Blog

Expert articles on compliance, identity, PKI and operations. Hands-on, with no marketing spin.

Topics

One Incident, Two Reporting Channels: CRA and NIS2 Since 11 September 2026

Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents under the Cyber Resilience Act. Anyone also in scope of NIS2 now serves two reporting duties with their own triggers, deadlines and channels.

Read more

The End of clientAuth: Why mTLS With Public Certificates Is Running Out

The Chrome Root Program requires dedicated server hierarchies: new intermediate CAs since June 2026, and leaf certificates from 15 March 2027, may assert serverAuth only. Where mTLS with public certificates breaks, and why client identities belong in a PKI of your own.

Read more

NIS2 After the Grace Period: From Registering to Reporting

The BSI's leniency on registration ended on 31 July 2026. The figures show many registrations and few reports. What counts as a significant incident, when the 24-hour clock starts, and how a company becomes ready to report.

Read more

More articles

E-Invoicing & GoBD

E-Invoicing From 2027: What Invoice Issuers Should Settle Before Year-End

3 min
NIS2 & Resilience

NIS2 Registration: Why 31 July 2026 Is the Deadline That Counts

3 min
E-Invoicing & GoBD

ViDA: What Comes After the German E-Invoicing Mandate

3 min
EU Sovereignty

The Cloud Sovereignty Framework: When Sovereignty Becomes a Measurable Procurement Criterion

3 min
Regulation & AI

When the Chatbot Has to Identify Itself: AI Transparency in Customer Service from August 2026

2 min
EU Sovereignty

The EU Data Act and the End of Switching Fees: Cloud Switching Becomes Mandatory

2 min
Digital Identity

Passkeys in the Enterprise: Phishing-Resistant Sign-In Beyond Passwords and OTPs

2 min
Security & APIs

APIs as Part of the Supply Chain: Why Interface Security Becomes a Matter of Evidence

2 min
Compliance & Product Security

The Cyber Resilience Act: What 11 September 2026 Means for Makers of Digital Products

3 min
Digital Identity

eIDAS 2.0 and the EUDI Wallet: What Relying Parties Must Prepare by the End of 2026

4 min
PKI & Certificates

47-Day Certificates: The CA/Browser Roadmap to 2029

4 min
EU Sovereignty

Data Sovereignty After the Data Privacy Framework: Why EU Hosting Becomes an Architecture Question

3 min
Regulation & AI

The EU AI Act: GPAI Enforcement from 2 August 2026 and What the Digital Omnibus Postponed

3 min
Digital Identity

SD-JWT VC and OpenID4VP: The Protocols Behind the EUDI Wallet

3 min
Accounting & Compliance

Archiving Structured E-Invoices the GoBD Way: The Eight-Year Question

3 min
NIS2 & Resilience

NIS2 in Practice: From Reporting Duty to Defensible Evidence

3 min
PKI & Certificates

ACME Beyond the Web Server: Certificate Automation for Internal Services and mTLS

3 min
DORA & Financial Sector

DORA for ICT Providers: Third-Party Risk and Incident Reporting

3 min
Crypto & PKI

Post-Quantum Cryptography: Why the Migration Starts in 2026, Not 2030

3 min
E-Invoicing & GoBD

Germany's E-Invoicing Mandate: The 2025 to 2028 Roadmap Without the Myths

3 min