<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Sameer Khairkar</title>
    <link>https://sameerkhairkar.com/</link>
    <description>EU digital regulation, made operational: practical resources for DORA, NIS2, the EU AI Act and GDPR.</description>
    <language>en-GB</language>
    <lastBuildDate>Tue, 01 Sep 2026 11:03:55 +0000</lastBuildDate>
    <atom:link href="https://sameerkhairkar.com/feed.xml" rel="self" type="application/rss+xml" />
    <copyright>Sameer Khairkar</copyright>
    <item>
      <title>A control framework is six hundred unchecked claims about a law</title>
      <link>https://sameerkhairkar.com/blog/2026/09/01/a-control-framework-is-six-hundred-unchecked-claims-about-a-law/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/09/01/a-control-framework-is-six-hundred-unchecked-claims-about-a-law/</guid>
      <description>A 200-control framework makes roughly 600 checkable claims about a law, and nobody checks them because there is no mechanism. regcheck is that mechanism: seven automated checks against the consolidated text, with a non-zero exit code.</description>
      <pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>EU AI Act</category>
      <category>Tools</category>
    </item>
    <item>
      <title>Which regulation wins? There is a rule for that</title>
      <link>https://sameerkhairkar.com/blog/2026/09/01/which-regulation-wins-there-is-a-rule-for-that/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/09/01/which-regulation-wins-there-is-a-rule-for-that/</guid>
      <description>DORA, NIS2, GDPR and the AI Act land on the same desk and appear to contradict each other. Three CJEU principles decide which one wins, and they are consulted in a fixed order.</description>
      <pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>Meta</category>
    </item>
    <item>
      <title>Your vendor questionnaire never asks who owns the company</title>
      <link>https://sameerkhairkar.com/blog/2026/08/31/your-vendor-questionnaire-never-asks-who-owns-the-company/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/08/31/your-vendor-questionnaire-never-asks-who-owns-the-company/</guid>
      <description>Third-party questionnaires ask what data a vendor touches and where it runs. They almost never ask who owns the company, which is a sanctions obligation with no size threshold and close to strict liability.</description>
      <pubDate>Mon, 31 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>NIS2</category>
    </item>
    <item>
      <title>The Digital Omnibus didn't delay the AI Act. It rewrote parts of it.</title>
      <link>https://sameerkhairkar.com/blog/2026/08/12/the-digital-omnibus-didnt-delay-the-ai-act-it-rewrote-parts-of-it/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/08/12/the-digital-omnibus-didnt-delay-the-ai-act-it-rewrote-parts-of-it/</guid>
      <description>Regulation (EU) 2026/1744, the Digital Omnibus on AI, did more than delay the AI Act. Six substantive changes, read from the consolidated EUR-Lex text rather than the press summaries.</description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>EU AI Act</category>
    </item>
    <item>
      <title>Stop asking how important your server is</title>
      <link>https://sameerkhairkar.com/blog/2026/08/12/stop-asking-how-important-your-server-is/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/08/12/stop-asking-how-important-your-server-is/</guid>
      <description>Asset registers rate servers on their own merits and produce numbers nobody can defend. BSI-Standard 200-2 and ISO/IEC 27005 do it the other way round: rate the process once, and let everything underneath inherit.</description>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>ISO 27001</category>
    </item>
    <item>
      <title>Clause 4 decides your certificate before you pick a single control</title>
      <link>https://sameerkhairkar.com/blog/2026/08/11/clause-4-decides-your-certificate-before-you-pick-a-single-control/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/08/11/clause-4-decides-your-certificate-before-you-pick-a-single-control/</guid>
      <description>ISO/IEC 27001 Clause 4 decides the ISMS before a single control is chosen. Four subclauses, four questions, and a scope decision that everything downstream inherits and the certificate names.</description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>ISO 27001</category>
    </item>
    <item>
      <title>The hard part of ISO 27001 is not the policies</title>
      <link>https://sameerkhairkar.com/blog/2026/08/11/the-hard-part-of-iso-27001-is-not-the-policies/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/08/11/the-hard-part-of-iso-27001-is-not-the-policies/</guid>
      <description>Most ISO 27001 template packs hand you the policies and leave the proving as an exercise. Inverting that, so the workbook is the centre and every requirement is a row that cannot be quietly skipped.</description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>ISO 27001</category>
    </item>
    <item>
      <title>The ESAs just told you what DORA expects about AI-driven attacks</title>
      <link>https://sameerkhairkar.com/blog/2026/08/10/the-esas-just-told-you-what-dora-expects-about-ai-driven-attacks/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/08/10/the-esas-just-told-you-what-dora-expects-about-ai-driven-attacks/</guid>
