Free tool · Framework selector

Which compliance framework do I need?

Seven questions about where you sell, who buys, what data you hold, your industry, AI and payments. You get a prioritised list of frameworks, each marked as a legal obligation, a contractual one, or buyer-driven, with a one-line reason and a checker to confirm it. Nothing leaves your browser.

Short answer

It depends on where your users are, who buys from you, and what data you hold. Laws such as GDPR, India's DPDP Act, HIPAA, CCPA, NIS2 and DORA apply when their tests are met, and PCI DSS is imposed by the card brands through your acquirer. SOC 2 and ISO 27001 are never legally required: buyers ask for them. Start with the obligations, then the frameworks your buyers name.

About your company

Your own and your customers'.
Open the startup checklist
Worked example: an Indian B2B SaaS company selling to enterprises worldwide, using AI features

Your frameworks, in order

An indication from your answers, not legal advice. Each obligation turns on facts a form cannot see; use the linked checker, then confirm with counsel.

10 frameworks to look at, in order. 6 may be legal or contractual obligations; check each with its checker. The rest are buyer-driven: no law requires them, but deals may.

  1. CERT-In Directions (India)Legal duty

    In force now: report listed cyber incidents within six hours, keep logs for 180 days, sync clocks. Check whether it applies.

  2. DPDP Act (India)Legal duty

    You process personal data in India. The DPDP Act has no size threshold; its main duties apply from 13 May 2027. Check whether it applies.

  3. GDPR and UK GDPRLegal duty

    Offering goods or services to people in the EU or UK, or monitoring them, brings a non-EU company into scope. Check whether it applies.

  4. CCPA / CPRA (California)Legal duty

    Applies only above a threshold: revenue over $26,625,000, 100,000 consumers or households, or 50% of revenue from data. Employee and B2B data count. Check whether it applies.

  5. EU AI ActLegal duty

    Building on third-party models can still make you a provider or deployer under the Act; what follows depends on the risk tier. Check whether it applies.

  6. PCI DSSContractual

    A hosted checkout keeps card data off your systems and your scope small, but your acquirer still decides how you validate. Check whether it applies.

  7. ISO 27001Buyer-driven

    Buyers in Europe, India and much of Asia more often ask for ISO 27001 certification. Voluntary, but often a procurement gate. Check whether it applies.

  8. SOC 2Buyer-driven

    US mid-market and enterprise buyers routinely ask for a SOC 2 report from vendors holding their data. No law requires it. Check whether it applies.

  9. AI governance policyBuyer-driven

    An AI use policy and a list of where AI touches customer data. Security questionnaires often ask for both. Check whether it applies.

  10. Device management (MDM)Buyer-driven

    Encrypted, patched, managed laptops are a control SOC 2 and ISO 27001 auditors test and questionnaires ask about. No law names MDM. Check whether it applies.

01

Obligations first, then what buyers ask for

The selector sorts its answer into three groups, and the order is deliberate.

  • Legal obligations apply when their test is met, whether or not a customer asks: GDPR for EU and UK users, India's DPDP Act and the CERT-In Directions, HIPAA for US health data, the CCPA above its thresholds, NIS2 for listed sectors in the EU, and DORA for EU financial entities and, by contract, their ICT providers.
  • Contractual obligations come from the parties you deal with. PCI DSS is not a law: the PCI Security Standards Council writes it, and whether you must comply or validate is decided by the card brands and your acquirer. Regulated customers in India pass RBI, SEBI or IRDAI rules down the same way.
  • Buyer-driven frameworks are voluntary in law. SOC 2, ISO 27001, ISO 42001 and Cyber Essentials are required only when a buyer makes them a condition of the deal. That can make them urgent, but it never makes them a legal duty. Device management and an AI governance policy sit here too: no law names them, but auditors and questionnaires look for them.
02

SOC 2 or ISO 27001?

Both prove the same thing, that you run a working security programme, to different audiences. US buyers mostly ask for a SOC 2 report; buyers in Europe, India and much of Asia more often ask for ISO 27001 certification. The controls overlap heavily, so the second costs much less than the first. SOC 2 vs ISO 27001 compares them, and cross-framework mapping shows how one set of controls covers several frameworks.

03

How the selector decides

Each framework has a short list of conditions. The first one your answers meet gives the reason shown. Legal and contractual items come first, then buyer-driven ones; within each group, the items most likely to apply to you come first. Nothing you answer leaves the browser. The answer is a starting list, not a ruling: every item links to a checker that applies the actual test.

04

Sources

Questions

The things people ask us

Which compliance framework should a startup start with?

Start with the legal obligations your users trigger: GDPR for EU or UK users, the DPDP Act and CERT-In for India, HIPAA for US health data. Then pick the assurance framework your buyers name, usually SOC 2 in the US and ISO 27001 elsewhere.

Is SOC 2 legally required?

No. No law requires SOC 2. It becomes a requirement when a customer's procurement policy or contract demands it, which is common with US mid-market and enterprise buyers.

Is ISO 27001 mandatory?

Not by law. ISO 27001 is a voluntary international standard. Buyers, especially in Europe and India, often make certification a condition of a contract or tender.

Is PCI DSS a law?

No. PCI DSS is a standard written by the PCI Security Standards Council. Whether a business must comply and validate is decided by the card brands and acquirers that run compliance programmes, so in practice it is a contractual obligation for anyone accepting cards.

Do I need GDPR compliance if I am not in Europe?

Yes, if you offer goods or services to people in the EU or monitor their behaviour there. Being based in the US, UK or India does not take you out of scope. The GDPR checker applies the Article 3 tests.

Can one set of controls cover several frameworks?

Largely, yes. Access control, encryption, logging, incident response and vendor management appear in SOC 2, ISO 27001, the DPDP security safeguards and most sector rules. Map controls once, then add what each framework asks for on top.

Does this tool tell me for certain what applies?

No. It gives a prioritised starting list from seven answers. Each obligation has a legal test with details a short form cannot capture, so use the linked checker for each, and confirm with counsel before relying on it.

Book a walkthrough

One set of controls, every framework you need.

TryTrustable maps your controls across SOC 2, ISO 27001, GDPR, DPDP and more, and keeps the evidence current.