Continuous effectiveness assessment, the constant-time fork that makes it cheap, and the Article 23 reporting timeline you cannot meet without forensic-grade artefacts.
Why the third-party-ICT register shrinks when the data plane never leaves your tenancy. A practical read of NIS2 Article 21(2)(d) for CISOs and procurement leads renegotiating DPAs in 2026.
The five-tool compliance stack mid-market essential entities are quietly assembling in 2026, what a self-hosted control plane collapses, and the line items that stay yours either way.