Solutions · SaaS
Every enterprise deal asks the same security questions. Answer them once, live.
A B2B software company processes customer personal data, uses AI in the product or the back office, and is asked for evidence by every procurement team. Not usually a NIS2 entity unless it is a listed digital provider or serves critical infrastructure.
Typical profile
- Sector
- Software or SaaS (not a listed digital provider)
- Employees
- 50 to 249
- AI
- Builds AI
- Flags
- None
- Software or SaaS is not an Annex I or II sector on its own; marketplaces, search engines and social platforms are.
- Building AI features makes you an AI Act provider; Article 4 literacy already applies.
- Selling to a bank can make you an ICT third-party provider under DORA. Tick the flag if so.
Obligations to prove
8
Outside NIS2's size gate on this profile; GDPR and any AI Act duties still apply.
- Regulation (EU) 2016/679 — data protection3
Applies to every organisation established in the EU that processes personal data.
- Regulation (EU) 2024/1689 — artificial intelligence5
You build or use AI systems — Art 4 AI literacy already applies; other tiers depend on classification.
First statutory clock if something goes wrong: GDPR breach notification, 72 hours (GDPR Art 33(1)).
Computed by the platform's scope finder. A starting point, not a legal determination.
The modules that matter here
Start with these 8 obligations.
Sign up, confirm the scope in onboarding, connect your first system.
Start free →