Ask a question.
Get a defensible compliance answer.

Start with a quick read of your compliance position. Then go deep: detailed, article-anchored assessments and branded reports built for banks, boards and regulators.

GDPREU AI ActNIS2DORACRAeIDAS 2.0MiFID IIMiCARMaRiskISO · soon
🔍 I want to know my GDPR status
63/100deterministic score
74controls, article-anchored
90 daysto High readiness

Grounded in the living law

Every finding cites its article and stays current with EU and national law.

🎯

Same facts, same score

Deterministic grading a consultant can defend in front of any auditor or bank.

📄

Reports worth handing over

Rebrandable, audience-tailored deliverables, from board one-pager to regulator dossier.

Coverage

Eleven frameworks. One assessment.

Each framework has different triggers, applies to different organisations, and demands different actions. Most tools cover one. This one covers all.

EU AI ActEU-wide

Risk-based regulation of AI systems. Four tiers: unacceptable, high-risk, limited risk, minimal risk.

All AI providers and deployers
In force 2024
DORAFinancial

Digital Operational Resilience Act. ICT risk management for financial institutions and their critical third parties.

Banks, insurers, ICT providers
Active 2025
NIS2Critical infra

Network and Information Security Directive 2. Cybersecurity obligations for essential and important entities.

18 sectors classified critical
EU 27 transposition
GDPREU-wide

General Data Protection Regulation. Rules for processing personal data: lawful basis, data subject rights, security, and 72-hour breach reporting.

Anyone handling EU personal data
In force 2018
MaRiskGerman banks

Minimum requirements for risk management. BaFin guidance binding on all German credit institutions.

German banks only
BaFin enforced
eIDAS 2.0Digital identity

European Digital Identity framework. Rules for EU Digital Identity Wallets, trust services and qualified certificates.

Wallet providers, trust services
In force 2024
BaFin SupervisionOversight

German Federal Financial Supervisory Authority oversight of AI-driven decisions in regulated firms.

All BaFin-supervised firms
Ongoing
ISO 42001Standard

International standard for AI management systems. Voluntary but increasingly demanded by procurement teams.

Voluntary, certifiable
Published 2023
MiFID IIInvestment firms

Markets in Financial Instruments Directive II. Rules for investment firms and trading venues (MTF/OTF), including algorithmic trading.

Investment firms, MTF/OTF
In force
MiCARCrypto

Markets in Crypto-Assets Regulation. Authorisation and conduct rules for crypto-asset issuers and service providers (CASPs).

Issuers, CASPs
Applies 2024
Cyber Resilience ActProducts

Mandatory cybersecurity for products with digital elements placed on the EU market.

Manufacturers, importers
Applies 2027
Educational content

Deep-dive lessons.

Long-form explainers on each framework. Built to be the clearest resource available on these topics, in English and German.

Lesson 01
EU AI Act Fundamentals
Four risk tiers, who is covered, what triggers each tier, and when each provision takes effect.
Available now
Lesson 02
DORA Deep Dive
ICT risk management requirements, incident reporting, third-party register, and resilience testing.
Available now
Lesson 03
NIS2 in Practice
Sector classification, registration thresholds, security measures, and breach notification timelines.
Available now
Lesson 04
MaRisk for AI
Model risk management under AT 4.3, IT risk under AT 7.2, and how AI-specific guidance is evolving.
Available now
Lesson 05
BAIT Explained
IT strategy, operations, outsourcing, and how BAIT interacts with the new AI-related MaRisk addendum.
Available now
Lesson 06
BaFin AI Supervision
How BaFin examines AI systems in scope, what evidence they ask for, and how to prepare.
Available now
Lesson 07
ISO 42001 Certification
Building an AI management system, the certification path, and how it complements EU AI Act compliance.
Available now
Lesson 08
MiFID II for Trading Venues
Investment firms, the RM/MTF/OTF venue types, algorithmic trading and RTS 6, best execution, and reporting.
Available now
Lesson 09
MiCAR for Crypto-Assets
Token categories (ARTs, EMTs, other), CASP authorisation, white papers, custody, and the 2024-2026 timeline.
Available now
Lesson 10
The Cyber Resilience Act
Products with digital elements, product classes, secure-by-design, SBOM, the 24h/72h reporting, and the timeline.
Available now
Lesson 11
GDPR Fundamentals
Who is in scope, the six lawful bases, data subject rights, records and DPIAs, the 72-hour breach clock, when a DPO is mandatory, and the fines.
Available now
Pricing

Free to start. Upgrade when you need more.

Start free; three paid tiers for power users.

Free

€0
forever
  • All 11 frameworks
  • 1 full assessment (view-only)
  • Unlimited quick checks
  • No card required
Try free now

Starter

€20
per month
  • Unlimited assessments
  • PDF report downloads
  • 250 credits / month

Pro

€39
per month
  • Everything in Starter
  • PDF, PPT & Excel + audience packs
  • Branded reports
  • 700 credits / month

Pro+

€79
per month
  • Everything in Pro
  • Premium branded & large reports
  • White-label
  • 1800 credits / month
⚡ Power extras - extra usage, OCR, on-demand branding, SMS - are available as pay-as-you-go credits.

Have a question? Get classified.

Free. No signup. No login. Your description is discarded after classification.

Check my system
SchutzIQ - EU compliance platform