Most of what a regulator publishes is not about you.
ShadowMap tracks what supervisory, national and standards authorities publish, and screens the non-cyber majority out before it ever reaches you. What survives is analysed into a structured obligation — binding or advisory, the deadline the document actually states, the security domains it touches, the entity types it names — and routed to the part of the platform that holds your evidence for it. That is programme context and a dated monitoring record. It is not a compliance opinion.
What this is
A monitoring capability, not a compliance opinion
Regulatory intelligence in ShadowMap watches what supervisors and national authorities publish, and turns it into something your programme can act on and evidence.
Two boundaries belong here rather than at the bottom of the page. The first: everything on this page is programme context. ShadowMap tells you what a regulator published, when, what it obliges and by when the document says so. Whether a given instrument binds your entity, and what it obliges you to do about it, is a determination for your compliance function and your legal advisers — we do not issue compliance opinions and this page is not one. The second: this is deliberately not compliance advisory. Assessment, gap analysis and framework readiness work is Security Brigade's practice, and the honest answer is to send you there — securitybrigade.com — rather than build a thinner second version of it here.
Coverage
The authorities under monitoring, and what is watched
Coverage is a maintained registry inside the product, not a page somebody updates by hand. All 31 are named below, because a coverage claim you cannot check is not a coverage claim.
| Jurisdiction | Authorities tracked | What is monitored |
|---|---|---|
| India | RBI, SEBI, CERT-In, IRDAI, TRAI, NPCI, MeitY, NCIIPC | Master directions, master circulars and notifications, the SEBI CSCRF and its amendments, Section 70B directions and the CISG guideline series, insurance and payments guidelines, telecom directions, national critical-infrastructure material |
| The deepest coverage in the set, and the reason the capability exists at all: CERT-In empanelment since 2008 meant RBI, SEBI CSCRF and IRDAI expectations were operational knowledge at Security Brigade long before they were a product feature. It shows in the sourcing — SEBI is read from its circulars, guidelines, regulations and enforcement orders separately, because the cyber-resilience material does not reliably appear in any one of them. | ||
| United States | CISA, NIST, SEC, OCC, FFIEC, FTC | Binding operational and emergency directives, SP 800-series and FIPS publications, disclosure rules, examination handbooks and enforcement guidance |
| European Union | ENISA, ECB, EBA, EDPB, DORA | Regulations and technical standards, supervisory guidelines and opinions, threat-led penetration-testing frameworks, ICT third-party and register-of-information material |
| DORA and NIS2 are the two instruments most often asked about here, and both place explicit obligations on third-party ICT risk and supplier monitoring. That is where vendor exposure — assessed with the same outside-in methodology applied to your own estate — produces dated, per-vendor evidence rather than an annual questionnaire. | ||
| United Kingdom | NCSC, FCA, PRA, ICO | Handbook changes, policy statements and consultation papers, operational-resilience material, data-protection enforcement and breach decisions |
| Singapore | MAS, CSA Singapore | Technology risk management guidelines and notices, outsourcing guidelines, incident notification and reporting instructions, national advisories |
| United Arab Emirates | CBUAE, DFSA, UAE-CSC | Central-bank cyber and cloud standards, DFSA rulebook modules and cyber-risk guidance covering the DIFC, national cyber-security directives |
| Australia | APRA, ACSC | Prudential standards including CPS 234, practice guides, national advisories and ransomware alerts |
| Global standards | PCI Security Standards Council | PCI DSS and the secure-software and card-production standards around it |
| Items with no single territory are carried as global rather than forced into a country. Adding an authority is a registry entry and a resync, so a regulator you are supervised by that is missing here is a request rather than a roadmap item. | ||
India
- Authorities tracked
- RBI, SEBI, CERT-In, IRDAI, TRAI, NPCI, MeitY, NCIIPC
- What is monitored
- Master directions, master circulars and notifications, the SEBI CSCRF and its amendments, Section 70B directions and the CISG guideline series, insurance and payments guidelines, telecom directions, national critical-infrastructure material
The deepest coverage in the set, and the reason the capability exists at all: CERT-In empanelment since 2008 meant RBI, SEBI CSCRF and IRDAI expectations were operational knowledge at Security Brigade long before they were a product feature. It shows in the sourcing — SEBI is read from its circulars, guidelines, regulations and enforcement orders separately, because the cyber-resilience material does not reliably appear in any one of them.
