DORA Article 28: Documenting Microsoft as a Critical ICT Third Party on Azure
How to register Microsoft as a critical ICT third party under DORA Article 28, run the criticality test, and review Azure contracts against Article 30. For ICT risk leads.
How to register Microsoft as a critical ICT third party under DORA Article 28, run the criticality test, and review Azure contracts against Article 30. For ICT risk leads.
NIS2 incident reporting on Azure means a 24-hour early warning, 72-hour notification, and one-month final report. Build the capability in Microsoft Sentinel. For SecOps leads.
DORA Article 11 requires a continuous ICT risk-management framework tied to your live Azure tenant: current asset register, per-workload recovery objectives, and Microsoft on your Article 28 register. What DNB actually asks to see.
SOC2 auditors ask for Azure architecture evidence. Not diagrams — evidence of controls implemented, assessed, and documented. This post explains what that evidence must contain and how a pre-audit assessment produces it.
Zero trust on Azure is an architecture you have to document and maintain, not a product you switch on. The evidence a NIS2 supervisor wants is the design rationale - and it drifts. For Azure architects and compliance leads.
A CNAPP tells you which resources are exploitable right now. It does not tell you whether your architecture should have been built that way. This is where runtime detection ends and design-time assessment begins.
De Rijksoverheid heeft bevestigd: de Cyberbeveiligingswet en de Wet weerbaarheid kritieke entiteiten treden op 15 augustus 2026 in werking. Vanaf die datum gelden NCSC-registratie, zorgplicht, meldplicht, aantoonbare bestuurderskennis en ketenrisicobeheer. Voor Nederlandse bestuurders en Cloud Architects op Azure.
NIS2-meldplicht voor Azure: vroege waarschuwing binnen 24 uur, melding binnen 72 uur, eindrapport binnen een maand. Detecteren met Microsoft Sentinel. Voor Nederlandse CISO's.
An Azure Zero Trust assessment scores six pillars with concrete Microsoft signals — Conditional Access, Intune, EIDSCA — mapped to NIS2. For security architects.
A fair read on Microsoft Defender for Cloud NIS2 compliance: strong first-party standards, real gating and scope limits. For security leads. With a coverage table.
Turn Microsoft Entra ID conditional access and PIM into NIS2 and DORA access-control evidence — exact policies, audit logs, artifacts. For identity leads.
NIS2 supply chain security on Azure means governing OAuth apps, service principals, and SaaS dependencies under Article 21(2)(d). What to configure and evidence. For CISOs.
Azure infrastructure drift is not a single event. It is continuous — and most organisations do not detect it until an audit or incident makes it visible. This post maps the categories of drift that create compliance and security risk, and what each category costs when it goes undetected.
A 35-item checklist covering architecture documentation, compliance mapping, and operational governance for Dutch organisations running Azure. Specific enough to audit against. Built for CTOs and Platform Leads who need to close gaps before 2026 ends.
The Cyberbeveiligingswet takes effect on 15 August 2026. Its hardest obligation is a board-level duty of care — personal, continuous, non-delegable — that vulnerability scanners cannot evidence. For directors and Cloud Architects at Dutch regulated organisations.
NIS2 Article 21 requires demonstrable Azure configuration evidence across ten security measure domains. This post maps each domain to specific Azure services and configuration settings. For Platform Engineers and Cloud Architects at Dutch regulated organisations.
The WAF security pillar assessment surfaces the same findings in nearly every Azure environment. This walkthrough names them specifically — so Platform Engineers know what to expect, and what to address before the assessment runs.
NIS2 Artikel 21 stelt concrete eisen aan uw Azure-configuratie. Deze gids vertaalt de tien technische maatregelen naar specifieke Azure-services en instellingen — voor IT-risicomanagers en compliance-professionals bij Nederlandse organisaties.
Most organizations treat architecture reviews as a compliance checkbox. That's a mistake. Here's what they should be instead.
Technical debt isn't just about code quality. It's about the decisions you can't make because of the decisions you made before.
Microsoft's WAF provides a structured approach to evaluating cloud architectures. Here's how to use it effectively without getting lost in the documentation.