Skip to main content
PLATFORM · OBLIGATION INTELLIGENCE

Determine what applies to you. Continuously, not once a year.

Determining which obligations actually apply — by country, sector, entity type, size, revenue/headcount, and criticality — is manual, legally nuanced, and constantly shifting. NIS2 alone has twenty-seven national transpositions, and they do not transpose the thresholds identically.

TruSecure's applicability engine resolves that determination continuously and flags changes as regulations or transpositions evolve — not on an annual review cycle. Getting the answer wrong in either direction is expensive: miss an obligation and you carry regulatory exposure; over-scope and you fund a compliance programme you never owed.

How it works

  1. Profile

    Your entity data goes in once: countries of operation, sectors, entity types, headcount and revenue bands, criticality of services.

  2. Determine

    The engine resolves which regimes apply — including which national NIS2 transposition governs each entity, not just the EU baseline.

  3. Monitor

    Transpositions evolve, thresholds move, your own profile changes. The determination is re-evaluated as inputs change, not once a year.

  4. Flag

    A change surfaces as a reviewable proposal — "this entity now appears in scope of X" — and a named person confirms or rejects it. The engine proposes; counsel and management decide.

What a determination looks like

Each applicability call shows its working — the inputs checked, the values found, the verdict per criterion. An illustrative determination:

Applicability engine
Country
Romania
CHECKED
Sector (Annex I/II)
Digital Infrastructure
IN SCOPE
Size threshold
250+ employees
EXCEEDED
Entity type
Essential Entity
CLASSIFIED

Which regulations it maps to

What applicability hinges on · by regime
RegimeThe applicability question
NIS2Sector annex plus size threshold — resolved per member-state transposition, all twenty-seven
DORAWhether the entity is a financial entity type the regulation enumerates
GDPRProcessing activities, not headcount — most organizations are already in scope
EU AI ActYour role (provider, deployer) and the risk class of the systems you operate
ISO 27001 / SOC 2Voluntary or contractual — tracked because customers and auditors demand them

Where the inputs come from

Headcount and org structure flow from HR systems; service criticality and ownership from your CMDB and asset inventory; entity and jurisdiction data from onboarding. The profile stays current because it is connected, not re-surveyed.

See all integrations

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.