eIDAS: EU Electronic Identification & Trust Services
eIDAS is the EU regulation establishing a cross-border legal framework for electronic signatures, seals, and trust services across all 27 member states.
eIDAS is the EU regulation establishing a cross-border legal framework for electronic signatures, seals, and trust services across all 27 member states.
The ESIGN Act is the US federal law granting electronic signatures the same legal validity as handwritten signatures across interstate and foreign commerce.
FERPA is the US federal law governing student education record privacy. Any open source tool deployed in K-12 or higher education handling student data must be FERPA-eligible.
PCI DSS v4.0 is the mandatory security standard for any organization handling card payments. Self-hosting payment infrastructure can radically reduce your compliance scope, or expand it.
FedRAMP 20x is the modernized US government standard for cloud security, focusing on automated validation and machine-readable authorization packages.
CMMC 2.0 is the US Department of Defense's mandatory cybersecurity certification framework for defense contractors and suppliers handling Federal Contract Information or Controlled Unclassified Information.
Cyber Essentials Plus is the UK government's independently verified cybersecurity certification, required for MOD contracts and central government suppliers handling sensitive data.
Germany's voluntary federal IT security label, issued by the BSI. A provider declares security properties against a DIN SPEC for its product category, backed by BSI monitoring.
FIPS 140-3 is the NIST standard validating cryptographic modules for US federal use. Software handling sensitive government data must use FIPS-validated cryptography, not just claim encryption.
WCAG 2.2 AA is the current W3C web accessibility standard, superseding 2.1 with new criteria for authentication, mobile interaction, and cognitive accessibility.
The EU CRA mandates security requirements for software products in the EU market, focusing on SBOMs and rapid vulnerability reporting.
DORA sets uniform ICT risk-management, incident-reporting, and third-party oversight rules for EU financial entities and the tech vendors that serve them.