53 regulatory families15 industry groups56 industry profiles
How we narrow the rules
Your business comes first.
Industry → Location → Activities → Regulatory scope → Document type
IndustryJurisdictionBusiness activitiesData handledLicenses, contracts & fundingSize & thresholdsDocument type
Industry alone does not establish applicability. Your location, activities, data, licenses, contracts, funding and relevant thresholds can change which rules matter. Recommendations are a starting point for review, not a legal conclusion.
Browse by business area
Start with your business.
Choose an area to explore the industries and regulatory families in our research catalog.
This narrows research candidates using catalog mappings. It does not determine which law applies. State or country, activities, thresholds and your answers to each pack’s applicability questions still require review.
Regulatory catalog
Explore 53 regulatory families.
Browse laws, regulations, standards and frameworks. Source identification and assessment availability are separate statuses.
Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries
Applies to: Potentially relevant to covered cloud, data-centre, DNS/CDN, managed service and managed security providers with an EU nexus. Confirm service definitions, size rules and exceptions, main establishment, and the applicable national implementing law. Commission Implementing Regulation (EU) 2024/2690 specifies risk-management measures and significant-incident criteria for listed digital providers; it does not replace national applicability review.
Check applicability for NIS2 and national transpositions
Do you operate or provide the relevant service in an EU or EEA member state?
Do you meet the employee or financial thresholds used by this authority?
Does your principal activity fall within a sector covered by this authority?
Do you provide one of the services identified by this authority?
Are you established, represented, or offering the service in the relevant jurisdiction?
Source and scope notes updated . Assessment review is separate.
Official references for NIS2 and national transpositions
Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries
Applies to: Distinguish regulated financial entities from their ICT suppliers. A cloud, MSP or security provider may face customer-contract duties; direct EU oversight follows designation as a critical ICT third-party provider. Check the service, EU financial customer, contract and critical-provider designation rather than treating every ICT supplier as a financial entity.
Check applicability for Digital Operational Resilience Act
Are you one of the financial-entity types named by the rule?
Do you supply ICT services to EU financial entities, and which services support their critical or important functions?
Which DORA security, incident, audit, exit and subcontracting obligations appear in your financial-customer contracts?
Do you operate or provide the relevant service in an EU or EEA member state?
Have the European Supervisory Authorities designated your organization as a critical ICT third-party provider?
Source and scope notes updated . Assessment review is separate.
Official references for Digital Operational Resilience Act
Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries
Applies to: Voluntary cybersecurity risk-management framework for organizations of any size or sector. Customer contracts may request alignment; it is not a law or a certification. Map the selected profile and desired outcomes; do not score optional framework alignment as a legal violation.
Check applicability for NIST Cybersecurity Framework 2.0
Has your organization or a customer selected a NIST CSF profile or outcomes to evaluate?
Does a customer contract, regulator or internal policy require a particular CSF profile or outcome set?
Source and scope notes updated . Assessment review is separate.
Authority / publisherNational Institute of Standards and Technology
Standard · ISO/IEC 27001:2022 · ISO/IEC 27001:2022/Amd 1:2024
Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries
Applies to: ISO/IEC 27001:2022 is an information-security management-system standard, with Amendment 1:2024 also listed by ISO. Certification or alignment may be requested by customers; this is not automatically a legal duty. Assessment content remains mapping-only until reuse rights and specialist review are resolved; AuditReady cannot issue certification.
Check applicability for ISO/IEC 27001:2022
Has a customer or your organization requested this standard or assurance engagement, and for which system boundary?
Which services, sites, assets and processes are inside the requested certification boundary?
Source and scope notes updated . Assessment review is separate.
Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries
Applies to: SOC 2 is an AICPA assurance reporting service for service organizations, not a general law or an ISO-style certification. Scope depends on the system, trust-services categories and engagement. Customer requirements can drive the engagement. Content-rights review and CPA expertise are required; AuditReady cannot issue a SOC report.
Check applicability for SOC 2 Trust Services Criteria
Has a customer or your organization requested this standard or assurance engagement, and for which system boundary?
Which trust-services categories and reporting period are in the planned SOC 2 engagement?
Source and scope notes updated . Assessment review is separate.
Best for: Data centers and colocation; Cloud providers; Fintech and payment processors
Applies to: PCI DSS v4.0.1 is a payment-account security standard. Check whether the organization stores, processes or transmits account data, or can affect the cardholder-data environment, and confirm its merchant/service-provider role. Customer and payment-brand arrangements determine validation obligations. Content permission and qualified review remain required; AuditReady readiness is not PCI validation.
Check applicability for PCI DSS v4.0.1
Do you store, process or transmit payment-account data, or provide services that can affect a cardholder-data environment?
What payment-brand/acquirer validation requirements apply to your merchant volume and channels?
Do you store, process or transmit cardholder data, or provide services that can affect payment-data security?
Which systems and services are within or can affect the cardholder-data environment?
Source and scope notes updated . Assessment review is separate.
Authority / publisherPCI Security Standards Council
FCC customer proprietary network information rules
Regulation · 47 USC 222 · 47 CFR Part 64 Subpart U
Best for: Telecom, VoIP, and internet providers
Applies to: For telecommunications carriers and interconnected VoIP providers handling customer proprietary network information. Ordinary cloud or IT services do not establish carrier status. Confirm service classification and the annual CPNI certification duty; the FCC filing page is guidance, while 47 USC 222 and the applicable Part 64 rules govern.
