Framework finder
Answer three questions to see which compliance laws, customer requirements and voluntary frameworks are likely to apply to you.
13 frameworks to look at
Law or regulation 6
Applies when the stated condition is met. Confirm scope with counsel.
- DPDP Act, 2023 and DPDP Rules, 2025
Applies to processing digital personal data in India, and to processing outside India connected with offering goods or services to people in India. Core obligations apply from 13 May 2027.
DPDP Act on QULDEXRead our coverage - CERT-In Directions (2022)
Service providers, intermediaries, data centres, body corporates and government organisations in India must report specified cyber incidents within 6 hours and keep ICT logs for 180 days.
Read our coverage - GDPR
Applies if you are established in the EU, or offer goods or services to, or monitor, people in the EU.
GDPR on QULDEXRead our coverage - NIS2 Directive
If you operate in a covered sector (for example digital infrastructure, ICT service management, health or manufacturing of critical products) and are medium-sized or larger, or are designated by a member state.
Read our coverage - EU Cyber Resilience Act
If you place software or connected hardware on the EU market. Reporting of exploited vulnerabilities applies since 11 September 2026; full rules from 11 December 2027. Pure SaaS is generally out of scope.
Read our coverage - EU AI Act
If you place AI systems on the EU market or use them in the EU. Transparency duties apply now; high-risk obligations from 2 December 2027.
Read our coverage
Contracts and customer expectations 3
Not law, but often a condition of doing business.
- DORA requirements passed on by financial customers
EU financial entities must put DORA terms into contracts with ICT providers, so SaaS vendors serving them inherit audit, incident and exit obligations.
Read our coverage - SOC 2 Type 2
US enterprise buyers commonly ask SaaS and service providers for a SOC 2 Type 2 report during procurement.
SOC 2 on QULDEXRead our coverage - ISO/IEC 27001
The most widely requested security certification worldwide, especially by customers outside the US.
ISO 27001 on QULDEXRead our coverage
Voluntary frameworks that help 4
Give your programme structure and make the others easier to evidence.
- ISO/IEC 42001
A certifiable AI management system: a recognised way to structure AI governance and impact assessment.
ISO 42001 on QULDEXRead our coverage - ISO/IEC 27701
Privacy management extension to ISO 27001; helps evidence accountability under GDPR, DPDP and similar laws.
ISO 27701 on QULDEXRead our coverage - ISO/IEC 27017 and 27018
Cloud security and cloud PII-protection extensions to ISO 27001, often requested of SaaS providers.
ISO 27017 on QULDEXRead our coverage - CIS Controls v8.1
Prioritised technical safeguards; a practical starting point for smaller teams.
CIS Controls on QULDEXRead our coverage
Several of these overlap. QULDEX maps controls once and reuses evidence across them.
Get a readiness assessmentBaseline laws by region
Laws that apply in each region regardless of industry. Sector rules such as DORA, HIPAA or SEBI CSCRF are added by the finder above.
| Region | Laws |
|---|---|
| India | DPDP Act, 2023 and DPDP Rules, 2025; CERT-In Directions (2022) |
| European Union | GDPR |
| United Kingdom | UK GDPR and Data Protection Act 2018 |
| United States | CCPA / CPRA |
| UAE | UAE Personal Data Protection Law |
| Saudi Arabia | Saudi Personal Data Protection Law |
| Singapore | Singapore PDPA |
| Australia | Australian Privacy Act 1988 |
| South Africa | POPIA |
| Nigeria | Nigeria Data Protection Act, 2023 |