What we check

Find the rules that may apply
to your organization.

You don’t need to know regulatory acronyms. Start with your business to narrow the laws, regulations, standards and frameworks worth reviewing.

53 regulatory families15 industry groups56 industry profiles
How we narrow the rules

Your business comes first.

Industry → Location → Activities → Regulatory scope → Document type

IndustryJurisdictionBusiness activitiesData handledLicenses, contracts & fundingSize & thresholdsDocument type

Industry alone does not establish applicability. Your location, activities, data, licenses, contracts, funding and relevant thresholds can change which rules matter. Recommendations are a starting point for review, not a legal conclusion.

Browse by business area

Start with your business.

Choose an area to explore the industries and regulatory families in our research catalog.

Find relevant rules

Tell us what you’re reviewing.

This narrows research candidates using catalog mappings. It does not determine which law applies. State or country, activities, thresholds and your answers to each pack’s applicability questions still require review.

Regulatory catalog

Explore 53 regulatory families.

Browse laws, regulations, standards and frameworks. Source identification and assessment availability are separate statuses.

Official source identified

NIS2 and national transpositions

Law · Directive (EU) 2022/2555 · Commission Implementing Regulation (EU) 2024/2690

Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries

Applies to: Potentially relevant to covered cloud, data-centre, DNS/CDN, managed service and managed security providers with an EU nexus. Confirm service definitions, size rules and exceptions, main establishment, and the applicable national implementing law. Commission Implementing Regulation (EU) 2024/2690 specifies risk-management measures and significant-incident criteria for listed digital providers; it does not replace national applicability review.

Check applicability for NIS2 and national transpositions
  • Do you operate or provide the relevant service in an EU or EEA member state?
  • Do you meet the employee or financial thresholds used by this authority?
  • Does your principal activity fall within a sector covered by this authority?
  • Do you provide one of the services identified by this authority?
  • Are you established, represented, or offering the service in the relevant jurisdiction?

Source and scope notes updated . Assessment review is separate.

Official references for NIS2 and national transpositions
Authority / publisherEuropean Union · Member-state authorities
Official source identified

Digital Operational Resilience Act

Regulation · Regulation (EU) 2022/2554

Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries

Applies to: Distinguish regulated financial entities from their ICT suppliers. A cloud, MSP or security provider may face customer-contract duties; direct EU oversight follows designation as a critical ICT third-party provider. Check the service, EU financial customer, contract and critical-provider designation rather than treating every ICT supplier as a financial entity.

Check applicability for Digital Operational Resilience Act
  • Are you one of the financial-entity types named by the rule?
  • Do you supply ICT services to EU financial entities, and which services support their critical or important functions?
  • Which DORA security, incident, audit, exit and subcontracting obligations appear in your financial-customer contracts?
  • Do you operate or provide the relevant service in an EU or EEA member state?
  • Have the European Supervisory Authorities designated your organization as a critical ICT third-party provider?

Source and scope notes updated . Assessment review is separate.

Official references for Digital Operational Resilience Act
Authority / publisherEuropean Union
Official source identified

NIST Cybersecurity Framework 2.0

Voluntary framework · NIST CSWP 29

Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries

Applies to: Voluntary cybersecurity risk-management framework for organizations of any size or sector. Customer contracts may request alignment; it is not a law or a certification. Map the selected profile and desired outcomes; do not score optional framework alignment as a legal violation.

Check applicability for NIST Cybersecurity Framework 2.0
  • Has your organization or a customer selected a NIST CSF profile or outcomes to evaluate?
  • Does a customer contract, regulator or internal policy require a particular CSF profile or outcome set?

Source and scope notes updated . Assessment review is separate.

Authority / publisherNational Institute of Standards and Technology
Assessment requires content rights

ISO/IEC 27001:2022

Standard · ISO/IEC 27001:2022 · ISO/IEC 27001:2022/Amd 1:2024

Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries

Applies to: ISO/IEC 27001:2022 is an information-security management-system standard, with Amendment 1:2024 also listed by ISO. Certification or alignment may be requested by customers; this is not automatically a legal duty. Assessment content remains mapping-only until reuse rights and specialist review are resolved; AuditReady cannot issue certification.

Check applicability for ISO/IEC 27001:2022
  • Has a customer or your organization requested this standard or assurance engagement, and for which system boundary?
  • Which services, sites, assets and processes are inside the requested certification boundary?

Source and scope notes updated . Assessment review is separate.

Authority / publisherISO · IEC
Assessment requires content rights

SOC 2 Trust Services Criteria

Standard · Trust Services Criteria

Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries

Applies to: SOC 2 is an AICPA assurance reporting service for service organizations, not a general law or an ISO-style certification. Scope depends on the system, trust-services categories and engagement. Customer requirements can drive the engagement. Content-rights review and CPA expertise are required; AuditReady cannot issue a SOC report.

Check applicability for SOC 2 Trust Services Criteria
  • Has a customer or your organization requested this standard or assurance engagement, and for which system boundary?
  • Which trust-services categories and reporting period are in the planned SOC 2 engagement?

Source and scope notes updated . Assessment review is separate.

Authority / publisherAICPA
Assessment requires content rights

PCI DSS v4.0.1

Standard · PCI DSS v4.0.1

Best for: Data centers and colocation; Cloud providers; Fintech and payment processors

Applies to: PCI DSS v4.0.1 is a payment-account security standard. Check whether the organization stores, processes or transmits account data, or can affect the cardholder-data environment, and confirm its merchant/service-provider role. Customer and payment-brand arrangements determine validation obligations. Content permission and qualified review remain required; AuditReady readiness is not PCI validation.

Check applicability for PCI DSS v4.0.1
  • Do you store, process or transmit payment-account data, or provide services that can affect a cardholder-data environment?
  • What payment-brand/acquirer validation requirements apply to your merchant volume and channels?
  • Do you store, process or transmit cardholder data, or provide services that can affect payment-data security?
  • Which systems and services are within or can affect the cardholder-data environment?

Source and scope notes updated . Assessment review is separate.

