New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content

Reference

The compliance legislation library

Every framework we cover, explained in plain language and linked to the official source. Browse the articles and obligations behind the requirements.

EU AI Act

27 articles

Regulation (EU) 2024/1689 on artificial intelligence

The EU Artificial Intelligence Act is the world's first comprehensive AI law. It classifies AI systems by risk and sets obligations for providers and deployers of high-risk systems, from risk management and data governance to human oversight, transparency, and post-market monitoring.

Browse EU AI Act →

GDPR

20 articles

Regulation (EU) 2016/679 on data protection

The General Data Protection Regulation governs how personal data of people in the EU is collected, processed, and protected. It sets out lawful bases, data subject rights, breach notification duties, and the accountability obligations organisations must be able to demonstrate.

Browse GDPR →

UK GDPR

19 articles

UK data protection after Brexit

The UK GDPR is the United Kingdom's version of the GDPR, retained in domestic law alongside the Data Protection Act 2018. It mirrors the EU regime closely while being enforced by the ICO under UK jurisdiction.

Browse UK GDPR →

CCPA

14 sections

California Consumer Privacy Act (as amended by the CPRA)

The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights over the personal information businesses collect about them, including the right to know, delete, correct, and opt out of sale or sharing.

Browse CCPA →

ISO 42001

51 clauses

ISO/IEC 42001 AI management system

ISO/IEC 42001 is the international standard for an Artificial Intelligence Management System (AIMS). It provides a certifiable framework for governing AI responsibly across its lifecycle, covering leadership, planning, controls, and continual improvement.

Browse ISO 42001 →

NIST AI RMF

72 subcategorys

NIST AI Risk Management Framework

The NIST AI Risk Management Framework is a voluntary US framework for managing risks from AI systems. It is organised around four functions, Govern, Map, Measure, and Manage, to help organisations build trustworthy and responsible AI.

Browse NIST AI RMF →

DORA

13 articles

Digital Operational Resilience Act

The Digital Operational Resilience Act sets uniform requirements for the security of network and information systems across EU financial entities and their critical ICT third-party providers, covering ICT risk management, incident reporting, resilience testing, and supplier oversight.

Browse DORA →

NIS2

5 articles

Directive (EU) 2022/2555 on cybersecurity

The NIS2 Directive strengthens cybersecurity across essential and important entities in the EU. It raises risk-management, governance, and incident-reporting requirements and holds management bodies accountable for compliance.

Browse NIS2 →

ISO 27001

99 clauses

ISO/IEC 27001 information security management

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It defines requirements for establishing, maintaining, and continually improving information security, backed by the Annex A control set.

Browse ISO 27001 →

ISO 23894

5 clauses

ISO/IEC 23894 AI risk management guidance

ISO/IEC 23894 provides guidance on managing risk specific to AI, aligning the ISO 31000 risk management process with the particular challenges of developing and using artificial intelligence.

Browse ISO 23894 →

CRA

8 articles

Regulation (EU) 2024/2847 on cyber resilience

The Cyber Resilience Act sets essential cybersecurity requirements for products with digital elements sold in the EU, covering secure design and development, vulnerability handling (including a software bill of materials), technical documentation, and mandatory reporting of actively exploited vulnerabilities and severe incidents to ENISA.

Browse CRA →

SOC 2

43 criterions

AICPA Trust Services Criteria

SOC 2 is the AICPA's Trust Services Criteria framework used in service-organization audits. It covers the Common Criteria (security) and, where in scope, Availability, Confidentiality, and Processing Integrity, spanning control environment, access control, system operations, change management, and risk mitigation.

Browse SOC 2 →

EHDS

33 articles

Regulation (EU) 2025/327 on the European Health Data Space

The European Health Data Space regulates electronic health record (EHR) systems and the primary and secondary use of health data across the EU: patient access rights, EHR system interoperability and logging, and the conditions for secondary use in research, policymaking, and AI training. Applies from 26 March 2027, staggered through 2031 for specific provisions.

Browse EHDS →

HIPAA

22 sections

45 CFR Parts 160 and 164 - the HIPAA Security Rule

HIPAA's Security Rule sets Administrative, Physical, and Technical Safeguards for protecting electronic protected health information (ePHI) in the United States. Essential for European health-tech vendors selling into the U.S. healthcare market, alongside Business Associate Agreements with any covered entity or business associate whose ePHI they handle.

Browse HIPAA →

Reading the law is the easy part

eurocompliant turns these obligations into tracked tasks, evidence, and regulator-ready documents across every framework at once.

Start free trial