Skip to main content
PLATFORM · OBLIGATION INTELLIGENCE

Determine what applies to you. Continuously, not once a year.

Determining which obligations actually apply — by country, sector, entity type, size, revenue/headcount, and criticality — is manual, legally nuanced, and constantly shifting. NIS2 alone has twenty-seven national transpositions, and they do not transpose the thresholds identically.

TruSecure's Applicability Engine resolves that determination continuously and flags changes as regulations or transpositions evolve — not on an annual review cycle. Getting the answer wrong in either direction is expensive: miss an obligation and you carry regulatory exposure; over-scope and you fund a compliance program you never owed.

How it works

  1. Profile

    Your entity data goes in once: countries of operation, sectors, entity types, headcount and revenue bands, criticality of services.

  2. Determine

    The engine resolves which regimes apply — including which national NIS2 transposition governs each entity, not just the EU baseline.

  3. Monitor

    Transpositions evolve, thresholds move, your own profile changes. The determination is re-evaluated as inputs change, not once a year.

  4. Flag

    A change surfaces as a reviewable proposal — "this entity now appears in scope of X" — and a named person confirms or rejects it. The engine proposes; counsel and management decide.

What a determination looks like

Each applicability call shows its working — the inputs checked, the values found, the verdict per criterion. An illustrative determination:

Applicability engine
Country
Romania
CHECKED
Sector (Annex I/II)
Digital Infrastructure
IN SCOPE
Size threshold
250+ employees
EXCEEDED
Entity type
Essential Entity
CLASSIFIED

Which regulations it maps to

What applicability hinges on · by regime
RegimeThe applicability question
NIS2Sector annex plus size threshold — resolved per member-state transposition, all twenty-seven
DORAWhether the entity is a financial entity type the regulation enumerates
GDPRProcessing activities, not headcount — most organizations are already in scope
EU AI ActYour role (provider, deployer) and the risk class of the systems you operate
ISO 27001 / SOC 2Voluntary or contractual — tracked because customers and auditors demand them

Where the inputs come from

Headcount and org structure flow from HR systems; service criticality and ownership from your CMDB and asset inventory; entity and jurisdiction data from onboarding. The profile stays current because it is connected, not re-surveyed.

See all integrations

The monitoring loop

continuous · every 6 hours
  1. 01

    Connect

    Read-only connectors into AWS, Azure, GCP, on-premise.

    AWSAzureGCPon-prem
  2. 02

    Collect

    AI pulls compliance evidence every 6 hours — not at audit time.

    every 6 h
  3. 03

    Detect

    Gaps and control drift flagged the moment they appear.

    24/7
  4. 04

    Remediate

    Routine fixes closed automatically; the rest routed to you.

    auto
  5. 05

    Approve

    A named person decides. The approval is the record.

    logged
90% less manual evidence work100% audit-ready, every day

The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

Frequently Asked Questions

How do I know which regulations apply to my organization?
The applicability engine determines which regulations apply by country, sector, entity type, size and criticality — and keeps that determination current continuously, not on an annual review cycle.
Does applicability change over time?
Yes — headcount crosses thresholds, entities expand into new member states, sectors change. The engine re-evaluates applicability as your organization and the law change, instead of freezing the answer at the last review.
Does it distinguish essential from important entities under NIS2?
Yes. Classification into essential or important is part of the applicability determination, per member state, because the supervisory regime differs between the two tiers.