Skip to main content
Intelligence · Programme context

Most of what a regulator publishes is not about you.

ShadowMap tracks what supervisory, national and standards authorities publish, and screens the non-cyber majority out before it ever reaches you. What survives is analysed into a structured obligation — binding or advisory, the deadline the document actually states, the security domains it touches, the entity types it names — and routed to the part of the platform that holds your evidence for it. That is programme context and a dated monitoring record. It is not a compliance opinion.

31
Authorities under monitoring
Since 2008
CERT-In empanelled

What this is

A monitoring capability, not a compliance opinion

Regulatory intelligence in ShadowMap watches what supervisors and national authorities publish, and turns it into something your programme can act on and evidence.

Two boundaries belong here rather than at the bottom of the page. The first: everything on this page is programme context. ShadowMap tells you what a regulator published, when, what it obliges and by when the document says so. Whether a given instrument binds your entity, and what it obliges you to do about it, is a determination for your compliance function and your legal advisers — we do not issue compliance opinions and this page is not one. The second: this is deliberately not compliance advisory. Assessment, gap analysis and framework readiness work is Security Brigade's practice, and the honest answer is to send you there — securitybrigade.com — rather than build a thinner second version of it here.

Coverage

The authorities under monitoring, and what is watched

Coverage is a maintained registry inside the product, not a page somebody updates by hand. All 31 are named below, because a coverage claim you cannot check is not a coverage claim.

JurisdictionAuthorities trackedWhat is monitored
India RBI, SEBI, CERT-In, IRDAI, TRAI, NPCI, MeitY, NCIIPC Master directions, master circulars and notifications, the SEBI CSCRF and its amendments, Section 70B directions and the CISG guideline series, insurance and payments guidelines, telecom directions, national critical-infrastructure material
The deepest coverage in the set, and the reason the capability exists at all: CERT-In empanelment since 2008 meant RBI, SEBI CSCRF and IRDAI expectations were operational knowledge at Security Brigade long before they were a product feature. It shows in the sourcing — SEBI is read from its circulars, guidelines, regulations and enforcement orders separately, because the cyber-resilience material does not reliably appear in any one of them.
United States CISA, NIST, SEC, OCC, FFIEC, FTC Binding operational and emergency directives, SP 800-series and FIPS publications, disclosure rules, examination handbooks and enforcement guidance
European Union ENISA, ECB, EBA, EDPB, DORA Regulations and technical standards, supervisory guidelines and opinions, threat-led penetration-testing frameworks, ICT third-party and register-of-information material
DORA and NIS2 are the two instruments most often asked about here, and both place explicit obligations on third-party ICT risk and supplier monitoring. That is where vendor exposure — assessed with the same outside-in methodology applied to your own estate — produces dated, per-vendor evidence rather than an annual questionnaire.
United Kingdom NCSC, FCA, PRA, ICO Handbook changes, policy statements and consultation papers, operational-resilience material, data-protection enforcement and breach decisions
Singapore MAS, CSA Singapore Technology risk management guidelines and notices, outsourcing guidelines, incident notification and reporting instructions, national advisories
United Arab Emirates CBUAE, DFSA, UAE-CSC Central-bank cyber and cloud standards, DFSA rulebook modules and cyber-risk guidance covering the DIFC, national cyber-security directives
Australia APRA, ACSC Prudential standards including CPS 234, practice guides, national advisories and ransomware alerts
Global standards PCI Security Standards Council PCI DSS and the secure-software and card-production standards around it
Items with no single territory are carried as global rather than forced into a country. Adding an authority is a registry entry and a resync, so a regulator you are supervised by that is missing here is a request rather than a roadmap item.

India

Authorities tracked
RBI, SEBI, CERT-In, IRDAI, TRAI, NPCI, MeitY, NCIIPC
What is monitored
Master directions, master circulars and notifications, the SEBI CSCRF and its amendments, Section 70B directions and the CISG guideline series, insurance and payments guidelines, telecom directions, national critical-infrastructure material

The deepest coverage in the set, and the reason the capability exists at all: CERT-In empanelment since 2008 meant RBI, SEBI CSCRF and IRDAI expectations were operational knowledge at Security Brigade long before they were a product feature. It shows in the sourcing — SEBI is read from its circulars, guidelines, regulations and enforcement orders separately, because the cyber-resilience material does not reliably appear in any one of them.

United States

Authorities tracked
CISA, NIST, SEC, OCC, FFIEC, FTC
What is monitored
Binding operational and emergency directives, SP 800-series and FIPS publications, disclosure rules, examination handbooks and enforcement guidance

European Union

Authorities tracked
ENISA, ECB, EBA, EDPB, DORA
What is monitored
Regulations and technical standards, supervisory guidelines and opinions, threat-led penetration-testing frameworks, ICT third-party and register-of-information material

DORA and NIS2 are the two instruments most often asked about here, and both place explicit obligations on third-party ICT risk and supplier monitoring. That is where vendor exposure — assessed with the same outside-in methodology applied to your own estate — produces dated, per-vendor evidence rather than an annual questionnaire.