United States
- Authorities tracked
- CISA, NIST, SEC, OCC, FFIEC, FTC
- What is monitored
- Binding operational and emergency directives, SP 800-series and FIPS publications, disclosure rules, examination handbooks and enforcement guidance
European Union
- Authorities tracked
- ENISA, ECB, EBA, EDPB, DORA
- What is monitored
- Regulations and technical standards, supervisory guidelines and opinions, threat-led penetration-testing frameworks, ICT third-party and register-of-information material
DORA and NIS2 are the two instruments most often asked about here, and both place explicit obligations on third-party ICT risk and supplier monitoring. That is where vendor exposure — assessed with the same outside-in methodology applied to your own estate — produces dated, per-vendor evidence rather than an annual questionnaire.
United Kingdom
- Authorities tracked
- NCSC, FCA, PRA, ICO
- What is monitored
- Handbook changes, policy statements and consultation papers, operational-resilience material, data-protection enforcement and breach decisions
Singapore
- Authorities tracked
- MAS, CSA Singapore
- What is monitored
- Technology risk management guidelines and notices, outsourcing guidelines, incident notification and reporting instructions, national advisories
United Arab Emirates
- Authorities tracked
- CBUAE, DFSA, UAE-CSC
- What is monitored
- Central-bank cyber and cloud standards, DFSA rulebook modules and cyber-risk guidance covering the DIFC, national cyber-security directives
Australia
- Authorities tracked
- APRA, ACSC
- What is monitored
- Prudential standards including CPS 234, practice guides, national advisories and ransomware alerts
Global standards
- Authorities tracked
- PCI Security Standards Council
- What is monitored
- PCI DSS and the secure-software and card-production standards around it
Items with no single territory are carried as global rather than forced into a country. Adding an authority is a registry entry and a resync, so a regulator you are supervised by that is missing here is a request rather than a roadmap item.
The mechanism
From a regulator’s website to something worth reading
A financial regulator publishes overwhelmingly about things that are not security. The work is not fetching the documents; it is throwing almost all of them away without throwing away the one that mattered.
-
Ingest
From the authority itself, not from an aggregator
Feeds where a regulator publishes them, the listing pages where it does not, and rendered fetches for the portals that need them. Each authority carries several sources in priority order with fallback, so one broken page does not silence a regulator, and a per-source health log flags a fetch that suddenly returns nothing — the signal that a site redesign has quietly broken a selector.
-
Screen
The non-cyber majority never reaches your queue
A deterministic gate runs before anything is analysed: index and navigation pages, individual CVE and patch advisories — those belong in vulnerability management, not here — and the large non-security body a financial regulator publishes alongside, from prudential norms and forex to monetary policy and insurance operations. What survives that is asked one question by a relevance model: does this document create or change a cyber, data-protection or technology-risk rule for more than one organisation? Procedural noise, comment-period extensions and speeches do not.
-
Extract
A document becomes a structured obligation
What passes is analysed against the source text and nothing else. Out comes a clean title, short and detailed summaries, the key findings, the discrete compliance requirements with their own deadlines, the entity types the instrument names, the security domains it touches, whether it is binding or advisory, and the earliest date the document actually commits you to. A deadline that cannot be pointed at in the text is discarded rather than estimated.
-
Route
Into the part of the platform that holds your evidence
The domains an item is tagged with map to where the matching evidence already sits — data protection to Data Breaches and Leaked Credentials, cryptography to SSL Certificates, application security to Web Applications, incident response to Alerts. Be clear about what this is: the feed is a shared intelligence stream scoped by the authorities, entity types, industries and geographies you configure, not a scan of your estate. The pivot into your own data is a route we open, not a match we assert.
