Compliance Colleague · Answers
Compliance answers, cited
- PCI DSS v4.0.1
Can we use SAQ A with a payment processor's iframe, and do we still need ASV scans? - ISO/IEC 27001:2022
How many Annex A controls are in ISO 27001:2022, and how are they grouped? - GDPR
How long do we have to answer a GDPR subject access request, and can we extend it? - EU AI Act
When do the EU AI Act's high-risk obligations apply to Annex III and Annex I systems? - India DPDPA
Does India's DPDP Act apply to a US SaaS company with no Indian entity, and to paper records? - NIS2
What are the NIS2 reporting deadlines for a significant incident? - DORA
What are DORA's deadlines for the initial notification and intermediate report of a major ICT incident? - SOC 2
If our SOC 2 covers only Availability, do the common criteria still apply? - HIPAA
Is a SaaS vendor that stores encrypted ePHI and never views it a HIPAA business associate? - CMMC 2.0
Are a SIEM and an MFA provider that don't touch CUI in scope for a CMMC Level 2 assessment?
Have a question that isn’t here? Ask it against any of 30+ security, privacy and AI governance standards. Try it free, no card required →
Research aid, not legal or audit advice.