Sixteen domains across four jurisdictions, plus the standards bodies and multilateral institutions whose output those four keep adopting. If your exposure is in here, we track it.

Jurisdictions

The European Union, the United Kingdom, the United States and Singapore. We read the instrument itself, the delegated acts under it, the consultations that will change it, and the supervisory statements that tell you how it will actually be examined.

A directive has to be transposed into national law. A regulation does not. We track the transpositions separately, because dates and obligations vary by member state. A statement about the European Union can be wrong in Germany.

The sixteen domains

Security and resilience

Cybersecurity regulation

NIS2 and its national transpositions, the UK NIS Regulations, and the sector rules that sit on top of them.

Operational resilience

DORA and the UK operational resilience regime. Impact tolerances, mapping, and threat-led testing.

Incident reporting

Who you have to tell, inside what window, and in what form. The reporting clocks under NIS2, DORA and the SEC disclosure rules.

Product security

The Cyber Resilience Act and the UK PSTI regime, and what they require of anything you ship with software in it.

Data security and privacy

The security obligations inside GDPR and UK GDPR, the Singapore PDPA, and the US state laws that keep adding to them.

Third-party and supply chain risk

DORA’s third-party rules and NIS2 supply chain duties, including the register of information nobody enjoys building.

Emerging technology

AI governance

The EU AI Act, ISO/IEC 42001, and the governance obligations arriving alongside them.

AI security

Securing the models and agents you deploy, and the guidance regulators and technical authorities are starting to issue about it.

Quantum security and PQC

The NIST post-quantum standards, migration timelines, and harvest-now-decrypt-later exposure.

Robotics and autonomous systems

Machinery, safety and AI Act obligations that attach once a system acts in the physical world.

Drone and UAS security

EASA and FAA rules, remote identification, and the counter-UAS powers that come with them.

Space systems security

Ground segment and payload security, as space systems move inside critical infrastructure regimes.

Infrastructure and geopolitics

Cyber-kinetic and OT security

Where an attack produces physical consequences. NIS2 essential entities, IEC 62443, and the sector regulators.

Telecommunications and 5G security

The UK Telecommunications Security Act, the EU 5G toolbox, and the vendor restrictions that follow from both.

Digital assets and blockchain

MiCA, the travel rule, and the security obligations attached to custody.

Export controls and dual-use technology

The EU dual-use regulation, the US export administration regulations, and entity list changes.

Why these sixteen

They are the domains where a security or risk leader is expected to have an answer and has nowhere obvious to get one. Each of them produces obligations that land on your programme, not on a compliance team somewhere else in the building.

We add a domain when subscribers start being asked about it, and say so when we do. The list is not padding.

What a domain page gives you

Each domain page names the instruments we track in it, the jurisdictions each one applies in, and the dates that matter. It then lists the recent Radar items filed against that domain.

Your organisation can narrow all of this with a Member Lens. You name the jurisdictions you operate in and the instruments you are already in scope for. The domains that do not apply stay out of the way.

Coverage is the easy half

Anyone can list sixteen domains. The Radar tells you what changed in them, what it means for you, and what to do about it. A named analyst approves every item, and former CISOs review it in their sectors.

See how the Radar works