EU COMPLIANCE ASSESSMENT
Find out which EU laws reach your product — before a regulator does.
Every applicable framework identified, every obligation mapped, every gap ranked by enforcement risk. Delivered as an audit-ready record you can put in front of a regulator, investor, or acquirer. One compliance assessment, delivered in 5 working days.
✓ 5-day turnaround ✓ 100% fixed pricing ✓ Regulatory alignment guarantee
Most products are subject to 3-8 EU regulations.
EU compliance is not one question with one answer. It is several questions — each from a different regulator — landing on the same product simultaneously. Our compliance assessment looks at 50+ regulations at once.
You don’t know which laws actually apply
The EU AI Act gets the coverage. The Cyber Resilience Act, DORA, the Data Act, the revised Product Liability Directive, and a dozen others reach the same product and almost nobody is mapping them. Not knowing which frameworks apply is a major gap. Everything else follows from it.
You are preparing for the wrong thing
Most compliance work happens at the organisation level — policies, governance frameworks, data protection officers. EU product regulation happens at the product level. The EU AI Act regulates your system. The CRA regulates your software. The revised PLD creates liability for your outputs. Preparing at the wrong level produces documentation that holds up nowhere.
The gaps between regulations are where the exposure sits
GDPR and EU obligations can apply to the same dataset with conflicting requirements. A CRA security incident and a DORA notification timeline can apply to the same event with different deadlines. Most assessments miss these interactions entirely because they look at one framework at a time. Regulators, notified bodies, and acquirer legal teams do not.
A lawyer-built compliance assessment against 50+ EU frameworks
The EU Product Compliance Assessment starts where most compliance tools stop. Not a generic framework overview. Not a checklist projected onto your architecture. A legal determination of your position, made by a lawyer who has read these regulations at drafting level and can apply them to what you are actually shipping.
Stage 1: Intake
A short structured questionnaire covering your product’s function, connectivity, data flows, intended market, and current documentation.
Stage 2: Framework Applicability
Every relevant EU regulation assessed against your product, each one ruled in or out with legal reasoning.
Stage 3: Obligation Mapping
Every requirement under every applicable framework, translated into concrete, product-specific obligations ranked by enforcement risk and deadline.
What You Get:
Delivery is a written assessment memo, a structured Living Compliance File™, and a debrief call walking through findings and next steps.

Why this assessment holds up when others don’t.
| Delivery | Generic compliance tool | Big Four advisory | EU Product Compliance Assessment |
|---|---|---|---|
| Output | Checklist | Slide deck or memo | Written legal determination |
| Framework coverage | One regime | One regime billed separately | Every applicable framework at intake |
| Basis | Template | General regulatory knowledge | Drafting-level EU regulatory expertise |
| Role determination | Not included | Sometimes included | Always included — drives the whole assessment |
| Audit-ready record | No | No | Yes — Living Compliance File™ |
| Price | Low — low depth | €15,000–€50,000+ | €1,250 fixed |
| Turnaround | Instant — generic | 4–8 weeks | 5 working days |
| Holds up under scrutiny | No | Depends | Yes — structured for regulator and notified body review |
| Refund guarantee | No | No | Full refund if it doesn’t deliver a defensible position |
Gap analysis for each applicable framework
Every obligation ranked by enforcement risk and statutory deadline — separating what is urgent now from what can wait, and what will surface first in a regulatory inquiry, due diligence process, or procurement questionnaire.
Written assessment memo and a debrief call
A single document your team, board, legal counsel, and any regulatory authority can all work from. Optional, a structured walkthrough of findings: what the assessment determined, what it means for your product roadmap, and what to do first.
A Quick Look Into Framework Applicability
| If your product… | These frameworks apply |
|---|---|
| Uses AI to make or influence decisions about individuals | EU AI Act + GDPR Article 22 |
| Connects to a network or another device | Cyber Resilience Act |
| Is supplied to EU banks, insurers, or investment firms | DORA |
| Processes personal data about EU residents | GDPR |
| Generates data from connected physical objects | Data Act |
| Makes AI-driven recommendations to EU consumers at scale | Digital Services Act |
| Could cause damage through defective AI output | Revised Product Liability Directive |
| Is used in hiring, credit, education, or biometrics | EU AI Act — high-risk (Annex III) |
| Is placed on the EU market by a non-EU company | Authorised Representative requirement |
| Qualifies as Software as a Medical Device | Medical Device Regulation |
How to Get Started
From intake to audit-ready record in five working days.
Step 1 — Complete your intake
A short form covering your product’s function, connectivity, data flows, intended market, and current documentation. Takes fifteen to twenty minutes and is the basis for everything that follows.
