The RBI, the SEC, the ECB and the MAS all publish on their own schedule.
ShadowMap tracks 31 supervisory, national and standards authorities across India, the United States, the European Union, the United Kingdom, Singapore, the UAE and Australia, and screens the non-cyber majority out before it ever reaches you. Most of what any regulator publishes is not about security at all. What survives is analysed into a structured obligation — binding or advisory, the deadline the document actually states, the security domains it touches, the entity types it names — and routed to the part of the platform that holds your evidence for it. That is programme context and a dated monitoring record. It is not a compliance opinion.
What this is
A monitoring capability, not a compliance opinion
Regulatory intelligence in ShadowMap watches what supervisory, national and standards authorities publish across seven territories, and turns it into something your programme can act on and evidence.
Two boundaries. The first: everything on this page is programme context. ShadowMap tells you what an authority published, when, what it obliges and by when the document says so. Whether a given instrument binds your entity, and what it obliges you to do about it, is a determination for your compliance function and your legal advisers — we do not issue compliance opinions and this page is not one. The second: this is deliberately not compliance advisory. Assessment, gap analysis and framework readiness work is Security Brigade's practice, and the honest answer is to send you there — securitybrigade.com — rather than build a thinner second version of it here.
Coverage
Seven territories, and the standards body that has none
Coverage is a maintained registry inside the product, not a page somebody updates by hand. All 31 authorities are named below — 23 of them outside India — because a coverage claim you cannot check is not a coverage claim. Territories are listed alphabetically, and the count of each one’s publication sources is in the methodology at the foot of the page.
| Territory | Authorities tracked | What is monitored |
|---|---|---|
| Australia | APRA, ACSC | Prudential standard CPS 234 and the practice guides around it, prudential news and publications, national alerts and advisories including the joint advisories issued with partner agencies |
| APRA is one of the six authorities with entity-type profiling configured, alongside the RBI, SEBI, IRDAI, MAS and CBUAE — so an item can be scoped to an Authorised Deposit-taking Institution the same way it is scoped to a Scheduled Commercial Bank. | ||
| European Union | ENISA, ECB, EBA, EDPB, DORA | DORA technical and implementing standards, EBA ICT risk-management guidelines, ECB material including the TIBER-EU threat-led testing framework, EDPB guidelines and binding decisions, ENISA threat landscapes and NIS2 guidance |
| DORA and NIS2 are the two instruments most often asked about here, and both place explicit obligations on third-party ICT risk and supplier monitoring. That is where vendor exposure — assessed with the same outside-in methodology applied to your own estate — produces dated, per-vendor evidence rather than an annual questionnaire. | ||
| India | RBI, SEBI, CERT-In, IRDAI, TRAI, NPCI, MeitY, NCIIPC | Master directions, master circulars and notifications, the SEBI CSCRF and its amendments, Section 70B directions and the CISG guideline series, insurance and payments guidelines, telecom directions, national critical-infrastructure material |
| Eight authorities and 40 of the 91 publication sources — the deepest coverage in the registry by a distance. Why it is sourced that hard, and what each authority contributes, is the section immediately below. | ||
| Singapore | MAS, CSA Singapore | Technology risk management guidelines and the cyber hygiene notice, outsourcing guidelines, incident notification and reporting instructions, national alerts, advisories and the legislation and guidelines listing |
| United Arab Emirates | CBUAE, DFSA, UAE-CSC | Central-bank rulebook, legislation and information-security standards, DFSA cyber reports, guides, handbooks and consultation papers covering the DIFC, the national cyber strategy and NIAF material |
| United Kingdom | NCSC, FCA, PRA, ICO | NCSC advisories, alerts and guidance including the Cyber Assessment Framework, FCA operational-resilience and critical-third-party material, PRA supervisory statements, ICO enforcement notices and UK GDPR guidance |
| United States | CISA, NIST, SEC, OCC, FFIEC, FTC | CISA binding operational directives and cybersecurity advisories, NIST CSF 2.0, SP 800-series and FIPS publications, SEC cyber disclosure rulemaking, OCC bulletins and alerts, the FFIEC IT Examination Handbook, FTC Safeguards Rule enforcement |
| Global standards | PCI Security Standards Council | PCI DSS and the secure-software and card-production standards around it |
| Items with no single territory are carried as global rather than forced into a country. Adding an authority is a registry entry and a resync, so an authority you are supervised by that is missing here is a request rather than a roadmap item. | ||
Australia
- Authorities tracked
- APRA, ACSC
- What is monitored
- Prudential standard CPS 234 and the practice guides around it, prudential news and publications, national alerts and advisories including the joint advisories issued with partner agencies
APRA is one of the six authorities with entity-type profiling configured, alongside the RBI, SEBI, IRDAI, MAS and CBUAE — so an item can be scoped to an Authorised Deposit-taking Institution the same way it is scoped to a Scheduled Commercial Bank.
