Technology · Cybersecurity · Privacy · AI Governance

SOC 2. NIS2. DORA.
45,134 obligations scored.

Cybersecurity frameworks, AI governance, digital services, data act, and information security standards for software and technology companies. AuditDSS decomposes 91 regulations into 45,134 individually testable obligations across 18 jurisdictions with 4-axis risk scoring.

Technology enforcement is intensifying globally

EDPB, EU AI Office, PCI SSC, and the FTC are pursuing record penalties against technology companies. The compliance gap you don't know about is the one that triggers a billion-dollar fine.

€6B

EDPB total fines

Meta $1.2B, TikTok €530M, Meta €405M — GDPR enforcement against tech companies dominates the global landscape

€1.9B

EU AI Office actions

Meta €1.3B, TikTok €345M — AI Act enforcement is already materialising before full implementation

$1.5B

PCI SSC penalties

Equifax $700M, Heartland $110M — payment card security failures trigger catastrophic enforcement and remediation costs

$1.3B

FTC enforcement

Equifax $575M, Epic $275M — the FTC is aggressively pursuing technology companies for data security and privacy failures

91

Regulations covered

4,539

Rules decomposed

45,134

Obligations scored

18

Jurisdictions

Geographic coverage

18 jurisdictions, 91 regulations

Complete technology regulatory coverage

From GDPR and the EU AI Act to PCI DSS and SOC 2, from NIST CSF to NIS2 and DORA — AuditDSS decomposes every regulation into independently testable obligations so your engineering and compliance teams speak the same language.

Key coverage areas

GDPR & UK GDPR
EU AI Act ({euAiAct?.obligations.toLocaleString()} obligations)
PCI DSS v4.0
SOC 2 & ISO 27001
NIST CSF & 800-53
NIS2 Directive
DORA (financial tech)
CCPA / CPRA

Purpose-built for technology compliance

SaaS & cloud platforms

Score your SOC 2, ISO 27001, and GDPR compliance in a single assessment. Identify the gaps auditors will find before your next certification cycle.

  • Map controls across SOC 2, ISO 27001, and NIST CSF simultaneously
  • Validate data processing agreements against GDPR Article 28
  • Prioritise remediation by enforcement risk

AI & machine learning companies

EU AI Act compliance scored at the obligation level. Know whether your system is high-risk and exactly which conformity assessment, transparency, and documentation requirements apply.

  • Score all 1,140 EU AI Act obligations by risk tier
  • Validate conformity assessment and documentation requirements
  • Pre-audit readiness before August 2026 deadline

E-commerce & payment platforms

PCI DSS v4.0 obligations decomposed into individually testable requirements. Payment security, cardholder data protection, and vulnerability management — all scored and risk-ranked.

  • All PCI DSS v4.0 requirements covered
  • Multi-jurisdiction privacy compliance for global platforms
  • Risk-scored obligation-level reporting

Regulatory coverage

All 91 regulations applicable to technology & software, grouped by theme. Every regulation links to its detailed obligation breakdown.

Cybersecurity Frameworks

🇦🇺
SOCI Act 2018

Cyber and Infrastructure Security Centre

10 · 32
🇨🇳
CSL

Cyberspace Administration of China

8 · 201
🇪🇺
DORA

Joint Committee of European Supervisory Authorities (EBA/ESMA/EIOPA)