Check applicability for FCC customer proprietary network information rules
Are you a telecommunications carrier or interconnected VoIP provider, and which services create CPNI?
Is an annual CPNI certification required for your service and reporting year?
Source and scope notes updated . Assessment review is separate.
Best for: Banks and credit unions; Broker-dealers; Fintech and payment processors; and other relevant industries
Applies to: For institutions subject to the appropriate Bank Secrecy Act rules. Banks must review 31 CFR Parts 1010 and 1020; other financial businesses have different institution-specific parts. The FFIEC examination manual is guidance, and a written policy alone does not demonstrate implementation of a risk-based AML program.
Check applicability for Bank Secrecy Act and AML program requirements
Are you a bank, MSB, casino or another defined financial institution, and which Chapter X part applies?
What products, customers, jurisdictions and delivery channels determine your money-laundering risk?
Source and scope notes updated . Assessment review is separate.
Authority / publisherFinCEN · Federal banking agencies
Federal banking and credit-union information security
Regulation · Agency-specific GLBA security guidelines · FDIC: 12 CFR Part 364 Appendix B; select the correct agency variant · NCUA: 12 CFR Part 748; distinguish regulatory provisions and guidance
Best for: Banks and credit unions
Applies to: For institutions overseen by the relevant banking agency or NCUA. Identify charter, insurer/supervisor and customer/member-information scope before selecting agency-specific security provisions. FDIC institutions use the appropriate Part 364 variant; federally insured credit unions require NCUA Part 748 review. Distinguish binding provisions from guidance, and check proposed guidance changes separately. These regimes and the FTC Safeguards Rule are not interchangeable.
Check applicability for Federal banking and credit-union information security
What is the institution’s charter and primary federal supervisor?
What customer information is maintained by the institution or its service providers?
Source and scope notes updated . Assessment review is separate.
Official references for Federal banking and credit-union information security
Best for: Managed service providers; Tax preparers and CPA firms; Auto dealers that finance or lease; and other relevant industries
Applies to: Certain financial institutions under FTC jurisdiction must safeguard customer information; activities and regulator routing determine coverage. Banks supervised under other GLBA regulators must be routed to their own rules. An MSP is not automatically a covered financial institution: assess customer-contract duties and any external Qualified Individual role separately from direct institutional duties.
Check applicability for FTC Safeguards Rule
Does the organization engage in a financial activity covered by the applicable GLBA rule?
Is the organization subject to FTC jurisdiction for the activity being assessed?
Does the organization maintain customer information covered by the rule?
How many consumers’ customer information records do you maintain, and do any section 314.6 exemptions apply?
Source and scope notes updated . Assessment review is separate.
Best for: Auto dealers that finance or lease; Mortgage lenders and servicers; Consumer lenders and debt collectors
Applies to: For FTC-supervised financial institutions and defined creditors that offer or maintain covered accounts. Deferred billing alone does not resolve every creditor condition. Evaluate personal/household accounts with multiple transactions and other accounts with reasonably foreseeable identity-theft risk; other regulators use their own rules.
Check applicability for FTC Red Flags Rule
Does the organization meet the rule’s financial-institution or creditor definition under FTC enforcement?
Which accounts involve multiple consumer transactions or reasonably foreseeable identity-theft risk?
Source and scope notes updated . Assessment review is separate.
Best for: Banks and credit unions; Fintech and payment processors; Money services and qualifying virtual-asset businesses; and other relevant industries
Applies to: Scope follows a New York DFS license, registration, charter or similar authorization under the Banking, Insurance or Financial Services Laws, with full/limited exemptions to review. An ICT supplier is not automatically a Covered Entity; customer contracts can require third-party controls. Review the current amended regulation and applicable phase-in dates. DFS also published risk-assessment guidance on September 10, 2026.
Check applicability for NYDFS Cybersecurity Regulation
Which New York DFS licenses, registrations or authorizations does the organization hold?
Does the licensed organization fall within the covered-entity definition for Part 500?
Which specific exemption conditions can the organization substantiate, and which duties remain?
Does the organization meet the Part 500 Class A definition or another applicable entity classification?
Source and scope notes updated . Assessment review is separate.
Authority / publisherNew York State Department of Financial Services
Applies to: For investment advisers registered with the SEC under Rule 206(4)-7. Registered investment companies have a separate Rule 38a-1 regime. Review written procedures, annual effectiveness review and the chief compliance officer for the actual adviser/fund role; state-registered advisers require their state-specific rules.
Check applicability for Investment adviser compliance program rule
Is this adviser registered or required to be registered with the SEC, or supervised at state level?
Is the document for an adviser or a registered investment company with separate board and compliance duties?
Source and scope notes updated . Assessment review is separate.
Authority / publisherSecurities and Exchange Commission
Regulation · 17 CFR Part 248 · 16 CFR Part 313 · 12 CFR Part 1016
Best for: Investment advisers and funds; Broker-dealers; Mortgage lenders and servicers; and other relevant industries
Applies to: The SEC Regulation S-P regime applies to defined SEC-covered institutions; FTC Part 313 and CFPB Regulation P are separate privacy regimes. The 2024 S-P safeguards and incident-response amendments had phased compliance dates in December 2025 and June 2026. Confirm institution category, covered customer information and the correct regulator before selecting requirements.
