ProjektDK BLOG

In this BLOG, you’ll find topics on which Claus has an opinion or wants to share insights and knowledge. The best way to understand stuff is to write about it and use it.

Visit Claus’ inspirational sources.

You might have read my lengthy articles on the Product Operating Model. Here is a consolidated recap as an interactive guide. For your convenience, here are some examples of my earlier articles on POM: The product operating model The product …

You, as a manufacturer of Products with Digital Elements (PwDE) within the CRA scope, are fully aware that your PwDE must comply with the CRA by the end of 2027. But where do you start? Here is a recommendation for approaching the challenge. I’m here to …

Artiklerne GRC and Third-Party Risk Management og ISMS Cookbook omhandler begge vinkler på  GRC og adresserer i nogen grad GDPR. Fokus i denne artikel og i den interaktive GDPR Compliance Guide nedenfor er at dykke ned i GDPR-kaninhullet. Artiklen er skrevet på dansk, …

This article focuses on outbound GRC (Governance, Risk, and Compliance) cybersecurity for third parties, in contrast to the inbound ISMS Unified Control Framework. DISCLAIMER: The interactive Vendor Risk Assessment Explorer is built with AI support. AI can make mistakes. I’ve done …

ISMS Cookbook

The original intention of this article was to provide guidance on structuring the “normal” ISO 27001 ISMS. Then reality hit. The ISMS cannot and should not be viewed in isolation. In real-world enterprise scenarios, many regulations, directives, and standards are in …

The Standardization Request M/606 has been referenced several times in the blog. But what is it? That is the topic for this article. The Standardization Request M/606 The Standardization Request M/606 is the official mandate issued by the European Commission …

Is the upcoming CRA-aligned EN IEC 62443/A11 harmonized standard up to the task of protecting against AI-driven attacks, or has it already been overtaken before it is cited in the OJEU? That is what the article is about. Today’s and definitely …

Regulation (EU) 2024/1689 [EU AI Act] establishes a uniform, risk-based legal framework to ensure trustworthy AI throughout the European Union while safeguarding fundamental rights. The AI Act strictly prohibits unacceptable practices, such as subliminal manipulation, social scoring, untargeted scraping of facial …

CRA Article 27 establishes the legal framework and mechanisms by which products with digital elements (and their manufacturers’ processes) can obtain a Presumption of Conformity with the Regulation’s essential cybersecurity requirements (as set out in Annex I). What you may not realize …

The (still-in-draft) Commission guidance on the Cyber Resilience Act assists economic operators (with a particular focus on microenterprises and SMEs) and market surveillance authorities in applying the CRA. It clarifies key provisions, regulatory boundaries, and practical compliance strategies without legally …

Various forms of CRA assistance are available. This article is the first in a series outlining the available help. The biggest help, without question, would have been to have all the harmonized standards ready and cited in OJEU by now. Unfortunately, …

Here you’ll find a condensed executive summary of the Cyber Resilience Act, what it is, and the key criteria for compliance. You might also want to visit The Cyber Resilience Act (CRA) and the CRA quiz. Let’s Turn Strategy Into …

You may have heard the terms Perdue, ISA-95, IEC 62443, and MES, but you are unclear about how they relate to one another. Help is on the way. In modern manufacturing, bridging the gap between enterprise IT and the factory …

A WTG (Wind Turbine Generator) manufacturer asks a supplier to design a sub-component in accordance with its specifications. How is the CRA responsibility split between the WTG manufacturer and the sub-component supplier? The sub-component is here assumed to be a …

The Cyber Resilience Act is just another expected-to-be-delayed NIS2 variant, right? No! You may recall that NIS2 is a Directive, whereas CRA is a Regulation. Does it matter? Yes! In short, a Directive tells us what to achieve, not strictly when; just look …

In the quest to help organizations approach ISO 27001, I’ve added an ISO 27001 Internal Audit Guide to the toolbox. Because it closely aligns with the standard’s details, I cannot share the link to the tool itself. What I can and will …