      <description>The ESAs joint statement of 31 July 2026 on frontier AI models used to find and exploit vulnerabilities, and what it implies for DORA asset and function mapping.</description>
      <pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>Nobody knows how to scope a control framework</title>
      <link>https://sameerkhairkar.com/blog/2026/07/30/nobody-knows-how-to-scope-a-control-framework/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/30/nobody-knows-how-to-scope-a-control-framework/</guid>
      <description>Three columns in the Secure Controls Framework are empty on purpose: MCR and DSR are where you record which of 252 instruments bind you. A tool that fills them, and the CC BY-ND licence lesson behind it.</description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>Tools</category>
    </item>
    <item>
      <title>DORA oversight, and the whole regulation on one page</title>
      <link>https://sameerkhairkar.com/blog/2026/07/29/dora-oversight-and-the-whole-regulation-on-one-page/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/29/dora-oversight-and-the-whole-regulation-on-one-page/</guid>
      <description>DORA Chapter V section II and the EU-level oversight of critical ICT third-party providers, plus the whole regulation mapped article to Level 2 standard on one page.</description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>DORA and the register of information: your vendor list is now a regulated filing</title>
      <link>https://sameerkhairkar.com/blog/2026/07/28/dora-and-the-register-of-information-your-vendor-list-is-now-a-regulated-filing/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/28/dora-and-the-register-of-information-your-vendor-list-is-now-a-regulated-filing/</guid>
      <description>DORA Article 28(3) and ITS 2024/2956: what the register of information must contain, and why one line of the regulation becomes a quarter of the implementation effort.</description>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>DORA Articles 28 to 30: your vendors are now your problem, in writing</title>
      <link>https://sameerkhairkar.com/blog/2026/07/27/dora-articles-28-to-30-your-vendors-are-now-your-problem-in-writing/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/27/dora-articles-28-to-30-your-vendors-are-now-your-problem-in-writing/</guid>
      <description>DORA Articles 28 to 30 on ICT third-party risk: the principles, the register, and the contractual clauses the regulation now requires, including the enhanced Article 30(3) set.</description>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>DORA Chapter IV: testing, and the TLPT that is not a normal pen test</title>
      <link>https://sameerkhairkar.com/blog/2026/07/26/dora-chapter-iv-testing-and-the-tlpt-that-is-not-a-normal-pen-test/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/26/dora-chapter-iv-testing-and-the-tlpt-that-is-not-a-normal-pen-test/</guid>
      <description>DORA Chapter IV, Articles 24 to 27: the digital operational resilience testing programme, and how threat-led penetration testing differs from the annual pen test most firms already buy.</description>
      <pubDate>Sun, 26 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>DORA Chapter III: incident reporting, where the clock is measured in hours</title>
      <link>https://sameerkhairkar.com/blog/2026/07/25/dora-chapter-iii-incident-reporting-where-the-clock-is-measured-in-hours/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/25/dora-chapter-iii-incident-reporting-where-the-clock-is-measured-in-hours/</guid>
      <description>DORA Chapter III, Articles 17 to 23: incident management and the reporting cascade, with the statutory deadlines that turn an outage into a regulated filing measured in hours.</description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>DORA Article 16: the simplified regime is lighter, not optional</title>
      <link>https://sameerkhairkar.com/blog/2026/07/24/dora-article-16-the-simplified-regime-is-lighter-not-optional/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/24/dora-article-16-the-simplified-regime-is-lighter-not-optional/</guid>
      <description>DORA Article 16, the simplified ICT risk management framework: who qualifies, what it still requires, and why it is a lighter regime rather than an exemption.</description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>DORA Articles 13 and 14: the quiet articles that decide if you improve</title>
      <link>https://sameerkhairkar.com/blog/2026/07/23/dora-articles-13-and-14-the-quiet-articles-that-decide-if-you-improve/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/23/dora-articles-13-and-14-the-quiet-articles-that-decide-if-you-improve/</guid>
      <description>DORA Articles 13 and 14 on learning and communicating after an incident. No hard thresholds, and in practice the difference between a mature resilience function and a merely compliant one.</description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>The document list BaFin walks in with</title>
      <link>https://sameerkhairkar.com/blog/2026/07/22/the-document-list-bafin-walks-in-with/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/22/the-document-list-bafin-walks-in-with/</guid>
      <description>BaFin published its own list of the documents it expects under DORA. Every one of them, mapped to the article that justifies it, plus the gap between that list and what most policy stacks actually contain.</description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>DORA Articles 11 and 12: what "recover" has to actually mean</title>
