Table of Contents

Reach SOC 2 Compliance in 6 Weeks or Less.

  /

  / SIG Lite Explained: Coverage, Uses, and Gaps

SIG Lite Explained: Coverage, Uses, and Gaps

The full SIG content library contains 1,936 questions. SIG Lite asks 128 of them. That difference is the entire point: most vendor relationships do not justify a multi-week questionnaire exchange, and SIG Lite exists so risk teams can run standardized due diligence on lower-risk vendors without burning analyst hours or vendor goodwill.

SIG Lite What It Covers, When to Use It, and Where It Falls Short

What Is SIG Lite?

SIG Lite is the streamlined version of the Standardized Information Gathering (SIG) questionnaire, the most widely used third-party risk assessment instrument in the industry. It condenses the full SIG question set into a short, high-level assessment of a vendor’s information security, privacy, and resilience controls. It is a self-assessment, not an audit: the vendor answers, the assessor evaluates, and the completed questionnaire becomes evidence of due diligence in a third-party risk management (TPRM) program.

Purpose of the SIG Lite Questionnaire

The purpose is speed with consistency. SIG Lite gives an outsourcing organization a broad understanding of a third party’s internal control environment using a standardized question set, so answers are comparable across an entire vendor portfolio. It works either as a complete assessment for low-risk vendors or as a preliminary screen that decides whether a deeper review is warranted. Because every vendor answers the same questions, risk teams can rank, tier, and triage instead of interpreting fifty differently formatted responses.

Who Created and Maintains SIG Lite?

SIG Lite is owned and maintained by Shared Assessments, a member-driven standards organization formed in 2005 when the Big Four accounting firms and six global banks set out to fix the inefficiency of every company writing its own vendor questionnaire. The SIG is developed through a formal governance process that draws on practitioner feedback and tracks evolving regulations and standards, which is a large part of why it has held its position as the de facto industry template.

SOC 2, ISO 27001 and HIPAA done for you. Fixed fee, 100% audit pass rate.

Audit-ready in 6 weeks. Not 6 months.

What’s Included in the SIG Lite Questionnaire?

Number of Questions and Structure

The 2025 release of SIG Lite contains 128 questions. The exact count shifts slightly with each annual update (recent versions have ranged from roughly 126 to 133), so always confirm the version you are working with. Questions are predominantly yes/no with room for comments and references to supporting evidence, and each question maps back to the SIG content library and to external frameworks. SIG Lite ships as a single-worksheet questionnaire, which keeps completion and review manageable.

Risk Domains Covered in SIG Lite

SIG Lite draws its questions from the same 21 risk domains that structure the entire SIG, grouped into four control areas: Governance and Risk Management, Information Protection, IT Operations and Business Resilience, and Security Incident and Threat Management. In practice, that means high-level coverage of access control, information security policy, data privacy, cloud security, business continuity, incident response, supply chain risk, human resources security, compliance management, and ESG, among others. The breadth is the same as SIG Core; the depth per domain is what gets trimmed.

Format and Delivery (Spreadsheet and Toolkit)

Historically, the SIG has been delivered as an Excel workbook generated by the SIG Manager, the macro-driven engine inside the SIG Questionnaire Toolkit that lets assessors scope, generate, store, and compare questionnaires. That is changing. In March 2026, Shared Assessments launched SIG EV (Evolution), a browser-based platform that moves questionnaire creation, distribution, comparison, and grading to the cloud while preserving the same content and methodology. Vendors can still respond in Excel, and assessors can upload completed files, so the transition does not break existing workflows.

Worth Knowing: SIG Questions & Permissions

SIG questions cannot be edited without written permission from Shared Assessments, but assessors can add up to 100 custom questions to a scoped questionnaire. That is usually enough headroom to cover industry-specific requirements without abandoning the standard.

When Should You Use SIG Lite?

Ideal Vendor Risk Scenarios

SIG Lite fits three situations well.

  • First, vendors with no access to sensitive data or critical systems, where a full assessment would be disproportionate.
  • Second, large vendor portfolios, where sending 600-plus questions to every supplier would stall onboarding across the board.
  • Third, early-stage evaluation, where you need enough signal to decide whether a relationship is worth deeper diligence.

