Which compliance framework do I need?
Seven questions about where you sell, who buys, what data you hold, your industry, AI and payments. You get a prioritised list of frameworks, each marked as a legal obligation, a contractual one, or buyer-driven, with a one-line reason and a checker to confirm it. Nothing leaves your browser.
It depends on where your users are, who buys from you, and what data you hold. Laws such as GDPR, India's DPDP Act, HIPAA, CCPA, NIS2 and DORA apply when their tests are met, and PCI DSS is imposed by the card brands through your acquirer. SOC 2 and ISO 27001 are never legally required: buyers ask for them. Start with the obligations, then the frameworks your buyers name.
Your frameworks, in order
10 frameworks to look at, in order. 6 may be legal or contractual obligations; check each with its checker. The rest are buyer-driven: no law requires them, but deals may.
- CERT-In Directions (India)Legal duty
In force now: report listed cyber incidents within six hours, keep logs for 180 days, sync clocks. Check whether it applies.
- DPDP Act (India)Legal duty
You process personal data in India. The DPDP Act has no size threshold; its main duties apply from 13 May 2027. Check whether it applies.
- GDPR and UK GDPRLegal duty
Offering goods or services to people in the EU or UK, or monitoring them, brings a non-EU company into scope. Check whether it applies.
- CCPA / CPRA (California)Legal duty
Applies only above a threshold: revenue over $26,625,000, 100,000 consumers or households, or 50% of revenue from data. Employee and B2B data count. Check whether it applies.
- EU AI ActLegal duty
Building on third-party models can still make you a provider or deployer under the Act; what follows depends on the risk tier. Check whether it applies.
- PCI DSSContractual
A hosted checkout keeps card data off your systems and your scope small, but your acquirer still decides how you validate. Check whether it applies.
- ISO 27001Buyer-driven
Buyers in Europe, India and much of Asia more often ask for ISO 27001 certification. Voluntary, but often a procurement gate. Check whether it applies.
- SOC 2Buyer-driven
US mid-market and enterprise buyers routinely ask for a SOC 2 report from vendors holding their data. No law requires it. Check whether it applies.
- AI governance policyBuyer-driven
An AI use policy and a list of where AI touches customer data. Security questionnaires often ask for both. Check whether it applies.
- Device management (MDM)Buyer-driven
Encrypted, patched, managed laptops are a control SOC 2 and ISO 27001 auditors test and questionnaires ask about. No law names MDM. Check whether it applies.
Obligations first, then what buyers ask for
The selector sorts its answer into three groups, and the order is deliberate.
- Legal obligations apply when their test is met, whether or not a customer asks: GDPR for EU and UK users, India's DPDP Act and the CERT-In Directions, HIPAA for US health data, the CCPA above its thresholds, NIS2 for listed sectors in the EU, and DORA for EU financial entities and, by contract, their ICT providers.
- Contractual obligations come from the parties you deal with. PCI DSS is not a law: the PCI Security Standards Council writes it, and whether you must comply or validate is decided by the card brands and your acquirer. Regulated customers in India pass RBI, SEBI or IRDAI rules down the same way.
- Buyer-driven frameworks are voluntary in law. SOC 2, ISO 27001, ISO 42001 and Cyber Essentials are required only when a buyer makes them a condition of the deal. That can make them urgent, but it never makes them a legal duty. Device management and an AI governance policy sit here too: no law names them, but auditors and questionnaires look for them.
SOC 2 or ISO 27001?
Both prove the same thing, that you run a working security programme, to different audiences. US buyers mostly ask for a SOC 2 report; buyers in Europe, India and much of Asia more often ask for ISO 27001 certification. The controls overlap heavily, so the second costs much less than the first. SOC 2 vs ISO 27001 compares them, and cross-framework mapping shows how one set of controls covers several frameworks.
How the selector decides
Each framework has a short list of conditions. The first one your answers meet gives the reason shown. Legal and contractual items come first, then buyer-driven ones; within each group, the items most likely to apply to you come first. Nothing you answer leaves the browser. The answer is a starting list, not a ruling: every item links to a checker that applies the actual test.
Sources
- EUR-Lex: GDPR, Regulation (EU) 2016/679, Article 3
- California Civil Code §1798.140 (CCPA business thresholds)
- CPPA: Updated monetary thresholds, effective 1 January 2025
- CERT-In: Directions of 28 April 2022
- MeitY: Digital Personal Data Protection Act, 2023
- eCFR: 45 CFR 160.103 (covered entity, business associate)
- PCI Security Standards Council: about the Council and compliance programmes
- EUR-Lex: NIS2, Directive (EU) 2022/2555, Article 2 and Annex I
- EUR-Lex: DORA, Regulation (EU) 2022/2554, Articles 2, 30 and 64
- EUR-Lex: EU AI Act, Regulation (EU) 2024/1689, Article 113
- NCSC: Cyber Essentials overview
Facts checked against these sources in October 2026. Laws, thresholds and dates change: check the source before you rely on a figure. Not legal advice.
The things people ask us
Which compliance framework should a startup start with?
Start with the legal obligations your users trigger: GDPR for EU or UK users, the DPDP Act and CERT-In for India, HIPAA for US health data. Then pick the assurance framework your buyers name, usually SOC 2 in the US and ISO 27001 elsewhere.
Is SOC 2 legally required?
No. No law requires SOC 2. It becomes a requirement when a customer's procurement policy or contract demands it, which is common with US mid-market and enterprise buyers.
Is ISO 27001 mandatory?
Not by law. ISO 27001 is a voluntary international standard. Buyers, especially in Europe and India, often make certification a condition of a contract or tender.
Is PCI DSS a law?
No. PCI DSS is a standard written by the PCI Security Standards Council. Whether a business must comply and validate is decided by the card brands and acquirers that run compliance programmes, so in practice it is a contractual obligation for anyone accepting cards.
Do I need GDPR compliance if I am not in Europe?
Yes, if you offer goods or services to people in the EU or monitor their behaviour there. Being based in the US, UK or India does not take you out of scope. The GDPR checker applies the Article 3 tests.
Can one set of controls cover several frameworks?
Largely, yes. Access control, encryption, logging, incident response and vendor management appear in SOC 2, ISO 27001, the DPDP security safeguards and most sector rules. Map controls once, then add what each framework asks for on top.
Does this tool tell me for certain what applies?
No. It gives a prioritised starting list from seven answers. Each obligation has a legal test with details a short form cannot capture, so use the linked checker for each, and confirm with counsel before relying on it.
One set of controls, every framework you need.
TryTrustable maps your controls across SOC 2, ISO 27001, GDPR, DPDP and more, and keeps the evidence current.