Skip to content

Methodology

How we decide what applies to you

Results are produced by a deterministic rule engine running against a versioned dataset built from official EU legal texts. The same answers always produce the same result, and every conclusion carries its source.

The engine, stage by stage

  1. 01

    Your facts

    Headquarters, EU customers, data, sectors, products and AI roles.

  2. 02

    Deterministic rules

    Your facts are evaluated against structured conditions in the versioned dataset, with no missing-fact guesswork.

  3. 03

    Applicability

    Each matched requirement is classified direct, customer-driven, possible or guidance.

  4. 04

    Evidence

    Your existing evidence is scored have, partial, missing or unknown against each relevant artifact.

  5. 05

    Roadmap

    Matched actions are sequenced into do now, next and later, using each requirement's recorded priority.

Deterministic matching, not generated opinion

Your answers are evaluated against structured conditions recorded for each requirement cluster. A cluster is shown when its conditions are satisfied, and it is shown with the reason it matched.

No language model produces your regulatory conclusions. There is no probabilistic scoring behind the applicability decision, so two companies with identical answers always receive identical findings for a given dataset version.

Official EU sources only

Each requirement is recorded against its primary legal instrument, identified by its CELEX number and linked to EUR-Lex. We do not build requirements from vendor blog posts, consultancy summaries or secondary commentary.

Where an instrument has been amended, the amending act is recorded alongside the base act.

Dataset versioning

The requirement library, the artifact library and the matching rules are versioned together. Every result records the dataset version and engine version used to produce it, so a result can be reproduced and audited later.

Changing the law does not silently change your past result: a new dataset version produces a new assessment.

Direct obligations and customer flow-down

A direct obligation is one the EU instrument places on your company. A customer-driven requirement is one your company meets because a European customer must satisfy its own obligation and passes the requirement down through contract or procurement.

These are shown separately because they behave differently: a direct obligation exists whether or not anyone asks about it, while a flow-down requirement is negotiated commercially and usually arrives as a security questionnaire or a contract clause.

Direct

Likely applies directly

The EU rule applies directly to your organisation based on the facts identified. It exists whether or not anyone asks about it.
Customer-driven

Reaches you through your EU customers

An EU customer may contractually or operationally push a requirement down to you, even though the EU rule itself does not name your company.

How uncertainty is handled

“Not sure” is a first-class answer. Where a condition depends on a fact you have not confirmed, the requirement is reported as possible rather than applicable, and the open question is stated.

We do not resolve ambiguity in either direction on your behalf. A possible requirement is a prompt to establish a fact, not a finding that the requirement applies.

  • A known fact feeds the deterministic rule engine directly and produces a definite result.
  • A missing material fact produces a possible finding and a stated open question, never a silent guess in either direction.

Limits: national implementation

Directives take effect through national law. Where an instrument is a directive, national implementation can change thresholds, deadlines and enforcement, and the assessment reports the EU-level position only.

Member-state specifics, sectoral supervisory guidance and national derogations are outside the V1 dataset.

Evidence readiness

Evidence readiness measures how much of the documentation expected for your matched requirements you already hold. Each expected artifact scores 1 when you have it, 0.5 when it is partial, and 0 when it is missing or unknown. The score is the weighted total, expressed as a rounded percentage.

It is deliberately not a compliance percentage. It says nothing about whether your controls are adequate. It only reflects whether the documents a European buyer or authority would expect to see exist.

Illustrative example

A company with four relevant artifacts: one already in place, one partial, and two missing or unconfirmed.

  • Evidence item 1In place · 1
  • Evidence item 2Partial · 0.5
  • Evidence item 3Missing · 0
  • Evidence item 4Missing · 0
38%
38% evidence readiness

This is a documentation-completeness score, not a compliance percentage. It says nothing about whether your controls are adequate.

General information, not legal advice

This service produces general information to help you scope work and prepare for buyer scrutiny. It is not legal advice and does not create a lawyer-client relationship. Material legal conclusions should be verified with qualified counsel in the relevant jurisdiction.

How we source and version this

  1. 01

    Official EU legislation

    Every requirement is recorded against its primary legal instrument, identified by CELEX number and linked to EUR-Lex.

  2. 02

    Versioned internal dataset

    The requirement library, artifact library and matching rules are versioned together, so a result can be reproduced and audited later.

  3. 03

    Deterministic engine

    The same dataset and the same answers always produce the same result. There is no generative step in between.

Dataset 2026-08-v4 · Engine v1 · Verified 2026-08-17 · 12 items flagged for legal verification

General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.