Fill in your company profile β€” RegQ checks it against 92 global regulations
RegQ by RiskQ
πŸ”‘ Have a RiskQ access key? Enter it to turn on Auto-Lookup β€” or fill in the profile manually below. Stored only in this browser tab. Want a guided demo? ariel@risk-q.com
Company Profile
πŸ“Š Financial & Scale
Total annual gross revenue
Total headcount β€” drives EU NIS2 / CIRCIA size thresholds
Total individuals whose data you process
🏭 Industry
πŸ—Ί US Jurisdiction
🌍 International Markets
⚠️ Vendor / Investor / Employment Ties
Vendors, cloud/data processors, investors, or employers tied to these countries β€” NOT customer/market countries (use International Markets above for that). Drives the DOJ Bulk Sensitive Data Rule.
πŸ—„ Data Types Processed
πŸ€– AI System Involvement
Drives EU AI Act scoping. Leave blank if the company does not build or deploy AI systems.
πŸ“ž Marketing Channels
Drives TCPA scoping. Leave blank if the company does not call or text consumers for marketing purposes.
βš–οΈ

Fill in your company profile and click Analyze
Have an access key? Auto-Lookup fills revenue, industry & geography for you.

RegQ identifies the regulations likely in scope and the thresholds that trigger them. Decision support, not legal advice.

🧭 Framework Alignment Voluntary β€” Not a Legal Requirement

These are widely-adopted security frameworks and attestation standards, not government regulations. Unlike the sections above, nothing here is legally required based on your company profile β€” organizations adopt them voluntarily, or because a customer, partner, or contract asks for them. RiskQ does not evaluate whether these apply to you; this section is reference information only.

NIST CSF 2.0
NIST Cybersecurity Framework

A voluntary risk-management framework published by NIST. Widely used as a common baseline across industries and often referenced by other laws (e.g., Ohio's data-breach safe harbor) as an accepted standard to point to.

Typically adopted by: organizations building a security program from scratch, or seeking Ohio-style safe-harbor protection.
ISO/IEC 27001:2022
Information Security Management Systems

An international standard for building and running an information security management system (ISMS). Can be independently certified by an accredited auditor.

Typically requested by: enterprise customers and partners during vendor security reviews, especially outside the US.
SOC 2 (Type II)
AICPA Service Organization Control Report

An attestation report β€” not a certification β€” covering security, availability, and confidentiality controls over an observation period, issued by a licensed CPA firm.

Typically requested by: B2B SaaS customers during procurement, particularly in the US market.
NIST SP 800-171
Protecting CUI in Non-Federal Systems

A NIST publication defining controls for protecting Controlled Unclassified Information. Becomes a contractual requirement (not a standalone law) for DoD suppliers via DFARS clauses and CMMC certification.

Typically required via contract for: defense contractors and subcontractors handling CUI β€” see the CMMC card above for the related legal/contractual trigger.
🎯 Named-Entity Regulations Binding β€” Applies Only to Designated Companies

These are real, legally binding regulations β€” not voluntary like the Framework Alignment section above β€” but they apply to a specific, named, small list of companies designated by a regulator, not to companies generally based on revenue, industry, or data volume. RiskQ does not score these against your company profile; check the named list directly.

EU DMA
Digital Markets Act (Regulation (EU) 2022/1925)

Applies only to companies the European Commission has formally designated as β€œgatekeepers” for specific β€œcore platform services.” As of 2026 the designated gatekeepers are Alphabet (Google), Amazon, Apple, ByteDance (TikTok), Meta, Microsoft, and Booking.com. Penalties reach up to 10% of global annual turnover (20% for repeat non-compliance), with daily fines up to 5% of average daily worldwide turnover for ongoing non-compliance. The Commission is escalating DMA/DSA enforcement in 2026, with potential fines against the named gatekeepers estimated to exceed €100 billion collectively.

Applies to: only the Commission-designated gatekeepers named above. If your company is not on that list, the DMA does not apply to you β€” no revenue or user-count threshold puts a company in scope on its own.