Compliance for businesses under 250 people

Which rules apply to you? Find out in 7 questions.

Answer seven plain questions about your business. We'll show you which laws and standards may apply, which ones your customers will ask about, and what to do first. Then Unified GRC gives you the policies, the plan and the evidence trail to get it done.

Explore the platform

No sign-up to see your results. Nothing you enter leaves your browser.

38-person IT support firm, WicklowExample result
GDPREU 2016/679 · Data Protection Commission
Applies
NIS2 cyber securityEU 2022/2555 · Managed IT services
Customers will ask
ISO/IEC 27001ISO/IEC 27001:2022 · Tenders and questionnaires
Customers will ask
EU AI ActEU 2024/1689 · Staff use Copilot
Good practice
SOC2AICPA · SOC2
Assurance option

Compliance Finder

Tell us about your business. We'll tell you what applies.

Seven questions, no jargon. You can go back and change any answer.

1Location2Size3Sector4Data5Online6AI7CustomersResults

Question 1 of 7

Where is your business based?

Your location and market help determine which rules to check.

No sign-up. Answers stay in this page’s memory and are cleared when you reload. No AI request is made.

Unified GRC shieldUnified GRC

How it works

From "what applies?" to "here's our evidence" in one place

Regulations and StandardsPMP aligned Project PlanPolicyProcessProcedureDemonstrable capabilityAudit Ready

You may be in scope already

Most small businesses find out about compliance from a customer, not a regulator

If any of these sound familiar, there's a rule or standard behind it. You don't need to know its name to start.

We keep a spreadsheet of customers and staff.

That's personal data. You need a record of what you hold, why, and for how long, plus a plan for a breach.

GDPR · Art. 30, 32, 33

A hospital asked us to fill in a 200-line security questionnaire.

Large organisations in essential sectors must check the security of their suppliers. That pressure lands on you.

NIS2 · Art. 21(2)(d)

Half the office uses ChatGPT for emails.

You should know which AI tools are in use, what data goes into them, and have a short staff policy.

EU AI Act · Art. 4, 26

Customers book and pay on our website.

Since June 2025, covered online consumer services have accessibility duties. Check service scope, exemptions and transition rules.

European Accessibility Act · EN 301 549

The tender asked if we're ISO 27001 certified.

It isn't law, but buyers can make it a shortlisting or contract requirement. Start with the scope your buyer needs.

ISO/IEC 27001:2022

We had a phishing scare last spring.

Depending on what was exposed, you may have had 72 hours to tell the regulator. An incident log is the first fix.

GDPR · Art. 33 · NIS2 · Art. 23

What we cover

Nine frameworks, explained without the jargon

Built-in requirements and reusable mappings provide a starting point. Review their relevance and completeness for your organisation.

FrameworkWho it's forWhat you get

GDPR

EU 2016/679 · Articles 3, 30, 32, 33 ↗
Organisations processing personal data within the GDPR territorial scope.

Linked privacy requirements, policies, risks and evidence, with RoPA and DPIA templates available.

NIS2

EU 2022/2555 · Articles 2, 21, 23 ↗
Specified essential and important sectors. Size, exceptions and national implementation matter.

Cyber risk-management citations, mapped controls and incident reporting templates.

EU AI Act

EU 2024/1689 · Articles 2, 4, 26 ↗
AI providers and deployers with an EU connection. Duties depend on role, risk and commencement dates.

AI inventory, risk-assessment and governance templates linked to requirements and controls.

ISO/IEC 27001

ISO/IEC 27001:2022 ↗
Any organisation seeking a structured ISMS or responding to customer security expectations.

Pre-populated requirements, control mappings, policies and a guided evidence trail.

SOC2

AICPA SOC2 ↗
Service organisations whose customers want independent assurance over their controls.

A pre-built SOC2 pack spanning Security, Availability, Processing Integrity, Confidentiality and Privacy. Tailor the scope for your examination.

SecurityAvailabilityProcessing IntegrityConfidentialityPrivacy

Connect SOC2 requirements to policies, processes, procedures and evidence, alongside controls and tests. Generate a readiness and evidence pack, not an independent attestation. A qualified CPA firm issues the formal SOC2 report.