Authority / publisherPCI Security Standards Council
Official source identified

FCC customer proprietary network information rules

Regulation · 47 USC 222 · 47 CFR Part 64 Subpart U

Best for: Telecom, VoIP, and internet providers

Applies to: For telecommunications carriers and interconnected VoIP providers handling customer proprietary network information. Ordinary cloud or IT services do not establish carrier status. Confirm service classification and the annual CPNI certification duty; the FCC filing page is guidance, while 47 USC 222 and the applicable Part 64 rules govern.

Check applicability for FCC customer proprietary network information rules
  • Are you a telecommunications carrier or interconnected VoIP provider, and which services create CPNI?
  • Is an annual CPNI certification required for your service and reporting year?

Source and scope notes updated . Assessment review is separate.

Authority / publisherFederal Communications Commission
Official source identified

Bank Secrecy Act and AML program requirements

Regulation · 31 CFR Chapter X

Best for: Banks and credit unions; Broker-dealers; Fintech and payment processors; and other relevant industries

Applies to: For institutions subject to the appropriate Bank Secrecy Act rules. Banks must review 31 CFR Parts 1010 and 1020; other financial businesses have different institution-specific parts. The FFIEC examination manual is guidance, and a written policy alone does not demonstrate implementation of a risk-based AML program.

Check applicability for Bank Secrecy Act and AML program requirements
  • Are you a bank, MSB, casino or another defined financial institution, and which Chapter X part applies?
  • What products, customers, jurisdictions and delivery channels determine your money-laundering risk?

Source and scope notes updated . Assessment review is separate.

Authority / publisherFinCEN · Federal banking agencies
Official source identified

Federal banking and credit-union information security

Regulation · Agency-specific GLBA security guidelines · FDIC: 12 CFR Part 364 Appendix B; select the correct agency variant · NCUA: 12 CFR Part 748; distinguish regulatory provisions and guidance

Best for: Banks and credit unions

Applies to: For institutions overseen by the relevant banking agency or NCUA. Identify charter, insurer/supervisor and customer/member-information scope before selecting agency-specific security provisions. FDIC institutions use the appropriate Part 364 variant; federally insured credit unions require NCUA Part 748 review. Distinguish binding provisions from guidance, and check proposed guidance changes separately. These regimes and the FTC Safeguards Rule are not interchangeable.

Check applicability for Federal banking and credit-union information security
  • What is the institution’s charter and primary federal supervisor?
  • What customer information is maintained by the institution or its service providers?

Source and scope notes updated . Assessment review is separate.

Official references for Federal banking and credit-union information security
Authority / publisherFDIC · OCC · Federal Reserve · NCUA · National Credit Union Administration
Draft · quote & pre-scan

FTC Safeguards Rule

Regulation · 16 CFR Part 314

Best for: Managed service providers; Tax preparers and CPA firms; Auto dealers that finance or lease; and other relevant industries

Applies to: Certain financial institutions under FTC jurisdiction must safeguard customer information; activities and regulator routing determine coverage. Banks supervised under other GLBA regulators must be routed to their own rules. An MSP is not automatically a covered financial institution: assess customer-contract duties and any external Qualified Individual role separately from direct institutional duties.

Check applicability for FTC Safeguards Rule
  • Does the organization engage in a financial activity covered by the applicable GLBA rule?
  • Is the organization subject to FTC jurisdiction for the activity being assessed?
  • Does the organization maintain customer information covered by the rule?
  • How many consumers’ customer information records do you maintain, and do any section 314.6 exemptions apply?

Source and scope notes updated . Assessment review is separate.

Official references for FTC Safeguards Rule
Authority / publisherFederal Trade Commission
Draft · quote & pre-scan

FTC Red Flags Rule

Regulation · 16 CFR Part 681

Best for: Auto dealers that finance or lease; Mortgage lenders and servicers; Consumer lenders and debt collectors

Applies to: For FTC-supervised financial institutions and defined creditors that offer or maintain covered accounts. Deferred billing alone does not resolve every creditor condition. Evaluate personal/household accounts with multiple transactions and other accounts with reasonably foreseeable identity-theft risk; other regulators use their own rules.

Check applicability for FTC Red Flags Rule
  • Does the organization meet the rule’s financial-institution or creditor definition under FTC enforcement?
  • Which accounts involve multiple consumer transactions or reasonably foreseeable identity-theft risk?

Source and scope notes updated . Assessment review is separate.

Authority / publisherFederal Trade Commission
Official source identified

NYDFS Cybersecurity Regulation

Regulation · 23 NYCRR Part 500

Best for: Banks and credit unions; Fintech and payment processors; Money services and qualifying virtual-asset businesses; and other relevant industries

Applies to: Scope follows a New York DFS license, registration, charter or similar authorization under the Banking, Insurance or Financial Services Laws, with full/limited exemptions to review. An ICT supplier is not automatically a Covered Entity; customer contracts can require third-party controls. Review the current amended regulation and applicable phase-in dates. DFS also published risk-assessment guidance on September 10, 2026.

Check applicability for NYDFS Cybersecurity Regulation
  • Which New York DFS licenses, registrations or authorizations does the organization hold?
  • Does the licensed organization fall within the covered-entity definition for Part 500?
  • Which specific exemption conditions can the organization substantiate, and which duties remain?
  • Does the organization meet the Part 500 Class A definition or another applicable entity classification?

Source and scope notes updated . Assessment review is separate.

Authority / publisherNew York State Department of Financial Services
Official source identified

Investment adviser compliance program rule

Regulation · Investment Advisers Act Rule 206(4)-7

Best for: Investment advisers and funds

Applies to: For investment advisers registered with the SEC under Rule 206(4)-7. Registered investment companies have a separate Rule 38a-1 regime. Review written procedures, annual effectiveness review and the chief compliance officer for the actual adviser/fund role; state-registered advisers require their state-specific rules.

Check applicability for Investment adviser compliance program rule
  • Is this adviser registered or required to be registered with the SEC, or supervised at state level?
  • Is the document for an adviser or a registered investment company with separate board and compliance duties?

Source and scope notes updated . Assessment review is separate.

