Fill in your company profile and click Analyze
Have an access key? Auto-Lookup fills revenue, industry & geography for you.
RegQ identifies the regulations likely in scope and the thresholds that trigger them. Decision support, not legal advice.
These are widely-adopted security frameworks and attestation standards, not government regulations. Unlike the sections above, nothing here is legally required based on your company profile β organizations adopt them voluntarily, or because a customer, partner, or contract asks for them. RiskQ does not evaluate whether these apply to you; this section is reference information only.
A voluntary risk-management framework published by NIST. Widely used as a common baseline across industries and often referenced by other laws (e.g., Ohio's data-breach safe harbor) as an accepted standard to point to.
An international standard for building and running an information security management system (ISMS). Can be independently certified by an accredited auditor.
An attestation report β not a certification β covering security, availability, and confidentiality controls over an observation period, issued by a licensed CPA firm.
A NIST publication defining controls for protecting Controlled Unclassified Information. Becomes a contractual requirement (not a standalone law) for DoD suppliers via DFARS clauses and CMMC certification.
These are real, legally binding regulations β not voluntary like the Framework Alignment section above β but they apply to a specific, named, small list of companies designated by a regulator, not to companies generally based on revenue, industry, or data volume. RiskQ does not score these against your company profile; check the named list directly.
Applies only to companies the European Commission has formally designated as βgatekeepersβ for specific βcore platform services.β As of 2026 the designated gatekeepers are Alphabet (Google), Amazon, Apple, ByteDance (TikTok), Meta, Microsoft, and Booking.com. Penalties reach up to 10% of global annual turnover (20% for repeat non-compliance), with daily fines up to 5% of average daily worldwide turnover for ongoing non-compliance. The Commission is escalating DMA/DSA enforcement in 2026, with potential fines against the named gatekeepers estimated to exceed β¬100 billion collectively.