Digital accessibility

WCAG 2.2 · EN 301 549 · EAA ↗
Covered consumer products and services, and public-sector requirements. Exemptions and transitions can apply.

Accessibility checklists and conformance templates to support review and remediation.

NIST SP 800-53

Revision 5 · Security and privacy controls ↗
Organisations using this control catalogue voluntarily or under an explicitly specified requirement.

Mapped controls and policy templates that connect security work to supporting evidence.

UK Cyber Essentials

NCSC · Cyber Essentials ↗
Organisations seeking UK baseline cyber security assurance, including where customers or procurement contracts require it.

A pre-built pack covering firewalls, secure configuration, security updates, user access control and malware protection. Mapped requirements connect to controls, tests, policies, processes, procedures, risks, issues and evidence. Certification requires the scheme’s assessment.

EU DORA Regulation

EU 2022/2554 · Digital operational resilience ↗
Covered EU financial entities, with ICT third-party obligations and oversight provisions depending on role and scope.

A pre-built pack for ICT risk management, incident reporting, resilience testing and ICT third-party risk. Mapped requirements connect to objectives, controls, tests, evidence, policies, processes, procedures, risks and issues. Review exact legal scope and mapping completeness.

Compare

The big platforms are built for compliance teams. You probably don't have one.

Enterprise GRC suites and SOC2 automation tools are good at what they do. They assume you already know what you need and have someone to run it.

Enterprise GRC suitesServiceNow, OneTrust, AuditBoardCompliance automationVanta, Drata, DelveUnified GRCBuilt for SMEs
Built forLarge organisations with risk, audit and legal teamsOften tech companies seeking customer assuranceBusinesses with no compliance team, often no IT team
Where you startConfiguration and implementation, depending on scopeSelecting frameworks and connecting supported toolsSeven questions about your business
European rulesCoverage depends on modules and configurationVaries by product and planGDPR, NIS2, DORA, EU AI Act and accessibility alongside SOC2 and UK Cyber Essentials
DocumentsLibraries and services vary by vendorTemplates and features vary by planTemplate library available, with linked records and a project plan
Do you need a consultant?Depends on implementation and internal expertiseDepends on scope and audit requirementsOptional. Start with the plan and confirm gaps with an adviser
How you payCheck the vendor’s current quote and contractCheck the vendor’s current quote and contractMonthly subscription, with optional templates and add-ons. See Pricing

Comparison reflects general product positioning, not a verified feature-by-feature assessment. Features and pricing change, so check with each vendor.

See Unified GRC in action

From requirements to customer assurance

See the linked assurance story, from everyday records to audit-ready materials.

Questions

Things small businesses ask us

We're only 15 people. Does any of this apply to us?

Size alone does not decide every obligation. GDPR may apply to smaller businesses, while other regimes have thresholds and exceptions. Bigger customers may also set requirements through contracts and questionnaires. The Finder distinguishes these signals.

How does NIS2 apply across Europe?

NIS2 is an EU directive implemented through national laws. Check the current rules and competent authority in each EU country where you operate, including sector definitions, thresholds and exceptions. National implementation and application dates can differ. Customers in scope can also ask suppliers for NIS2-aligned controls, even where suppliers are not directly covered.

Do we need a consultant as well?

Not to get started. Unified GRC gives you templates, a project plan and an evidence trail. Some firms bring in an adviser to confirm scope or review gaps before an audit. Software alone does not guarantee compliance.

Can we just buy the policy templates?

Yes. The template library is available on its own. See Pricing for the current options. You can move onto the full platform later.

Is the Finder legal advice?

No. It's a guide based on your answers and the published scope of each regulation. Use it to see where you stand, and take professional advice on anything borderline.

Does SOC2 mean we are certified?

No. SOC2 is an independent attestation based on the AICPA SOC2 framework. Unified GRC supports readiness, mappings and evidence collection. An independent CPA firm conducts the examination and issues the formal report.

Big-firm compliance, without the big-firm bill

One app, ready-made documents, and a plan you can tailor. Connect requirements, policies and evidence, with monthly pricing and optional add-ons.