Determine what applies to you. Continuously, not once a year.
Determining which obligations actually apply — by country, sector, entity type, size, revenue/headcount, and criticality — is manual, legally nuanced, and constantly shifting. NIS2 alone has twenty-seven national transpositions, and they do not transpose the thresholds identically.
TruSecure's Applicability Engine resolves that determination continuously and flags changes as regulations or transpositions evolve — not on an annual review cycle. Getting the answer wrong in either direction is expensive: miss an obligation and you carry regulatory exposure; over-scope and you fund a compliance program you never owed.
How it works
- Profile
Your entity data goes in once: countries of operation, sectors, entity types, headcount and revenue bands, criticality of services.
- Determine
The engine resolves which regimes apply — including which national NIS2 transposition governs each entity, not just the EU baseline.
- Monitor
Transpositions evolve, thresholds move, your own profile changes. The determination is re-evaluated as inputs change, not once a year.
- Flag
A change surfaces as a reviewable proposal — "this entity now appears in scope of X" — and a named person confirms or rejects it. The engine proposes; counsel and management decide.
What a determination looks like
Each applicability call shows its working — the inputs checked, the values found, the verdict per criterion. An illustrative determination:
Which regulations it maps to
| Regime | The applicability question |
|---|---|
| NIS2 | Sector annex plus size threshold — resolved per member-state transposition, all twenty-seven |
| DORA | Whether the entity is a financial entity type the regulation enumerates |
| GDPR | Processing activities, not headcount — most organizations are already in scope |
| EU AI Act | Your role (provider, deployer) and the risk class of the systems you operate |
| ISO 27001 / SOC 2 | Voluntary or contractual — tracked because customers and auditors demand them |
Where the inputs come from
Headcount and org structure flow from HR systems; service criticality and ownership from your CMDB and asset inventory; entity and jurisdiction data from onboarding. The profile stays current because it is connected, not re-surveyed.
The monitoring loop
continuous · every 6 hours- 01
01
Connect
Read-only connectors into AWS, Azure, GCP, on-premise.
AWSAzureGCPon-prem - 02
02
Collect
AI pulls compliance evidence every 6 hours — not at audit time.
every 6 h - 03
03
Detect
Gaps and control drift flagged the moment they appear.
24/7 - 04
04
Remediate
Routine fixes closed automatically; the rest routed to you.
auto - 05
05
Approve
A named person decides. The approval is the record.
logged
The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.