Field notes from security operations and the audit room.
Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.
The security annex, clause by clause: what a prime contractor is really asking for
The questionnaire is a filter. The annex is the contract. Ten clauses that now appear in almost every prime contractor security schedule, what each one costs a supplier to satisfy, and the three that are genuinely negotiable.
Ground segment access: what a satellite operator checks before letting you in
The satellite is the hard target. The ground station sits on a network reachable from an office. That is why the access review a space operator runs on a supplier is stricter than anything in the directive, and why it arrives years before the EU Space Act does.
Space suppliers: the four regimes you actually sit under
A company selling into satellite operators sits under four separate regimes at once: NIS2, the proposed EU Space Act, national space authorisation, and whatever the prime contractor writes into the contract. Only one of them will reach you this year.
Telecom suppliers: the two ways NIS2 reaches you, and the one people miss
Most suppliers to telecom operators assume NIS2 reaches them only through their customer's contract. For managed service providers, cloud, data centre, DNS and trust services, there is a second route, and it is more prescriptive than the first.
The Cyber Resilience Act reporting duty starts on 11 September
From 11 September 2026, anyone who places a product with digital elements on the EU market has 24 hours to report an actively exploited vulnerability. Not the company using the product. The company that made it.
EASA Part-IS: what it means if you supply the aviation industry
Part-IS has applied to aerodromes and production organisations since 16 October 2025, and to airlines, MROs and air navigation providers since 22 February 2026. If you supply any of them, it reaches you by contract. Here is how far it actually goes.