      <link>https://sameerkhairkar.com/blog/2026/07/22/dora-articles-11-and-12-what-recover-has-to-actually-mean/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/22/dora-articles-11-and-12-what-recover-has-to-actually-mean/</guid>
      <description>DORA Articles 11 and 12 on ICT business continuity and backup. Recovery objectives are testable in a way policies are not: either you restored inside your stated objective or you did not.</description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>DORA Article 10: detection, and the exact numbers that make an incident "major"</title>
      <link>https://sameerkhairkar.com/blog/2026/07/21/dora-article-10-detection-and-the-exact-numbers-that-make-an-incident-major/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/21/dora-article-10-detection-and-the-exact-numbers-that-make-an-incident-major/</guid>
      <description>DORA Article 10 on ICT incident detection, and the classification thresholds in RTS 2024/1772 that decide when an incident becomes major and the reporting clock starts.</description>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>The DPIA and the FRIA are one assessment, not two</title>
      <link>https://sameerkhairkar.com/blog/2026/07/21/the-dpia-and-the-fria-are-one-assessment-not-two/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/21/the-dpia-and-the-fria-are-one-assessment-not-two/</guid>
      <description>AI Act Article 27(4) says the FRIA complements the DPIA rather than replacing it. Running them as two separate exercises duplicates the work and lets the two risk registers drift apart.</description>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>EU AI Act</category>
      <category>GDPR</category>
    </item>
    <item>
      <title>DORA Article 9: protection and prevention, where the RTS stops being polite</title>
      <link>https://sameerkhairkar.com/blog/2026/07/20/dora-article-9-protection-and-prevention-where-the-rts-stops-being-polite/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/20/dora-article-9-protection-and-prevention-where-the-rts-stops-being-polite/</guid>
      <description>DORA Article 9 on protection and prevention, and the point where the RTS stops speaking in principles and starts naming encryption, patching, logging and network segmentation.</description>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>DORA on one page — now interactive</title>
      <link>https://sameerkhairkar.com/blog/2026/07/20/dora-on-one-page--now-interactive/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/20/dora-on-one-page--now-interactive/</guid>
      <description>The DORA package as an interactive graph rather than a table: 14 legal acts, 215 articles, and the implements-links and cross-references between them.</description>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
      <category>Tools</category>
    </item>
    <item>
      <title>DORA Articles 7 and 8: you cannot protect what you have not written down</title>
      <link>https://sameerkhairkar.com/blog/2026/07/19/dora-articles-7-and-8-you-cannot-protect-what-you-have-not-written-down/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/19/dora-articles-7-and-8-you-cannot-protect-what-you-have-not-written-down/</guid>
      <description>DORA Articles 7 and 8 demand a complete, current picture of the ICT systems and functions you run. Most organisations quietly do not have one, and everything downstream inherits that gap.</description>
      <pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>DORA Article 6: the framework on paper, and the RTS that makes it real</title>
      <link>https://sameerkhairkar.com/blog/2026/07/18/dora-article-6-the-framework-on-paper-and-the-rts-that-makes-it-real/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/18/dora-article-6-the-framework-on-paper-and-the-rts-that-makes-it-real/</guid>
      <description>DORA Article 6 and the ICT risk management framework, read together with the delegated regulation that carries the half of the requirement most write-ups leave out.</description>
      <pubDate>Sat, 18 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>DORA Article 5: what the management body actually signs up for</title>
      <link>https://sameerkhairkar.com/blog/2026/07/17/dora-article-5-what-the-management-body-actually-signs-up-for/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/17/dora-article-5-what-the-management-body-actually-signs-up-for/</guid>
      <description>DORA Article 5 puts the management body on the hook for ICT risk before a single control is mentioned. What the board actually signs up for, and what the defined terms mean.</description>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>DORA</category>
    </item>
    <item>
      <title>Why this site exists</title>
      <link>https://sameerkhairkar.com/blog/2026/07/12/why-this-site-exists/</link>
      <guid isPermaLink="true">https://sameerkhairkar.com/blog/2026/07/12/why-this-site-exists/</guid>
      <description>Most writing about regulation answers what the rules say. The harder question is what to build. Why this site exists and what it publishes.</description>
      <pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Sameer Khairkar</dc:creator>
      <category>Meta</category>
    </item>
  </channel>
</rss>