European Union
- Authorities tracked
- ENISA, ECB, EBA, EDPB, DORA
- What is monitored
- DORA technical and implementing standards, EBA ICT risk-management guidelines, ECB material including the TIBER-EU threat-led testing framework, EDPB guidelines and binding decisions, ENISA threat landscapes and NIS2 guidance
DORA and NIS2 are the two instruments most often asked about here, and both place explicit obligations on third-party ICT risk and supplier monitoring. That is where vendor exposure — assessed with the same outside-in methodology applied to your own estate — produces dated, per-vendor evidence rather than an annual questionnaire.
India
- Authorities tracked
- RBI, SEBI, CERT-In, IRDAI, TRAI, NPCI, MeitY, NCIIPC
- What is monitored
- Master directions, master circulars and notifications, the SEBI CSCRF and its amendments, Section 70B directions and the CISG guideline series, insurance and payments guidelines, telecom directions, national critical-infrastructure material
Eight authorities and 40 of the 91 publication sources — the deepest coverage in the registry by a distance. Why it is sourced that hard, and what each authority contributes, is the section immediately below.
Singapore
- Authorities tracked
- MAS, CSA Singapore
- What is monitored
- Technology risk management guidelines and the cyber hygiene notice, outsourcing guidelines, incident notification and reporting instructions, national alerts, advisories and the legislation and guidelines listing
United Arab Emirates
- Authorities tracked
- CBUAE, DFSA, UAE-CSC
- What is monitored
- Central-bank rulebook, legislation and information-security standards, DFSA cyber reports, guides, handbooks and consultation papers covering the DIFC, the national cyber strategy and NIAF material
United Kingdom
- Authorities tracked
- NCSC, FCA, PRA, ICO
- What is monitored
- NCSC advisories, alerts and guidance including the Cyber Assessment Framework, FCA operational-resilience and critical-third-party material, PRA supervisory statements, ICO enforcement notices and UK GDPR guidance
United States
- Authorities tracked
- CISA, NIST, SEC, OCC, FFIEC, FTC
- What is monitored
- CISA binding operational directives and cybersecurity advisories, NIST CSF 2.0, SP 800-series and FIPS publications, SEC cyber disclosure rulemaking, OCC bulletins and alerts, the FFIEC IT Examination Handbook, FTC Safeguards Rule enforcement
Global standards
- Authorities tracked
- PCI Security Standards Council
- What is monitored
- PCI DSS and the secure-software and card-production standards around it
Items with no single territory are carried as global rather than forced into a country. Adding an authority is a registry entry and a resync, so an authority you are supervised by that is missing here is a request rather than a roadmap item.
India
Where the coverage goes deepest, and what pays for it
Eight of the 31 authorities are Indian, and between them they carry 40 of the 91 publication sources in the registry — more than the United States, the European Union and the United Kingdom combined.
CERT-In empanelment since 2008 meant RBI, SEBI and IRDAI expectations were operational knowledge at Security Brigade long before they were a product feature, and it shows in the sourcing rather than in a badge. The RBI is read from its master directions, master circulars, notifications, press releases and legal-framework pages as five separate streams. SEBI is read from its circulars, guidelines, regulations and enforcement orders separately, because the cyber-resilience material does not reliably appear in any one of them, and its portal is rendered rather than fetched because it will not answer a plain request. CERT-In carries its Section 70B directions alongside its homepage, so a direction is picked up the day it is posted. NPCI alone contributes twelve circular streams — UPI, RuPay, IMPS, NACH, AePS, NETC and the rest — because payment-scheme security instructions are published per scheme and consolidated nowhere. MeitY covers the IT Act, the DPDP Act and the AI governance guidelines; NCIIPC covers critical-infrastructure advisories and responsible-disclosure guidance; TRAI covers telecom directions and regulations. The pipeline that runs over all of it is the same one that runs over the SEC and the FCA, and so is the boundary: what an instrument obliges your entity to do remains a determination for your compliance function.
The mechanism
From an authority’s website to something worth reading
A financial regulator publishes overwhelmingly about things that are not security. The work is not fetching the documents; it is throwing almost all of them away without throwing away the one that mattered.
