Welcome to Compliance Labs

Join us

  • Readiness engagement:

    • Submit software for SSDF / CRA Readiness assessment and report. Compliance Labs reviews your software and secure development lifecycle for alignment with NIST SSDF practices and EU Cyber Resilience Act essential requirements.
    • CRA scope, product classification and conformity route.
    • Gap analysis for CRA requirements and SSDF practices.
    • Compliance documentation assessment. For alignment with CRA conformity and SSDF attestation requirements.
    • Cybersecurity risk assessment and prioritized remediation roadmap.
    • Custom testing applied to pre-release software, internal applications, cloud connectors and proprietary pipelines. Same rigour as your production software.

    Everything in Get Proven, plus:

    • Submit 1 software for an Evidence Effectiveness Evaluation (EEE) report, extending the documentary examination to direct testing. Compliance Labs independently tests your software and verifies its capabilities and contribution, providing the technical evidence expected by assessors such as QSA, ISO and DORA, in a structured audit dossier.
    • Dedicated compliance analyst as one point of contact across evaluation, regulatory changes and audit preparation.
    • Monthly performance report covering evaluation results and compliance posture.
    • Full access to exclusive resources, tools, guides, templates, and policies. Accelerate your compliance work with ready-to-use materials.

    Everything in Get Listed, plus:

    • Submit 1 software for a full CAE report. Compliance Labs reviews your proprietary documentation, technical manuals, installation guides, and configuration references, plus SBOM, internal documentation and audit reports, and independently confirms capabilities and software contribution as examined across the regulations and frameworks in scope.
    • Coverage extended to up to 10 regulations and frameworks. Aligned with your target markets, drawn from a library of 40+.
    • Pre-audit evidence pack, with unlimited RFP-ready extracts of your listing. Your CAE report formatted for QSA, ISO and DORA assessor requests.
    • Report refreshed twice a year. Plus quarterly regulatory alerts.
    • Annual regulatory position report. From a Compliance Labs analyst, covering your current coverage, and gaps.
    • Access to 1000+ compliance-relevant solutions and CAE reports.

    Features:

    • Submit 1 software for a baseline CAE report. Compliance Labs reviews public documentation and maps capabilities and software contribution as stated to the regulations and frameworks in scope.
    • Up to 3 regulations and frameworks from a standard set. Including PCI DSS, HIPAA, GDPR, NIST CSF, NIST SP 800-53, and MITRE ATT&CK, with no selective scoping.
    • One RFP-ready extract per year, marked Vendor-Stated. For use in buyer responses.
    • Benchmarking capabilities and coverage compared to competing vendors.
    • Access to compliance-relevant software solutions and their CAE reports.
    • Browse 50 evaluated solutions, your own listing always fully accessible. Selected to cover every software category.
    • Save, export and share vendor lists.

    Everything in Evaluate, plus:

    • Compliance Stack Assessment mapping your IT and OT software across DORA, NIS2, GDPR and more. Identifies gaps, overlaps and remediation priorities across your stack.
    • NIS2 Readiness assessment with gaps and a prioritized roadmap. Covers your obligations as an essential or important entity, OT included.
    • Custom Evaluation with hands-on testing. Evidence Effectiveness Evaluation (EEE) applied to your own software across cloud, SaaS, ICS or SCADA environments.
    • Dedicated Analyst as your point of contact across evaluations, regulatory changes and audit preparation.
    • Regulatory watch retainer. Continuous monitoring of regulatory changes on your stack, with impact analysis and recommendations.
    • Full access to exclusive resources. Accelerate your compliance work with ready-to-use materials.

    Everything in Discover, plus:

    • Download CAE and EEE reports for client deliverables or audit preparation.
    • Access to 1000+ compliance-relevant software solutions, with their CAE and EEE reports where available.
    • Analyst support via email for compliance questions.
    • Quarterly regulatory alerts. Notified when regulations change.

    Features:

    • Map your current software stack to your compliance obligations.
    • Benchmark capabilities and regulatory coverage across vendors, with sector insights.
    • Browse by regulation, framework, sector or capability.
    • Access to 50 evaluated solutions and their CAE reports. Selected to cover every software category.
    • Save, export and share vendor shortlists for internal or client projects.
  • Payment Details

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Vendor
  • Category
  • CL Tier
  • Short description
  • Website
  • What it is
  • Best for
  • Does NOT do
  • CL verdict
  • Regulatory coverage
  • Frameworks tested
  • Capabilities
  • MITRE ATT&CK
  • Strengths
  • Cautions
  • Anti-hype claims
  • Operational metrics
  • Evidence pack
Compare
Compare ×
View comparison Continue browsing software