Low-Risk vs. High-Risk Vendor Assessments

The dividing line is data and criticality. A marketing tool that touches no customer records, a facilities contractor, or a niche SaaS product with read-only access to public data can all be assessed adequately with SIG Lite. A payroll processor, a cloud provider hosting production data, or any vendor storing regulated information under HIPAA, PCI DSS, GDPR, or GLBA should get SIG Core. Using Lite on a high-risk vendor is a documented gap waiting to be found in your next audit.

Initial vs. In-Depth Risk Screening

Many mature programs use SIG Lite as a gate rather than a destination. The Lite response feeds an initial risk score; vendors that trip defined thresholds (a missing incident response plan, no encryption at rest, no independent certification) graduate to SIG Core or a targeted domain-level assessment. This two-stage pattern keeps effort proportional to risk and gives vendors a lighter first touch.

SIG Lite vs SIG Core

SIG Lite vs. SIG Core: Key Differences

Both questionnaires come from the same content library and cover the same 21 risk domains. The differences are scope, depth, and effort.

Question Count and Scope

SIG Lite’s 128 questions sit at the top of the control hierarchy: does a policy exist, is a program in place, and is there independent validation? SIG Core’s 627 questions descend into how each control actually operates. Beyond both sits the full SIG Detail library of 1,936 questions, which assessors use to build custom scopes by regulation, domain, or control family.

Depth of Assessment

A SIG Lite answer tells you a vendor has an access control program. A SIG Core response tells you how privileged accounts are reviewed, how quickly access is revoked at termination, and how authentication is enforced across environments. If your obligation is to demonstrate that a vendor’s controls are designed and operating effectively, Lite alone will not carry that weight.

Typical Use Cases for Each

Use SIG Lite for onboarding screens, low-risk tiers, annual re-checks of stable low-risk vendors, and portfolio-wide baselining. Use SIG Core for vendors that store or process sensitive or regulated data, critical service providers, and any relationship where a regulator or enterprise customer expects evidence-level diligence.

Benefits of Using SIG Lite

Faster Vendor Onboarding

A prepared vendor can turn around a SIG Lite in days rather than the weeks a Core response takes, because 128 high-level questions can usually be answered by one or two people rather than a cross-functional committee. For the assessor, shorter responses mean faster review cycles and fewer stalled deals waiting on security sign-off.

Lower Resource Requirements

Both sides save effort. Vendors avoid mobilizing IT, legal, HR, and compliance for every prospect. Assessors reduce review time per vendor, which matters enormously when a lean risk team is responsible for hundreds of third parties. Verizon’s Data Breach Investigations Report has linked a substantial share of breaches to third-party access, so the pressure to assess everyone is real; SIG Lite makes broad coverage feasible.

Standardized, Industry-Recognized Framework

SIG questions map to widely adopted frameworks and regulations, including ISO 27001, the NIST Cybersecurity Framework, PCI DSS, GDPR, HIPAA, and GLBA. That mapping means a single well-maintained SIG response can evidence posture across multiple frameworks at once, and it puts SIG Lite in the same standardized category as instruments like the Cloud Security Alliance’s CAIQ, but with broader, industry-agnostic coverage.

Complete SIG Lite Questionnaire

How to Complete a SIG Lite Questionnaire

Preparing Documentation and Evidence

Before answering a single question, gather the artifacts the questions will point to: information security policies, your SOC 2 report or ISO 27001 certificate, incident response and business continuity plans, access control procedures, privacy notices, and subprocessor lists. Most SIG Lite questions can be answered directly from a reasonably mature ISMS. If the documentation does not exist, that is your real finding, and it is better discovered internally than by a prospect.

Answering Questions Efficiently

Build an answer library. The SIG’s standardization is an asset for responders too: an answer written once, kept current, and mapped to the SIG question serial numbers can be reused across every SIG Lite you receive. Assign domains to named owners (security answers access control, legal answers privacy, operations answers continuity) and have a single reviewer check the assembled response for consistency of voice and fact before it leaves the building.

Common Pitfalls to Avoid

Three mistakes recur constantly.

  • Aspirational answers: claiming controls that are planned but not implemented, which unravel the moment an assessor asks for evidence.
  • N/A abuse: marking questions not applicable without justification, which reads as evasion and triggers follow-up.
  • And inconsistency: SIG answers that contradict your SOC 2 report exceptions or your ISO Statement of Applicability, which damages credibility across the entire response.