Check applicability for Regulation S-P and financial privacy
Is this an SEC-covered broker-dealer, investment company, registered adviser or covered transfer agent?
Which SEC, FTC or CFPB privacy regime governs the institution and consumer relationship?
Which 2024 S-P amendment provisions apply to your institution’s category and size?
Source and scope notes updated . Assessment review is separate.
Official references for Regulation S-P and financial privacy
Applies to: For mortgage servicing within Regulation X Subpart C. Section 1024.30 excludes specified loans and servicers from sections 1024.38–1024.41, including qualifying small servicers subject to the stated exceptions. Confirm the mortgage type and actual servicing role; a small-servicer exemption does not remove every servicing obligation.
Check applicability for Regulation X servicing policies and procedures
Do you service mortgage loans within section 1024.31 rather than only originate or broker them?
Do the section 1024.30 loan, small-servicer or other exemptions apply, and which obligations remain?
Source and scope notes updated . Assessment review is separate.
Official references for Regulation X servicing policies and procedures
Best for: Money services and qualifying virtual-asset businesses
Applies to: For businesses within the relevant MSB definitions and AML program rules in 31 CFR 1022.210. Identify money-services activities, principal/agent roles and exemptions separately from registration. FinCEN guidance explains that a principal and its agents cannot contract away their own AML responsibilities; agent monitoring must reflect risk.
Check applicability for Money services business AML program
Which money-services activities do you perform, and do any definition or exemption conditions apply?
Are you an MSB principal, an agent, or both, and how do you monitor the relevant agents?
Source and scope notes updated . Assessment review is separate.
Official references for Money services business AML program
Applies to: For licensed or authorized casinos and card clubs meeting the BSA definition, including the gross annual gaming revenue threshold above $1 million. Confirm state, territory or tribal gaming authority and the actual gaming activities. The older FinCEN FAQ uses historical Part 103 citations; current obligations must be traced to Parts 1010 and 1021.
Check applicability for Casino AML program requirements
Is this a duly licensed or authorized casino or card club under the relevant jurisdiction?
Does gross annual gaming revenue exceed the applicable $1 million BSA threshold?
Source and scope notes updated . Assessment review is separate.
Official references for Casino AML program requirements
HIPAA Security, Privacy, and Breach Notification Rules
Regulation · 45 CFR Parts 160 and 164
Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries
Applies to: 63 draft policy-wording checks for US medical and dental covered entities without patient data. Covered-entity, ePHI and vendor facts require confirmation. Addressable safeguards allow documented alternatives when appropriate. Privacy, Breach Notification, group-health-plan, clearinghouse-specific and business-associate-only duties are outside this preview. Proposed rules do not affect findings.
Check applicability for HIPAA Security, Privacy, and Breach Notification Rules
Are you a HIPAA covered entity, or do you create, receive, maintain or transmit PHI for a covered entity or another business associate?
Which protected health information does the service handle, and under whose business-associate agreement?
Does your service handle electronic PHI, including encrypted information for which you do not hold the decryption key?
What size, complexity, capabilities and risk factors affect implementation of your HIPAA safeguards?
For each addressable implementation specification, have you evaluated reasonableness and documented any alternative?
Source and scope notes updated . Assessment review is separate.
Official references for HIPAA Security, Privacy, and Breach Notification Rules
Confidentiality of substance use disorder patient records
Regulation · 42 CFR Part 2
Best for: Behavioral health and substance-use treatment
Applies to: Applies to qualifying federally assisted substance-use-disorder programs and other recipients subject to Part 2 duties, not every behavioral-health record. HHS reports that the 2024 final rule became effective April 16, 2024, with compliance required February 16, 2026. Confirm program/recipient role and the records involved.
Check applicability for Confidentiality of substance use disorder patient records
Is the organization or record system a Part 2 program or lawful holder of Part 2 records?
Does the substance-use-disorder program receive federal assistance within the Part 2 definition?
Are these patient-identifying substance-use-disorder records within Part 2 scope?
Are you the originating Part 2 program, a lawful holder or another recipient, and what authorizes use/disclosure?
Will any uploaded document contain electronic protected health information?
Source and scope notes updated . Assessment review is separate.
Official references for Confidentiality of substance use disorder patient records
Regulation · Provider-specific Medicare Conditions of Participation and Coverage
Best for: Hospitals and health systems; Long-term care, home health, hospice, and dialysis
Applies to: For provider and supplier types participating under the applicable Medicare/Medicaid Conditions of Participation or Coverage. Hospitals, home health agencies, hospices, ambulatory surgery centers and other providers have different conditions. Identify the specific facility and certification pathway; this umbrella family cannot supply one universal healthcare checklist.
Check applicability for CMS Conditions of Participation and Coverage
Which exact CMS provider or supplier category and facility certification apply?
Under which Medicare or Medicaid participation conditions is this facility certified?
Will any uploaded document contain electronic protected health information?
Source and scope notes updated . Assessment review is separate.
Authority / publisherCenters for Medicare & Medicaid Services
Best for: Hospitals and health systems; Long-term care, home health, hospice, and dialysis
Applies to: For provider and supplier categories covered by the CMS emergency-preparedness regulations. The program covers risk assessment/planning, policies and procedures, communication, and training/testing, with requirements that vary by provider category. Use the applicable provider regulation and survey guidance; a generic emergency plan does not establish facility compliance.