This article aims to illustrate the full journey from a software product manufacturer’s Product Vision to a Release Candidate ready for deployment at customer sites. Of course, the full and detailed journey involves a range of disciplines, roles, competencies, and principles that are …

Based on publicly available information about ITIL 5, I’ve created, supported by AI, an interactive guide to bring you up to speed in no time. The original intent of this article was to shed light on the new ITIL 5, but …

Based on publicly available information about PRINCE2 and PRINCE2 Agile, I’ve created an interactive guide with AI support to bring you up to speed in no time.  First, let me clearly declare a couple of my firm convictions: Dogmatism is …

CER-loven (Lov om kritiske enheders modstandsdygtighed) er en relativt ny dansk lov, der har til formål at sikre, at samfundskritiske virksomheder og organisationer kan fortsætte deres drift, selv hvis de rammes af kriser, naturkatastrofer, strømsvigt, sabotage eller forsyningssvigt. Mens den …

OPDATERING 29-7-2026: Det interaktive NIS2-auditværktøj er opdateret, og der er nu også en interaktiv guide til at navigere i NIS2-loven. OPDATERING 15-8-2026: Det interaktive NIS2-auditværktøj er blevet forbedret. Formålet med denne artikel er at hjælpe danske virksomheder med at implementere og dokumentere …

Formålet med denne artikel er at hjælpe danske forsyningsselskaber med at implementere og dokumentere kravene i Lov om styrket beredskab i energisektoren (Lov nr. 258). Denne artikel, dens grafik og interaktive værktøjer er baseret på offentlig tilgængelige kilder: Energistyrelsen om …

I’ve created an online tool to help my customers get an overview of and apply the Security Evaluation Methodology in EN IEC 62443-4-2:2019/A11:2026©. I aim to get as close as possible to the actual (to come) EN IEC 62443-4-2:2019/A11:2026© standard. …

What does it, seen from an EN IEC 62443-4-1:2018/A11:2026 auditor’s point of view, take to cross the finishing line? You know it from product and project management: Start with the end, and have that understanding guide your work in the …

This article takes a closer look at the forthcoming (not yet cited in OJEU) EN IEC 62443-4-1:2018/A11:2026© harmonized standard. The primary objective of the A11 amendment is to align the standard’s requirements and associated clauses with the CRA essential cybersecurity requirements. DISCLAIMER: …

This article explores the vertical standard ETSI EN 304 633© for internet-connected toys and the CRA presumption of conformity. While currently in its draft stages, it serves as the definitive roadmap for manufacturers to ensure their playthings aren’t just fun, …

We’ll take a closer look at the technical and structural changes introduced in the coming EN IEC 62443-4-2/A11©. The A11 amendment represents the transition of the IEC 62443 series, a technical best-practice standard, to a harmonized standard (hEN) designed for legal …

This article explores the CRA standards sandwich and specifically where EN IEC 62443/A11 fits. The citation of EN IEC 62443/A11 in the OJEU is currently anticipated for late 2026 or early 2027. The CRA standards sandwich The CRA uses the …

We’re taking a sneak-peek under the hood of the coming EN 40000-1-x family of harmonized horizontal standards using a hypothetical smart-home thermostat product. DISCLAIMER: The EN 40000-1-x series has not yet been cited on OJEU. This article is based on …

Understand how the horizontal standards (EN 40000‑1‑x family) relate to the presumption of conformity under the CRA Regulation (EU) 2024/2847, what the pathway looks like, and what to do while harmonized standards are still being finalized. Note: The relevance for …

This is the first in a series of articles on the Cyber Resilience Act (CRA). The rationale behind CRA The Cyber Resilience Act addresses the Union’s urgent need to strengthen cybersecurity as connected devices proliferate and cyberattacks increasingly affect the …

Each of the core ingredients for a successful product organization is a deep rabbit hole in its own right. This article intentionally keeps it short and does not explore the rabbit holes in detail.  For more ingredients, visit, e.g., my …