Important: Never answer ‘yes’ to a control question you cannot evidence on request. A truthful ‘no, with a remediation date’ costs you a scoring point; a ‘yes’ that collapses under scrutiny can cost you the deal and, in regulated relationships, create contractual misrepresentation risk.

 

How to Send and Evaluate a SIG Lite Questionnaire as an Assessor

Distributing the Questionnaire to Vendors

Scope and generate the questionnaire from the SIG Manager or SIG EV, set a clear deadline (two to three weeks is reasonable for a Lite), and tell the vendor what evidence, if any, you expect alongside answers. Include your escalation criteria up front so vendors understand that certain answers will trigger a deeper assessment rather than a rejection. SIG EV supports secure one-time links for vendor access; TPRM platforms can automate the same distribution at portfolio scale.

Scoring and Interpreting Responses

Score against a rubric, not a gut feeling. Binary or weighted scoring per question, rolled up by risk domain, produces a comparable rating across vendors. Weight the domains that matter most for the specific relationship: data privacy and access control for a data processor, business continuity for an operationally critical supplier. Read comments as carefully as answers; hedged language around encryption, subprocessors, or incident notification usually marks the exact spot to probe.

Follow-Up and Remediation Steps

Every gap needs a disposition: accept the risk with documented rationale, require remediation with a deadline, escalate to a SIG Core or targeted assessment, or decline the vendor. Track remediation commitments to closure rather than filing them, and feed the results back into the vendor’s risk tier so the next review cycle reflects reality.

Pro Tip: Cross-check SIG Lite Answers

Cross-check SIG Lite answers against the exceptions section of the vendor's SOC 2 Type II report before scoring. Vendors rarely lie outright, but a clean SIG answer sitting next to a related audit exception tells you exactly where the optimistic self-assessment is.

SIG Lite Update Cycle

How Often SIG Lite Is Updated

Shared Assessments updates the entire SIG annually, adding, retiring, and renumbering questions to track new regulations, threats, and standards. Question counts move accordingly, which is why quoting ‘the’ SIG Lite count without a year is a minor sin among TPRM practitioners. Always request responses on the current release; accepting a version more than a year or two old undermines comparability across your portfolio.

Recent Changes in the Latest Release

The 2026 SIG release added no new risk domains but made three substantive moves: comprehensive mapping to ISO 42001, the AI management system standard, bringing third-party AI governance into standard due diligence; enhanced mapping to NIST SP 800-171 for organizations handling Controlled Unclassified Information; and alignment with the Business Resilience Council’s Operational Resilience Framework, shifting continuity questions from recovery planning toward evidence of sustained operations. Mappings were also refreshed for the restructured ISO 27001:2022 Annex A controls. Alongside the content update, the launch of SIG EV in March 2026 marks the first delivery-model change in the SIG’s history.

Insider Note: The ISO 42001 mapping is the sleeper change in the 2026 release. Once AI governance questions exist in the standard questionnaire, not asking them starts to look like an oversight gap. Expect enterprise assessors to treat vendor AI due diligence as table stakes within a couple of assessment cycles, well ahead of any regulatory mandate forcing the issue.

SOC 2, ISO 27001 and HIPAA done for you. Fixed fee, 100% audit pass rate.

Audit-ready in 6 weeks. Not 6 months.

Best Practices for SIG Lite Assessments

Segmenting Vendors by Risk Tier

Tier vendors before choosing a questionnaire, not after. A simple three-tier model based on data sensitivity, system access, and operational criticality lets you assign SIG Lite to the low tier, SIG Core to the high tier, and a scoped custom SIG to the middle. Document the tiering criteria; auditors and enterprise customers increasingly ask why a given vendor got the light-touch treatment.

Automating Distribution and Scoring

Manual SIG handling does not scale past a few dozen vendors. Automate the mechanical layer: distribution, reminders, response collection, first-pass scoring, and flagging of answers that breach thresholds. Keep humans on interpretation, follow-up questioning, and risk acceptance decisions. That division preserves judgment where it matters while removing the spreadsheet-wrangling that consumes most TPRM analyst time.

Integrating SIG Lite With Your TPRM Program

A SIG Lite response should not live in a folder. Feed scores into vendor risk registers, tie remediation items to contract renewals, and pair point-in-time questionnaire data with continuous monitoring signals such as security ratings and breach intelligence. The questionnaire tells you what a vendor says about its controls; monitoring tells you whether the outside world agrees.