Check applicability for CMS emergency preparedness requirements
Which CMS provider/supplier regulation governs this facility’s emergency-preparedness program?
What patient needs, local hazards, utilities, communications and continuity dependencies must its plan address?
Will any uploaded document contain electronic protected health information?
Source and scope notes updated . Assessment review is separate.
Authority / publisherCenters for Medicare & Medicaid Services
Applies to: For laboratory examination of human specimens for diagnosis, prevention, treatment or health assessment within CLIA scope. Confirm certificate type and test complexity; waived, provider-performed microscopy and nonwaived testing have different requirements. Research-only testing without patient-specific reporting and other exceptions need review. State requirements can also apply.
Check applicability for Clinical Laboratory Improvement Amendments
Are human specimens tested for patient diagnosis/treatment or only for exempt research purposes?
What CLIA certificate and test-complexity categories cover the actual testing?
Will any uploaded document contain electronic protected health information?
Source and scope notes updated . Assessment review is separate.
Authority / publisherCenters for Medicare & Medicaid Services
Regulation · 21 CFR Part 820 · ISO 13485:2016 incorporated by reference
Best for: Medical-device manufacturers
Applies to: QMSR is effective from February 2, 2026. Confirm the device-manufacturer role and applicable requirements of 21 CFR Part 820; ISO 13485:2016 is incorporated by reference and its text remains rights-sensitive.
Check applicability for FDA Quality Management System Regulation
What medical-device manufacturing role places the organization within FDA QMSR scope?
Which device classifications and product-specific regulatory requirements apply?
Which design, manufacturing, servicing or other operations are covered by the quality-system boundary?
Do any device-specific exemptions apply, and which quality-system duties remain?
Source and scope notes updated . Assessment review is separate.
Official references for FDA Quality Management System Regulation
Applies to: ISO 13485:2016 identifies a medical-device quality-management standard. Confirm the organization’s device lifecycle role, certification boundary and applicable market rules. FDA QMSR incorporates this edition for covered US device manufacturers, but certification alone does not establish FDA compliance. Requirement-text use remains subject to licensing.
Check applicability for ISO 13485:2016
Do you design, manufacture, install, service or supply medical devices, and within which certification boundary?
Which national device regulations or customer contracts require this standard for that role?
Source and scope notes updated . Assessment review is separate.
Authority / publisherInternational Organization for Standardization
Best for: Medical-device manufacturers; Pharmaceutical and biotechnology manufacturers; Clinical research sites and contract research organizations
Applies to: Applies to electronic records and signatures within the scope of FDA predicate-rule record requirements and qualifying electronic submissions. It is not a universal rule for every electronic business document. Identify the predicate rule, record/signature use and system before assessing requirements.
Check applicability for FDA electronic records and signatures
Which FDA predicate rule requires these records to be maintained or submitted?
Are required records maintained/submitted electronically rather than only paper records or convenience copies?
Are electronic signatures used in place of signatures required by the applicable FDA rules?
Source and scope notes updated . Assessment review is separate.
Drug manufacturing current good manufacturing practice
Regulation · 21 CFR Parts 210 and 211
Best for: Pharmaceutical and biotechnology manufacturers; Pharmacies and compounding facilities
Applies to: For drug manufacturing and related operations within the applicable FDA CGMP regime. Parts 210 and 211 address finished pharmaceuticals; product type and operations can require other provisions. FDA production/process Q&A is nonbinding guidance, not the complete rule. Distinguish manufacturer, contract operation and outsourcing roles before choosing checks.
Check applicability for Drug manufacturing current good manufacturing practice
What drug product and manufacturing, packaging, testing or holding operations are performed?
Is the organization the manufacturer, contract facility or an outsourcing operation with its own applicable regime?
Source and scope notes updated . Assessment review is separate.
Official references for Drug manufacturing current good manufacturing practice
Regulation · 21 CFR Parts 50, 56, 312, and 812 as applicable
Best for: Clinical research sites and contract research organizations
Applies to: Route by study and organization role: informed consent and IRBs (21 CFR Parts 50/56), investigational drugs (Part 312) and investigational devices (Part 812). A generic clinical-research label does not establish all four regimes; identify sponsor, investigator, IRB and study type first.
Check applicability for FDA-regulated clinical research
Does the clinical investigation involve drugs, biologics or medical devices, and which FDA regime applies?
Is an IND, IDE or a defined exemption applicable to this investigation?
Are you the sponsor, investigator, sponsor-investigator or another responsible study party?
What clinical investigation and participant/IRB protections fall within the applicable FDA rules?
Source and scope notes updated . Assessment review is separate.
Regulation · 21 CFR Part 117 (human food) · 21 CFR Part 507 (animal food)
Best for: Food manufacturers and warehouses; Seafood, juice, and produce operations; Food cold-chain operators
Applies to: For food facilities within the applicable FDA preventive-controls rules. Human food Part 117 and animal food Part 507 are separate regimes, and registration, activities and exemptions affect scope. FDA’s Food Safety Plan Builder is optional and does not approve a plan. Qualified-facility or other modified requirements require a facts-based review.
Check applicability for FSMA preventive controls and food safety plans
Does the facility manufacture, process, pack or hold human or animal food within the applicable registration/rule scope?
Do qualified-facility, activity-specific or other exemption/modified-requirement conditions apply?
Source and scope notes updated . Assessment review is separate.
