Compliance Engine Features / Services by Framework

Services by Framework: One engine core, every regime covered

Every regulatory obligation is its own service, grouped by framework: NIS2, DORA, ISO 27001, EU AI Act, GDPR, and SOC 2 all run on the same assessment core — a single control counts automatically across all booked services.

What is Framework Packs

A deterministic engine instead of manual checklists.

Instead of maintaining a separate spreadsheet or tool for every regime, ReportAct runs frameworks (DORA, NIS2, ISO 27001, EU AI Act, GDPR TOMs, SOC 2) as activatable packs, each with its own control catalog. A deterministic assessment engine automatically calculates implementation status from existing evidence data — complemented by an AI-assisted guidance function that suggests the next sensible steps.

For NIS2, the core controls — risk analysis, 24h/72h incident reporting, registration obligations, business continuity evidence, management-body training, and more — are already assessed automatically from existing evidence data instead of having to be ticked off by hand.

When requirements change, the changes arrive as a feed; accepting a change is documented with a signature — your control status stays verifiably current.

Core capabilities

What the Framework Packs engine delivers.

Deterministic control assessment

Control status is calculated automatically from existing evidence data, not ticked off by hand — already live for NIS2, covering risk analysis, reporting deadlines, registration obligations, and more.

AI-assisted guidance

Alongside the automated assessment, an AI function suggests the appropriate next steps for each regime.

Regulatory change feed

Ongoing changes to frameworks and control objectives are delivered as a feed; every accepted change is documented with a signature.

One control catalog per regime

DORA, NIS2, ISO 27001, EU AI Act, GDPR TOMs, and SOC 2 each run as standalone packs on the same engine core.

Policies & governance decisions

A policy register with templates per policy type and a separate register for governance decisions — both as binding, approved documents that automatically supply evidence across all framework packs.

How it works

From pack to control status.

Activate the pack

You unlock the framework pack you need — the control catalog and assessment logic are ready immediately.

Collect evidence

Existing evidence data (vendors, assets, incidents, policies, and more) feeds into the assessment.

Calculate status automatically

The engine deterministically calculates implementation status per control and shows the next sensible steps.

Connected regulations

Covers six regimes on one core.

NIS2 & NISG

Ten risk-management measures (Art. 21(2) NIS2) as a control catalog, assessed automatically.

Regulation details →
DORA

ICT risk management controls on the same engine core.

Regulation details →
ISO/IEC 27001

93 Annex A controls as a complete Statement of Applicability.

Regulation details →
Next step

One control catalog, six regimes covered.

We'll show you live how a framework pack is activated and how control status is calculated automatically.