United Kingdom

Authorities tracked
NCSC, FCA, PRA, ICO
What is monitored
Handbook changes, policy statements and consultation papers, operational-resilience material, data-protection enforcement and breach decisions

Singapore

Authorities tracked
MAS, CSA Singapore
What is monitored
Technology risk management guidelines and notices, outsourcing guidelines, incident notification and reporting instructions, national advisories

United Arab Emirates

Authorities tracked
CBUAE, DFSA, UAE-CSC
What is monitored
Central-bank cyber and cloud standards, DFSA rulebook modules and cyber-risk guidance covering the DIFC, national cyber-security directives

Australia

Authorities tracked
APRA, ACSC
What is monitored
Prudential standards including CPS 234, practice guides, national advisories and ransomware alerts

Global standards

Authorities tracked
PCI Security Standards Council
What is monitored
PCI DSS and the secure-software and card-production standards around it

Items with no single territory are carried as global rather than forced into a country. Adding an authority is a registry entry and a resync, so a regulator you are supervised by that is missing here is a request rather than a roadmap item.

The mechanism

From a regulator’s website to something worth reading

A financial regulator publishes overwhelmingly about things that are not security. The work is not fetching the documents; it is throwing almost all of them away without throwing away the one that mattered.

What arrives

Severity you can audit the rule for

Severity here is not a house style. It is assigned under fixed, published rules, and whether an instrument binds you is carried on a separate axis — so guidance can never be quietly read as an obligation.

Severity you can audit the rule for
StateWhat it meansWhat follows
Critical A binding obligation with a stated deadline under 90 days and penalties attached to missing it. This one moves dates in the programme plan.
High Binding, with either a stated deadline or significant penalties. Plan against it inside the current cycle.
Medium Advisory or best-practice guidance — and the value anything unclassifiable falls back to, so nothing is silently promoted upward. Read it, decide, and record the decision.
Low Informational. Awareness. No obligation implied and none claimed.
Key
  • Dated and enforceable
  • Binding — plan for it
  • Guidance — your call
  • Informational

Evidence

Did the control run, on what date, over what scope, with what result

That is the question an auditor actually asks, and it is why regulatory intelligence sits inside the platform rather than beside it. A control that exists and a control that operated are different things, and only one of them leaves a record.

What the auditor asksThe artefact that answers itWhere it comes from
Did the monitoring run, and over what? Per-asset detection timestamps and the attributed inventory each run covered, with the date an asset entered scope and the date any asset left it Asset Explorer
Who touched our systems, and what did they do? Each validation probe recorded with its evidence, its timestamp and its outcome, so a challenged finding can be reconstructed rather than re-argued Continuous Automated Red-Teaming
Validation runs only where it is safe and authorised. The scan profile, the named exclusions and the rate limit that bounded a run are part of the same record, so the answer to "what did you not test" is written down alongside the answer to "what did you".
What did the team decide about this finding? The four-state disposition — Needs Review, Investigating, Accepted Risk, Closed — with the assignee, the comment thread and the timestamps Action Center
The analyst decision and the scanner’s own detection status are deliberately separate axes: a re-scan can never silently erase a decision a person made, and a decision can never hide an exposure that is still live. Accepted Risk is held as a documented exception rather than a deletion, which is exactly the form an examiner asks for.
Was it handled inside the timeframe our own policy commits to? SLA policy records, including the breaches SLA policies
The breaches are in the record too, and that is deliberate. A monitoring trail showing only the occasions you met your own SLA is not evidence; an auditor who cannot find a single miss in a year stops trusting the whole set.
What has the team actually been doing with findings? A chronological feed of assignments, status changes, tags, comments and shares, each against the specific finding it was performed on Activity logs
Who changed the monitoring configuration itself? The actor, the action, the source IP and the timestamp for every privileged change — members and roles, integrations and cloud sources, SLA and tag rules, two-factor status Audit logs
ShadowMap produces the record. Whether that record satisfies a particular clause is a judgement for your auditor and your advisers.

Did the monitoring run, and over what?

The artefact that answers it
Per-asset detection timestamps and the attributed inventory each run covered, with the date an asset entered scope and the date any asset left it
Where it comes from
Asset Explorer

Who touched our systems, and what did they do?

The artefact that answers it
Each validation probe recorded with its evidence, its timestamp and its outcome, so a challenged finding can be reconstructed rather than re-argued
Where it comes from
Continuous Automated Red-Teaming

Validation runs only where it is safe and authorised. The scan profile, the named exclusions and the rate limit that bounded a run are part of the same record, so the answer to "what did you not test" is written down alongside the answer to "what did you".

