Skip to main content
PLATFORM · OBLIGATION INTELLIGENCE

Determine what applies to you. Continuously, not once a year.

Determining which obligations actually apply — by country, sector, entity type, size, revenue/headcount, and criticality — is manual, legally nuanced, and constantly shifting. NIS2 alone has twenty-seven national transpositions, and they do not transpose the thresholds identically.

TruSecure's Applicability Engine resolves that determination continuously and flags changes as regulations or transpositions evolve — not on an annual review cycle. Getting the answer wrong in either direction is expensive: miss an obligation and you carry regulatory exposure; over-scope and you fund a compliance program you never owed.

How it works

  1. Profile

    Your entity data goes in once: countries of operation, sectors, entity types, headcount and revenue bands, criticality of services.

  2. Determine

    The engine resolves which regimes apply — including which national NIS2 transposition governs each entity, not just the EU baseline.

  3. Monitor

    Transpositions evolve, thresholds move, your own profile changes. The determination is re-evaluated as inputs change, not once a year.

  4. Flag

    A change surfaces as a reviewable proposal — "this entity now appears in scope of X" — and a named person confirms or rejects it. The engine proposes; counsel and management decide.

What a determination looks like

Each applicability call shows its working — the inputs checked, the values found, the verdict per criterion. An illustrative determination:

Applicability engine
Country
Romania
CHECKED
Sector (Annex I/II)
Digital Infrastructure
IN SCOPE
Size threshold
250+ employees
EXCEEDED
Entity type
Essential Entity
CLASSIFIED

Which regulations it maps to

What applicability hinges on · by regime
RegimeThe applicability question
NIS2Sector annex plus size threshold — resolved per member-state transposition, all twenty-seven
DORAWhether the entity is a financial entity type the regulation enumerates
GDPRProcessing activities, not headcount — most organizations are already in scope
EU AI ActYour role (provider, deployer) and the risk class of the systems you operate
ISO 27001 / SOC 2Voluntary or contractual — tracked because customers and auditors demand them

Where the inputs come from

Headcount and org structure flow from HR systems; service criticality and ownership from your CMDB and asset inventory; entity and jurisdiction data from onboarding. The profile stays current because it is connected, not re-surveyed.

See all integrations

The monitoring loop

continuous · every 6 hours
  1. 01

    Connect

    Read-only connectors into AWS, Azure, GCP, on-premise.

    AWSAzureGCPon-prem
  2. 02

    Collect

    AI pulls compliance evidence every 6 hours — not at audit time.

    every 6 h
  3. 03

    Detect

    Gaps and control drift flagged the moment they appear.

    24/7
  4. 04

    Remediate

    Routine fixes closed automatically; the rest routed to you.

    auto
  5. 05

    Approve

    A named person decides. The approval is the record.

    logged
90% less manual evidence work100% audit-ready, every day

The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.