Latest¶
The newest thing I have built, at the top. Everything here is free, hosted on this domain, and made to be downloaded and adapted rather than admired.
Each one has a post explaining it over on the blog.
Verifying a control framework against the regulation¶
New — the check nobody runs. A two-hundred-control framework makes about six hundred checkable
claims about a law: the provision exists, it says roughly that, nothing repealed it. regcheck
checks them. Seven automated checks against the consolidated text, a non-zero exit code, and an
honest account of what a green run does not prove.
Reg. (EU) 2024/1689 (EU AI Act) · Reg. (EU) 2016/679 (GDPR), consolidated texts
The hierarchy of EU law, Treaties to RTS¶
New — the map. Where every EU rule sits, from the Treaties every Member State signs down to a technical standard the ESAs draft for one product line. Regulation, Directive, Decision, Delegated act, Implementing act, RTS, ITS and national law, each box carrying the article it lives in and a real example. Plus the three CJEU principles that settle which rule wins when two of them apply to the same situation, and the order you consult them in.
TFEU Arts. 288 to 291 · Case 11/70 · C-582/08 · NIS2 Art. 4 and Recital 28 · DORA · Reg. (EU) 2026/1744
The supplier register, with the check nobody builds in¶
New — worked example and workbook. A supplier and third-party risk register for NIS2 and ISO 27001: a plain-language intake form that scores itself across five axes, twenty-one stop signals that sit between the request and the approval, and the sanctions and ownership screening that almost every register leaves out. Twelve steps, every one of them screenshotted from a live worked example.
CIR (EU) 2024/2690 Annex 5.1 and 5.2 · NIS2 Art. 21(2)(d) · ISO/IEC 27001:2022 A.5.19 to A.5.23 · Reg. (EU) No 269/2014 Art. 2
ISO/IEC 27001:2022 Implementation Kit¶
New — a complete kit. Seventeen documents and a 27-tab workbook that take an organisation from nothing to certified. Every requirement of Clauses 4 to 10 and all 93 Annex A controls is its own row, with an owner, a status, a date and an evidence pointer, so nothing can be quietly skipped. Comes with the milestones, the working sessions and the questions that get real answers out of a room.
ISO/IEC 27001:2022 · Amd 1:2024 · 27002 · 27003 · 27004 · 27005
DPIA + AI Act FRIA, done as one assessment¶
Worked example and tool. GDPR Article 35 and AI Act Article 27 as a single exercise: one scope, one risk register, two legal lenses. A cross-mapping of every required element from both regimes, a joint process flow, a worked example, and a self-contained interactive assessor that drives the decision and exports the record.
GDPR Article 35 · AI Act Article 27 · WP248 · EDPB Opinion 28/2024
Third-party (ICT) risk assessment, start to finish¶
Worked example. The full DORA Chapter V lifecycle, from deciding whether a function is critical or important through to a tested exit. Comes with a CIF-driven assessment workbook and a process document with flowchart and RACI, both downloadable.
DORA · Articles 28 to 30 · RTS 2024/1773 · ITS 2024/2956
Also recent¶
| What it is | |
|---|---|
| DORA Navigator | An interactive map of the DORA package: the regulation, its technical standards, and how the pieces reference one another. |
| The blog | Walking DORA article by article, each post ending in something you can actually use. |
| The resource library | Official texts for DORA, NIS2, the EU AI Act and GDPR, with the Level 2 acts linked to EUR-Lex. |
| The toolshop | Working tools rather than templates: things that do something when you open them. |
Verify before you rely on any of it
Everything here is practitioner material, not legal advice. Article and standard references are drawn from the primary texts, but check them against the current version on EUR-Lex before operational use.