What did the team decide about this finding?

The artefact that answers it
The four-state disposition — Needs Review, Investigating, Accepted Risk, Closed — with the assignee, the comment thread and the timestamps
Where it comes from
Action Center

The analyst decision and the scanner’s own detection status are deliberately separate axes: a re-scan can never silently erase a decision a person made, and a decision can never hide an exposure that is still live. Accepted Risk is held as a documented exception rather than a deletion, which is exactly the form an examiner asks for.

Was it handled inside the timeframe our own policy commits to?

The artefact that answers it
SLA policy records, including the breaches
Where it comes from
SLA policies

The breaches are in the record too, and that is deliberate. A monitoring trail showing only the occasions you met your own SLA is not evidence; an auditor who cannot find a single miss in a year stops trusting the whole set.

What has the team actually been doing with findings?

The artefact that answers it
A chronological feed of assignments, status changes, tags, comments and shares, each against the specific finding it was performed on
Where it comes from
Activity logs

Who changed the monitoring configuration itself?

The artefact that answers it
The actor, the action, the source IP and the timestamp for every privileged change — members and roles, integrations and cloud sources, SLA and tag rules, two-factor status
Where it comes from
Audit logs

ShadowMap produces the record. Whether that record satisfies a particular clause is a judgement for your auditor and your advisers.

How the figure is derived

Where the coverage count comes from

A coverage number is only useful if you can see what was counted. This one is a direct count of the regulator registry that ships in the product, not a tally maintained separately from the thing it describes.

31 authorities, counted from the registry the monitoring runs against As of August 2026
  • A direct count of the regulator entries configured in the product, read from the same registry the ingestion runs against. When the configuration moves, the number moves with it.
  • One entry per supervisory, national or standards authority, counted once however many publication streams it operates. RBI is one authority even though its master directions, master circulars, notifications, press releases and legal-framework pages are each fetched separately.
  • Every authority in the count is named in the coverage table above. There is no unpublished remainder inflating the figure.
  • Territory follows the authority that issues the instrument, not the text of the document. Bodies whose standards apply everywhere are carried as global rather than assigned to a country they happen to be incorporated in.
  • Regulatory Intelligence is a section of the product with its own preferences and notification frequency, not a briefing somebody compiles by hand each month.

Deliberately excluded

  • No legal interpretation. Nothing here tells you whether an instrument binds your entity.
  • No mapping of a published item to a clause in your own control framework. Where you need that, it is assessment work, and Security Brigade does it properly at securitybrigade.com.
  • No filing, submission or regulatory-reporting workflow. ShadowMap watches what authorities publish; it lodges nothing on your behalf.
  • No claim over material that is not published. Supervisory correspondence addressed to your entity never reaches us, and should not.
  • No scan-derived applicability. This is a shared intelligence stream tailored by the profile you configure, not a match against your discovered assets — and the page says so where it makes the claim, not only here.

Questions buyers actually ask

Before you evaluate this

Can it tell us whether a circular applies to our entity?

It can narrow it a long way, and then it stops — deliberately. You configure the authorities you are supervised by, your industries, your geographies and your entity types, and entity types are specific to each authority: Scheduled Commercial Bank or NBFC under RBI, Stock Broker or Registrar and Transfer Agent under SEBI, Major Payment Institution under MAS. Items are scoped and prioritised against that profile, and each one carries the entity types the instrument itself names. What we will not do is convert that into a determination that the instrument binds you. That is a legal question about your registration and your permissions, and it belongs to your compliance function and your advisers, not to a monitoring platform.

How is this different from subscribing to the regulators we care about?

A subscription gives you everything an authority publishes, and for most financial regulators the overwhelming majority of that is not about security at all. Here the non-cyber body is screened out deterministically before anything is analysed, individual CVE advisories are pushed back to vulnerability management where they belong, and what remains is asked whether it actually changes a rule. What reaches you is then structured rather than attached: the requirements, the entity types, the domains, binding or advisory, and the deadline the document itself states. The second difference is the record. The monitoring around it is dated, scoped and logged, which is the form an auditor asks for and the form an inbox cannot produce.

Which authorities do you track, and can you add one?

All 31 are named in the coverage table on this page — eight in India, six in the United States, five at EU level, four in the United Kingdom, three in the UAE, two each in Singapore and Australia, and the PCI Security Standards Council globally. Adding one is a registry entry and a resync rather than a release, so an authority you are supervised by that is missing is a request rather than a roadmap item. Ask and we will tell you what it would take and when.

See the estate your obligations actually apply to

One apex domain, two business days. The written snapshot carries what we found from outside, and the dated record of the monitoring that found it.