Compliance matrix
Regulation × sector.
Filtered to what's real.
Cross-reference matrix: every regulation we cover, every sector we serve. The honest cut — 36 substantive cells out of 8 × 12 = 96 possible. The blank cells aren't oversights. They're regulations that don't meaningfully apply to that sector — GDPR Art. 22 doesn't engage cybersecurity threat detection; ePrivacy doesn't apply to healthtech CDS. Better an honest 36 than a junk 96.
| Sector ↓ · Regulation → | EU AI Act | GDPR Art. 22 | DORA | NIS2 | MDR | HIPAA | PSD3 + PSR | EU AI Act Art. 50 |
|---|---|---|---|---|---|---|---|---|
| Fintech & Payments | Primary | Primary | Primary | Adjacent | — | — | Primary | — |
| Healthtech | Primary | Adjacent | — | Adjacent | Primary | Primary | — | — |
| HR Tech & Recruiting | Primary | Primary | — | — | — | — | — | — |
| InsurTech | Primary | Primary | Primary | — | — | — | — | — |
| EdTech | Primary | Adjacent | — | — | — | — | — | Adjacent |
| LegalTech | Adjacent | — | — | — | — | — | — | — |
| Govtech & Public Sector | Primary | Primary | — | Adjacent | — | — | — | Adjacent |
| PropTech & Real Estate | Primary | Primary | — | — | — | — | — | — |
| AdTech & Marketing | Primary | Adjacent | — | — | — | — | — | Primary |
| Customer Support SaaS | Primary | Adjacent | — | — | — | — | — | Primary |
| Cybersecurity | Adjacent | — | Primary | Primary | — | — | — | — |
| Energy & Utilities | Primary | — | — | Primary | — | — | — | — |
Legend
- Primary — regulation clearly + substantively applies to this sector
- Adjacent — regulation applies but in a narrower / second-order way (e.g. supply-chain risk, value-chain responsibility)
- —Not applicable — regulation does not meaningfully engage this sector. Not an oversight; intentionally blank.
By regulation
EU AI Act
EU · 12 sectors
GDPR Art. 22
EU · 9 sectors
NIS2
EU · 5 sectors