<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Auditly Blog</title>
    <link>https://auditly.to/blog</link>
    <description>Guides on compliance audits, the frameworks behind them, and how Auditly works.</description>
    <language>en</language>
    <lastBuildDate>Sat, 05 Sep 2026 09:00:00 GMT</lastBuildDate>
    <atom:link href="https://auditly.to/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The EU AI Act Calendar: What Applies When</title>
      <link>https://auditly.to/blog/eu-ai-act-timeline</link>
      <guid isPermaLink="true">https://auditly.to/blog/eu-ai-act-timeline</guid>
      <pubDate>Sat, 05 Sep 2026 09:00:00 GMT</pubDate>
      <description>The regulation phases in over three years. Which obligations are already live, which arrive in August 2026, and what a company that builds or buys AI should have done by each date.</description>
      <category>guide</category>
      <category>eu-ai-act</category>
      <category>eu</category>
      <category>ai</category>
    </item>
    <item>
      <title>ISO/IEC 42001, Explained for People Who Have to Pass It</title>
      <link>https://auditly.to/blog/iso-42001-explained</link>
      <guid isPermaLink="true">https://auditly.to/blog/iso-42001-explained</guid>
      <pubDate>Tue, 01 Sep 2026 09:00:00 GMT</pubDate>
      <description>The first certifiable standard for managing AI. What it asks for, how it relates to ISO 27001 and the EU AI Act, and what an audit against it actually checks.</description>
      <category>guide</category>
      <category>iso-42001</category>
      <category>ai</category>
    </item>
    <item>
      <title>DORA: What Financial Entities and Their ICT Suppliers Must Show</title>
      <link>https://auditly.to/blog/dora-explained</link>
      <guid isPermaLink="true">https://auditly.to/blog/dora-explained</guid>
      <pubDate>Fri, 28 Aug 2026 09:00:00 GMT</pubDate>
      <description>The Digital Operational Resilience Act has applied since January 2025. Its five pillars, who it reaches, and the evidence an auditor asks for under each.</description>
      <category>guide</category>
      <category>dora</category>
      <category>eu</category>
      <category>financial-services</category>
    </item>
    <item>
      <title>SOC 2 Type I or Type II: Which Report to Get First</title>
      <link>https://auditly.to/blog/soc-2-type-1-vs-type-2</link>
      <guid isPermaLink="true">https://auditly.to/blog/soc-2-type-1-vs-type-2</guid>
      <pubDate>Tue, 25 Aug 2026 09:00:00 GMT</pubDate>
      <description>The two report types test different things over different periods. When a Type I is the right first step, when it is wasted money, and how the observation window works.</description>
      <category>guide</category>
      <category>soc-2</category>
      <category>us</category>
    </item>
    <item>
      <title>ISO 27001:2022: What Changed, and What Auditors Test Now</title>
      <link>https://auditly.to/blog/iso-27001-2022-what-changed</link>
      <guid isPermaLink="true">https://auditly.to/blog/iso-27001-2022-what-changed</guid>
      <pubDate>Fri, 21 Aug 2026 09:00:00 GMT</pubDate>
      <description>The 2022 edition restructured Annex A into four themes and 93 controls and added eleven new ones. The transition deadline has passed; here is what a current audit expects to see.</description>
      <category>guide</category>
      <category>iso-27001</category>
    </item>
    <item>
      <title>When GDPR Requires a DPIA, and How to Run One That Holds Up</title>
      <link>https://auditly.to/blog/gdpr-dpia-when-and-how</link>
      <guid isPermaLink="true">https://auditly.to/blog/gdpr-dpia-when-and-how</guid>
      <pubDate>Tue, 18 Aug 2026 09:00:00 GMT</pubDate>
      <description>Article 35 makes a data protection impact assessment mandatory for high-risk processing. The nine criteria regulators use, the structure of a defensible assessment, and what an audit checks.</description>
      <category>guide</category>
      <category>gdpr</category>
      <category>eu</category>
      <category>privacy</category>
    </item>
    <item>
      <title>The 90-Day Audit Readiness Checklist</title>
      <link>https://auditly.to/blog/audit-readiness-checklist</link>
      <guid isPermaLink="true">https://auditly.to/blog/audit-readiness-checklist</guid>
      <pubDate>Fri, 14 Aug 2026 09:00:00 GMT</pubDate>
      <description>What to do in the three months before an ISO or SOC 2 audit, week by week, so the auditor's first request list is answered before it arrives.</description>
      <category>guide</category>
      <category>iso-27001</category>
      <category>soc-2</category>
      <category>checklist</category>
    </item>
    <item>
      <title>How an Escrow-Backed Audit Engagement Works</title>
      <link>https://auditly.to/blog/how-escrow-audit-engagements-work</link>
