One evidence model that connects a finding from a scanner/pentest/SOC to evidence ready to present to the board, audit, and the regulator — in the home market (EU/PL) and in parallel in target markets (US, AU, further jurisdictions). This is the product-launch page: it shows regulatory timing, numbers from the code, and a clear MVP/ROADMAP status — without promises that evidence does not support.
DORA, NIS2, the AI Act in the EU; SEC disclosure obligations and a patchwork of state-level AI regulations
in the US; Privacy Act reform and the SOCI Act in AU — each market requires a different report format, but the
same foundation: documented, time-consistent evidence of an incident and of corrective action. ipIII
builds this foundation once —
import → incident → evidence-package (hash) → retest → close — and configures the output
(regulatory pack) for the market in which the client operates.
The dates and act names below are public facts as of the review date (2026-07-05), cited for information only. This is not legal advice — qualification for a specific company, sector, and factual situation is determined by the client's lawyer/DPO/law firm. Deadlines get moved (see Digital Omnibus below) — always verify the current status in the Official Journal / register applicable to the jurisdiction.
| Market | Key frameworks and deadlines | ipIII support status |
|---|---|---|
| EU home market |
DORA — Regulation (EU) 2022/2554, applicable since 17.01.2025 (operational resilience of the financial sector) · NIS2 — Directive (EU) 2022/2555, transposition into national law ongoing across member states · AI Act — prohibited practices since 2.02.2025, GPAI obligations unchanged, high-risk (Annex III, e.g., scoring/HR) postponed from 2.08.2026 to 2.12.2027 (the Digital Omnibus package, pending confirmation in the EU Official Journal) · GDPR — personal data protection, 72-hour breach notification obligation. | MVP — the Legal Trigger Engine and evidence-package map to these frameworks today; see /legal-engine and /dora-tiber. |
| US target market |
SEC cyber disclosure rules — obligation to disclose a material cyber incident in Form 8-K (Item 1.05) for listed companies · state AI laws, e.g., the Colorado AI Act (regulation of algorithmic discrimination; effective dates have been pushed back before — verify current state-level status) · breach notification laws — data breach notification obligations vary state by state. | ROADMAP — US mapping requires a dedicated regulatory pack; today available as informational material, see /global-compliance. |
| AU target market |
Privacy Act 1988 — reform (further tranches of amendments underway, including strengthened transparency and individual rights) · SOCI Act (Security of Critical Infrastructure Act) — cyber incident reporting obligations for critical infrastructure entities, with reporting deadlines varying by incident severity. | ROADMAP — no dedicated regulatory pack yet; this market is queued for prioritization after the US. |
| Global cross-cutting trend |
A growing, cross-cutting obligation for documented evidence of cyber and AI incidents — regardless of jurisdiction: voluntary frameworks (NIST AI RMF, ISO/IEC 42001, ISO/IEC 27001) are increasingly becoming a reference point for regulators and auditors assessing the maturity of risk management. | MVP — the evidence model import → incident → evidence-package →
retest → close is by design independent of any specific framework; the regulatory pack is a
configuration layer on top. |
The doctrine on which ipIII is built does not depend on the market: every claim has code, a test, and an endpoint, or it is explicitly labeled ROADMAP. The same evidence-package (hash, chain-of-custody) serves as the starting point for an EU, US, or AU review.
Mapping obligations to deadlines and form fields is a configuration layer on top of a shared incident model — not a separate system per country. EU already works (MVP); US/AU are ROADMAP, prioritized by pilot demand.
The same evidence-package feeds the Board Pack for the board, the package for the auditor, and the draft regulator filing — without manually re-entering data between country-specific formats.
ipIII is not a scanner, a SIEM, or a GRC system. It ingests their outputs (19 import parsers) and builds an evidence layer on top of the client's existing tool stack — in every market where the client already operates.
Every number below is computed at runtime from /api/ip3/ssot (an endpoint that parses the repo
files on every call) — zero market estimates presented as fact. The test-suite count is a static, manually updated number
(tests/ip3-*) — it has no dedicated field in /api/ip3/ssot.
routes/ip3-*.jstests/ip3-* (static count, as of 2026-07-09)numbers (except test suites) refreshed from /api/ip3/ssot — values above are fallback (last known state); loading live…
Hardening layers in progress (status ROADMAP, see /known-limitations): OIDC/identity federation, hash-chain + evidence signing (PAdES/TSA), multi-tenant isolation (tenancy/RLS), transport mTLS.
Banks, insurers, payment institutions — under pressure from DORA (EU) and SEC disclosure (US); they need a Board Pack and evidence ready before the auditor/regulator.
Energy, telecommunications, healthcare — under NIS2 (EU) and the SOCI Act (AU); they need a consistent incident register regardless of which regulator is asking.
Companies building/deploying high-risk systems under the AI Act (EU) and state AI laws (US); they need evidence from the model card and human oversight, not just declarations.
Teams producing findings (Burp, ZAP, Nessus, SARIF) need a layer that turns a test result into time-closed evidence — for their own clients, in any market.
No. EU is MVP today — the Legal Trigger Engine and evidence-package map to DORA/NIS2/AI Act/GDPR. US and AU are ROADMAP: informational material is available (/global-compliance), but a dedicated regulatory pack has not been built yet. Global launch describes direction and timing, not a finished feature set.
No. All information about regulations and deadlines is decision-support — organizing material for a conversation with the lawyer/DPO/law firm applicable to the client's jurisdiction and sector. Deadlines get moved (example: the postponement of AI Act Annex III via the Digital Omnibus package) and require ongoing verification.
No. ipIII ingests the outputs of existing tools (19 import parsers: SARIF, SBOM, secrets, cloud posture, SIEM/CTI, DefectDojo, Burp, Nessus, CSV and more) and builds from them an evidence-package with a checksum and a decision-ready Board Pack. Detection, scanning, and risk management remain with the client's dedicated tools.
A controlled pilot (PoC) on synthetic data, after signing Rules of Engagement, an NDA, and a DPA. Submit a request via /pilot-intake; partner terms via /partner and /partner-program.
Yes. This English page is a translation of the Polish source as published on 2026-07-05; the Polish page
remains the primary reference and is updated first. hreflang tags link both language versions,
with Polish set as x-default. If the two versions ever diverge, treat the Polish original as
authoritative pending a sync.
Related: known-limitations register → /known-limitations · status matrix → /status-matrix · detailed market review → /global-compliance.