Research listings are separate from implemented scans. No quote or assessment is available for this profile yet. Public uploads must contain no patient data or other restricted information.
Documents to review
Availability planResearch document type
Ddos response planResearch document type
Incident response planResearch document type
Access control policyResearch document type
Scope questions
Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.
Where does the organization operate, and which regulator, license, permit or contract governs the activity?
Which business activities, data types and organization roles does the document describe?
Do the relevant thresholds or exceptions change which requirements apply?
Unknown answers stay unresolved. Document detection does not answer these questions for you.
A fictional example to explore
This short policy outline demonstrates the document's structure and research questions. It is a navigation example; scans for this profile are not available yet.
Potentially relevant to covered cloud, data-centre, DNS/CDN, managed service and managed security providers with an EU nexus. Confirm service definitions, size rules and exceptions, main establishment, and the applicable national implementing law. Commission Implementing Regulation (EU) 2024/2690 specifies risk-management measures and significant-incident criteria for listed digital providers; it does not replace national applicability review.
Jurisdictions: EU-EEA
Research applicability questions
Do you operate or provide the relevant service in an EU or EEA member state?
Do you meet the employee or financial thresholds used by this authority?
Does your principal activity fall within a sector covered by this authority?
Do you provide one of the services identified by this authority?
Are you established, represented, or offering the service in the relevant jurisdiction?
Check EU establishment, offering goods/services to or monitoring people in the EU, and the controller/processor role. A cloud, MSP or security provider may be a processor with contract and security duties. EU data-subject location alone does not establish every territorial-scope condition; verify Articles 3 and 28 and relevant national rules.
Jurisdictions: EU-EEA
Research applicability questions
Does processing occur in the context of an EU establishment’s activities?
Does the organization offer goods/services to people in the EU or monitor their behavior there?
Do you determine the purposes and means of processing personal data, or process it on a customer’s documented instructions?
Where are the relevant people located for the processing activity, and which Article 3 scope condition is met?
Voluntary cybersecurity risk-management framework for organizations of any size or sector. Customer contracts may request alignment; it is not a law or a certification. Map the selected profile and desired outcomes; do not score optional framework alignment as a legal violation.
Jurisdictions: GLOBAL
Research applicability questions
Has your organization or a customer selected a NIST CSF profile or outcomes to evaluate?
Does a customer contract, regulator or internal policy require a particular CSF profile or outcome set?