      <guid isPermaLink="true">https://auditly.to/blog/how-escrow-audit-engagements-work</guid>
      <pubDate>Tue, 11 Aug 2026 09:00:00 GMT</pubDate>
      <description>Why we put money in the middle of every Auditly engagement, what a milestone is, and what happens when the two sides disagree.</description>
      <category>product</category>
      <category>escrow</category>
      <category>contracts</category>
    </item>
    <item>
      <title>Stage 1, Stage 2, Surveillance, Recertification: The ISO Audit Cycle</title>
      <link>https://auditly.to/blog/iso-certification-cycle</link>
      <guid isPermaLink="true">https://auditly.to/blog/iso-certification-cycle</guid>
      <pubDate>Fri, 07 Aug 2026 09:00:00 GMT</pubDate>
      <description>An ISO certificate is not one audit but a three-year cycle of them. What each stage checks, how nonconformities are graded, and how to keep a certificate rather than just win one.</description>
      <category>guide</category>
      <category>iso-27001</category>
      <category>iso-42001</category>
    </item>
    <item>
      <title>NIS2, DORA or the Cyber Resilience Act: Which One Reaches You</title>
      <link>https://auditly.to/blog/nis2-dora-cra-which-applies</link>
      <guid isPermaLink="true">https://auditly.to/blog/nis2-dora-cra-which-applies</guid>
      <pubDate>Tue, 04 Aug 2026 09:00:00 GMT</pubDate>
      <description>Three EU cyber laws with overlapping vocabulary and different scopes. How to tell which applies to your organisation, and where they stack.</description>
      <category>guide</category>
      <category>nis2</category>
      <category>dora</category>
      <category>cra</category>
      <category>eu</category>
    </item>
    <item>
      <title>Why Your Consultant Cannot Certify You</title>
      <link>https://auditly.to/blog/auditor-independence</link>
      <guid isPermaLink="true">https://auditly.to/blog/auditor-independence</guid>
      <pubDate>Sun, 02 Aug 2026 09:00:00 GMT</pubDate>
      <description>Independence rules decide who is allowed to sign your certificate. Understanding them before you buy saves an engagement.</description>
      <category>guide</category>
      <category>independence</category>
      <category>iso-17021</category>
    </item>
    <item>
      <title>ISO 27001 or SOC 2: Which One Does Your Buyer Actually Want?</title>
      <link>https://auditly.to/blog/iso-27001-vs-soc-2</link>
      <guid isPermaLink="true">https://auditly.to/blog/iso-27001-vs-soc-2</guid>
      <pubDate>Sun, 02 Aug 2026 09:00:00 GMT</pubDate>
      <description>The two frameworks answer different questions and are checked in different ways. Here is how to tell which one your customers are asking for.</description>
      <category>guide</category>
      <category>iso-27001</category>
      <category>soc-2</category>
    </item>
    <item>
      <title>NIS2: How to Tell If You Are In Scope</title>
      <link>https://auditly.to/blog/nis2-who-is-in-scope</link>
      <guid isPermaLink="true">https://auditly.to/blog/nis2-who-is-in-scope</guid>
      <pubDate>Sun, 02 Aug 2026 09:00:00 GMT</pubDate>
      <description>The directive applies by sector and company size, and it reaches suppliers who never read it. A practical way to work out whether it applies to you.</description>
      <category>guide</category>
      <category>nis2</category>
      <category>eu</category>
    </item>
    <item>
      <title>What an Auditor Will Ask For, and Why</title>
      <link>https://auditly.to/blog/what-auditors-ask-for</link>
      <guid isPermaLink="true">https://auditly.to/blog/what-auditors-ask-for</guid>
      <pubDate>Sun, 02 Aug 2026 09:00:00 GMT</pubDate>
      <description>The evidence requests that arrive in week one of most engagements, what each is really testing, and how to have it ready.</description>
      <category>guide</category>
      <category>audit-preparation</category>
      <category>evidence</category>
    </item>
    <item>
      <title>How to Choose an Auditor</title>
      <link>https://auditly.to/blog/choose-an-auditor</link>
      <guid isPermaLink="true">https://auditly.to/blog/choose-an-auditor</guid>
      <pubDate>Sat, 18 Jul 2026 09:00:00 GMT</pubDate>
      <description>A practical framework for evaluating and selecting an auditor for your next compliance engagement.</description>
      <category>guide</category>
      <category>compliance</category>
    </item>
    <item>
      <title>Introducing Auditly</title>
      <link>https://auditly.to/blog/introducing-auditly</link>
      <guid isPermaLink="true">https://auditly.to/blog/introducing-auditly</guid>
      <pubDate>Sat, 18 Jul 2026 09:00:00 GMT</pubDate>
      <description>Why we are building a marketplace that matches companies with vetted auditors.</description>
      <category>announcement</category>
      <category>product</category>
    </item>
  </channel>
</rss>