Authority / publisherSecurities and Exchange Commission
Official source identified

Regulation S-P and financial privacy

Regulation · 17 CFR Part 248 · 16 CFR Part 313 · 12 CFR Part 1016

Best for: Investment advisers and funds; Broker-dealers; Mortgage lenders and servicers; and other relevant industries

Applies to: The SEC Regulation S-P regime applies to defined SEC-covered institutions; FTC Part 313 and CFPB Regulation P are separate privacy regimes. The 2024 S-P safeguards and incident-response amendments had phased compliance dates in December 2025 and June 2026. Confirm institution category, covered customer information and the correct regulator before selecting requirements.

Check applicability for Regulation S-P and financial privacy
  • Is this an SEC-covered broker-dealer, investment company, registered adviser or covered transfer agent?
  • Which SEC, FTC or CFPB privacy regime governs the institution and consumer relationship?
  • Which 2024 S-P amendment provisions apply to your institution’s category and size?

Source and scope notes updated . Assessment review is separate.

Official references for Regulation S-P and financial privacy
Authority / publisherSecurities and Exchange Commission · Federal Trade Commission · Consumer Financial Protection Bureau
Official source identified

Regulation X servicing policies and procedures

Regulation · 12 CFR 1024.38

Best for: Mortgage lenders and servicers

Applies to: For mortgage servicing within Regulation X Subpart C. Section 1024.30 excludes specified loans and servicers from sections 1024.38–1024.41, including qualifying small servicers subject to the stated exceptions. Confirm the mortgage type and actual servicing role; a small-servicer exemption does not remove every servicing obligation.

Check applicability for Regulation X servicing policies and procedures
  • Do you service mortgage loans within section 1024.31 rather than only originate or broker them?
  • Do the section 1024.30 loan, small-servicer or other exemptions apply, and which obligations remain?

Source and scope notes updated . Assessment review is separate.

Official references for Regulation X servicing policies and procedures
Authority / publisherConsumer Financial Protection Bureau
Official source identified

Money services business AML program

Regulation · 31 CFR 1022.210

Best for: Money services and qualifying virtual-asset businesses

Applies to: For businesses within the relevant MSB definitions and AML program rules in 31 CFR 1022.210. Identify money-services activities, principal/agent roles and exemptions separately from registration. FinCEN guidance explains that a principal and its agents cannot contract away their own AML responsibilities; agent monitoring must reflect risk.

Check applicability for Money services business AML program
  • Which money-services activities do you perform, and do any definition or exemption conditions apply?
  • Are you an MSB principal, an agent, or both, and how do you monitor the relevant agents?

Source and scope notes updated . Assessment review is separate.

Official references for Money services business AML program
Authority / publisherFinancial Crimes Enforcement Network
Official source identified

Casino AML program requirements

Regulation · 31 CFR 1021.210

Best for: Casinos and card clubs

Applies to: For licensed or authorized casinos and card clubs meeting the BSA definition, including the gross annual gaming revenue threshold above $1 million. Confirm state, territory or tribal gaming authority and the actual gaming activities. The older FinCEN FAQ uses historical Part 103 citations; current obligations must be traced to Parts 1010 and 1021.

Check applicability for Casino AML program requirements
  • Is this a duly licensed or authorized casino or card club under the relevant jurisdiction?
  • Does gross annual gaming revenue exceed the applicable $1 million BSA threshold?

Source and scope notes updated . Assessment review is separate.

Official references for Casino AML program requirements
Authority / publisherFinancial Crimes Enforcement Network
Draft · quote & pre-scan

HIPAA Security, Privacy, and Breach Notification Rules

Regulation · 45 CFR Parts 160 and 164

Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries

Applies to: 63 draft policy-wording checks for US medical and dental covered entities without patient data. Covered-entity, ePHI and vendor facts require confirmation. Addressable safeguards allow documented alternatives when appropriate. Privacy, Breach Notification, group-health-plan, clearinghouse-specific and business-associate-only duties are outside this preview. Proposed rules do not affect findings.

Check applicability for HIPAA Security, Privacy, and Breach Notification Rules
  • Are you a HIPAA covered entity, or do you create, receive, maintain or transmit PHI for a covered entity or another business associate?
  • Which protected health information does the service handle, and under whose business-associate agreement?
  • Does your service handle electronic PHI, including encrypted information for which you do not hold the decryption key?
  • What size, complexity, capabilities and risk factors affect implementation of your HIPAA safeguards?
  • For each addressable implementation specification, have you evaluated reasonableness and documented any alternative?

Source and scope notes updated . Assessment review is separate.

Official references for HIPAA Security, Privacy, and Breach Notification Rules
Authority / publisherDepartment of Health and Human Services
Official source identified

Confidentiality of substance use disorder patient records

Regulation · 42 CFR Part 2

Best for: Behavioral health and substance-use treatment

Applies to: Applies to qualifying federally assisted substance-use-disorder programs and other recipients subject to Part 2 duties, not every behavioral-health record. HHS reports that the 2024 final rule became effective April 16, 2024, with compliance required February 16, 2026. Confirm program/recipient role and the records involved.

Check applicability for Confidentiality of substance use disorder patient records
  • Is the organization or record system a Part 2 program or lawful holder of Part 2 records?
  • Does the substance-use-disorder program receive federal assistance within the Part 2 definition?
  • Are these patient-identifying substance-use-disorder records within Part 2 scope?
  • Are you the originating Part 2 program, a lawful holder or another recipient, and what authorizes use/disclosure?
  • Will any uploaded document contain electronic protected health information?

Source and scope notes updated . Assessment review is separate.

Official references for Confidentiality of substance use disorder patient records
Authority / publisherDepartment of Health and Human Services
Official source identified

CMS Conditions of Participation and Coverage

Regulation · Provider-specific Medicare Conditions of Participation and Coverage

Best for: Hospitals and health systems; Long-term care, home health, hospice, and dialysis

Applies to: For provider and supplier types participating under the applicable Medicare/Medicaid Conditions of Participation or Coverage. Hospitals, home health agencies, hospices, ambulatory surgery centers and other providers have different conditions. Identify the specific facility and certification pathway; this umbrella family cannot supply one universal healthcare checklist.

Check applicability for CMS Conditions of Participation and Coverage
  • Which exact CMS provider or supplier category and facility certification apply?
  • Under which Medicare or Medicaid participation conditions is this facility certified?
  • Will any uploaded document contain electronic protected health information?

Source and scope notes updated . Assessment review is separate.

