Research only

Telecom, VoIP, and internet providers

Explore the policy documents and regulatory sources relevant to this industry. Assessment checks for this profile are in development.

Research listings are separate from implemented scans. No quote or assessment is available for this profile yet. Public uploads must contain no patient data or other restricted information.

Documents to review

  • Cpni policyResearch document type
  • Customer authentication procedureResearch document type
  • Breach response planResearch document type
  • Network change procedureResearch document type

Scope questions

Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.

  • Where does the organization operate, and which regulator, license, permit or contract governs the activity?
  • Which business activities, data types and organization roles does the document describe?
  • Do the relevant thresholds or exceptions change which requirements apply?

Unknown answers stay unresolved. Document detection does not answer these questions for you.

A fictional example to explore

This short policy outline demonstrates the document's structure and research questions. It is a navigation example; scans for this profile are not available yet.

PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.

Regulations and frameworks to explore

These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.

Research only

FCC customer proprietary network information rules

47 USC 222 · 47 CFR Part 64 Subpart U

For telecommunications carriers and interconnected VoIP providers handling customer proprietary network information. Ordinary cloud or IT services do not establish carrier status. Confirm service classification and the annual CPNI certification duty; the FCC filing page is guidance, while 47 USC 222 and the applicable Part 64 rules govern.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Are you a telecommunications carrier or interconnected VoIP provider, and which services create CPNI?
  • Is an annual CPNI certification required for your service and reporting year?
Research only

NIS2 and national transpositions

Directive (EU) 2022/2555 · Commission Implementing Regulation (EU) 2024/2690

Potentially relevant to covered cloud, data-centre, DNS/CDN, managed service and managed security providers with an EU nexus. Confirm service definitions, size rules and exceptions, main establishment, and the applicable national implementing law. Commission Implementing Regulation (EU) 2024/2690 specifies risk-management measures and significant-incident criteria for listed digital providers; it does not replace national applicability review.

Jurisdictions: EU-EEA

Research applicability questions
  • Do you operate or provide the relevant service in an EU or EEA member state?
  • Do you meet the employee or financial thresholds used by this authority?
  • Does your principal activity fall within a sector covered by this authority?
  • Do you provide one of the services identified by this authority?
  • Are you established, represented, or offering the service in the relevant jurisdiction?
Research only

NIST Cybersecurity Framework 2.0

NIST CSWP 29

Voluntary cybersecurity risk-management framework for organizations of any size or sector. Customer contracts may request alignment; it is not a law or a certification. Map the selected profile and desired outcomes; do not score optional framework alignment as a legal violation.

Jurisdictions: GLOBAL

Research applicability questions
  • Has your organization or a customer selected a NIST CSF profile or outcomes to evaluate?
  • Does a customer contract, regulator or internal policy require a particular CSF profile or outcome set?