Official references for FSMA preventive controls and food safety plans
Regulation · FSIS HACCP and Sanitation SOP regulations
Best for: Meat, poultry, and egg-product facilities
Applies to: For official establishments and products under the relevant USDA FSIS inspection regime. HACCP Part 417 and sanitation SOP Part 416 duties must be matched to the establishment, product and process category. FSIS inspection directives guide agency verification; they are not a substitute for the establishment’s binding regulatory requirements.
Check applicability for FSIS HACCP and sanitation SOP requirements
Which products and establishment operations are subject to FSIS inspection or an applicable state inspection program?
Which process categories and reasonably likely food-safety hazards determine the HACCP plan?
Source and scope notes updated . Assessment review is separate.
Official references for FSIS HACCP and sanitation SOP requirements
Best for: Food cold-chain operators; Chemical and petrochemical manufacturing; Petroleum refining, terminals, and fuel storage; and other relevant industries
Applies to: For processes meeting OSHA 1910.119 chemical or flammable-material quantity conditions, subject to exclusions and applicable state-plan rules. Assess the process boundary and Appendix A substances rather than the industry name. PSM and EPA RMP have separate scope tests; one program does not automatically satisfy the other.
Check applicability for OSHA Process Safety Management
Which connected or nearby process vessels contain covered chemicals or flammable materials, and in what quantities?
Do retail, fuel-use, remote-facility or other exclusions and state-plan variations affect this process?
Source and scope notes updated . Assessment review is separate.
Authority / publisherOccupational Safety and Health Administration
Best for: Chemical and petrochemical manufacturing; Petroleum refining, terminals, and fuel storage; Industrial gas and bulk chemical storage; and other relevant industries
Applies to: For stationary-source processes containing regulated substances above the applicable 40 CFR Part 68 thresholds. Determine substance, process, exceptions and program level separately from OSHA PSM. Current regulatory text and compliance dates govern; a 2026 EPA reconsideration proposal must not be treated as an effective replacement rule.
Check applicability for EPA Risk Management Program
Does a stationary-source process contain a listed regulated substance above its threshold, after applicable exceptions?
Which RMP program level and prevention/emergency-response duties apply to this process?
Source and scope notes updated . Assessment review is separate.
Official references for EPA Risk Management Program
Chemical Facility Anti-Terrorism Standards monitor
Law · 6 CFR Part 27 historical program
Best for: Chemical and petrochemical manufacturing
Applies to: Historical chemical-facility security research only: statutory CFATS authority lapsed on July 28, 2023. This entry remains inactive and is not a current assessment requirement. Review any reauthorization against enacted authority before changing status; pre-lapse protected information can still have handling restrictions.
Check applicability for Chemical Facility Anti-Terrorism Standards monitor
Has enacted authority actually reauthorized CFATS, rather than only a proposal or historical CFR text?
Does the document contain chemical-terrorism vulnerability information protected under remaining handling authorities?
Source and scope notes updated . Assessment review is separate.
Official references for Chemical Facility Anti-Terrorism Standards monitor
Applies to: For community drinking-water systems serving more than 3,300 people under SDWA section 1433 as amended by AWIA. Risk/resilience assessments and emergency-response plans require certification and five-year review. ERP certification follows RRA certification within six months. Wastewater and smaller systems are not automatically covered by this population-based duty.
Check applicability for AWIA water-system risk and resilience
Is this a community drinking-water system serving more than 3,300 people?
When was its RRA certified, and what five-year review and six-month ERP certification dates follow?
Source and scope notes updated . Assessment review is separate.
Regulation · 10 CFR 50.47 and 10 CFR Part 50 Appendix E
Best for: Nuclear power facilities
Applies to: For NRC licensees/facilities within their applicable emergency-planning regime. Nuclear power plant requirements include 10 CFR 50.47 and Part 50 Appendix E; other facility and license types require separate scope review. Evaluate the licensed facility, onsite/offsite planning responsibilities and approved licensing basis, rather than applying a single nuclear-industry template.
Check applicability for NRC nuclear emergency preparedness
What NRC license, reactor/facility type and licensing basis govern this site?
Which onsite/offsite emergency-planning standards and approved plan commitments apply?
Source and scope notes updated . Assessment review is separate.
Official references for NRC nuclear emergency preparedness
Best for: Data centers and colocation; Hospitals and health systems; Medical and dental practices; and other relevant industries
Applies to: An emergency action plan is required when another OSHA standard triggers 29 CFR 1910.38. Confirm the triggering standard and state-plan coverage. A plan must generally be written and available to employees; employers with ten or fewer employees may communicate it orally. Do not infer a written-plan violation solely from the industry label.
Check applicability for OSHA emergency action plans
Which OSHA standard requires an emergency action plan for this workplace?
How many employees does the employer have, and does the ten-or-fewer oral-plan exception apply?
Does an OSHA-approved state plan apply, and does it impose different workplace requirements?
What work activities, hazards and other OSHA standards trigger this workplace emergency-plan duty?
Source and scope notes updated . Assessment review is separate.
Authority / publisherOccupational Safety and Health Administration
Regulation · Clean Water Act NPDES industrial stormwater permit requirements
Best for: Wastewater utilities; General and metal manufacturing; Hazardous waste, landfill, and recycling facilities; and other relevant industries
Applies to: For covered industrial activities with stormwater discharges requiring NPDES permit coverage. Identify the industrial sector, discharge, permitting authority and applicable state/EPA permit. A no-exposure exclusion has specific conditions and certification duties. EPA sector fact sheets and templates are guidance; the operative permit determines facility requirements.