-
Ingest
From the authority itself, not from an aggregator
Feeds where an authority publishes them — CISA’s cybersecurity advisories, the EBA’s news and publications, the ACSC’s alerts, the RBI’s press releases — listing pages where it does not, and rendered fetches for the portals that need them, which is the only reason SEBI’s Java-rendered portal is reachable at all. Each authority carries several sources in priority order with fallback, so one broken page does not silence a regulator, and a per-source health log flags a fetch that suddenly returns nothing — the signal that a site redesign has quietly broken a selector.
-
Screen
The non-cyber majority never reaches your queue
A deterministic gate runs before anything is analysed: index and navigation pages, individual CVE and patch advisories — CISA KEV additions and CERT-In vulnerability notes among them, which belong in vulnerability management, not here — and the large non-security body a financial regulator publishes alongside, from prudential norms and forex to monetary policy and insurance operations. What survives that is asked one question by a relevance model: does this document create or change a cyber, data-protection or technology-risk rule for more than one organisation? Procedural noise, comment-period extensions and speeches do not.
-
Extract
A document becomes a structured obligation
What passes is analysed against the source text and nothing else. Out comes a clean title, short and detailed summaries, the key findings, the discrete compliance requirements with their own deadlines, the entity types the instrument names, the security domains it touches, whether it is binding or advisory, and the earliest date the document actually commits you to. Territory is the one field not read out of the document: it is assigned from the issuing authority’s registered country, so an item cannot become Singaporean by mentioning Singapore. A deadline that cannot be pointed at in the text is discarded rather than estimated.
-
Route
Into the part of the platform that holds your evidence
The domains an item is tagged with map to where the matching evidence already sits — data protection to Data Breaches and Leaked Credentials, cryptography to SSL Certificates, application security to Web Applications, incident response to Alerts. Be clear about what this is: the feed is a shared intelligence stream scoped by the authorities, entity types, industries and geographies you configure, not a scan of your estate. The pivot into your own data is a route we open, not a match we assert.
What arrives
Severity you can audit the rule for
Severity here is not a house style. It is assigned under fixed, published rules, and whether an instrument binds you is carried on a separate axis — so guidance can never be quietly read as an obligation.
| State | What it means | What follows |
|---|---|---|
| Critical | A binding obligation with a stated deadline under 90 days and penalties attached to missing it. | This one moves dates in the programme plan. |
| High | Binding, with either a stated deadline or significant penalties. | Plan against it inside the current cycle. |
| Medium | Advisory or best-practice guidance — and the value anything unclassifiable falls back to, so nothing is silently promoted upward. | Read it, decide, and record the decision. |
| Low | Informational. | Awareness. No obligation implied and none claimed. |
- Dated and enforceable
- Binding — plan for it
- Guidance — your call
- Informational
Evidence
Did the control run, on what date, over what scope, with what result
That is the question an auditor actually asks, and it is why regulatory intelligence sits inside the platform rather than beside it. A control that exists and a control that operated are different things, and only one of them leaves a record.
| What the auditor asks | The artefact that answers it | Where it comes from |
|---|---|---|
| Did the monitoring run, and over what? | Per-asset detection timestamps and the attributed inventory each run covered, with the date an asset entered scope and the date any asset left it | Asset Explorer |
| Who touched our systems, and what did they do? | Each validation probe recorded with its evidence, its timestamp and its outcome, so a challenged finding can be reconstructed rather than re-argued | Continuous Automated Red-Teaming |
| Validation runs only where it is safe and authorised. The scan profile, the named exclusions and the rate limit that bounded a run are part of the same record, so the answer to "what did you not test" is written down alongside the answer to "what did you". | ||
| What did the team decide about this finding? | The four-state disposition — Needs Review, Investigating, Accepted Risk, Closed — with the assignee, the comment thread and the timestamps | Action Center |
| The analyst decision and the scanner’s own detection status are deliberately separate axes: a re-scan can never silently erase a decision a person made, and a decision can never hide an exposure that is still live. Accepted Risk is held as a documented exception rather than a deletion, which is exactly the form an examiner asks for. | ||
| Was it handled inside the timeframe our own policy commits to? | SLA policy records, including the breaches | SLA policies |
| The breaches are in the record too, and that is deliberate. A monitoring trail showing only the occasions you met your own SLA is not evidence; an auditor who cannot find a single miss in a year stops trusting the whole set. | ||
| What has the team actually been doing with findings? | A chronological feed of assignments, status changes, tags, comments and shares, each against the specific finding it was performed on | Activity logs |
| Who changed the monitoring configuration itself? | The actor, the action, the source IP and the timestamp for every privileged change — members and roles, integrations and cloud sources, SLA and tag rules, two-factor status | Audit logs |
| ShadowMap produces the record. Whether that record satisfies a particular clause is a judgement for your auditor and your advisers. | ||
Did the monitoring run, and over what?