Step 2 — Scope confirmation
We review your intake within one working day and confirm which frameworks apply to your product. If your product triggers significant cross-framework interactions, we will tell you before work begins — not after delivery.
Step 3 – Delivery and debrief
Written assessment memo and Living Compliance File™ delivered within five working days of scope confirmation. A debrief call is included. Book it when the documents land, or skip it if the record speaks for itself.
FAQ
What is an EU product compliance assessment?
It is a lawyer-built legal assessment of one specific product against every EU regulatory framework that reaches it — identifying which laws apply, what each one requires, what role you hold under each, and where your gaps sit ranked by enforcement risk. The output is a written record you can put in front of a regulator, notified body, investor, or acquirer. It is not a checklist, not a tool output, and not generic regulatory advice — it is a legal determination made for your specific product.
Which EU regulations does this assessment cover?
Every framework that reaches your product, confirmed at intake. The starting list includes the EU AI Act, Cyber Resilience Act, GDPR, DORA, NIS2, Data Act, Digital Services Act, revised Product Liability Directive, MiFID II, MDR, and AMLD6 — among others. Frameworks are ruled in or out with legal reasoning as part of the assessment. You are not paying for coverage of laws that do not reach your product.
How is this different from the Cross-Regime Compliance Strategy?
The €1,250 assessment is the right starting point if you need to establish your position under one or two primary frameworks first. The €4,950 Cross-Regime Compliance Strategy adds a cross-framework conflict map — showing where frameworks interact, where one piece of evidence satisfies multiple obligations, and where two regimes pull in opposite directions — and covers up to three systems.
If your product is subject to multiple frameworks with significant interactions, the cross-regime strategy produces something the single-framework assessment cannot: a view of how the laws relate to each other against your specific product.
How long does the assessment take?
Five working days from receipt of a completed intake checklist. The scoping call and intake process typically take one to two days. Total time from first contact to delivered assessment is usually seven to ten working days. If you have a due diligence deadline or a procurement timeline, raise it on the scoping call and we will confirm whether it is achievable before any commitment.
What is the Living Compliance File™?
It is the audit-ready compliance record produced by the assessment — structured by framework and product development stage, formatted so a regulator, notified body, investor, or acquirer can open it and find what they need. It is not a summary of the assessment. It is a working document — designed to be updated as your product develops and your compliance position matures, and to hold up under scrutiny from any of the relevant authorities.
Does this assessment cover conformity assessment preparation?
No. Conformity assessment preparation — determining the correct conformity assessment pathway, preparing the technical file for notified body review, and supporting the assessment process — is not included in the €1,250 engagement. It is included in the €4,950 Cross-Regime Compliance Strategy. If conformity assessment preparation is your primary need, the scoping call will establish which engagement is the right fit.
Do I need this compliance assessment if my product is minimal risk?
If you are certain your product is minimal risk under every applicable framework, you do not need this compliance assessment to confirm it — you already have your answer. But most teams that believe they are minimal risk have not systematically assessed their product against every applicable framework, have not settled their role determination, and have not considered how secondary frameworks interact with their primary one.
Can I use this assessment for investor or acquirer due diligence?
Yes. The written compliance assessment memo and Living Compliance File™ are specifically structured to hold up under due diligence scrutiny. Investors and acquirers are asking about multi-regime regulatory exposure as a standard due diligence question. A documented legal position across every applicable framework — produced by a qualified lawyer, structured for regulatory review — is the form of answer their legal teams expect. A self-assessment or a tool output is not.
What if my product changes after the assessment?
This compliance assessment reflects your product’s regulatory position at the point of delivery. Material changes — new functionality, new connectivity, new use cases, new markets — may change which frameworks apply and what they require. The Living Compliance File™ is designed to be updated as your product develops. If a material change occurs and you are unsure whether it affects your compliance position, a short review call is available as a separate engagement before changes are deployed.
What is the full-refund guarantee?
If the compliance assessment does not give you a clear, defensible answer on which frameworks apply to your product and what they require, we keep working until it does — or refund the engagement in full. The guarantee is against the deliverable standard, not against the findings. If the assessment determines that your product has significant compliance gaps, that is the deliverable working as intended — finding a problem early is the point. The guarantee protects against a compliance assessment that fails to give you a clear, documented position. It does not protect against a position you would have preferred.
Is this legal advice?
This compliance assessment is a legal determination made by a qualified EU regulatory lawyer — it is not generic information or a tool output. It constitutes legal analysis of your product’s regulatory position under applicable EU frameworks. It does not constitute legal representation in proceedings, cover domestic law outside the EU frameworks in scope, or substitute for specialist legal advice on matters outside its defined scope — including litigation, criminal liability, or sector-specific regulatory matters beyond the frameworks assessed. If you are unsure whether the assessment covers what you need, raise it on the scoping call.