Authority / publisherCenters for Medicare & Medicaid Services
Official source identified

CMS emergency preparedness requirements

Regulation · Provider-specific emergency preparedness regulations

Best for: Hospitals and health systems; Long-term care, home health, hospice, and dialysis

Applies to: For provider and supplier categories covered by the CMS emergency-preparedness regulations. The program covers risk assessment/planning, policies and procedures, communication, and training/testing, with requirements that vary by provider category. Use the applicable provider regulation and survey guidance; a generic emergency plan does not establish facility compliance.

Check applicability for CMS emergency preparedness requirements
  • Which CMS provider/supplier regulation governs this facility’s emergency-preparedness program?
  • What patient needs, local hazards, utilities, communications and continuity dependencies must its plan address?
  • Will any uploaded document contain electronic protected health information?

Source and scope notes updated . Assessment review is separate.

Authority / publisherCenters for Medicare & Medicaid Services
Official source identified

Clinical Laboratory Improvement Amendments

Regulation · 42 CFR Part 493

Best for: Clinical and medical laboratories

Applies to: For laboratory examination of human specimens for diagnosis, prevention, treatment or health assessment within CLIA scope. Confirm certificate type and test complexity; waived, provider-performed microscopy and nonwaived testing have different requirements. Research-only testing without patient-specific reporting and other exceptions need review. State requirements can also apply.

Check applicability for Clinical Laboratory Improvement Amendments
  • Are human specimens tested for patient diagnosis/treatment or only for exempt research purposes?
  • What CLIA certificate and test-complexity categories cover the actual testing?
  • Will any uploaded document contain electronic protected health information?

Source and scope notes updated . Assessment review is separate.

Authority / publisherCenters for Medicare & Medicaid Services
Official source identified

FDA Quality Management System Regulation

Regulation · 21 CFR Part 820 · ISO 13485:2016 incorporated by reference

Best for: Medical-device manufacturers

Applies to: QMSR is effective from February 2, 2026. Confirm the device-manufacturer role and applicable requirements of 21 CFR Part 820; ISO 13485:2016 is incorporated by reference and its text remains rights-sensitive.

Check applicability for FDA Quality Management System Regulation
  • What medical-device manufacturing role places the organization within FDA QMSR scope?
  • Which device classifications and product-specific regulatory requirements apply?
  • Which design, manufacturing, servicing or other operations are covered by the quality-system boundary?
  • Do any device-specific exemptions apply, and which quality-system duties remain?

Source and scope notes updated . Assessment review is separate.

Official references for FDA Quality Management System Regulation
Authority / publisherFood and Drug Administration
Assessment requires content rights

ISO 13485:2016

Standard · ISO 13485:2016

Best for: Medical-device manufacturers

Applies to: ISO 13485:2016 identifies a medical-device quality-management standard. Confirm the organization’s device lifecycle role, certification boundary and applicable market rules. FDA QMSR incorporates this edition for covered US device manufacturers, but certification alone does not establish FDA compliance. Requirement-text use remains subject to licensing.

Check applicability for ISO 13485:2016
  • Do you design, manufacture, install, service or supply medical devices, and within which certification boundary?
  • Which national device regulations or customer contracts require this standard for that role?

Source and scope notes updated . Assessment review is separate.

Authority / publisherInternational Organization for Standardization
Official source identified

FDA electronic records and signatures

Regulation · 21 CFR Part 11

Best for: Medical-device manufacturers; Pharmaceutical and biotechnology manufacturers; Clinical research sites and contract research organizations

Applies to: Applies to electronic records and signatures within the scope of FDA predicate-rule record requirements and qualifying electronic submissions. It is not a universal rule for every electronic business document. Identify the predicate rule, record/signature use and system before assessing requirements.

Check applicability for FDA electronic records and signatures
  • Which FDA predicate rule requires these records to be maintained or submitted?
  • Are required records maintained/submitted electronically rather than only paper records or convenience copies?
  • Are electronic signatures used in place of signatures required by the applicable FDA rules?

Source and scope notes updated . Assessment review is separate.

Authority / publisherFood and Drug Administration
Official source identified

Drug manufacturing current good manufacturing practice

Regulation · 21 CFR Parts 210 and 211

Best for: Pharmaceutical and biotechnology manufacturers; Pharmacies and compounding facilities

Applies to: For drug manufacturing and related operations within the applicable FDA CGMP regime. Parts 210 and 211 address finished pharmaceuticals; product type and operations can require other provisions. FDA production/process Q&A is nonbinding guidance, not the complete rule. Distinguish manufacturer, contract operation and outsourcing roles before choosing checks.

Check applicability for Drug manufacturing current good manufacturing practice
  • What drug product and manufacturing, packaging, testing or holding operations are performed?
  • Is the organization the manufacturer, contract facility or an outsourcing operation with its own applicable regime?

Source and scope notes updated . Assessment review is separate.

Official references for Drug manufacturing current good manufacturing practice
Authority / publisherFood and Drug Administration
Official source identified

FDA-regulated clinical research

Regulation · 21 CFR Parts 50, 56, 312, and 812 as applicable

Best for: Clinical research sites and contract research organizations

Applies to: Route by study and organization role: informed consent and IRBs (21 CFR Parts 50/56), investigational drugs (Part 312) and investigational devices (Part 812). A generic clinical-research label does not establish all four regimes; identify sponsor, investigator, IRB and study type first.

Check applicability for FDA-regulated clinical research
  • Does the clinical investigation involve drugs, biologics or medical devices, and which FDA regime applies?
  • Is an IND, IDE or a defined exemption applicable to this investigation?
  • Are you the sponsor, investigator, sponsor-investigator or another responsible study party?
  • What clinical investigation and participant/IRB protections fall within the applicable FDA rules?

Source and scope notes updated . Assessment review is separate.

Authority / publisherFood and Drug Administration
Official source identified

FSMA preventive controls and food safety plans

Regulation · 21 CFR Part 117 (human food) · 21 CFR Part 507 (animal food)

Best for: Food manufacturers and warehouses; Seafood, juice, and produce operations; Food cold-chain operators

Applies to: For food facilities within the applicable FDA preventive-controls rules. Human food Part 117 and animal food Part 507 are separate regimes, and registration, activities and exemptions affect scope. FDA’s Food Safety Plan Builder is optional and does not approve a plan. Qualified-facility or other modified requirements require a facts-based review.