 

Challenges of SIG Lite (and How to Solve Them)

SIG Lite is not free: it requires a Shared Assessments subscription or membership, which smaller assessors sometimes balk at, though the cost is modest against the analyst hours a standardized instrument saves. It is shallow by design, so treat escalation paths as part of the methodology rather than a failure of it. It is a point-in-time self-assessment, which is why pairing it with continuous monitoring matters. Vendors suffer questionnaire fatigue, which an answer library and a willingness to accept a vendor’s proactively shared SIG response both ease. And version drift across a portfolio erodes comparability year by year; standardize on the current release each year and migrate stored responses forward using the SIG’s built-in tools.

 

Tools and Automation for SIG Lite

The tooling landscape has three layers. Shared Assessments’ own stack, the SIG Manager workbook, and now SIG EV, handles creation, comparison, and grading. TPRM and VRM platforms embed licensed SIG content and automate the full assessment lifecycle, from distribution through remediation tracking, with SIG answers mapped automatically to frameworks like ISO 27001 and NIST. And on the vendor side, security questionnaire automation tools draft SIG responses from an organization’s existing documentation and prior answers, cutting response time from days to hours. Whichever layer you invest in, the standard itself stays the same, which is precisely what makes the automation reliable.

SIG Lite earns its place by matching assessment effort to actual risk: 128 standardized questions, 21 risk domains, annual updates, and an ecosystem of tooling that both sides of the assessment already understand. Use it as the broad, fast layer of a tiered TPRM program, escalate to SIG Core when data sensitivity demands it, and keep responses current with each annual release.

Frequently Asked Questions

How many questions are in SIG Lite?

The 2025 release contains 128 questions. The count changes slightly with each annual update, so check the version year before quoting a number.

No. The SIG, including SIG Lite, is a licensed product available through a Shared Assessments subscription or membership. Vendors responding to a SIG Lite sent by a customer do not need their own license to complete it.

A vendor with a mature answer library and current documentation can complete one in a day or two. A first-time responder assembling evidence from scratch should budget one to two weeks. SIG Core, by comparison, routinely takes several weeks of cross-functional effort.

Yes, on both sides. Small assessors get an industry-recognized framework without building one, and small vendors benefit because a completed SIG Lite is far less burdensome to produce than a Core, while still satisfying many customers’ due diligence requirements.

They embed licensed SIG content, automate distribution and reminders, collect responses, apply scoring rubrics, flag threshold breaches, and map answers to compliance frameworks. This removes most of the manual overhead and makes portfolio-wide SIG Lite assessment practical for lean teams.

Yes. The annual update cycle folds new frameworks into the standard question set and mappings; the 2026 release added ISO 42001 for AI governance and deepened NIST SP 800-171 coverage. Assessors can also append up to 100 custom questions to address requirements the standard set does not yet cover.

No. SIG Lite is a self-assessment questionnaire, not independent verification. It documents what a vendor claims about its controls; a SOC 2 report or ISO 27001 certification independently validates those claims. Mature programs use both the SIG for standardized information gathering and the audit report as supporting evidence.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

