Methodology
How we decide what applies to you
Results are produced by a deterministic rule engine running against a versioned dataset built from official EU legal texts. The same answers always produce the same result, and every conclusion carries its source.
The engine, stage by stage
01
Your facts
Headquarters, EU customers, data, sectors, products and AI roles.
02
Deterministic rules
Your facts are evaluated against structured conditions in the versioned dataset, with no missing-fact guesswork.
03
Applicability
Each matched requirement is classified direct, customer-driven, possible or guidance.
04
Evidence
Your existing evidence is scored have, partial, missing or unknown against each relevant artifact.
05
Roadmap
Matched actions are sequenced into do now, next and later, using each requirement's recorded priority.
Deterministic matching, not generated opinion
Your answers are evaluated against structured conditions recorded for each requirement cluster. A cluster is shown when its conditions are satisfied, and it is shown with the reason it matched.
No language model produces your regulatory conclusions. There is no probabilistic scoring behind the applicability decision, so two companies with identical answers always receive identical findings for a given dataset version.
Official EU sources only
Each requirement is recorded against its primary legal instrument, identified by its CELEX number and linked to EUR-Lex. We do not build requirements from vendor blog posts, consultancy summaries or secondary commentary.
Where an instrument has been amended, the amending act is recorded alongside the base act.
Dataset versioning
The requirement library, the artifact library and the matching rules are versioned together. Every result records the dataset version and engine version used to produce it, so a result can be reproduced and audited later.
Changing the law does not silently change your past result: a new dataset version produces a new assessment.
Direct obligations and customer flow-down
A direct obligation is one the EU instrument places on your company. A customer-driven requirement is one your company meets because a European customer must satisfy its own obligation and passes the requirement down through contract or procurement.
These are shown separately because they behave differently: a direct obligation exists whether or not anyone asks about it, while a flow-down requirement is negotiated commercially and usually arrives as a security questionnaire or a contract clause.
- Direct
Likely applies directly
- The EU rule applies directly to your organisation based on the facts identified. It exists whether or not anyone asks about it.
- Customer-driven
Reaches you through your EU customers
- An EU customer may contractually or operationally push a requirement down to you, even though the EU rule itself does not name your company.
How uncertainty is handled
“Not sure” is a first-class answer. Where a condition depends on a fact you have not confirmed, the requirement is reported as possible rather than applicable, and the open question is stated.
We do not resolve ambiguity in either direction on your behalf. A possible requirement is a prompt to establish a fact, not a finding that the requirement applies.
- A known fact feeds the deterministic rule engine directly and produces a definite result.
- A missing material fact produces a possible finding and a stated open question, never a silent guess in either direction.
Limits: national implementation
Directives take effect through national law. Where an instrument is a directive, national implementation can change thresholds, deadlines and enforcement, and the assessment reports the EU-level position only.
Member-state specifics, sectoral supervisory guidance and national derogations are outside the V1 dataset.
Evidence readiness
Evidence readiness measures how much of the documentation expected for your matched requirements you already hold. Each expected artifact scores 1 when you have it, 0.5 when it is partial, and 0 when it is missing or unknown. The score is the weighted total, expressed as a rounded percentage.
It is deliberately not a compliance percentage. It says nothing about whether your controls are adequate. It only reflects whether the documents a European buyer or authority would expect to see exist.
Illustrative example
A company with four relevant artifacts: one already in place, one partial, and two missing or unconfirmed.
- Evidence item 1In place · 1
- Evidence item 2Partial · 0.5
- Evidence item 3Missing · 0
- Evidence item 4Missing · 0
This is a documentation-completeness score, not a compliance percentage. It says nothing about whether your controls are adequate.
General information, not legal advice
This service produces general information to help you scope work and prepare for buyer scrutiny. It is not legal advice and does not create a lawyer-client relationship. Material legal conclusions should be verified with qualified counsel in the relevant jurisdiction.
How we source and version this
- 01
Official EU legislation
Every requirement is recorded against its primary legal instrument, identified by CELEX number and linked to EUR-Lex.
- 02
Versioned internal dataset
The requirement library, artifact library and matching rules are versioned together, so a result can be reproduced and audited later.
- 03
Deterministic engine
The same dataset and the same answers always produce the same result. There is no generative step in between.
Dataset 2026-08-v4 · Engine v1 · Verified 2026-08-17 · 12 items flagged for legal verification
General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.