Blogs, articles and news
What our consultants are writing about: what auditors actually look for, what implementation involves and what a certificate is worth to the people asking you for it.
Blogs
- 13 September 2026Why Auto Component Suppliers Score Poorly on OEM Cybersecurity Assessments, and the Nine Documents That Close Most of the GapScored assessments award marks for documented evidence, not for practice. That is why secure suppliers score badly, and nine documents close most of the gap.Read the article
- 13 September 2026Business Continuity Carries Disproportionate Weight in an OEM Cybersecurity Assessment, and Most Suppliers Leave It BlankContinuity is among the most heavily weighted sections of a customer cybersecurity assessment, and the one suppliers most often leave empty. What it asks for.Read the article
- 30 Ogos 2026What a readiness score out of 100 tells you before an auditA self assessment is not an audit result. Here is what a readiness score can honestly tell you, and the four things it cannot.Read the article
- 27 Jun 2026What Is a Statement of Applicability (SoA) in ISO/IEC 27001 Certification?The Statement of Applicability (SoA) is a crucial document of ISO/IEC 27001 certification. Learn what it includes, which security controls an organisation needs & learn how MSCi’s ISMS consultants helps you build an Information Security Management System (ISMS).Read the article
- 27 April 2026SOC 2 Type 2 for SaaS: A Practical Compliance Guide for Growing BusinessesLearn what SOC 2 Type 2 means for SaaS companies in India and Mongolia, how it connects to the DPDP Act and Mongolia's data protection law, and how to get certified.Read the article
- 30 Mac 2026ISO Certification in Bahrain for Oil & Gas, Petrochemical & Industrial SectorsGet ISO Certification in Bahrain for oil & gas, petrochemical, and industrial sectors. Learn cost, process, benefits & IAS accredited certification for global compliance.Read the article
News
- 13 September 2026Automotive Suppliers Face Stricter Cybersecurity AssessmentsCybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.Read the article
- 13 September 2026Data Privacy and AI Governance Enter Automotive Vendor Cybersecurity AssessmentsPrivacy, cloud data and AI governance now appear as mandatory sections in automotive vendor assessments, bringing DPDP duties into a commercial process.Read the article
- 12 September 2026ISO 9001:2026 Is Now Published: What Businesses Need to KnowThe new ISO 9001 standard was released on 16 September 2026. Organisations are expected to get three years to transition. Let’s understand what’s new, what stays the same, and when you should take actionRead the article
- 12 September 2026India’s DPDP Consent Manager Rules Take Effect in November 2026India’s DPDP compliance timeline is taking shape, with Rule 4 effective from November 2026 and broader requirements following in May 2027.Read the article
- 12 September 2026Nigeria’s Data Regulator Collects ₦7.2 Billion: What It MeansThe NDPC has completed 246 investigations and plans to strengthen enforcement throughout 2026. For businesses in Nigeria, registration is now an important compliance requirement, not just a formality.Read the article
- 12 September 2026South Africa Strengthens Enforcement of POPIA Data Protection RulesPOPIA compliance is no longer just about paperwork. With enforcement actions continuing through 2026, a ransomware-related finding against SABS, and penalties reaching up to R10 million, organisations need to take data protection seriously and put compliance into practice.Read the article
Articles
- 13 September 2026Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask ForThe nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.Read the article
- 13 September 2026Cybersecurity Across the Automotive Lifecycle: Production, Operational Technology and the Scope GapGovernance, the shop floor and the product in the field: where automotive cyber exposure actually sits, and why an ISO 27001 certificate may not reach it.Read the article
- 12 September 2026What a certification audit actually samplesAuditors do not read your manual cover to cover. They sample, and the sample is predictable. Knowing what gets pulled changes how you prepare.Read the article
- 12 September 2026Why a second standard costs far less than the firstClauses 4 to 10 are shared across the ISO management system standards. That is why the second certificate costs far less than the first.Read the article
- 12 September 2026Certification for Indian exporters: what buyers actually ask forWhich standard an Indian exporter needs is decided by the buyer, the destination market and the sector — not by which certificate is cheapest to obtain.Read the article
- 12 September 2026Mining supply chains and ISO 45001 in MongoliaIn Mongolia, safety certification usually arrives before quality certification, because an international operator asked for it. What that changes about the project.Read the article
Knowledge base
- 13 September 2026Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards MappingWhat does an automotive vendor cybersecurity assessment cover?Read the article
- 13 September 2026Cybersecurity and Data Protection Requirements for Manufacturing Companies in IndiaA Simple Guide to the DPDP Act, CERT-In Directions, IT Act and Customer Cybersecurity AssessmentsRead the article
- 12 September 2026DPDP Act: documentation and compliance requirementsEverything DPDP Act requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.Read the article
- 12 September 2026GDPR Requirements — Explained in Simple LanguageThis document explains what GDPR requires you to do, clause by clause, and what an auditor or regulator may ask you to show as evidence.Read the article
- 12 September 2026HIPAA: documentation and compliance requirementsEverything HIPAA requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.Read the article
- 12 September 2026ISO 13485:2016: Documentation and Compliance RequirementsA simple, clause-by-clause guide to what ISO 13485:2016 requires you to document and what an auditor may ask to see as evidence.Read the article
Not sure which standard applies to you?
Send us the requirement you have been given. We will tell you which standard satisfies it, what it takes and what it costs, before you commit.
