Skip to main content

Regulations

What each regulation asks of your vendors

The third-party provisions of 9 regulations and standards, each with its citation and the vendor evidence that may support it, checked against the CertReports index. Reviewed 21 Sep 2026.

Check my stack

What vendors publish

Across 6,433 indexed vendors, the evidence these requirements ask for most.

SOC 2 or ISO 27001
758

vendors, at least

Published subprocessor list
436

vendors

Data processing agreement
191

vendors list one

Penetration test report
441

vendors list one

Questions buyers ask

Which regulations require vendor due diligence?

GDPR and UK GDPR (Article 28 for processors), DORA (Articles 28 and 30 for ICT third-party providers), NIS2 (Article 21(2)(d) supply chain security), HIPAA (business associate agreements under 45 CFR 164.308(b) and 164.314), PCI DSS (Requirement 12.8) and, for AI, the EU AI Act (Articles 25, 26 and 53). ISO/IEC 27001 and SOC 2 carry the same expectation as controls 5.19 to 5.23 and CC9.2.

Does a SOC 2 report make a vendor compliant with GDPR or DORA?

No. A SOC 2 report or ISO 27001 certificate is evidence that may support a requirement such as GDPR Article 28(1) or DORA Article 28(5). Each regulation also asks for things a security report does not cover, such as a data processing agreement, subprocessor control, data locations and incident assistance.

How does CertReports decide whether evidence was found?

Each requirement lists the kinds of evidence that usually support it. CertReports looks for them in registry rows, trust-centre documents and statements, legal documents and subprocessor lists, each with a date and a source. A requirement shows evidence found, available on request, partial, expired or no public evidence.

Is this legal advice?

No. It maps obligations to evidence so a review starts from what is public. Scope, sufficiency and contract terms are for your counsel or auditor.

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.