Moonlight Journal

Notes on certification, without the jargon

Practical guides on ISO 27001, ISO 42001 and the EU AI Act — written for founders and teams who want systems that actually work, not just pass an audit.

ISO 27001 · SOC 2

SOC 2 vs ISO 27001: which one do you actually need?

A report or a certificate, a US buyer or a European one — how to pick the right framework, and how to sequence both without doing the work twice.

2026 · 8 min read
ISO 27001

The ISO 27001 Statement of Applicability, explained

The one document every auditor opens first — what belongs in each column, when exclusions are defensible, and the mistakes that turn into findings.

2026 · 8 min read
ISO 42001

ISO 42001 explained: how to build an AI Management System from scratch

What ISO 42001 actually requires, who needs it, and a step-by-step path from zero to a certifiable AI Management System.

2026 · 9 min read
EU AI Act

The EU AI Act compliance checklist for 2026

Risk tiers, obligations and deadlines — a plain-language checklist to find out what the EU AI Act means for your business and where to start.

2026 · 8 min read
ISO 27001

ISO 27001 for startups: a realistic path to certification

Why enterprise clients ask for it, how long it really takes, what it costs in effort, and how to get certified without drowning your team in paperwork.

2026 · 8 min read

Not sure where to start?

Tell us where you are and what standard you're targeting — we'll reply within 48 hours, in writing.

Start with a Gap Analysis