Blog
Getting through compliance
Practical guides to the frameworks buyers and regulators ask for. How to prepare, the deadlines that matter, and what to expect, from the people building the tooling.
What Is a Business Associate Agreement (and Why Does It Matter)?A Business Associate Agreement is the contract HIPAA requires before a covered entity can legally share protected health information with a vendor. Here is what it actually obligates you to do.Will Clients Require ISO 27001 From You?ISO 27001 asks come from a different buyer than SOC 2. Here are the signals that predict one is coming, and what to do the day it arrives mid-deal.Cloud Storage and HIPAA Compliance: What Connected Device Makers Get WrongThe most common HIPAA gap for a connected device company is not malicious. It is a telemetry pipeline built for uptime before anyone decided the product would touch patient data.5 Common SOC 2 Compliance Mistakes (and How to Avoid Them)The common SOC 2 mistakes are not paperwork errors. They are decisions made too early, on the wrong scope, with policies nobody follows, and a vendor picked on price instead of implementation.What Does It Actually Cost a Company to Skip AI Governance?ISO 42001 itself carries no statutory penalty. The real cost of skipping AI governance shows up in EU AI Act exposure, stalled deals, ungoverned failures, and retrofits.What Happens If a Customer Requires SOC 2?A prospect just asked for a SOC 2 report. Here is what to do in the next 48 hours, what timeline is actually achievable, and the vendor mistake that stalls deals for months.Do I Actually Need SOC 2 for My Business?SOC 2 is not a law. It becomes necessary when a customer, investor, or procurement process asks for it. Here is a real decision framework for when to start now versus when to wait.Does ISO 27001 Certification Guarantee Data Protection?No, not automatically. ISO 27001 certifies that a real risk-management system and its controls exist and operate, examined by an accredited auditor. That is real evidence, not an absolute guarantee against every incident.EU AI Act vs ISO 42001: What Is Actually Mandatory?The EU AI Act is binding law with its own obligations for AI systems on the EU market. ISO 42001 is a voluntary certification of your AI governance, and it does not replace the Act.HIPAA Requirements for Connected Medical Device CompaniesWhat HIPAA actually requires of a device maker or software vendor whose product touches patient data, not a hospital employee. Business Associate status, the Security Rule, and the BAA signal.What Does a HIPAA Violation Actually Cost a Company?Most HIPAA cost content is written for a worried employee. This is the vendor-side accounting: penalties, a lost BAA, breach costs, and trust.Will Investors Expect ISO 42001 Certification From an AI Startup?Not yet, not as a fixed checklist item. Most seed and Series A diligence still centers on data privacy, IP ownership, and basic security hygiene, but the underlying governance question is already showing up.Is ISO 42001 Just Another Compliance Box to Check?It can be, and if it is, it is close to worthless. The value is in the underlying discipline, not the certificate that describes it.Is ISO 42001 Required by Law in Europe?No. ISO 42001 is a voluntary international certification, not a legal requirement anywhere, including the EU. The EU AI Act is the separate law that actually carries binding obligations.Is SOC 2 Compliance Really Necessary for Startups?Most early-stage startups do not need SOC 2 on day one. The honest answer is about timing, not principle, and there is a real signal that tells you when it arrives.Is SOC 2 Compliance the Same as Being Secure?No, not automatically. SOC 2 shows a defined set of controls existed and operated over a period, examined by an auditor. It is real signal, but it is not a guarantee against every incident.The ISO 27001 Compliance Checklist: What You Actually Need in PlaceThe real ISO 27001 compliance checklist. Ten ordered steps from ISMS scope to surveillance audits, not a vague list of platitudes.Can a Remote Team Maintain ISO 27001 Compliance?Yes. ISO 27001 has no requirement that anyone work from a physical office. What changes for a remote team is which controls carry the most weight, not whether certification is possible.How to Measure the ROI of ISO 27001 ImplementationISO 27001 return is mostly revenue-side, not cost-avoidance. Track deals unblocked, sales-cycle compression, and lighter questionnaire overhead against the real cost of the ISMS.Can a Small Company Actually Get ISO 27001 Certified?Yes. Certification scope is defined by the company, not headcount, so a small company usually has a smaller ISMS to run. The real constraint is who has the hours to own it.ISO 27001 vs the Cyber Resilience Act: What Actually OverlapsISO 27001 certifies an organisation's security management system while the CRA regulates products sold in the EU. Different subjects, but real technical overlap in risk assessment and vulnerability handling.ISO 27001 vs GDPR: What Is Actually DifferentISO 27001 is a voluntary certification of your information security management system. GDPR is binding EU law on personal data. They overlap on security controls but neither substitutes for the other.How Does ISO 42001 Actually Affect AI Product Development?Most teams building AI features call a third-party model instead of training one. ISO 42001 still expects the team using it to document, monitor, and govern that choice.Do You Need ISO 42001 If You Already Have ISO 27001?ISO 42001 and ISO 27001 share the same management-system structure but govern different risk. Here is what each one actually covers, and when the second one is worth building.How Much Does SOC 2 Compliance Actually Cost?SOC 2 cost is not one number. The audit fee is usually the smallest line item; engineering time to close control gaps is usually the largest.Can a Small Team Actually Afford SOC 2 Compliance?The real constraint on SOC 2 for a small team is not budget, it is bandwidth. Here is why the cheapest path often costs the most engineering time, and what to actually ask a vendor.SOC 2 Type 1 vs Type 2: Which One Do You Need?SOC 2 Type I checks whether your controls are designed correctly at one point in time. Type II checks whether they actually worked over