Compliance Checker — NIS2, GDPR, DORA in 3 Minutes

Free interactive compliance checker. Which Irish/EU cybersecurity regulations apply to your business — NIS2, GDPR, DORA, PCI DSS? Answered in under 3 minutes.

Answer 6 questions to find out which cybersecurity regulations apply to your business. Takes about 2 minutes.

This free interactive checker identifies which cybersecurity regulations and frameworks likely apply to your Irish business — covering NIS2, GDPR, DORA, PCI DSS, and sector-specific requirements — and gives you a personalised compliance requirements report.

The Six Questions

  • Do you process personal data of EU residents (customers, employees, etc.)?
  • Do you process, store, or transmit credit/debit card payments?
  • What industry does your business operate in?
  • How many employees does your organisation have?
  • Who are your primary customers — Irish/EU businesses, US/international businesses, consumers, or government?
  • Does your business provide essential services (energy, transport, health, digital infrastructure, water), or supply essential service providers?

How It Works

Your answers are matched against eight regulations and frameworks. Each applicable result is prioritised as High Priority, Medium Priority, or Recommended, and comes with a plain-English description, a list of key actions, and a link to a detailed guide. You can download the full result as a PDF report.

Regulations and Frameworks Covered

GDPR (General Data Protection Regulation)

Applies to all organisations that process personal data of EU residents. Requires data protection policies, breach notification, and privacy by design.

NIS2 (Network and Information Security Directive 2)

EU directive requiring essential and important entities to implement cybersecurity risk management measures and report significant incidents.

PCI DSS (Payment Card Industry Data Security Standard)

Required for any organisation that processes, stores, or transmits credit card data. Mandates specific security controls for cardholder data.

DORA (Digital Operational Resilience Act)

EU regulation for financial entities requiring ICT risk management, incident reporting, digital operational resilience testing, and third-party risk management.

ISO 27001 (Information Security Management System)

International standard for information security management. Often required by enterprise customers and investors as proof of security maturity.

SOC 2 (Service Organization Control 2)

Trust service criteria for service organisations. Often required by US enterprise customers for SaaS and cloud service providers.

CyFUN (Cyber Fundamentals Framework)

Belgian-origin framework adopted in Ireland. Provides a structured approach to cybersecurity fundamentals for SMEs.

Cyber Essentials

UK-origin certification scheme that covers five key technical controls. Increasingly recognised in Ireland and required for some government contracts.

What Your Results Include

  • A count of how many regulations likely apply to your business
  • A priority-ordered card for each applicable regulation with its description and key actions
  • Links to detailed compliance guides for each regulation
  • A downloadable PDF compliance report

Important Disclaimer

This tool provides general guidance only and does not constitute legal or compliance advice. Regulatory requirements depend on your specific circumstances. We recommend consulting with a qualified professional to confirm your compliance obligations.

Need to Close Compliance Gaps Fast?

We handle procurement and implementation of the controls you're missing — from MFA and endpoint protection to backup and monitoring. One team, one invoice. Related tools include the Security Maturity Assessment, the vCISO ROI Calculator, and the Grants Eligibility Checker.