Why now
Compliance stopped being a certificate.
It became market access.
For companies selling into the US and the European Union — tech or not — the question is no longer whether you'll be asked to prove your digital estate is healthy. It's whether you can, before the deal, the deadline, or the auditor arrives.
Three parties now grade your digital estate.
None of them asks whether you're a technology company. All three ask whether you can prove it — and the same evidence answers all three at once.
Tier 1 · Required by law
The regulator
GDPR, the EU AI Act, NIS2, DORA, the CRA; SEC cyber disclosure, the FTC Act, 20 US state privacy laws, HIPAA, SOX, CMMC. You don't choose these. Your market chooses them for you — and several now carry extraterritorial reach, so a US-only company is not out of range.
Tier 2 · Required to sell
Your customers
SOC 2, ISO 27001, DPAs, questionnaires, audit rights. No statute — but a missing report ends the procurement conversation. In 2026 the evidence bar rejects screenshots and expects continuous-monitoring exports with timestamps.
Tier 3 · Elective
Your choice
Maturity and differentiation frameworks you adopt to stand out. Deliberately the smallest tier — the contrast is what makes the first two land.
What applies to a company like yours?
Tick the facts that describe you. The count comes from the same resolver the product runs on your estate — required by law, required to sell, or elective — with the triggering statute named on every row. Nothing is asserted as law until a fact you supply actually triggers it.
Describe your company
Nothing ticked yet. Tick the facts that describe you — the count below is computed by the same engine the product runs, not a marketing claim.
Elective · 12
CIS Controls
CIS Controls are a voluntary prioritized hardening baseline
Cyber Essentials
Cyber Essentials is elective outside UK contract requirements
HITRUST CSF
HITRUST is elective outside healthcare-partner procurement
ISO/IEC 27001
ISO/IEC 27001 is elective until enterprise procurement asks for it
ISO/IEC 42001
ISO/IEC 42001 is an elective AI-management-system standard
NIST 800-171
NIST 800-171 is elective outside federal-contract CUI obligations
NIST 800-53
NIST 800-53 is elective outside federal authorization boundaries
NIST AI RMF
NIST AI RMF is a voluntary AI risk-management framework
NIST CSF
NIST CSF is a voluntary cybersecurity framework (a common baseline reference)
SOC 1
SOC 1 is elective unless customers' financial-reporting auditors ask for it
SOC 2
SOC 2 is elective until enterprise procurement asks for it
SOX ITGC
SOX ITGC is elective until an IPO/public-company path makes it required
The clock is already running.
Every date here was verified in late August 2026. As one deadline passes, the next anchors the page.
Fine ceilings and enforcement dates are the regulators' own; nothing here is invented. Not legal advice.
"Out of scope" is a category error.
Modern regulation rarely stops at the named company. Each regime carries a flow-down clause obliging the regulated party to push evidence-backed requirements onto its suppliers. The question is never "does the law name you?" — it's "does it name anyone you sell to?" That is how a non-tech, non-EU company inherits the same demands.
The enforcer you meet first is procurement, not a regulator — and its remedy is losing the renewal, with no appeal.
What "not ready" costs.
No invented figures — only the mechanisms and the regulators' own ceilings: stalled security reviews and deals lost to the vendor who already has the report; audit fire drills; insurance repriced or denied when controls can't be evidenced; and, at Tier 1, fines up to €10M / 2% of turnover under NIS2 with personal management liability. The pattern underneath all of them is the gap between what you say and what you can evidence — on clocks as short as 24 hours.
Turn "trust us" into "audit us."
ShipReady collects the evidence continuously and scores it honestly — one ShipReady Score, nine health scores, and a prioritized agenda your board, your insurer, and an acquirer's diligence team can all interrogate. The output isn't a compliance report. It's the proof that survives the question.