← Back to blog

Running ISO work as an ongoing habit

ISO and NIS2 work collapses when it is treated as a once-a-year project. Small, recurring habits beat heroic audit sprints—especially for EU and Bulgarian teams.

July 29, 2026 · Nisium team · Compliance practice

Every year someone suggests “we should finally get ISO sorted.” Then Q4 arrives, calendars fill with workshops, and the Statement of Applicability becomes a shared document that nobody wants to open.

Certification projects have a place. But if your only rhythm is the certification cycle, the system will always feel fake between audits.

Projects vs habits

A project has a start, a finish, and a celebration. A habit is what you do when nobody is watching.

ISO 27001-style management systems reward habits: risk reviews on a cadence, control owners who know their jobs, incidents that feed improvements, suppliers that get reassessed when the relationship changes. NIS2 expectations for essential and important entities point the same way—ongoing capability, not a binder that ages in SharePoint.

If your SoA only moves when a consultant is on-site, you do not have a living system. You have a snapshot.

Make the SoA useful

The Statement of Applicability is often treated as a compliance artefact to generate, not a decision log. Flip that:

  • For each control, write why it applies (or why it does not) in language your own team understands.
  • Tie owners to names, not departments.
  • Note what evidence proves the control without hunting through three drives.
  • Review exclusions when the business changes—new cloud region, new processing activity, new critical vendor.

When the SoA is a living map, gap analysis stops being a surprise. You already know where the weak joints are.

A lightweight monthly rhythm

You do not need a thirty-person governance forum. Try a short monthly loop:

  1. Risks — anything new from incidents, vendors, or product changes?
  2. Controls — which owners reported drift or overdue reviews?
  3. Evidence — what was captured this month that you will need later?
  4. External — regulatory or CERT-facing obligations on the horizon (notifications, reporting windows, sector guidance)?

Keep notes. Keep owners. Skip the theatre.

Bulgarian and EU context without overclaiming

Operators in Bulgaria sit inside EU rules and national supervisory practice. That means timelines, reporting channels, and sector expectations can matter as much as the ISO clause number on a slide. Aligning internal habits with those external clocks—incident notification windows, supervisory contact paths, documentation that survives scrutiny—is part of “doing ISO for real,” not a separate project.

You do not need to name-drop every framework in every meeting. You need your team to know what happens on a Tuesday when something breaks.

Stop waiting for the big push

Heroic sprints create artefacts. Habits create resilience.

If you are starting from scratch, pick three controls that already hurt—access reviews, vendor onboarding, incident logging—and make them boring and repeatable. Expand from there. The certificate, if you pursue one, will be easier. The Monday morning after the auditor leaves will be calmer either way.