170 · 781
🇪🇺
Data Act

European Parliament and Council

32 · 221
🇪🇺
DMA

European Commission — Digital Markets Act Enforcement

20 · 63
🇪🇺
DSA

European Commission — Digital Services Act Enforcement

47 · 258
🇺🇸
Safeguards Rule

Federal Trade Commission

6 · 176
🇪🇺
NIS2

European Union Agency for Cybersecurity

190 · 602
🇺🇸
NIST SP 800-53 Rev 5

National Institute of Standards and Technology

1196 · 2,844
🇺🇸
NIST CSF 2.0

National Institute of Standards and Technology

6 · 103
🇺🇸
23 NYCRR 500

New York Department of Financial Services

21 · 183
🇺🇸
PCI DSS

PCI Security Standards Council

342 · 1,532
🇸🇦
CCC-2:2024

National Cybersecurity Authority

24 · 175
🇸🇦
CSCC-1:2019

National Cybersecurity Authority

21 · 105
🇸🇦
DCC-1:2022

National Cybersecurity Authority

10 · 46
🇸🇦
NCA ECC-2:2024

National Cybersecurity Authority

28 · 108
🇸🇦
OTCC-1:2022

National Cybersecurity Authority

23 · 169
🇸🇦
TCC-1:2021

National Cybersecurity Authority

16 · 63
🇸🇦
SAMA Open Banking

Saudi Arabian Monetary Authority

10 · 46
🇸🇦
SAMA CSF

Saudi Arabian Monetary Authority

16 · 64
🇺🇸
CIRCIA

Cybersecurity and Infrastructure Security Agency

13 · 159
🇺🇸
FedRAMP

General Services Administration

14 · 172
🇺🇸
FedRAMP Rev 5

General Services Administration

19 · 183
🇺🇸
FISMA

Office of Management and Budget

12 · 174

Privacy & Data Protection

🇦🇺
Privacy Act 1988

Office of the Australian Information Commissioner

29 · 203
🇧🇷
LGPD

Autoridade Nacional de Proteção de Dados

19 · 200
🇺🇸
CCPA/CPRA

California Attorney General / California Privacy Protection Agency

46 · 572
🇨🇳
PIPL

Cyberspace Administration of China

15 · 203
🇺🇸
COPPA

Federal Trade Commission

13 · 156
🇦🇪
DIFC Law No. 5/2020

DIFC Commissioner of Data Protection

10 · 65
🇪🇺
ePrivacy Directive

European Parliament and Council

19 · 137
🇪🇺
GDPR

European Data Protection Board

272 · 947
🇺🇸
FCC CPNI

Federal Communications Commission

8 · 99
🇺🇸
FCRA Reg V

Consumer Financial Protection Bureau

43 · 751
🇺🇸
GLBA Reg P

Consumer Financial Protection Bureau

17 · 496
🇭🇰
PDPO

Privacy Commissioner for Personal Data

14 · 155
🇮🇳
DPDP Act 2023

Data Protection Board of India

19 · 183
🇯🇵
APPI

Personal Information Protection Commission

26 · 180
🇰🇷
PIPA

Personal Information Protection Commission

20 · 160
🇲🇽
LFPDPPP

National Institute for Transparency, Access to Information and Protection of Personal Data (INAI)

12 · 158
🇴🇲
Royal Decree 6/2022

Ministry of Transport, Communications and Information Technology

5 · 32
🇸🇦
PDPL

Saudi Data and AI Authority

10 · 135
🇸🇬
PDPA

Personal Data Protection Commission

20 · 184
🇹🇭
PDPA

Personal Data Protection Committee (PDPC)

12 · 180
🇦🇪
Federal Decree-Law 45/2021

UAE Data Office

8 · 31
🇬🇧
UK GDPR

Information Commissioner's Office

53 · 402
🇬🇧
Online Safety Act

Office of Communications

17 · 231
🇿🇦
POPIA

Information Regulator of South Africa

17 · 176

SOC 2 & Audit Frameworks

Trust Services Criteria, governance frameworks, and assurance standards for SOC 2 compliance

AI Governance

Defense Cybersecurity

For technology companies in the defense supply chain

Corporate Governance & Anti-Corruption

ESG & Climate Disclosure

Employment & Modern Slavery

Workplace Safety

Consumer Protection

Saudi Technology

Compliance Program Builder

Generate your technology & software compliance program

Answer a few questions about your business. Get a complete compliance program — policies, procedures, and operational forms — tailored to your risk profile and mapped to every obligation. Ready in minutes.

  • AI-guided questionnaire adapts to your entity type
  • Every clause traces to specific regulatory obligations
  • Export to PDF — ready for board review or audit

Technology & Software Compliance Policy

Risk-calibrated · 10–15 sections

Policy

Operational Procedures

Step-by-step · Staff-ready

Procedures

Forms & Checklists

Operational forms · Ready to use

Forms

Score your technology & software compliance

Score your existing policies against 45,134 obligations — or generate a complete compliance program tailored to your business in minutes.