Check applicability for FSMA preventive controls and food safety plans
  • Does the facility manufacture, process, pack or hold human or animal food within the applicable registration/rule scope?
  • Do qualified-facility, activity-specific or other exemption/modified-requirement conditions apply?

Source and scope notes updated . Assessment review is separate.

Official references for FSMA preventive controls and food safety plans
Authority / publisherFood and Drug Administration
Official source identified

FSIS HACCP and sanitation SOP requirements

Regulation · FSIS HACCP and Sanitation SOP regulations

Best for: Meat, poultry, and egg-product facilities

Applies to: For official establishments and products under the relevant USDA FSIS inspection regime. HACCP Part 417 and sanitation SOP Part 416 duties must be matched to the establishment, product and process category. FSIS inspection directives guide agency verification; they are not a substitute for the establishment’s binding regulatory requirements.

Check applicability for FSIS HACCP and sanitation SOP requirements
  • Which products and establishment operations are subject to FSIS inspection or an applicable state inspection program?
  • Which process categories and reasonably likely food-safety hazards determine the HACCP plan?

Source and scope notes updated . Assessment review is separate.

Official references for FSIS HACCP and sanitation SOP requirements
Authority / publisherFood Safety and Inspection Service
Official source identified

OSHA Process Safety Management

Regulation · 29 CFR 1910.119

Best for: Food cold-chain operators; Chemical and petrochemical manufacturing; Petroleum refining, terminals, and fuel storage; and other relevant industries

Applies to: For processes meeting OSHA 1910.119 chemical or flammable-material quantity conditions, subject to exclusions and applicable state-plan rules. Assess the process boundary and Appendix A substances rather than the industry name. PSM and EPA RMP have separate scope tests; one program does not automatically satisfy the other.

Check applicability for OSHA Process Safety Management
  • Which connected or nearby process vessels contain covered chemicals or flammable materials, and in what quantities?
  • Do retail, fuel-use, remote-facility or other exclusions and state-plan variations affect this process?

Source and scope notes updated . Assessment review is separate.

Authority / publisherOccupational Safety and Health Administration
Official source identified

EPA Risk Management Program

Regulation · 40 CFR Part 68

Best for: Chemical and petrochemical manufacturing; Petroleum refining, terminals, and fuel storage; Industrial gas and bulk chemical storage; and other relevant industries

Applies to: For stationary-source processes containing regulated substances above the applicable 40 CFR Part 68 thresholds. Determine substance, process, exceptions and program level separately from OSHA PSM. Current regulatory text and compliance dates govern; a 2026 EPA reconsideration proposal must not be treated as an effective replacement rule.

Check applicability for EPA Risk Management Program
  • Does a stationary-source process contain a listed regulated substance above its threshold, after applicable exceptions?
  • Which RMP program level and prevention/emergency-response duties apply to this process?

Source and scope notes updated . Assessment review is separate.

Official references for EPA Risk Management Program
Authority / publisherEnvironmental Protection Agency
Inactive · monitored

Chemical Facility Anti-Terrorism Standards monitor

Law · 6 CFR Part 27 historical program

Best for: Chemical and petrochemical manufacturing

Applies to: Historical chemical-facility security research only: statutory CFATS authority lapsed on July 28, 2023. This entry remains inactive and is not a current assessment requirement. Review any reauthorization against enacted authority before changing status; pre-lapse protected information can still have handling restrictions.

Check applicability for Chemical Facility Anti-Terrorism Standards monitor
  • Has enacted authority actually reauthorized CFATS, rather than only a proposal or historical CFR text?
  • Does the document contain chemical-terrorism vulnerability information protected under remaining handling authorities?

Source and scope notes updated . Assessment review is separate.

Official references for Chemical Facility Anti-Terrorism Standards monitor
Authority / publisherCybersecurity and Infrastructure Security Agency
Official source identified

AWIA water-system risk and resilience

Law · SDWA Section 1433 / AWIA Section 2013

Best for: Drinking-water utilities

Applies to: For community drinking-water systems serving more than 3,300 people under SDWA section 1433 as amended by AWIA. Risk/resilience assessments and emergency-response plans require certification and five-year review. ERP certification follows RRA certification within six months. Wastewater and smaller systems are not automatically covered by this population-based duty.

Check applicability for AWIA water-system risk and resilience
  • Is this a community drinking-water system serving more than 3,300 people?
  • When was its RRA certified, and what five-year review and six-month ERP certification dates follow?

Source and scope notes updated . Assessment review is separate.

Authority / publisherEnvironmental Protection Agency
Official source identified

NRC nuclear emergency preparedness

Regulation · 10 CFR 50.47 and 10 CFR Part 50 Appendix E

Best for: Nuclear power facilities

Applies to: For NRC licensees/facilities within their applicable emergency-planning regime. Nuclear power plant requirements include 10 CFR 50.47 and Part 50 Appendix E; other facility and license types require separate scope review. Evaluate the licensed facility, onsite/offsite planning responsibilities and approved licensing basis, rather than applying a single nuclear-industry template.

Check applicability for NRC nuclear emergency preparedness
  • What NRC license, reactor/facility type and licensing basis govern this site?
  • Which onsite/offsite emergency-planning standards and approved plan commitments apply?

Source and scope notes updated . Assessment review is separate.

Official references for NRC nuclear emergency preparedness
Authority / publisherNuclear Regulatory Commission
Official source identified

OSHA emergency action plans

Regulation · 29 CFR 1910.38

Best for: Data centers and colocation; Hospitals and health systems; Medical and dental practices; and other relevant industries

Applies to: An emergency action plan is required when another OSHA standard triggers 29 CFR 1910.38. Confirm the triggering standard and state-plan coverage. A plan must generally be written and available to employees; employers with ten or fewer employees may communicate it orally. Do not infer a written-plan violation solely from the industry label.

Check applicability for OSHA emergency action plans
  • Which OSHA standard requires an emergency action plan for this workplace?
  • How many employees does the employer have, and does the ten-or-fewer oral-plan exception apply?
  • Does an OSHA-approved state plan apply, and does it impose different workplace requirements?
  • What work activities, hazards and other OSHA standards trigger this workplace emergency-plan duty?