months. Here is the direct answer.SOC 2 vs the Cyber Resilience Act: Are They the Same Thing?SOC 2 and the CRA get asked about together, but one is a voluntary attestation report and the other is EU product law. Here is what actually separates them.SOC 2 vs ISO 27001: Which One Do You Actually Need?SOC 2 vs ISO 27001 is a question about your buyer, not which framework is better. SOC 2 is a US-centric attestation report, ISO 27001 is an internationally recognized ISMS certification, and here is how to tell which one your pipeline actually needs.How to Manage SOC 2 Compliance Without a Pile of Manual TemplatesThe failure mode in most SOC 2 attempts is not a missing template. It is a control matrix that goes stale the moment engineering ships something new, unnoticed until the audit.Vanta, Drata, Secureframe, and Oneleet: How the Fix-First Model Is DifferentAn honest comparison of Vanta, Drata, Secureframe, and Oneleet. Each is genuinely good at what it does. None of them remediate findings, which is the one real gap Scadable is built to close.CRA penalties and fines: what non-compliance actually costsThe Cyber Resilience Act fine tiers, the market-surveillance powers behind them, and why the real cost of non-compliance is losing EU market access mid-deal rather than the fine itself.CRA SBOM requirements explainedWhat the Cyber Resilience Act actually requires for SBOMs. The Annex I Part II wording, what machine-readable means in practice, whether the SBOM must be public, and how it feeds vulnerability handling.CRA technical documentation: what goes in the technical file (Annex VII)What the CRA technical file must contain under Annex VII, from the product description and risk assessment to the SBOM and test reports, who can ask to see it, and how long you have to keep it current.CRA vs NIS2: which one applies to you (and when both do)CRA vs NIS2 in plain terms. The CRA regulates products with digital elements placed on the EU market while NIS2 regulates organisations running critical services. A device maker can be under both, and here is how to tell.CRA vulnerability reporting: the 24-hour, 72-hour, and 14-day clocks (Article 14)From 11 September 2026 manufacturers must report actively exploited vulnerabilities within 24 hours of awareness. How the Article 14 early warning, 72-hour notification, and final report work, and why the hard part is operational.Who does the CRA apply to? Manufacturers, importers, distributors, and open sourceWho the Cyber Resilience Act covers and who it does not. Manufacturers including non-EU and white-label brands, importers, distributors, open source, SaaS, and the sector carve-outs, in one decision flow.The EU CRA compliance checklist: 8 things you need in placeThe EU Cyber Resilience Act compliance checklist for connected-product teams. The eight things you need in place, from SBOM to the 24-hour reporting process.CRA exemptions: legacy products, small business, and who is exemptThe Cyber Resilience Act has narrow, specific exemptions. Company size alone is not one of them, and most fielded products do not escape scope for long.How the Cyber Resilience Act applies to IoT and embedded devicesThe CRA classifies connected products by risk, not by industry label. Here is how IoT and embedded devices actually get classified, and why fielded units are the hard part.How the Cyber Resilience Act treats open source softwareThe CRA does not regulate open-source maintainers the way it regulates manufacturers. It regulates the company that ships open source inside a commercial product.CRA supply chain requirements: what to ask vendors and suppliersThe Cyber Resilience Act makes you responsible for components you did not write. Here is what to ask vendors and how to document what you find.Does the Cyber Resilience Act apply if you are not based in the EU?Yes. The Cyber Resilience Act applies based on where a product is sold, not where the manufacturer is located. Non-EU companies are squarely in scope.GDPR vs. the Cyber Resilience Act: what is actually differentGDPR governs personal data. The Cyber Resilience Act governs product security. Most connected product teams need both, not one instead of the other.How to choose a CRA compliance partner before you signMost CRA offerings produce paperwork, not fixed devices. Here is what to ask before hiring a consultant, auditor, or compliance platform.CRA conformity assessment, self-assessment or notified bodyHow CRA conformity assessment works. The three product classes, when you can self-assess, when you need a notified body, and what the assessment actually checks before your product reaches the EU market.The EU CRA timeline, what to expect and whenThe EU Cyber Resilience Act timeline in plain terms. The two dates that decide your roadmap, what changes on each, and what to expect in the months between now and the deadlines.How to prepare for the EU Cyber Resilience ActA practical readiness checklist for the EU Cyber Resilience Act. The two deadlines that matter, the artifacts an auditor will ask for, and the work to start now if you sell connected products in the EU.Generating an SBOM from your ESP-IDF build, and what esp-idf-sbom does not tell youEspressif ships an official SBOM tool for ESP-IDF. It works. It also has gaps that matter the moment you have more than one device. A walkthrough plus the layer that goes on top.What the EU CRA actually requires from your ESP32 product, and the ship list before September 2026Two dates, twelve months, and a concrete list of artifacts every connected-product team needs to produce on demand. With ESP-IDF specifics, a worked patch-rollout example, and the auditor checklist you will eventually be asked for.From CVE alert to deployed patch, the missing pipeline between OSV.dev and your gateway fleetYou have an OTA pipe. You do not have CVE management. Five steps connect a feed entry to a deployed remediation, and most teams skip three of them. A walkthrough plus the data shapes that make the join cheap.CycloneDX or SPDX for embedded firmware, a decision matrix for ESP-IDF, Yocto, and custom Rust gatewaysMost embedded teams end up generating SBOMs in both formats. The question is which one to emit at build time and how to normalize for everything downstream. With per-stack recommendations and a normalization-layer sketch.
