Pick your regulatory framework below. Get a verified readiness score, your top control gaps with regulatory citations, and penalty exposure — including CMMC for DoD contractors and EU AI Act enforcement updates.
Select the regulatory framework your organization needs to comply with. Not sure? Start with the one that carries the highest penalties for your industry.
Applies to healthcare providers, health plans, clearinghouses, and their business associates. Governs protected health information (PHI) privacy, security, and breach notification.
Applies to SEC-registered public companies and their subsidiaries. Requires CEO/CFO certifications (Sec. 302), internal controls assessments (Sec. 404), and criminal certifications (Sec. 906).
Applies to virtually all US employers with workers. Covers workplace safety standards, injury/illness recordkeeping (OSHA 300), Hazard Communication, and industry-specific standards for construction, manufacturing, and healthcare.
Applies to any organization that processes personal data of EU residents — including US companies with EU customers, users, or employees. Covers consent, data subject rights, breach notification, and DPA requirements.
Applies to all merchants and service providers that store, process, or transmit cardholder data. PCI DSS 4.0 is now the required standard (March 2024). Non-compliance can result in card acceptance being revoked.
Applies to broker-dealers, investment advisers, public companies, and financial technology firms. Key rules include Regulation S-P cybersecurity (amended 2024), Reg BI, Form ADV, and cybersecurity incident disclosure (Form 8-K).
Applies to any company deploying AI systems to EU users — including US SaaS, HR platforms, fintech products, and healthcare AI. Classify your systems before August 2, 2026 enforcement or face fines up to €35M.
Applies to all DoD contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Level 2 requires NIST 800-171 compliance and C3PAO assessment by 2026 under DFARS 7012.
The US cybersecurity baseline. Six Functions (Govern/Identify/Protect/Detect/Respond/Recover), four Tiers (Partial→Adaptive), and Current-vs-Target Profiles. Adoption mandated by SEC Reg S-P (2024), OMB M-22-15 for federal agencies, CISA BOD 23-01 for FCEB, and EU NIS2 Article 21. Pairs with NIST SP 800-53 / 800-171 and CMMC 2.0.
Applies to any SaaS, healthcare-tech, or fintech service organization that handles customer data and must demonstrate controls to enterprise buyers. Five Trust Services Criteria (Security + Availability + Processing Integrity + Confidentiality + Privacy), nine Common Criteria (CC1-CC9), and a Type I point-in-time audit vs. a Type II 3–12 month operating-effectiveness audit. ComplianceStack's TSC gap analyzer delivers the CC1-CC9 readiness score + Type I/II recommendation instantly.
Applies to any Department of Defense prime contractor or subcontractor handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Three Maturity Levels (Level 1 FCI baseline + Level 2 CUI / NIST 800-171 Rev 2 + Level 3 DIB-priority / NIST SP 800-172), DFARS 252.204-7012 flow-down to every tier, SPRS scoring on the -203 to +110 scale, and the C3PAO / DIBCAO assessment ladder for Conditional vs Final designations. ComplianceStack's CMMC readiness analyzer delivers the Level-applicability score + SPRS submission readiness + DFARS 7012 flow-down completeness check instantly.
Applies to any provider or deployer placing an AI system on the EU market — including US SaaS, HR platforms, fintech products, and healthcare AI. Four risk tiers (Art. 5 Prohibited / Art. 6 + Annex III High-Risk / Art. 50 Limited-Risk / Minimal-Risk), Articles 9–15 high-risk obligations, Articles 51–55 GPAI obligations, Article 99 penalty tiers (€35M / €15M / €7.5M), Annex IV self-assessment or Annex VII Notified Body conformity path, and the August 2, 2026 transparency deadline + the December 2, 2027 deferred high-risk enforcement per the May 7, 2026 AI Omnibus.
Select your profile
Choose your industry, entity type, and key risk factors. Framework-specific questions — no generic checkbox lists.
Instant risk scoring
Our scoring engine calculates your readiness risk score (0–100) against a framework-specific control library. All computed in-browser — no data leaves your device.
Act on your results
Get prioritized control gaps, upcoming deadlines, and penalty exposure. Save your results to email, PDF, or your dashboard.
Turn your risk score into a complete audit report with verified citations, remediation roadmap, and audit-ready documentation. Starting at $49.
See Full Reports Starting at $49 →Want a week-by-week action plan instead of just the gap report?
🗺️ Get 90-Day Compliance Roadmap → $299