What arrives
Severity you can audit the rule for
Severity here is not a house style. It is assigned under fixed, published rules, and whether an instrument binds you is carried on a separate axis — so guidance can never be quietly read as an obligation.
| State | What it means | What follows |
|---|---|---|
| Critical | A binding obligation with a stated deadline under 90 days and penalties attached to missing it. | This one moves dates in the programme plan. |
| High | Binding, with either a stated deadline or significant penalties. | Plan against it inside the current cycle. |
| Medium | Advisory or best-practice guidance — and the value anything unclassifiable falls back to, so nothing is silently promoted upward. | Read it, decide, and record the decision. |
| Low | Informational. | Awareness. No obligation implied and none claimed. |
- Dated and enforceable
- Binding — plan for it
- Guidance — your call
- Informational
Evidence
Did the control run, on what date, over what scope, with what result
That is the question an auditor actually asks, and it is why regulatory intelligence sits inside the platform rather than beside it. A control that exists and a control that operated are different things, and only one of them leaves a record.
| What the auditor asks | The artefact that answers it | Where it comes from |
|---|---|---|
| Did the monitoring run, and over what? | Per-asset detection timestamps and the attributed inventory each run covered, with the date an asset entered scope and the date any asset left it | Asset Explorer |
| Who touched our systems, and what did they do? | Each validation probe recorded with its evidence, its timestamp and its outcome, so a challenged finding can be reconstructed rather than re-argued | Continuous Automated Red-Teaming |
| Validation runs only where it is safe and authorised. The scan profile, the named exclusions and the rate limit that bounded a run are part of the same record, so the answer to "what did you not test" is written down alongside the answer to "what did you". | ||
| What did the team decide about this finding? | The four-state disposition — Needs Review, Investigating, Accepted Risk, Closed — with the assignee, the comment thread and the timestamps | Action Center |
| The analyst decision and the scanner’s own detection status are deliberately separate axes: a re-scan can never silently erase a decision a person made, and a decision can never hide an exposure that is still live. Accepted Risk is held as a documented exception rather than a deletion, which is exactly the form an examiner asks for. | ||
| Was it handled inside the timeframe our own policy commits to? | SLA policy records, including the breaches | SLA policies |
| The breaches are in the record too, and that is deliberate. A monitoring trail showing only the occasions you met your own SLA is not evidence; an auditor who cannot find a single miss in a year stops trusting the whole set. | ||
| What has the team actually been doing with findings? | A chronological feed of assignments, status changes, tags, comments and shares, each against the specific finding it was performed on | Activity logs |
| Who changed the monitoring configuration itself? | The actor, the action, the source IP and the timestamp for every privileged change — members and roles, integrations and cloud sources, SLA and tag rules, two-factor status | Audit logs |
| ShadowMap produces the record. Whether that record satisfies a particular clause is a judgement for your auditor and your advisers. | ||
Did the monitoring run, and over what?
- The artefact that answers it
- Per-asset detection timestamps and the attributed inventory each run covered, with the date an asset entered scope and the date any asset left it
- Where it comes from
- Asset Explorer
Who touched our systems, and what did they do?
- The artefact that answers it
- Each validation probe recorded with its evidence, its timestamp and its outcome, so a challenged finding can be reconstructed rather than re-argued
- Where it comes from
- Continuous Automated Red-Teaming
Validation runs only where it is safe and authorised. The scan profile, the named exclusions and the rate limit that bounded a run are part of the same record, so the answer to "what did you not test" is written down alongside the answer to "what did you".
What did the team decide about this finding?
- The artefact that answers it
- The four-state disposition — Needs Review, Investigating, Accepted Risk, Closed — with the assignee, the comment thread and the timestamps
- Where it comes from
- Action Center
The analyst decision and the scanner’s own detection status are deliberately separate axes: a re-scan can never silently erase a decision a person made, and a decision can never hide an exposure that is still live. Accepted Risk is held as a documented exception rather than a deletion, which is exactly the form an examiner asks for.
Was it handled inside the timeframe our own policy commits to?