Check applicability for NPDES industrial stormwater planning
Which industrial activities and stormwater discharges occur at this site?
Which permit authority and current permit or certified no-exposure exclusion cover the discharge?
Source and scope notes updated . Assessment review is separate.
Authority / publisherEnvironmental Protection Agency · Authorized state agencies
Spill Prevention, Control, and Countermeasure plans
Regulation · 40 CFR Part 112
Best for: Petroleum refining, terminals, and fuel storage; Industrial gas and bulk chemical storage; Pipeline and LNG operators; and other relevant industries
Applies to: For non-transportation-related facilities within 40 CFR Part 112 oil-capacity and discharge-potential conditions. Evaluate facility-wide storage and the potential to discharge to covered waters. A Tier I template is limited to qualified facilities, including container-size and spill-history conditions; state professional-engineer rules can affect self-certification.
Check applicability for Spill Prevention, Control, and Countermeasure plans
What aboveground/buried oil capacities and discharge pathways place the facility within Part 112?
Does it meet qualified-facility, container-size and spill-history conditions for Tier I self-certification?
Source and scope notes updated . Assessment review is separate.
Regulation · 30 CFR Parts 46 and 48; MINER Act emergency plans where applicable
Best for: Mines, quarries, and mining contractors
Applies to: For miners and relevant mine contractors under the applicable MSHA training regime. Part 46 covers specified surface nonmetal operations; Part 48 covers underground and other mine categories. Training-plan approval and instructor rules differ. Mine emergency-response obligations require separate mine/type-specific review rather than a generic training checklist.
Check applicability for MSHA training and mine emergency plans
What commodity and surface/underground mine type determine Part 46 or Part 48 coverage?
Which miners and contractors perform covered work, and which training-plan/instructor requirements apply?
Source and scope notes updated . Assessment review is separate.
Official references for MSHA training and mine emergency plans
Regulation · 49 CFR Part 40 and mode-specific rules
Best for: Pipeline and LNG operators; Battery manufacturing and hazardous-material warehousing; Commercial trucking and hazardous-material carriers; and other relevant industries
Applies to: Part 40 specifies procedures for DOT-required drug/alcohol testing; the applicable transportation agency rule determines who and when to test. Confirm the mode and safety-sensitive role, such as FMCSA-covered CDL operations under Part 382. Employers remain responsible when service agents perform testing tasks.
Check applicability for DOT drug and alcohol testing procedures
Which DOT agency rule and safety-sensitive job make testing required for these workers?
Who is the employer and which service agents perform collection, testing and return-to-duty functions?
Source and scope notes updated . Assessment review is separate.
Authority / publisherDepartment of Transportation · Modal administrations
Regulation · 14 CFR Part 5 and applicable Part 139 SMS requirements
Best for: Airlines, airports, and repair stations
Applies to: For operations/certificate holders within the applicable FAA SMS rule. The 2024 Part 5 expansion includes specified Part 21, Part 135 and section 91.147 operations; other organizations can participate voluntarily. Part 139 airport SMS has separate triggers/timelines. Existing covered Part 135 and 91.147 operators generally have a May 28, 2027 implementation date; new entrants follow their applicable certification/LOA conditions.
Check applicability for FAA Safety Management Systems
Which FAA operation, certificate or airport category determines mandatory versus voluntary SMS?
When was the certificate/LOA issued or application received, and which implementation timeline applies?
Source and scope notes updated . Assessment review is separate.
Official references for FAA Safety Management Systems
Best for: Schools, districts, colleges, and universities; EdTech and children's online services
Applies to: For educational agencies/institutions receiving funds under US Department of Education programs. Confirm funding and education-record scope; not every private school is automatically covered. Rights transfer to eligible students at age 18 or attendance at a postsecondary institution. Vendor access and disclosures require their own exception and control review.
Check applicability for Family Educational Rights and Privacy Act
Does the educational institution receive covered Department of Education funding and maintain education records?
Are the relevant rights held by a parent or an eligible student, and what authorizes any vendor access/disclosure?
Source and scope notes updated . Assessment review is separate.
Official references for Family Educational Rights and Privacy Act
Applies to: Check whether an online service is directed to children under 13 or has actual knowledge it collects their personal information. The FTC FAQ reflects the rule amended April 22, 2025; source current requirements from 16 CFR Part 312 and keep guidance separate from binding provisions.
Check applicability for Children's Online Privacy Protection Rule
Is the website or online service directed to children under 13, including a mixed-audience service?
Do you have actual knowledge that you collect personal information from children under 13?
What identifiers or other COPPA-defined personal information does the service collect, use or disclose?
Are you the service operator or another party collecting children’s information through that service?
Source and scope notes updated . Assessment review is separate.
Official references for Children's Online Privacy Protection Rule
CMMC, DFARS, and NIST SP 800-171 contract requirements
Regulation · 32 CFR Part 170 · DFARS 252.204-7012 · NIST SP 800-171 as contractually applicable · DFARS 252.204-7021
Best for: Cloud providers; Managed service providers; Managed security and SOC providers; and other relevant industries
Applies to: Check the actual DoD contract clauses, FCI/CDI/CUI, system boundary, required CMMC level and assessment obligations. DFARS 252.204-7012 covers safeguarding and cyber-incident duties; 252.204-7021 and 32 CFR Part 170 address CMMC. Under 7012(b)(2)(ii)(D), external cloud services handling covered defense information need FedRAMP Moderate-equivalent security and specified incident/evidence duties. This is separate from general FedRAMP scope; ordinary commercial hosting is not automatically covered.
