Insights & articles
Practical guidance on test management, risk-based testing and established testing practices, with a focus on evidence-based release decisions.
Risk-based testing: getting test depth right
How likelihood and impact let you direct test effort to where the risk actually sits.
Read the article → RegulationThe EU AI Act: when AI is involved, evidence becomes mandatory
Which deadlines apply after the amendment of July 2026, what the AI Act actually requires and why the postponement to December 2027 is no reason to sit back.
Read the article → RegulationNIS2 and the Cyber Resilience Act: demonstrating effectiveness
Which deadlines have applied since the German NIS2 implementation act, why the CRA expressly requires regular testing, and what security updates have to do with regression testing.
Read the article → MethodWhat belongs in a test plan under ISO/IEC/IEEE 29119
The seven areas set out in the standard, why the risk register and the exit criteria are the heart of the document, and what is better left out.
Read the article → MethodAcceptance criteria, Definition of Done and exit criteria
Why “are we done?” is not one question but three, and how keeping the levels apart shortens release discussions.
Read the article → PracticeTest data and the GDPR: why copying production is the expensive shortcut
The assessment sequence set out by the German federal data protection authority, the limits of anonymisation, and how test-data requirements should be captured in the test plan without access to production data.
Read the article →Further articles to follow.