Blog
Expert articles on compliance, identity, PKI and operations. Hands-on, with no marketing spin.
One Incident, Two Reporting Channels: CRA and NIS2 Since 11 September 2026
Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents under the Cyber Resilience Act. Anyone also in scope of NIS2 now serves two reporting duties with their own triggers, deadlines and channels.
Read moreThe End of clientAuth: Why mTLS With Public Certificates Is Running Out
The Chrome Root Program requires dedicated server hierarchies: new intermediate CAs since June 2026, and leaf certificates from 15 March 2027, may assert serverAuth only. Where mTLS with public certificates breaks, and why client identities belong in a PKI of your own.
Read moreNIS2 After the Grace Period: From Registering to Reporting
The BSI's leniency on registration ended on 31 July 2026. The figures show many registrations and few reports. What counts as a significant incident, when the 24-hour clock starts, and how a company becomes ready to report.
Read moreMore articles
E-Invoicing From 2027: What Invoice Issuers Should Settle Before Year-End
NIS2 Registration: Why 31 July 2026 Is the Deadline That Counts
ViDA: What Comes After the German E-Invoicing Mandate
The Cloud Sovereignty Framework: When Sovereignty Becomes a Measurable Procurement Criterion
When the Chatbot Has to Identify Itself: AI Transparency in Customer Service from August 2026
The EU Data Act and the End of Switching Fees: Cloud Switching Becomes Mandatory
Passkeys in the Enterprise: Phishing-Resistant Sign-In Beyond Passwords and OTPs
APIs as Part of the Supply Chain: Why Interface Security Becomes a Matter of Evidence
The Cyber Resilience Act: What 11 September 2026 Means for Makers of Digital Products
eIDAS 2.0 and the EUDI Wallet: What Relying Parties Must Prepare by the End of 2026
47-Day Certificates: The CA/Browser Roadmap to 2029
Data Sovereignty After the Data Privacy Framework: Why EU Hosting Becomes an Architecture Question
The EU AI Act: GPAI Enforcement from 2 August 2026 and What the Digital Omnibus Postponed
SD-JWT VC and OpenID4VP: The Protocols Behind the EUDI Wallet
Archiving Structured E-Invoices the GoBD Way: The Eight-Year Question
NIS2 in Practice: From Reporting Duty to Defensible Evidence
ACME Beyond the Web Server: Certificate Automation for Internal Services and mTLS
DORA for ICT Providers: Third-Party Risk and Incident Reporting
Post-Quantum Cryptography: Why the Migration Starts in 2026, Not 2030
Germany's E-Invoicing Mandate: The 2025 to 2028 Roadmap Without the Myths
No posts for this selection. Reset the filter with „All“.