My earlier article on product delivery recommended the core strategy of implementing Continuous Delivery as described by Dave Farley. To recap, Continuous Delivery rests on three legs, all equally important for success. This article will take a closer look at …

This is the fourth in the series of articles on the product operating model. To recap, it has three dimensions. The right problems to solve The right solutions to the problems Solutions delivered the right way This article will examine …

This is the third in the series of articles on the product operating model. To recap, it has three dimensions. The right problems to solve The right solutions to the problems Solutions delivered the right way The previous article was …

This is the second in a series of articles on the product operating model. To recap, it has three dimensions. The right problems to solve The right solutions to the problems Solutions delivered the right way This and the next …

This is the first in a series of articles on the product operating model. It’ll be a mix of my practical experience and various inspirational sources. In one of my earlier articles, I outlined what it takes to achieve fast-paced …

Product Innovation

I’ve addressed the Product Innovation topic numerous times in the BLOG, and much of the referenced literature concerns Product Innovation. Having worked with various organizations, and joined various network discussions, my aim is here to share my (subjective) understanding of where we in …

Have we gotten to the point where everything – including Modern Leadership – is getting the “Agile” label?  This is what this post is about. From early on, I’ve been a strong advocate for doing software development the Agile way …

Before discussing what makes a process good, bad, or directly ugly, let’s start with the basics. An often used way to describe a process in e.g., Lean Six Sigma or ISO 9001:2015, is SIPOC dating back to Total Quality Management …

What would happen if we ask the teams, what they need to be successful?  It can hardly have missed your attention that it has become a “management thing” how teams are supposed to work. Just look e.g., at the “Agile …

The fact that nothing beats a good start, is not a new insight.  Neither is the importance of a good plan. Executive summary You do in fact have some kind of a crystal ball. A bad start will most likely …

WHAT? Look around and you’ll find problems everywhere! Well – no. What you experience are often symptoms originating from some underlying problem. In our high-paced society, we’re constantly tempted to do something fast on the symptom, just to realize the …

I’m a bit puzzled why in 2022 people still contrast Management with Leadership. It makes no sense. First of all – a Manager is a job (functional manager, product manager, project manager ..). Being a Leader is not a job …

Quotes from Marty Cagan on a visit to ProductTank in Oslo during a talk about pitfalls during the transformation towards a product-led organization: Marty Cagan describes this as the “European Process Disease“. You’re most likely already familiar with the process-quotes …

I believe that most modern Product Leaders will agree that leading with business problems within a context is the way forward. Or rephrased – ask empowered Product Teams to find solutions to business problems – do not tell them what …

You may have wondered – what is the secret sauce enabling e.g., Amazon to grow exponentially, yet keep the start-up mentality with strong customer focus and fast-paced innovation? Some of the important ingredients in the sauce are found in what …

In the “Old Days” the rate of change was not at todays extreme level. The predominant way of thinking and organizing work had clear traces back to Max Weber, Frederic Tailor and Henry Fayol. In our “Modern Times” we cannot …

In the “old days”, Project Management and Product Management were two separate and often fully disconnected disciplines. Not anymore. The trend today, at least in product-led companies, is a merge of the best from both worlds into a new (and …

Product Discovery

Modern product-led organizations with a strong product culture will typically apply what has come to be known as dual-track Agile, each track with a specific purpose: All organizations, not restricted to the product-led ones, want to be effective and efficient. …

How do we come from our vision to delivery and Outcome? And why talk Outcome and not only Output? Melissa Perri has written a whole worthy-to-read book Escaping the Build Trap explaining exactly, why we need to focus on Outcome …

An organization is much like an orchestra: you need highly skilled individuals working together in an aligned and transparent way according to a common heartbeat. Focus will in this post primarily be on OKR and Product. Objectives and Key Results …

Generally speaking we’re as humans driven by a few intrinsic motivators The deep feeling of a (higher) purpose Being part of a team Providing results and making a difference Having a genuine influence on the decisions Doing real and value-adding …

