Why now

Compliance stopped being a certificate.
It became market access.

For companies selling into the US and the European Union — tech or not — the question is no longer whether you'll be asked to prove your digital estate is healthy. It's whether you can, before the deal, the deadline, or the auditor arrives.

Three parties now grade your digital estate.

None of them asks whether you're a technology company. All three ask whether you can prove it — and the same evidence answers all three at once.

Tier 1 · Required by law

The regulator

GDPR, the EU AI Act, NIS2, DORA, the CRA; SEC cyber disclosure, the FTC Act, 20 US state privacy laws, HIPAA, SOX, CMMC. You don't choose these. Your market chooses them for you — and several now carry extraterritorial reach, so a US-only company is not out of range.

Tier 2 · Required to sell

Your customers

SOC 2, ISO 27001, DPAs, questionnaires, audit rights. No statute — but a missing report ends the procurement conversation. In 2026 the evidence bar rejects screenshots and expects continuous-monitoring exports with timestamps.

Tier 3 · Elective

Your choice

Maturity and differentiation frameworks you adopt to stand out. Deliberately the smallest tier — the contrast is what makes the first two land.

What applies to a company like yours?

Tick the facts that describe you. The count comes from the same resolver the product runs on your estate — required by law, required to sell, or elective — with the triggering statute named on every row. Nothing is asserted as law until a fact you supply actually triggers it.

Describe your company

Nothing ticked yet. Tick the facts that describe you — the count below is computed by the same engine the product runs, not a marketing claim.

Elective · 12

CIS Controls

CIS Controls are a voluntary prioritized hardening baseline

Cyber Essentials

Cyber Essentials is elective outside UK contract requirements

HITRUST CSF

HITRUST is elective outside healthcare-partner procurement

ISO/IEC 27001

ISO/IEC 27001 is elective until enterprise procurement asks for it

ISO/IEC 42001

ISO/IEC 42001 is an elective AI-management-system standard

NIST 800-171

NIST 800-171 is elective outside federal-contract CUI obligations

NIST 800-53

NIST 800-53 is elective outside federal authorization boundaries

NIST AI RMF

NIST AI RMF is a voluntary AI risk-management framework

NIST CSF

NIST CSF is a voluntary cybersecurity framework (a common baseline reference)

SOC 1

SOC 1 is elective unless customers' financial-reporting auditors ask for it

SOC 2

SOC 2 is elective until enterprise procurement asks for it

SOX ITGC

SOX ITGC is elective until an IPO/public-company path makes it required

Computed live by the product's own resolver. Tiering is a prioritization aid, not legal advice — every basis is shown so your counsel can check it.Map it to your estate →

The clock is already running.

Every date here was verified in late August 2026. As one deadline passes, the next anchors the page.

2026-09-11
CRA 24-hour early warning. Manufacturers of products with digital elements made available in the EU — non-EU companies and free commercial software included — must file a 24-hour early warning of an actively-exploited vulnerability, a 72-hour notification, and a final report within 14 days of a fix, even for products already on the market. (Standalone browser-only SaaS is generally out of CRA scope; it faces NIS2 instead. The ENISA reporting platform is scheduled to be operational by this date.)
A capability deadline disguised as a reporting deadline. You cannot warn in 24 hours about what you aren't continuously watching — which is exactly what ShipReady does with CISA-KEV tracking.
Live now
NIS2. Binding across most of the EU; first national fines imposed; management personally liable. Its 18 sectors include manufacturing, food, logistics and health — non-tech is directly in scope.
The EU has moved from writing rules to collecting fines.
Live now
DORA — the EU Digital Operational Resilience Act (Reg. 2022/2554), the law enforced by the ESAs, distinct from the DevOps DORA metrics ShipReady also measures. Applying since Jan 2025; the first critical ICT providers are under direct EU oversight.
Every ICT vendor to an EU financial entity is inside the perimeter via Art. 30 contract clauses.
2026-08-02
EU AI Act transparency duties and GPAI enforcement went live. High-risk obligations were resequenced by the July 2026 Digital Omnibus to 2027-12-02 (Annex III) and 2028-08-02 (Annex I) — sequenced, not withdrawn.
Stating this precisely is itself the proof: most competitor copy still cites the dead August-2026 high-risk date.
Live now
US: prove what you said. SEC 4-business-day incident disclosure; the FTC now treats misrepresenting security as the deceptive act itself; CMMC self-attestation gates contract award with False Claims Act exposure; 20 state privacy laws in effect.
US exposure shifted from "weak security" to "unable to evidence the claim."

Fine ceilings and enforcement dates are the regulators' own; nothing here is invented. Not legal advice.

"Out of scope" is a category error.

Modern regulation rarely stops at the named company. Each regime carries a flow-down clause obliging the regulated party to push evidence-backed requirements onto its suppliers. The question is never "does the law name you?" — it's "does it name anyone you sell to?" That is how a non-tech, non-EU company inherits the same demands.

NIS2 Art. 21(2)(d)/(3)EU entities must assess and contractually bind every direct supplier.
DORA Art. 30Prescribed contract clauses for all ICT vendors to EU finance: audit rights, incident assistance, exit plans.
GDPR Art. 28(4)The data-processing chain: identical obligations at every sub-processor tier, liability flowing upward.
HIPAA §164.308(b)The business-associate chain runs no matter how far down the information flows.
DFARS 252.204-7021CMMC flows to every subcontractor touching controlled information, verified before award.
EU AI Act Art. 25(4)Mandatory written cooperation down the AI value chain; rebrand or fine-tune and you become the provider.

The enforcer you meet first is procurement, not a regulator — and its remedy is losing the renewal, with no appeal.

What "not ready" costs.

No invented figures — only the mechanisms and the regulators' own ceilings: stalled security reviews and deals lost to the vendor who already has the report; audit fire drills; insurance repriced or denied when controls can't be evidenced; and, at Tier 1, fines up to €10M / 2% of turnover under NIS2 with personal management liability. The pattern underneath all of them is the gap between what you say and what you can evidence — on clocks as short as 24 hours.

Turn "trust us" into "audit us."

ShipReady collects the evidence continuously and scores it honestly — one ShipReady Score, nine health scores, and a prioritized agenda your board, your insurer, and an acquirer's diligence team can all interrogate. The output isn't a compliance report. It's the proof that survives the question.