Framework finder

Answer three questions to see which compliance laws, customer requirements and voluntary frameworks are likely to apply to you.

General guidance, not legal adviceReviewed 29 Sept 2026

1Where do you operate or have customers?
2What is your industry?
3Which of these are true?

13 frameworks to look at

Law or regulation 6

Applies when the stated condition is met. Confirm scope with counsel.

  • DPDP Act, 2023 and DPDP Rules, 2025

    Applies to processing digital personal data in India, and to processing outside India connected with offering goods or services to people in India. Core obligations apply from 13 May 2027.

    DPDP Act on QULDEXRead our coverage
  • CERT-In Directions (2022)

    Service providers, intermediaries, data centres, body corporates and government organisations in India must report specified cyber incidents within 6 hours and keep ICT logs for 180 days.

    Read our coverage
  • GDPR

    Applies if you are established in the EU, or offer goods or services to, or monitor, people in the EU.

    GDPR on QULDEXRead our coverage
  • NIS2 Directive

    If you operate in a covered sector (for example digital infrastructure, ICT service management, health or manufacturing of critical products) and are medium-sized or larger, or are designated by a member state.

    Read our coverage
  • EU Cyber Resilience Act

    If you place software or connected hardware on the EU market. Reporting of exploited vulnerabilities applies since 11 September 2026; full rules from 11 December 2027. Pure SaaS is generally out of scope.

    Read our coverage
  • EU AI Act

    If you place AI systems on the EU market or use them in the EU. Transparency duties apply now; high-risk obligations from 2 December 2027.

    Read our coverage

Contracts and customer expectations 3

Not law, but often a condition of doing business.

  • DORA requirements passed on by financial customers

    EU financial entities must put DORA terms into contracts with ICT providers, so SaaS vendors serving them inherit audit, incident and exit obligations.

    Read our coverage
  • SOC 2 Type 2

    US enterprise buyers commonly ask SaaS and service providers for a SOC 2 Type 2 report during procurement.

    SOC 2 on QULDEXRead our coverage
  • ISO/IEC 27001

    The most widely requested security certification worldwide, especially by customers outside the US.

    ISO 27001 on QULDEXRead our coverage

Voluntary frameworks that help 4

Give your programme structure and make the others easier to evidence.

Several of these overlap. QULDEX maps controls once and reuses evidence across them.

Get a readiness assessment

Baseline laws by region

Laws that apply in each region regardless of industry. Sector rules such as DORA, HIPAA or SEBI CSCRF are added by the finder above.

RegionLaws
IndiaDPDP Act, 2023 and DPDP Rules, 2025; CERT-In Directions (2022)
European UnionGDPR
United KingdomUK GDPR and Data Protection Act 2018
United StatesCCPA / CPRA
UAEUAE Personal Data Protection Law
Saudi ArabiaSaudi Personal Data Protection Law
SingaporeSingapore PDPA
AustraliaAustralian Privacy Act 1988
South AfricaPOPIA
NigeriaNigeria Data Protection Act, 2023