Check applicability for CMMC, DFARS, and NIST SP 800-171 contract requirements
Does an applicable contract contain the cited safeguarding or cyber clause?
Will your systems process, store or transmit federal contract information in contract performance?
Will the uploaded package contain Controlled Unclassified Information or covered defense information?
Which CMMC level and assessment type are specified in the solicitation or contract?
What CMMC assessment level and assessment/affirmation requirements does the actual solicitation or contract specify?
Source and scope notes updated . Assessment review is separate.
Official references for CMMC, DFARS, and NIST SP 800-171 contract requirements
Export Administration Regulations compliance program
Regulation · 15 CFR Parts 730-774
Best for: Semiconductor and electronics manufacturing; Aerospace and defense manufacturing; DoD contractors and defense manufacturers; and other relevant industries
Applies to: EAR scope depends on items, software/technology, destination, end user/use and relevant US-person activities. BIS export-compliance program guidance supports internal controls but does not determine a transaction’s classification, license or exception. Restricted/export-controlled materials require an approved processing environment; this family is not an ITAR assessment.
Check applicability for Export Administration Regulations compliance program
What items/technology, destinations, end users and end uses are involved, including any reexport or transfer?
Which EAR classification, restrictions, license or exception and US-person activity conditions apply?
Source and scope notes updated . Assessment review is separate.
Authority / publisherBureau of Industry and Security
SEC cybersecurity incident and governance disclosures
Regulation · SEC Release 33-11216; applicable Regulation S-K and Form 8-K provisions
Best for: Investment advisers and funds; Broker-dealers; SEC reporting companies
Applies to: For SEC reporting issuers under the applicable forms and disclosure rules. Domestic issuers and foreign private issuers have different form requirements. Evaluate incident materiality decisions and governance/risk-management disclosures separately; the reporting trigger is not every cyber incident and is not determined solely by discovery time.
Check applicability for SEC cybersecurity incident and governance disclosures
Is this a domestic reporting issuer or foreign private issuer, and which forms govern its disclosures?
Who determines incident materiality, and how does the organization meet its applicable disclosure deadlines and governance disclosures?
Source and scope notes updated . Assessment review is separate.
Authority / publisherSecurities and Exchange Commission
Insurance data security laws based on NAIC Model 668
Model law · State-enacted insurance data security laws; NAIC Model Law 668 as research seed
Best for: Insurance carriers, agencies, and licensees
Applies to: NAIC Model 668 is a model, not binding law by itself. An insurer or other licensee must review each applicable state enactment, licensing scope, exemptions and notification/security-program provisions. Do not apply a single nationwide threshold or deadline from the model; state law and the licensee’s facts control.
Check applicability for Insurance data security laws based on NAIC Model 668
In which states is the organization licensed, and which enacted insurance data-security laws apply?
What licensee type, size/data thresholds and statutory exemptions apply under each state enactment?
Source and scope notes updated . Assessment review is separate.
Authority / publisherState insurance regulators · National Association of Insurance Commissioners
Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries
Applies to: Check EU establishment, offering goods/services to or monitoring people in the EU, and the controller/processor role. A cloud, MSP or security provider may be a processor with contract and security duties. EU data-subject location alone does not establish every territorial-scope condition; verify Articles 3 and 28 and relevant national rules.
Check applicability for EU General Data Protection Regulation
Does processing occur in the context of an EU establishment’s activities?
Does the organization offer goods/services to people in the EU or monitor their behavior there?
Do you determine the purposes and means of processing personal data, or process it on a customer’s documented instructions?
Where are the relevant people located for the processing activity, and which Article 3 scope condition is met?
Source and scope notes updated . Assessment review is separate.
Authority / publisherEuropean Union · Supervisory authorities
Applies to: For registered entities and BES Cyber Systems within the applicable NERC CIP standards and impact classifications. A single CIP-011 page does not establish complete CIP coverage or every effective version. Verify the applicable approved standard/implementation plan and asset boundary. Rights review remains required, and BES Cyber System Information cannot enter ordinary self-service intake.
Check applicability for NERC Critical Infrastructure Protection standards
Which registered-entity functions, BES Cyber Systems and impact ratings define the applicable CIP scope?
Which approved CIP versions and implementation dates govern those assets and document package?
Will the uploaded package contain BES Cyber System Information?
Source and scope notes updated . Assessment review is separate.
Authority / publisherNorth American Electric Reliability Corporation · Federal Energy Regulatory Commission
Regulatory family · 44 USC 3607–3616 · OMB Memorandum M-24-15 · FedRAMP Consolidated Rules for 2026 — Scope
Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries
Applies to: Potentially relevant to cloud offerings handling federal information for US agencies. The agency determines whether its use case is in scope; not every government user, internet service, MSP or physical data centre needs FedRAMP. Check the offering boundary and exceptions. This research family does not authorize AuditReady to process CUI or issue a FedRAMP certification.
Check applicability for FedRAMP federal cloud service scope
Will a US federal agency use this cloud service for an agency function?