We’ve all had that repeated feeling – tumbling-down a rabbit hole of complexity only to conclude that the GPS signal is lost.  We’re like Alice in Wonderland in the search of where to go. Alice encountered the Cheshire Cat, hoping that …

The balances and the forces of complexity are all around us: Invest vs consolidate Bureaucracy vs humanocracy Technology standardization vs freedom to chose Build vs buy Risks vs opportunities Centralization vs decentralization Dictate vs empowerment In-source vs out-source … With …

This is part two in the series of two posts, discussing the Technology perspective. Missed part one? Find it here. We’ll in this post discuss the Technology perspective in IT Projects. The technology perspective – a double-edged sward The technology perspective …

You might have noticed it: there is no “Project Manager” role in Scrum, nor in SAFe. Is that it then – end of Project Management? The aim for this post is to have a nuanced discussion on the fate of …

This is the first in a series of two posts discussing the nature of the IT Project.  We’ll in this post discuss the generally applicable characteristics of a modern IT Project seen from a Leadership perspective. This will be followed …

Finding the optimal balance between process prescription and flexibility, is what all organizations are aiming for in their quest for excellence. There is, however, no textbook-optimal balancing -point. What works best for you in your organizational context, will differ from  …

Are you “only” involved in purely digital / IT products, then you might want to skip this post … unless you want to appreciate the complexity being faced by people working with multidisciplinary products.  The modern high-tech product company needs …

Congratulations – you, as an external project management consultant, have been asked to run a project for your customer. Now what? How do you as fast as possible get a firm grip on the steering wheel? Are there some fairly …

If you’re in a company “only” developing purely digital products, lucky you. You do not have to manage the added complexity in developing and producing multidisciplinary / mechatronics products. Should you not be so “lucky” and happen to be with …

The ambition with this post is to provide a, hopefully, quick and easy to grasp understanding of What ISO 9001:2015 and its purpose is Where ISO 9001:2015 makes sense The structural overview of ISO 9001:2015 ISO 9001:2015 and its purpose …

Here in part 3 we’ll discuss Renewable Tech [RT]’s strategy for how to bring live to its vision. Recap from part 2 Part 2 outlined RT’s vision to become a strong Product company thus making a radical shift in the …

This is part 2 in the series of posts discussing the journey towards becoming a strong Product company. Here we’ll focus on the Vision as formulated by RT’s executive team. Recap from part 1 In part 1 the strategic context of …

This post is the first in a series of posts discussing the hypothetical company, Renewable Tech [RT]’s journey towards the vision of becoming a strong and undisputed market-leading Product company within renewables technology, from primarily being a provider of customer-specific …

If you are new to AI and Data Science and need quickly to get your head wrapped around the basic terms, this post is for you. Are you already experienced in the field, you might want not to spend your …

Two craftsmen are working on a cathedral, each having their own toolbox. During the coffee break they have a heated debate on which toolbox is best. Why not discuss the bigger issue – the cathedral? Because the toolbox is easy …

I’ve made a quick (non-scientific) survey of Danish blog-posts related to Agile and job-postings from high-tech companies HQ’ed in Denmark, searching for Output vs Outcome. Focus is still predominantly on Project and Agile teams providing efficient and continuous delivery of …

We all know it: selecting the right tool for the right problem renders the best quality with the shortest time and least cost spent. Of course you need also to have the competence and experience using that given tool. In …

The aim with this post is through a scenario to illustrate the gap between the majority and the best when it comes to innovation of high-tech Products. Setting the scene Team Beetle and Team Mc Laren are both Product companies …

Most people with an “agile mindset” will agree that we’re here to serve the customer in the Product company. By customer we here mean the real customer, purchasing and using the Products we’ve developed. Sounds obvious – what else? In …

What is business agility? Try google the definitions of  “Agile”, “agile” and “agility” and get confused. In this post we’ll use the simple definition: The nature of “business agility” is highly dependent on the specific business context. In this post …