Source and scope notes updated . Assessment review is separate.

Authority / publisherOccupational Safety and Health Administration
Official source identified

NPDES industrial stormwater planning

Regulation · Clean Water Act NPDES industrial stormwater permit requirements

Best for: Wastewater utilities; General and metal manufacturing; Hazardous waste, landfill, and recycling facilities; and other relevant industries

Applies to: For covered industrial activities with stormwater discharges requiring NPDES permit coverage. Identify the industrial sector, discharge, permitting authority and applicable state/EPA permit. A no-exposure exclusion has specific conditions and certification duties. EPA sector fact sheets and templates are guidance; the operative permit determines facility requirements.

Check applicability for NPDES industrial stormwater planning
  • Which industrial activities and stormwater discharges occur at this site?
  • Which permit authority and current permit or certified no-exposure exclusion cover the discharge?

Source and scope notes updated . Assessment review is separate.

Authority / publisherEnvironmental Protection Agency · Authorized state agencies
Official source identified

Spill Prevention, Control, and Countermeasure plans

Regulation · 40 CFR Part 112

Best for: Petroleum refining, terminals, and fuel storage; Industrial gas and bulk chemical storage; Pipeline and LNG operators; and other relevant industries

Applies to: For non-transportation-related facilities within 40 CFR Part 112 oil-capacity and discharge-potential conditions. Evaluate facility-wide storage and the potential to discharge to covered waters. A Tier I template is limited to qualified facilities, including container-size and spill-history conditions; state professional-engineer rules can affect self-certification.

Check applicability for Spill Prevention, Control, and Countermeasure plans
  • What aboveground/buried oil capacities and discharge pathways place the facility within Part 112?
  • Does it meet qualified-facility, container-size and spill-history conditions for Tier I self-certification?

Source and scope notes updated . Assessment review is separate.

Authority / publisherEnvironmental Protection Agency
Official source identified

MSHA training and mine emergency plans

Regulation · 30 CFR Parts 46 and 48; MINER Act emergency plans where applicable

Best for: Mines, quarries, and mining contractors

Applies to: For miners and relevant mine contractors under the applicable MSHA training regime. Part 46 covers specified surface nonmetal operations; Part 48 covers underground and other mine categories. Training-plan approval and instructor rules differ. Mine emergency-response obligations require separate mine/type-specific review rather than a generic training checklist.

Check applicability for MSHA training and mine emergency plans
  • What commodity and surface/underground mine type determine Part 46 or Part 48 coverage?
  • Which miners and contractors perform covered work, and which training-plan/instructor requirements apply?

Source and scope notes updated . Assessment review is separate.

Official references for MSHA training and mine emergency plans
Authority / publisherMine Safety and Health Administration
Official source identified

DOT drug and alcohol testing procedures

Regulation · 49 CFR Part 40 and mode-specific rules

Best for: Pipeline and LNG operators; Battery manufacturing and hazardous-material warehousing; Commercial trucking and hazardous-material carriers; and other relevant industries

Applies to: Part 40 specifies procedures for DOT-required drug/alcohol testing; the applicable transportation agency rule determines who and when to test. Confirm the mode and safety-sensitive role, such as FMCSA-covered CDL operations under Part 382. Employers remain responsible when service agents perform testing tasks.

Check applicability for DOT drug and alcohol testing procedures
  • Which DOT agency rule and safety-sensitive job make testing required for these workers?
  • Who is the employer and which service agents perform collection, testing and return-to-duty functions?

Source and scope notes updated . Assessment review is separate.

Authority / publisherDepartment of Transportation · Modal administrations
Official source identified

FAA Safety Management Systems

Regulation · 14 CFR Part 5 and applicable Part 139 SMS requirements

Best for: Airlines, airports, and repair stations

Applies to: For operations/certificate holders within the applicable FAA SMS rule. The 2024 Part 5 expansion includes specified Part 21, Part 135 and section 91.147 operations; other organizations can participate voluntarily. Part 139 airport SMS has separate triggers/timelines. Existing covered Part 135 and 91.147 operators generally have a May 28, 2027 implementation date; new entrants follow their applicable certification/LOA conditions.

Check applicability for FAA Safety Management Systems
  • Which FAA operation, certificate or airport category determines mandatory versus voluntary SMS?
  • When was the certificate/LOA issued or application received, and which implementation timeline applies?

Source and scope notes updated . Assessment review is separate.

Official references for FAA Safety Management Systems
Authority / publisherFederal Aviation Administration
Official source identified

Family Educational Rights and Privacy Act

Regulation · 20 USC 1232g; 34 CFR Part 99

Best for: Schools, districts, colleges, and universities; EdTech and children's online services

Applies to: For educational agencies/institutions receiving funds under US Department of Education programs. Confirm funding and education-record scope; not every private school is automatically covered. Rights transfer to eligible students at age 18 or attendance at a postsecondary institution. Vendor access and disclosures require their own exception and control review.

Check applicability for Family Educational Rights and Privacy Act
  • Does the educational institution receive covered Department of Education funding and maintain education records?
  • Are the relevant rights held by a parent or an eligible student, and what authorizes any vendor access/disclosure?

Source and scope notes updated . Assessment review is separate.

Official references for Family Educational Rights and Privacy Act
Authority / publisherDepartment of Education
Official source identified

Children's Online Privacy Protection Rule

Regulation · 16 CFR Part 312

Best for: EdTech and children's online services

Applies to: Check whether an online service is directed to children under 13 or has actual knowledge it collects their personal information. The FTC FAQ reflects the rule amended April 22, 2025; source current requirements from 16 CFR Part 312 and keep guidance separate from binding provisions.

Check applicability for Children's Online Privacy Protection Rule
  • Is the website or online service directed to children under 13, including a mixed-audience service?
  • Do you have actual knowledge that you collect personal information from children under 13?
  • What identifiers or other COPPA-defined personal information does the service collect, use or disclose?
  • Are you the service operator or another party collecting children’s information through that service?

Source and scope notes updated . Assessment review is separate.