- The artefact that answers it
- SLA policy records, including the breaches
- Where it comes from
- SLA policies
The breaches are in the record too, and that is deliberate. A monitoring trail showing only the occasions you met your own SLA is not evidence; an auditor who cannot find a single miss in a year stops trusting the whole set.
What has the team actually been doing with findings?
- The artefact that answers it
- A chronological feed of assignments, status changes, tags, comments and shares, each against the specific finding it was performed on
- Where it comes from
- Activity logs
Who changed the monitoring configuration itself?
- The artefact that answers it
- The actor, the action, the source IP and the timestamp for every privileged change — members and roles, integrations and cloud sources, SLA and tag rules, two-factor status
- Where it comes from
- Audit logs
ShadowMap produces the record. Whether that record satisfies a particular clause is a judgement for your auditor and your advisers.
How the figure is derived
Where the coverage count comes from
A coverage number is only useful if you can see what was counted. This one is a direct count of the regulator registry that ships in the product, not a tally maintained separately from the thing it describes.
31 authorities, counted from the registry the monitoring runs against As of August 2026
- A direct count of the regulator entries configured in the product, read from the same registry the ingestion runs against. When the configuration moves, the number moves with it.
- One entry per supervisory, national or standards authority, counted once however many publication streams it operates. RBI is one authority even though its master directions, master circulars, notifications, press releases and legal-framework pages are each fetched separately.
- Every authority in the count is named in the coverage table above. There is no unpublished remainder inflating the figure.
- Territory follows the authority that issues the instrument, not the text of the document. Bodies whose standards apply everywhere are carried as global rather than assigned to a country they happen to be incorporated in.
- Regulatory Intelligence is a section of the product with its own preferences and notification frequency, not a briefing somebody compiles by hand each month.
Deliberately excluded
- No legal interpretation. Nothing here tells you whether an instrument binds your entity.
- No mapping of a published item to a clause in your own control framework. Where you need that, it is assessment work, and Security Brigade does it properly at securitybrigade.com.
- No filing, submission or regulatory-reporting workflow. ShadowMap watches what authorities publish; it lodges nothing on your behalf.
- No claim over material that is not published. Supervisory correspondence addressed to your entity never reaches us, and should not.
- No scan-derived applicability. This is a shared intelligence stream tailored by the profile you configure, not a match against your discovered assets — and the page says so where it makes the claim, not only here.
Where this gets sharper
Regulatory Intelligence works from one correlated exposure model
Questions buyers actually ask
Before you evaluate this
Can it tell us whether a circular applies to our entity?
It can narrow it a long way, and then it stops — deliberately. You configure the authorities you are supervised by, your industries, your geographies and your entity types, and entity types are specific to each authority: Scheduled Commercial Bank or NBFC under RBI, Stock Broker or Registrar and Transfer Agent under SEBI, Major Payment Institution under MAS. Items are scoped and prioritised against that profile, and each one carries the entity types the instrument itself names. What we will not do is convert that into a determination that the instrument binds you. That is a legal question about your registration and your permissions, and it belongs to your compliance function and your advisers, not to a monitoring platform.
How is this different from subscribing to the regulators we care about?
A subscription gives you everything an authority publishes, and for most financial regulators the overwhelming majority of that is not about security at all. Here the non-cyber body is screened out deterministically before anything is analysed, individual CVE advisories are pushed back to vulnerability management where they belong, and what remains is asked whether it actually changes a rule. What reaches you is then structured rather than attached: the requirements, the entity types, the domains, binding or advisory, and the deadline the document itself states. The second difference is the record. The monitoring around it is dated, scoped and logged, which is the form an auditor asks for and the form an inbox cannot produce.
Which authorities do you track, and can you add one?
All 31 are named in the coverage table on this page — eight in India, six in the United States, five at EU level, four in the United Kingdom, three in the UAE, two each in Singapore and Australia, and the PCI Security Standards Council globally. Adding one is a registry entry and a resync rather than a release, so an authority you are supervised by that is missing is a request rather than a roadmap item. Ask and we will tell you what it would take and when.
See the estate your obligations actually apply to
One apex domain, two business days. The written snapshot carries what we found from outside, and the dated record of the monitoring that found it.