>Article 32 names encryption and resilience but refuses to give you a checklist. Here is how regulators read it after a breach, and which ISO 27001 and CIS controls map to each clause.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Mapping ISO 27001 to SOC 2: what actually overlaps, and where teams get burned</title>
      <link>https://www.cybercompliance.app/en/blog/iso-27001-to-soc-2-mapping</link>
      <guid isPermaLink="true">https://www.cybercompliance.app/en/blog/iso-27001-to-soc-2-mapping</guid>
      <description>A practitioner&apos;s view of the ISO 27001 Annex A to SOC 2 Trust Services Criteria mapping. The real overlap, the parts that don&apos;t map, and the evidence mistakes that cost you a second audit.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>NIS2 vs DORA: which one applies to you, and how to avoid building two programs</title>
      <link>https://www.cybercompliance.app/en/blog/nis2-vs-dora</link>
      <guid isPermaLink="true">https://www.cybercompliance.app/en/blog/nis2-vs-dora</guid>
      <description>Scope, incident reporting timelines, and the lex specialis rule that decides whether a financial entity follows DORA or NIS2. Plus how both map onto ISO 27001 so you run one control set.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>