RegRoute
Selling into Europe?Know what applies before it blocks a deal.
Get a tailored view of your EU regulatory exposure, customer requirements, evidence gaps and the steps to become ready to sell into Europe. Takes about 3 minutes.
Before you invest in consultants, audits or a full GRC platform, start with a simple, evidence-based readiness check.
No account. Evidence-based results. Every regulatory finding links to its source.
Why this matters
EU readiness is not only about avoiding a fine
For a company outside Europe, European regulation usually reaches the business in three different ways.
01
Market access
Whether the product or service can be offered, or placed, on the EU market as planned. Some EU rules apply directly depending on what you offer, where the people you serve are located, or how your product reaches the EU, regardless of where your company is incorporated.
02
Customer readiness
Whether the company can respond when an EU customer asks: procurement questionnaires, security and compliance reviews, and evidence requests pushed down contractually, even where no EU law reaches you directly.
03
Regulatory exposure
Which direct obligations and enforcement consequences may apply. Those consequences reach further than fines, and can include market or product access constraints, customer procurement requirements, compliance and security reviews, evidence and documentation requests, contractual flow-down, and remediation work.
The dataset
Built from official EU legal texts
Product scope
- 7
- EU regulation families screened
- 3
- distinct applicability categories
- 30
- evidence artifacts mapped
Statutory maximum penalties
- Up to €20M or 4%
- GDPR
- Up to €35M or 7%
- EU AI Act
- Up to €15M or 2.5%
- Cyber Resilience Act
- €10M / 2%+
- NIS2
For certain infringements, where GDPR applies.
GDPR Article 83(5).
For non-compliance with the prohibited AI practices in Article 5.
AI Act Article 99(3).
For SMEs, including start-ups, the lower maximum applies (Article 99(6)).
For certain infringements of the essential cybersecurity requirements and specified obligations.
CRA Article 64(2).
For certain infringements by essential entities, Member States must set a maximum of at least €10 million or 2% of worldwide turnover, whichever is higher. National implementation and enforcement vary.
NIS2 Article 34(4).
Maximum statutory penalties. Actual exposure depends on applicability, role, infringement and enforcement circumstances.
How it works
01
Answer 6 short steps
Your company, EU activity, customers and current evidence.
02
See what applies, and why
Separate direct EU obligations from requirements flowing down from European customers.
03
Get your action plan
See your evidence gaps and the exact steps required to become EU-market ready.
04
Build the evidence
Documents, controls and a sequenced remediation roadmap, in the order to tackle them.
What this covers
RegRoute is built for companies headquartered outside Europe that need a clear, sourced view of where they stand.
- Which requirements are relevant
- Scoped to your company type, your EU activity and the customers you sell to.
- What kind of requirement it is
- Direct legal obligation, customer-driven requirement, market expectation, or a possible requirement depending on facts.
- Which evidence you are missing
- The documents and records European buyers and authorities expect you to hold.
- What to do next
- The concrete steps required to become ready to sell into Europe.
A key distinction
Not everything is a direct legal obligation
Every finding in your result is labelled with one of these, so you always know why something applies.
- Direct
Likely applies directly
- The EU rule applies directly to your organisation based on the facts identified. It exists whether or not anyone asks about it.
- Customer-driven
Reaches you through your EU customers
- An EU customer may contractually or operationally push a requirement down to you, even though the EU rule itself does not name your company.
- Possible
Possible applicability: facts need confirmation
- Important facts are still missing, or applicability depends on additional conditions. This is a prompt to confirm a fact, not a finding that the requirement applies.
What you receive
A management report, not a dashboard
Your result and, once unlocked, your complete plan are built to be read by a customer's security team or your own leadership, not just clicked through.
Illustrative example
EU market readiness
Direct, customer-driven and possible requirements, plus evidence readiness.
Your roadmap
Actions sequenced into do now, next and later.
Evidence
Have, partial, missing and unknown, artifact by artifact.
What you get
Free
Your situation
- Which EU regulations reach your company, and whether each one is a direct obligation or a customer-driven requirement
- Your evidence readiness and the documents you are missing
- Your first priority action, in full
$149 one-time
RegRoute EU Readiness Pack
- A detailed readiness report: applicability, priorities and the reasoning behind them
- A full evidence gap analysis: what you have, what is partial and what is missing
- A prioritized action roadmap: what to address first, and why
- Practical evidence templates: reusable starting points for your documentation
- A shareable PDF report, for internal stakeholders and customer or procurement discussions
- Bilingual report delivery: English, plus Japanese or Korean when your assessment was taken in that language
One-time payment. No account, no subscription.
Who it is for
Built for technology companies headquartered outside Europe, preparing to sell into Europe, support EU customers, or respond to EU-driven compliance and procurement requirements.
Company types
- B2B SaaS
- Software vendors
- AI companies
- IT and professional services
- Hardware companies
- Manufacturers of products with digital elements
Market-specific guidance is currently available for Singapore, Australia, Japan and South Korea.
Guide
Guides
Each guide answers one question directly, separates direct legal obligations from customer-driven requirements, and links to the official EU source.
- Which EU Regulations Apply to Non-EU SaaS Companies?
Which EU regulations can reach a non-EU SaaS company: what applies directly, what arrives through EU customers, and the facts that decide each one.
- DORA for SaaS vendors serving EU financial firms
How DORA reaches SaaS vendors serving EU financial firms, what is direct, what flows through the contract, and what evidence customers ask for.
- GDPR compliance checklist for technology companies outside Europe
A practical GDPR checklist for technology companies outside Europe: scope, roles, EU data, customer contracts, transfers, security and evidence.
- Does the Cyber Resilience Act Apply to SaaS?
Does the EU Cyber Resilience Act apply to SaaS, cloud software or non-EU tech companies? Product scope, remote data processing and operator roles, sourced.
- Does NIS2 Apply to Non-EU Companies?
Does NIS2 apply to your non-EU SaaS or technology company? Direct statutory scope, customer-driven security requests, and the facts that decide each.
- EU AI Act for Non-EU Companies: Provider, Deployer or Neither?
Does the EU AI Act apply to your non-EU AI or SaaS company? Provider vs deployer roles, territorial scope, and why AI-enabled does not mean high-risk.
Find out what applies to your company.
About 3 minutes. No account.
This assessment currently covers the EU-level framework. National implementation may change the result.