Determine what applies to you. Continuously, not once a year.
Determining which obligations actually apply — by country, sector, entity type, size, revenue/headcount, and criticality — is manual, legally nuanced, and constantly shifting. NIS2 alone has twenty-seven national transpositions, and they do not transpose the thresholds identically.
TruSecure's applicability engine resolves that determination continuously and flags changes as regulations or transpositions evolve — not on an annual review cycle. Getting the answer wrong in either direction is expensive: miss an obligation and you carry regulatory exposure; over-scope and you fund a compliance programme you never owed.
How it works
- Profile
Your entity data goes in once: countries of operation, sectors, entity types, headcount and revenue bands, criticality of services.
- Determine
The engine resolves which regimes apply — including which national NIS2 transposition governs each entity, not just the EU baseline.
- Monitor
Transpositions evolve, thresholds move, your own profile changes. The determination is re-evaluated as inputs change, not once a year.
- Flag
A change surfaces as a reviewable proposal — "this entity now appears in scope of X" — and a named person confirms or rejects it. The engine proposes; counsel and management decide.
What a determination looks like
Each applicability call shows its working — the inputs checked, the values found, the verdict per criterion. An illustrative determination:
Which regulations it maps to
| Regime | The applicability question |
|---|---|
| NIS2 | Sector annex plus size threshold — resolved per member-state transposition, all twenty-seven |
| DORA | Whether the entity is a financial entity type the regulation enumerates |
| GDPR | Processing activities, not headcount — most organizations are already in scope |
| EU AI Act | Your role (provider, deployer) and the risk class of the systems you operate |
| ISO 27001 / SOC 2 | Voluntary or contractual — tracked because customers and auditors demand them |
Where the inputs come from
Headcount and org structure flow from HR systems; service criticality and ownership from your CMDB and asset inventory; entity and jurisdiction data from onboarding. The profile stays current because it is connected, not re-surveyed.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.