SOC 2 and ISO 27001 Engagement

After a SOC 2 and ISO 27001 engagement, there are two documents out of the whole pile that actually close deals: the SOC 2 attestation report and the ISO 27001 certificate. Everything else your engagement produces exists to create those two, support them, or keep them alive for another year. Companies routinely ask their auditor for a SOC 2 certificate, which doesn’t exist. They send a prospect their full ISMS documentation when a one-page certificate would have done. They pay for six months of readiness work and then can’t say what they’re holding at the end of it. So here’s the full list. What a SOC 2 engagement produces, what an ISO 27001 engagement produces, what a combined program produces, and who gets to see each one. Understanding SOC 2 and ISO 27001 Engagement Outputs The Core Difference: Report vs. Certificate SOC 2 is an attestation. A licensed CPA firm examines your controls against the Trust Services Criteria under standards set by the AICPA, then writes up what it found and signs an opinion. No certificate. No logo from the AICPA. No pass or fail stamp. What you get is the report, and it usually runs 60 to 120 pages. ISO 27001 is a certification. An accredited certification body audits your Information Security Management System (ISMS) against ISO/IEC 27001:2022, and if you conform, it issues a certificate of registration. The certificate itself is a page or two. All the detail lives behind it, in your ISMS documentation and the audit reports the certification body writes as it goes. SOC 2 Engagement Deliverables The SOC 2 Attestation Report The report is the engagement. The AICPA’s illustrative SOC 2 report lays out the standard structure: auditor’s report, management’s assertion, system description, the Trust Services Criteria in scope, and the controls tested with their results. A Type I covers control design at one point in time. A Type II covers whether those controls actually operated over a period, usually three to twelve months, and most enterprise buyers now won’t accept anything else. Independent Auditor’s Opinion Letter First section of the report, and the first thing anyone experienced turns to. It gives the scope, the examination period, and the auditor’s conclusion. An unqualified opinion means the description held up and the controls worked. A qualified opinion means the auditor found something material, and every serious reviewer will want to talk about it. Management Assertion Your leadership signs a written statement stating that the system description is accurate and that the controls were properly designed and are operating. It reads like a formality, and it isn’t. The auditor’s entire examination runs against what management asserts here, so overstating anything creates real exposure. System Description Usually the longest part of the report, and you write it, not the auditor. It covers the services in scope, your infrastructure, software, people, processes, how data moves, which subservice organizations you depend on, and the complementary user entity controls your customers have to run on their side for your controls to hold up. Trust Services Criteria Applied Security (the Common Criteria) is in every SOC 2. Availability, Processing Integrity, Confidentiality, and Privacy are optional, and the report names exactly which ones you picked. Whatever you decide during scoping ends up printed in a document your customers read for the next several years. Description of Tests of Controls and Results (Type II) The matrix: every control, what the auditor did to test it, and what came back, including exceptions. Reviewers spend most of their time here, because the exceptions tell them things the opinion letter won’t. Bridge Letter / Gap Letter Your report covers a fixed window, so one ending December 31 leaves a hole for a customer doing diligence in June. A bridge letter from your management, not the auditor, confirms that nothing material changed in the control environment between the report’s end date and today. You’ll write these often enough to keep a template. Management Letter and Observations Plenty of auditors also send an internal-only letter covering observations, minor exceptions, and suggestions that never reached the threshold of a qualified opinion. It’s the closest thing to free consulting you’ll get before next year’s audit starts. Insider Note: Ask early whether your auditor issues a management letter, and whether exceptions land in the report body or only in that letter. Firms handle this differently, and the answer decides what your customers see versus what stays behind your firewall. It rarely comes up in the proposal, but it changes how the finished report reads to a buyer. ISO 27001 Engagement Deliverables ISO 27001 Certificate of Registration The document everyone asks for. It names the certified legal entity, states the ISMS scope, identifies the certification body, carries an accreditation mark from a body recognized under the International Accreditation Forum such as UKAS or ANAB, and shows the validity dates. It’s good for three years as long as you pass annual surveillance audits. Read the scope statement carefully, on your own certificate as much as anyone else’s. A certificate covering one office or one product line says nothing about the rest of the business. Statement of Applicability (SoA) After the certificate, this is the document buyers request most. The Statement of Applicability runs through all 93 Annex A controls in ISO/IEC 27001:2022, says which apply to you, justifies the ones you excluded, and records where each stands. Auditors use it as the map of your control environment, and larger customers increasingly want to see it or a summary of it during diligence. Risk Assessment and Risk Treatment Plan Your methodology, the register it produced, and the Risk Treatment Plan showing what you decided to do about each significant risk: mitigate it with a control, transfer it, avoid it, or accept it. ISO 27001 is built around risk, so these documents are what justify every control decision recorded in the SoA. Information Security Management System (ISMS) Documentation The policy and procedure set, plus the operational records that prove any of it happens. Information