Will the offering create, collect, process, store or maintain federal information on behalf of the agency?
Is this an operated IaaS, PaaS or SaaS cloud offering, rather than only consulting or physical colocation?
Does the agency use a shared cloud offering with a provider/agency responsibility boundary?
Has the agency assessed any applicable FedRAMP scope exception?
Source and scope notes updated . Assessment review is separate.
Authority / publisherGeneral Services Administration · Office of Management and Budget
FDA seafood, juice and produce-specific food safety
Regulation · 21 CFR Part 123 (seafood HACCP) · 21 CFR Part 120 (juice HACCP) · 21 CFR Part 112 (produce safety)
Best for: Seafood, juice, and produce operations
Applies to: Seafood processors, juice processors and covered produce farms have distinct FDA product/activity-specific regimes. Identify the product, processing or farm role and exclusions before selecting Parts 123, 120 or 112. These are not one universal food checklist, and Part 117 preventive-controls exemptions do not eliminate every food-safety duty.
Check applicability for FDA seafood, juice and produce-specific food safety
Are you processing seafood or juice, or growing/harvesting/packing/holding covered produce?
Which product, farm/activity, retail, size or other exclusions and modified requirements apply?
Source and scope notes updated . Assessment review is separate.
Official references for FDA seafood, juice and produce-specific food safety
Regulation · 40 CFR Parts 260–273; select generator, transporter and facility provisions
Best for: Pharmaceutical and biotechnology manufacturers; Chemical and petrochemical manufacturing; General and metal manufacturing; and other relevant industries
Applies to: For activities involving wastes classified as hazardous under the applicable federal/state RCRA program. Generator category, accumulation, transport, treatment/storage/disposal and permit status determine requirements. Authorized state programs can be broader or more stringent. An industrial-sector label or a recycling operation alone does not establish every hazardous-waste duty.
Check applicability for RCRA hazardous-waste management
What hazardous-waste determinations and generator, transporter or treatment/storage/disposal roles apply?
Which federal or authorized-state program, generator category, exclusions and permits govern the facility?
Source and scope notes updated . Assessment review is separate.
Official references for RCRA hazardous-waste management
Regulation · 49 CFR Parts 190–199; Parts 192 and 195 as applicable
Best for: Pipeline and LNG operators
Applies to: For pipelines and operators within the applicable federal/state pipeline-safety regime. Gas and hazardous-liquid systems have different Parts 192 and 195 requirements; facility jurisdiction, pipeline classification, location and exclusions matter. LNG has additional requirements to review. DOT testing and a generic emergency action plan do not supply complete pipeline-safety coverage.
Check applicability for PHMSA pipeline safety
What commodity, pipeline/facility classification and operator responsibilities are involved?
Which PHMSA or state jurisdiction, exclusions and operating/integrity-management provisions apply?
Source and scope notes updated . Assessment review is separate.
Best for: Chemical and petrochemical manufacturing; Battery manufacturing and hazardous-material warehousing; Hazardous waste, landfill, and recycling facilities; and other relevant industries
Applies to: For hazardous materials offered or transported in commerce within the DOT Hazardous Materials Regulations. Classification, quantity, packaging, offeror/carrier roles and highway/rail/air/vessel modes determine duties and exceptions. Review special permits and security-plan triggers separately. Part 40 employee testing does not replace hazardous-materials transport requirements.
Check applicability for DOT hazardous-materials transportation
Which materials, classifications, quantities and offeror/carrier functions are involved?
Which transport modes, packaging, exceptions or special permits and security-plan triggers apply?
Source and scope notes updated . Assessment review is separate.
Authority / publisherPipeline and Hazardous Materials Safety Administration
Showing 53 of 53 research packs. A listing is not a legal applicability conclusion or a claim that assessment coverage is ready.
Current assessment packs
Assessment packs currently in development.
Safeguards and Red Flags can enter today’s quote flow. The Safeguards layer includes 55 Safeguards checks plus 3 Disposal checks at no additional charge: 58 checks for $0.25 per page. Red Flags adds 13 checks as a separate layer. HIPAA Security adds 63 policy checks for medical and dental covered entities at $0.50 per page, without patient data. All four packs remain drafts.
Draft · quote candidate63requirements
HIPAA Security Rule
45 CFR Part 164 · Department of Health and Human Services
We distinguish researched regulations, identified official sources, draft assessment packs and reviewed coverage so you can see what AuditReady can and cannot assess. A catalog listing does not mean paid analysis is available.
How we build a rule pack
Official text first. Review before findings.
DoneOfficial text pinned
eCFR XML is retrieved, dated and fingerprinted with SHA-256.
Done · draftRequirements authored
Each atomic requirement stores a citation, official link and passage hash.
Coming soonIndependent review
A named compliance and legal reviewer signs the version.
Coming soonPublished version
The reviewed pack is frozen before customer findings open.
How we count our numbers
Generated from versioned files—not marketing estimates.
162 instruments
Laws, regulations, guidance and frameworks in the research catalog as of 2026-09-26. A listing is not assessment coverage.
40 source registries
Government publishers, agencies, self-regulatory bodies and framework libraries we track. “Registry” does not always mean a government authority.
134 draft requirements
134/134 have an official section URL and passage hash across the FTC and HIPAA draft packs.
6 pinned texts
Official eCFR source snapshots with retrieval dates and SHA-256 fingerprints in the repository.