We keep a spreadsheet of customers and staff.
That's personal data. You need a record of what you hold, why, and for how long, plus a plan for a breach.
GDPR · Art. 30, 32, 33Compliance for businesses under 250 people
Answer seven plain questions about your business. We'll show you which laws and standards may apply, which ones your customers will ask about, and what to do first. Then Unified GRC gives you the policies, the plan and the evidence trail to get it done.
No sign-up to see your results. Nothing you enter leaves your browser.
Compliance Finder
Seven questions, no jargon. You can go back and change any answer.
Question 1 of 7
Your location and market help determine which rules to check.
No sign-up. Answers stay in this page’s memory and are cleared when you reload. No AI request is made.
Unified GRCHow it works
You may be in scope already
If any of these sound familiar, there's a rule or standard behind it. You don't need to know its name to start.
That's personal data. You need a record of what you hold, why, and for how long, plus a plan for a breach.
GDPR · Art. 30, 32, 33Large organisations in essential sectors must check the security of their suppliers. That pressure lands on you.
NIS2 · Art. 21(2)(d)You should know which AI tools are in use, what data goes into them, and have a short staff policy.
EU AI Act · Art. 4, 26Since June 2025, covered online consumer services have accessibility duties. Check service scope, exemptions and transition rules.
European Accessibility Act · EN 301 549It isn't law, but buyers can make it a shortlisting or contract requirement. Start with the scope your buyer needs.
ISO/IEC 27001:2022Depending on what was exposed, you may have had 72 hours to tell the regulator. An incident log is the first fix.
GDPR · Art. 33 · NIS2 · Art. 23What we cover
Built-in requirements and reusable mappings provide a starting point. Review their relevance and completeness for your organisation.
| Framework | Who it's for | What you get |
|---|---|---|
GDPREU 2016/679 · Articles 3, 30, 32, 33 ↗ | Organisations processing personal data within the GDPR territorial scope. | Linked privacy requirements, policies, risks and evidence, with RoPA and DPIA templates available. |
NIS2EU 2022/2555 · Articles 2, 21, 23 ↗ | Specified essential and important sectors. Size, exceptions and national implementation matter. | Cyber risk-management citations, mapped controls and incident reporting templates. |
EU AI ActEU 2024/1689 · Articles 2, 4, 26 ↗ | AI providers and deployers with an EU connection. Duties depend on role, risk and commencement dates. | AI inventory, risk-assessment and governance templates linked to requirements and controls. |
ISO/IEC 27001ISO/IEC 27001:2022 ↗ | Any organisation seeking a structured ISMS or responding to customer security expectations. | Pre-populated requirements, control mappings, policies and a guided evidence trail. |
SOC2AICPA SOC2 ↗ | Service organisations whose customers want independent assurance over their controls. | A pre-built SOC2 pack spanning Security, Availability, Processing Integrity, Confidentiality and Privacy. Tailor the scope for your examination. SecurityAvailabilityProcessing IntegrityConfidentialityPrivacy Connect SOC2 requirements to policies, processes, procedures and evidence, alongside controls and tests. Generate a readiness and evidence pack, not an independent attestation. A qualified CPA firm issues the formal SOC2 report. |
Digital accessibilityWCAG 2.2 · EN 301 549 · EAA ↗ | Covered consumer products and services, and public-sector requirements. Exemptions and transitions can apply. | Accessibility checklists and conformance templates to support review and remediation. |
NIST SP 800-53Revision 5 · Security and privacy controls ↗ | Organisations using this control catalogue voluntarily or under an explicitly specified requirement. | Mapped controls and policy templates that connect security work to supporting evidence. |
UK Cyber EssentialsNCSC · Cyber Essentials ↗ | Organisations seeking UK baseline cyber security assurance, including where customers or procurement contracts require it. | A pre-built pack covering firewalls, secure configuration, security updates, user access control and malware protection. Mapped requirements connect to controls, tests, policies, processes, procedures, risks, issues and evidence. Certification requires the scheme’s assessment. |
EU DORA RegulationEU 2022/2554 · Digital operational resilience ↗ | Covered EU financial entities, with ICT third-party obligations and oversight provisions depending on role and scope. | A pre-built pack for ICT risk management, incident reporting, resilience testing and ICT third-party risk. Mapped requirements connect to objectives, controls, tests, evidence, policies, processes, procedures, risks and issues. Review exact legal scope and mapping completeness. |
Compare
Enterprise GRC suites and SOC2 automation tools are good at what they do. They assume you already know what you need and have someone to run it.
| Enterprise GRC suitesServiceNow, OneTrust, AuditBoard | Compliance automationVanta, Drata, Delve | Unified GRCBuilt for SMEs | |
|---|---|---|---|
| Built for | Large organisations with risk, audit and legal teams | Often tech companies seeking customer assurance | Businesses with no compliance team, often no IT team |
| Where you start | Configuration and implementation, depending on scope | Selecting frameworks and connecting supported tools | Seven questions about your business |
| European rules | Coverage depends on modules and configuration | Varies by product and plan | GDPR, NIS2, DORA, EU AI Act and accessibility alongside SOC2 and UK Cyber Essentials |
| Documents | Libraries and services vary by vendor | Templates and features vary by plan | Template library available, with linked records and a project plan |
| Do you need a consultant? | Depends on implementation and internal expertise | Depends on scope and audit requirements | Optional. Start with the plan and confirm gaps with an adviser |
| How you pay | Check the vendor’s current quote and contract | Check the vendor’s current quote and contract | Monthly subscription, with optional templates and add-ons. See Pricing |
Comparison reflects general product positioning, not a verified feature-by-feature assessment. Features and pricing change, so check with each vendor.
See Unified GRC in action
Questions
Size alone does not decide every obligation. GDPR may apply to smaller businesses, while other regimes have thresholds and exceptions. Bigger customers may also set requirements through contracts and questionnaires. The Finder distinguishes these signals.
NIS2 is an EU directive implemented through national laws. Check the current rules and competent authority in each EU country where you operate, including sector definitions, thresholds and exceptions. National implementation and application dates can differ. Customers in scope can also ask suppliers for NIS2-aligned controls, even where suppliers are not directly covered.
Not to get started. Unified GRC gives you templates, a project plan and an evidence trail. Some firms bring in an adviser to confirm scope or review gaps before an audit. Software alone does not guarantee compliance.
Yes. The template library is available on its own. See Pricing for the current options. You can move onto the full platform later.
No. It's a guide based on your answers and the published scope of each regulation. Use it to see where you stand, and take professional advice on anything borderline.
No. SOC2 is an independent attestation based on the AICPA SOC2 framework. Unified GRC supports readiness, mappings and evidence collection. An independent CPA firm conducts the examination and issues the formal report.
One app, ready-made documents, and a plan you can tailor. Connect requirements, policies and evidence, with monthly pricing and optional add-ons.