The EU AI Act’s transparency requirements take effect on 2 August 2026, and most of the companies they cover still think the rules are not their problem. Article 50 applies to any business that publishes AI-generated content or runs an AI system that talks to people in the EU. That includes the marketing team generating campaign images and the support team running a chatbot. It also covers the AI agents you’ve wired into customer email. Penalties reach €15 million or 3% of total worldwide annual turnover, whichever is higher, and you don’t need an office in Europe to be in scope. If your content or your chatbot reaches EU users, the obligations reach you. In a nutshell: if you publish AI-generated images or video, deploy chatbots or AI agents that interact with EU users, or publish AI-written text on matters of public interest, then yes, the EU AI Act applies, starting 2 August 2026. A quick word on the “AI Act delay” headlines. The Digital Omnibus package did push the high-risk system deadlines back, in some cases by more than a year, but it did not move the deployer obligations in Article 50. Companies that read those headlines and stood down their AI Act work made an expensive mistake, because the rules most likely to touch an ordinary business are the ones that stayed on the calendar. What Article 50 Actually Requires Article 50 of the AI Act sets out transparency obligations in four situations. In plain English: Tell people when they’re talking to AI. Systems designed to interact directly with people — chatbots, voice assistants, and AI agents — must make clear that the user is dealing with AI, unless that’s already obvious. Mark AI-generated content so machines can detect it. Providers of generative AI systems must mark outputs in a machine-readable format, typically through metadata and watermarking, so the content is detectable as artificially generated. Label deepfakes. Anyone deploying AI to generate or manipulate image, audio, or video content that resembles real people, places, objects, or events, and could falsely appear authentic, must disclose that the content is artificial. Label AI-generated text on matters of public interest. Text published to inform the public must carry a label if AI-generated or manipulated, unless a human reviewed it and a person or organization holds editorial responsibility for it. Article 50 also covers emotion recognition and biometric categorization systems, which carry their own disclosure duties. Far fewer businesses run into those, so this article sticks to the four above. The distinction running through all of this is provider vs deployer. The provider builds or supplies the AI system. The deployer uses it professionally. Most companies reading this are deployers. If You Use AI-Generated Images Realistic AI images sit closer to the deepfake rules than most marketing teams assume. The Act’s definition covers content depicting people, objects, places, and events that could falsely appear authentic to a viewer, which describes a large share of what image generators produce for campaigns, social posts, and landing pages. So what does “clearly and distinguishably labeled” mean? The threshold is best described by its failures: a tiny disclosure hidden in the website footer doesn’t qualify. Neither does a faint label on an image, a label that flashes for an instant in a video, or a disclosure buried in your terms and conditions. The label has to be visible right where someone sees the content, and it has to meet accessibility standards so people with disabilities can perceive it too. The Code of Practice proposes a standardized “AI” visual label, localized per language (“KI” in German, “IA” in French). It also draws a useful line between fully AI-generated content and AI-assisted content, with lighter requirements for the latter. A designer who used AI to extend a background is in a different position from a team publishing a fully synthetic image of a person who doesn’t exist. Important: The deepfake duty doesn’t care about intent. A flattering, harmless AI image of your CEO at an event that never happened is still a deepfake under the Act. Marketing teams generate this kind of content casually. From August, every one of those images needs a label. If You Deploy AI Agents or Chatbots The rule itself is simple: people must know they’re dealing with AI. The provider carries the design obligation, but as the deployer you’re the one putting the system in front of your customers, and you’re the one an EU regulator will contact if your branded assistant pretends to be human. The Act contains an exception for cases where it’s “obvious” the user is talking to AI, judged from the perspective of a reasonably well-informed and observant person. Don’t lean on it. What’s obvious to your product team isn’t obvious to every customer, and the human-sounding voice agents and email-writing AI agents rolling out right now are designed specifically to not feel like software. If an AI agent negotiates a renewal over email or handles a support ticket end to end, disclose it. Pro Tip: Put the Disclosure at the Start of the Interaction Put the disclosure at the start of the interaction, in the interface itself: “You’re chatting with an AI assistant.” A line in your privacy policy doesn’t meet the standard, and a disclosure that appears after the conversation ends is worthless. For voice agents, say it up front in the greeting. What Your AI Vendors Owe You The machine-readable marking obligation in Article 50(2) sits with providers — the companies supplying your generative AI tools. The final Code of Practice expects providers to apply at least two layers of marking where necessary, such as embedded metadata combined with watermarking, and to offer detection mechanisms so deployers, authorities, and researchers can verify whether a piece of content came from AI. One timing caveat: the Digital Omnibus gives generative AI systems already on the market before 2 August 2026 until 2 December 2026 to comply with the marking requirement. Every other Article 50 obligation stays on

How Axipro Guided Technovative Solutions & DigiProd Pass to ISO 27001