πΊπΈ HIPAA
Healthcare Privacy Β· 1996
Awareness Federal US law protecting Protected Health Information (PHI). Applies to Covered Entities (healthcare providers, health plans, clearinghouses) and their Business Associates (any vendor that creates, receives, maintains, or transmits PHI on their behalf).
6 common violations documented
πͺπΊ EU AI Act
AI Governance Β· 2024
Awareness World's first comprehensive AI law. Classifies AI systems by risk level and applies tiered requirements. Applies to providers and deployers of AI systems in the EU β including companies outside the EU whose AI systems are used in the EU.
5 common violations documented
πΊπΈ SOC 2
Security Certification Β· 2011
Awareness AICPA security certification demonstrating that a service organization's controls meet the Trust Services Criteria. Not legally required but commercially essential β most enterprise buyers require it before signing contracts. Type I covers design; Type II covers operating effectiveness over 6β12 months.
6 common violations documented
π ISO 27001
Security Certification Β· 2022
Awareness International standard for Information Security Management Systems (ISMS). Provides a framework of 93 controls across 4 themes (organizational, people, physical, technological). Required for many government contracts worldwide and increasingly expected by enterprise buyers in the EU and APAC.
4 common violations documented
π PCI DSS
Payment Security Β· 2004
Awareness Security standard required by Visa, Mastercard, American Express, Discover, and JCB for any organization that stores, processes, or transmits cardholder data. Non-compliance can result in fines and loss of the ability to accept card payments β effectively shutting down an e-commerce business.
5 common violations documented
πΊπΈ SOX
Financial Controls Β· 2002
Awareness US federal law requiring publicly traded companies to maintain strict financial controls and reporting. Section 302: CEO/CFO must personally certify financial statements. Section 404: annual assessment of internal controls over financial reporting. Criminal penalties for knowing violations.
4 common violations documented
π ISO 42001
AI Governance Β· 2023
Awareness Published December 2023. The first international standard for AI Management Systems (AIMS). Often called 'the SOC 2 for AI' β increasingly required by enterprise customers before purchasing AI products. Aligns closely with the EU AI Act's requirements for high-risk AI systems.
4 common violations documented
πΊπΈ FERPA
Education Privacy Β· 1974
Awareness Federal US law protecting the privacy of student education records. Applies to all educational institutions receiving federal funding (virtually all schools and universities). Gives parents and eligible students rights to access, review, and request corrections to education records.
4 common violations documented
πͺπΊ DORA
Financial Resilience Β· 2025
Awareness EU regulation effective January 17, 2025, requiring financial entities to manage ICT risks and ensure operational resilience. Applies to banks, insurers, investment firms, crypto asset service providers, and their critical ICT third-party providers. Significant new obligations for cloud providers and SaaS companies serving EU financial institutions.
4 common violations documented