Compliance matrix

Regulation × sector.
Filtered to what's real.

Cross-reference matrix: every regulation we cover, every sector we serve. The honest cut — 36 substantive cells out of 8 × 12 = 96 possible. The blank cells aren't oversights. They're regulations that don't meaningfully apply to that sector — GDPR Art. 22 doesn't engage cybersecurity threat detection; ePrivacy doesn't apply to healthtech CDS. Better an honest 36 than a junk 96.

Sector ↓ · Regulation →EU AI ActGDPR Art. 22DORANIS2MDRHIPAAPSD3 + PSREU AI Act Art. 50
Fintech & PaymentsPrimaryPrimaryPrimaryAdjacentPrimary
HealthtechPrimaryAdjacentAdjacentPrimaryPrimary
HR Tech & RecruitingPrimaryPrimary
InsurTechPrimaryPrimaryPrimary
EdTechPrimaryAdjacentAdjacent
LegalTechAdjacent
Govtech & Public SectorPrimaryPrimaryAdjacentAdjacent
PropTech & Real EstatePrimaryPrimary
AdTech & MarketingPrimaryAdjacentPrimary
Customer Support SaaSPrimaryAdjacentPrimary
CybersecurityAdjacentPrimaryPrimary
Energy & UtilitiesPrimaryPrimary

Legend

  • Primary — regulation clearly + substantively applies to this sector
  • Adjacent — regulation applies but in a narrower / second-order way (e.g. supply-chain risk, value-chain responsibility)
  • Not applicable — regulation does not meaningfully engage this sector. Not an oversight; intentionally blank.

By regulation