# Notes from the engagement, not the sales deck

Long-form notes on what useful offensive security work actually looks like — methodology, scoping discipline, reporting craft, and the market practices we think need calling out. Written for CISOs, Heads of Security, CTOs, and the engineers and platform teams behind them.

-

## [Morocco's CNDP and Law 09-08: a practical compliance guide for companies](/content/blog/cndp-declaration-guide-morocco/index.html)

CNDP declaration or prior authorization, processing inventory, security evidence and cross-border transfers — Law 09-08 explained for companies in Morocco.

-

## [Morocco's DGSSI, Law 05-20 and the DNSSI: what organizations actually have to do](/content/blog/dgssi-law-05-20-guide/index.html)

Morocco's DGSSI, Law 05-20, the DNSSI directive and decree 2-21-406: who is in scope, what is required, and where to start for organizations in Morocco.

-

## [Penetration testing buyer guide — what a useful pen test actually produces](/content/blog/pen-test-buyer-guide/index.html)

Penetration testing buyer guide for CISOs and CTOs: the RFP questions to ask a provider, what a good report contains, and how to scope honestly.