Official references for Children's Online Privacy Protection Rule
Authority / publisherFederal Trade Commission
Official source identified

CMMC, DFARS, and NIST SP 800-171 contract requirements

Regulation · 32 CFR Part 170 · DFARS 252.204-7012 · NIST SP 800-171 as contractually applicable · DFARS 252.204-7021

Best for: Cloud providers; Managed service providers; Managed security and SOC providers; and other relevant industries

Applies to: Check the actual DoD contract clauses, FCI/CDI/CUI, system boundary, required CMMC level and assessment obligations. DFARS 252.204-7012 covers safeguarding and cyber-incident duties; 252.204-7021 and 32 CFR Part 170 address CMMC. Under 7012(b)(2)(ii)(D), external cloud services handling covered defense information need FedRAMP Moderate-equivalent security and specified incident/evidence duties. This is separate from general FedRAMP scope; ordinary commercial hosting is not automatically covered.

Check applicability for CMMC, DFARS, and NIST SP 800-171 contract requirements
  • Does an applicable contract contain the cited safeguarding or cyber clause?
  • Will your systems process, store or transmit federal contract information in contract performance?
  • Will the uploaded package contain Controlled Unclassified Information or covered defense information?
  • Which CMMC level and assessment type are specified in the solicitation or contract?
  • What CMMC assessment level and assessment/affirmation requirements does the actual solicitation or contract specify?

Source and scope notes updated . Assessment review is separate.

Official references for CMMC, DFARS, and NIST SP 800-171 contract requirements
Authority / publisherDepartment of Defense
Official source identified

Export Administration Regulations compliance program

Regulation · 15 CFR Parts 730-774

Best for: Semiconductor and electronics manufacturing; Aerospace and defense manufacturing; DoD contractors and defense manufacturers; and other relevant industries

Applies to: EAR scope depends on items, software/technology, destination, end user/use and relevant US-person activities. BIS export-compliance program guidance supports internal controls but does not determine a transaction’s classification, license or exception. Restricted/export-controlled materials require an approved processing environment; this family is not an ITAR assessment.

Check applicability for Export Administration Regulations compliance program
  • What items/technology, destinations, end users and end uses are involved, including any reexport or transfer?
  • Which EAR classification, restrictions, license or exception and US-person activity conditions apply?

Source and scope notes updated . Assessment review is separate.

Authority / publisherBureau of Industry and Security
Official source identified

SEC cybersecurity incident and governance disclosures

Regulation · SEC Release 33-11216; applicable Regulation S-K and Form 8-K provisions

Best for: Investment advisers and funds; Broker-dealers; SEC reporting companies

Applies to: For SEC reporting issuers under the applicable forms and disclosure rules. Domestic issuers and foreign private issuers have different form requirements. Evaluate incident materiality decisions and governance/risk-management disclosures separately; the reporting trigger is not every cyber incident and is not determined solely by discovery time.

Check applicability for SEC cybersecurity incident and governance disclosures
  • Is this a domestic reporting issuer or foreign private issuer, and which forms govern its disclosures?
  • Who determines incident materiality, and how does the organization meet its applicable disclosure deadlines and governance disclosures?

Source and scope notes updated . Assessment review is separate.

Authority / publisherSecurities and Exchange Commission
Official source identified

Insurance data security laws based on NAIC Model 668

Model law · State-enacted insurance data security laws; NAIC Model Law 668 as research seed

Best for: Insurance carriers, agencies, and licensees

Applies to: NAIC Model 668 is a model, not binding law by itself. An insurer or other licensee must review each applicable state enactment, licensing scope, exemptions and notification/security-program provisions. Do not apply a single nationwide threshold or deadline from the model; state law and the licensee’s facts control.

Check applicability for Insurance data security laws based on NAIC Model 668
  • In which states is the organization licensed, and which enacted insurance data-security laws apply?
  • What licensee type, size/data thresholds and statutory exemptions apply under each state enactment?

Source and scope notes updated . Assessment review is separate.

Authority / publisherState insurance regulators · National Association of Insurance Commissioners
Official source identified

EU General Data Protection Regulation

Regulation · Regulation (EU) 2016/679

Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries

Applies to: Check EU establishment, offering goods/services to or monitoring people in the EU, and the controller/processor role. A cloud, MSP or security provider may be a processor with contract and security duties. EU data-subject location alone does not establish every territorial-scope condition; verify Articles 3 and 28 and relevant national rules.

Check applicability for EU General Data Protection Regulation
  • Does processing occur in the context of an EU establishment’s activities?
  • Does the organization offer goods/services to people in the EU or monitor their behavior there?
  • Do you determine the purposes and means of processing personal data, or process it on a customer’s documented instructions?
  • Where are the relevant people located for the processing activity, and which Article 3 scope condition is met?

Source and scope notes updated . Assessment review is separate.

Authority / publisherEuropean Union · Supervisory authorities
Assessment requires content rights

NERC Critical Infrastructure Protection standards

Standard · NERC CIP Reliability Standards

Best for: Electric utilities and power generation

Applies to: For registered entities and BES Cyber Systems within the applicable NERC CIP standards and impact classifications. A single CIP-011 page does not establish complete CIP coverage or every effective version. Verify the applicable approved standard/implementation plan and asset boundary. Rights review remains required, and BES Cyber System Information cannot enter ordinary self-service intake.

Check applicability for NERC Critical Infrastructure Protection standards
  • Which registered-entity functions, BES Cyber Systems and impact ratings define the applicable CIP scope?
  • Which approved CIP versions and implementation dates govern those assets and document package?
  • Will the uploaded package contain BES Cyber System Information?

Source and scope notes updated . Assessment review is separate.

Authority / publisherNorth American Electric Reliability Corporation · Federal Energy Regulatory Commission
Official source identified

FedRAMP federal cloud service scope

Regulatory family · 44 USC 3607–3616 · OMB Memorandum M-24-15 · FedRAMP Consolidated Rules for 2026 — Scope

Best for: Data centers and colocation; Cloud providers; Managed service providers; and other relevant industries

Applies to: Potentially relevant to cloud offerings handling federal information for US agencies. The agency determines whether its use case is in scope; not every government user, internet service, MSP or physical data centre needs FedRAMP. Check the offering boundary and exceptions. This research family does not authorize AuditReady to process CUI or issue a FedRAMP certification.

Check applicability for FedRAMP federal cloud service scope
  • Will a US federal agency use this cloud service for an agency function?
  • Will the offering create, collect, process, store or maintain federal information on behalf of the agency?
  • Is this an operated IaaS, PaaS or SaaS cloud offering, rather than only consulting or physical colocation?
  • Does the agency use a shared cloud offering with a provider/agency responsibility boundary?
  • Has the agency assessed any applicable FedRAMP scope exception?

Source and scope notes updated . Assessment review is separate.

Authority / publisherGeneral Services Administration · Office of Management and Budget
Official source identified

FDA seafood, juice and produce-specific food safety

Regulation · 21 CFR Part 123 (seafood HACCP) · 21 CFR Part 120 (juice HACCP) · 21 CFR Part 112 (produce safety)

Best for: Seafood, juice, and produce operations

Applies to: Seafood processors, juice processors and covered produce farms have distinct FDA product/activity-specific regimes. Identify the product, processing or farm role and exclusions before selecting Parts 123, 120 or 112. These are not one universal food checklist, and Part 117 preventive-controls exemptions do not eliminate every food-safety duty.

Check applicability for FDA seafood, juice and produce-specific food safety
  • Are you processing seafood or juice, or growing/harvesting/packing/holding covered produce?
  • Which product, farm/activity, retail, size or other exclusions and modified requirements apply?

Source and scope notes updated . Assessment review is separate.

Official references for FDA seafood, juice and produce-specific food safety
Authority / publisherFood and Drug Administration
Official source identified

RCRA hazardous-waste management

Regulation · 40 CFR Parts 260–273; select generator, transporter and facility provisions

Best for: Pharmaceutical and biotechnology manufacturers; Chemical and petrochemical manufacturing; General and metal manufacturing; and other relevant industries

Applies to: For activities involving wastes classified as hazardous under the applicable federal/state RCRA program. Generator category, accumulation, transport, treatment/storage/disposal and permit status determine requirements. Authorized state programs can be broader or more stringent. An industrial-sector label or a recycling operation alone does not establish every hazardous-waste duty.

Check applicability for RCRA hazardous-waste management
  • What hazardous-waste determinations and generator, transporter or treatment/storage/disposal roles apply?
  • Which federal or authorized-state program, generator category, exclusions and permits govern the facility?

Source and scope notes updated . Assessment review is separate.

Official references for RCRA hazardous-waste management
Authority / publisherEnvironmental Protection Agency
Official source identified

PHMSA pipeline safety

Regulation · 49 CFR Parts 190–199; Parts 192 and 195 as applicable

Best for: Pipeline and LNG operators

Applies to: For pipelines and operators within the applicable federal/state pipeline-safety regime. Gas and hazardous-liquid systems have different Parts 192 and 195 requirements; facility jurisdiction, pipeline classification, location and exclusions matter. LNG has additional requirements to review. DOT testing and a generic emergency action plan do not supply complete pipeline-safety coverage.

Check applicability for PHMSA pipeline safety
  • What commodity, pipeline/facility classification and operator responsibilities are involved?
  • Which PHMSA or state jurisdiction, exclusions and operating/integrity-management provisions apply?

Source and scope notes updated . Assessment review is separate.

Official references for PHMSA pipeline safety
Authority / publisherPipeline and Hazardous Materials Safety Administration
Official source identified

DOT hazardous-materials transportation

Regulation · 49 CFR Parts 171–180

Best for: Chemical and petrochemical manufacturing; Battery manufacturing and hazardous-material warehousing; Hazardous waste, landfill, and recycling facilities; and other relevant industries

Applies to: For hazardous materials offered or transported in commerce within the DOT Hazardous Materials Regulations. Classification, quantity, packaging, offeror/carrier roles and highway/rail/air/vessel modes determine duties and exceptions. Review special permits and security-plan triggers separately. Part 40 employee testing does not replace hazardous-materials transport requirements.

Check applicability for DOT hazardous-materials transportation
  • Which materials, classifications, quantities and offeror/carrier functions are involved?
  • Which transport modes, packaging, exceptions or special permits and security-plan triggers apply?

Source and scope notes updated . Assessment review is separate.

Authority / publisherPipeline and Hazardous Materials Safety Administration
Showing 53 of 53 regulatory families.

Showing 53 of 53 research packs. A listing is not a legal applicability conclusion or a claim that assessment coverage is ready.

Current assessment packs

Assessment packs currently in development.

Safeguards and Red Flags can enter today’s quote flow. The Safeguards layer includes 55 Safeguards checks plus 3 Disposal checks at no additional charge: 58 checks for $0.25 per page. Red Flags adds 13 checks as a separate layer. HIPAA Security adds 63 policy checks for medical and dental covered entities at $0.50 per page, without patient data. All four packs remain drafts.

Draft · quote candidate63requirements

HIPAA Security Rule

45 CFR Part 164 · Department of Health and Human Services

Learn about the draft pack
Draft · quote candidate13requirements

FTC Identity Theft Red Flags Rule

16 CFR Part 681 · Federal Trade Commission

Learn about the draft pack
Research broadly. Claim coverage carefully.

We distinguish researched regulations, identified official sources, draft assessment packs and reviewed coverage so you can see what AuditReady can and cannot assess. A catalog listing does not mean paid analysis is available.

How we build a rule pack

Official text first. Review before findings.

DoneOfficial text pinned

eCFR XML is retrieved, dated and fingerprinted with SHA-256.

Done · draftRequirements authored

Each atomic requirement stores a citation, official link and passage hash.

Coming soonIndependent review

A named compliance and legal reviewer signs the version.

Coming soonPublished version

The reviewed pack is frozen before customer findings open.

How we count our numbers

Generated from versioned files—not marketing estimates.

162 instruments

Laws, regulations, guidance and frameworks in the research catalog as of 2026-09-26. A listing is not assessment coverage.

40 source registries

Government publishers, agencies, self-regulatory bodies and framework libraries we track. “Registry” does not always mean a government authority.

134 draft requirements

134/134 have an official section URL and passage hash across the FTC and HIPAA draft packs.

6 pinned texts

Official eCFR source snapshots with retrieval dates and SHA-256 fingerprints in the repository.