- The artefact that answers it
- Per-asset detection timestamps and the attributed inventory each run covered, with the date an asset entered scope and the date any asset left it
- Where it comes from
- Asset Explorer
Who touched our systems, and what did they do?
- The artefact that answers it
- Each validation probe recorded with its evidence, its timestamp and its outcome, so a challenged finding can be reconstructed rather than re-argued
- Where it comes from
- Continuous Automated Red-Teaming
Validation runs only where it is safe and authorised. The scan profile, the named exclusions and the rate limit that bounded a run are part of the same record, so the answer to "what did you not test" is written down alongside the answer to "what did you".
What did the team decide about this finding?
- The artefact that answers it
- The four-state disposition — Needs Review, Investigating, Accepted Risk, Closed — with the assignee, the comment thread and the timestamps
- Where it comes from
- Action Center
The analyst decision and the scanner’s own detection status are deliberately separate axes: a re-scan can never silently erase a decision a person made, and a decision can never hide an exposure that is still live. Accepted Risk is held as a documented exception rather than a deletion, which is exactly the form an examiner asks for.
Was it handled inside the timeframe our own policy commits to?
- The artefact that answers it
- SLA policy records, including the breaches
- Where it comes from
- SLA policies
The breaches are in the record too, and that is deliberate. A monitoring trail showing only the occasions you met your own SLA is not evidence; an auditor who cannot find a single miss in a year stops trusting the whole set.
What has the team actually been doing with findings?
- The artefact that answers it
- A chronological feed of assignments, status changes, tags, comments and shares, each against the specific finding it was performed on
- Where it comes from
- Activity logs
Who changed the monitoring configuration itself?
- The artefact that answers it
- The actor, the action, the source IP and the timestamp for every privileged change — members and roles, integrations and cloud sources, SLA and tag rules, two-factor status
- Where it comes from
- Audit logs
ShadowMap produces the record. Whether that record satisfies a particular clause is a judgement for your auditor and your advisers.
How the figures are derived
Where the coverage counts come from
A coverage number is only useful if you can see what was counted. These are direct counts of the regulator registry that ships in the product, not a tally maintained separately from the thing it describes.
31 authorities and 91 sources, counted from the registry the monitoring runs against As of August 2026
- A direct count of the regulator entries configured in the product, read from the same registry the ingestion runs against. When the configuration moves, the numbers move with it.
- One entry per supervisory, national or standards authority, counted once however many publication streams it operates. The RBI is one authority even though its master directions, master circulars, notifications, press releases and legal-framework pages are each fetched separately.
- The 91 is the count of those streams — the individual feeds, listing pages and rendered fetches configured across the 31 authorities. India carries 40 of them, the United States 15, the UAE nine, the European Union and the United Kingdom eight each, Singapore five, Australia four, and the global card standards two.
- 23 of the 31 authorities are outside India, and 15 are American, British or EU-level. Both are counts of the same registry, taken the same way as the 31.
- Every authority in the count is named in the coverage table above. There is no unpublished remainder inflating the figure.
- Territory follows the authority that issues the instrument, not the text of the document. Bodies whose standards apply everywhere are carried as global rather than assigned to a country they happen to be incorporated in, which is why seven territories account for 30 of the 31 authorities and the thirty-first sits outside all of them.
- Regulatory Intelligence is a section of the product with its own preferences and notification frequency, not a briefing somebody compiles by hand each month.
Deliberately excluded
- No legal interpretation. Nothing here tells you whether an instrument binds your entity.
- No mapping of a published item to a clause in your own control framework. Where you need that, it is assessment work, and Security Brigade does it properly at securitybrigade.com.
- No filing, submission or regulatory-reporting workflow. ShadowMap watches what authorities publish; it lodges nothing on your behalf.
- No claim over material that is not published. Supervisory correspondence addressed to your entity never reaches us, and should not.
- No scan-derived applicability. This is a shared intelligence stream tailored by the profile you configure, not a match against your discovered assets — and the page says so where it makes the claim, not only here.
Where this gets sharper
Regulatory Intelligence works from one correlated exposure model
Questions buyers actually ask
Before you evaluate this
We are supervised in more than one country. Can the feed be scoped to that?
That is what the preferences are for. You select the authorities, entity types, industries and geographies that apply to you, and the timeline, the counts above it and the notification cadence are all scoped to that selection. Entity types are specific to each authority, and they are configured for six of them: the RBI, SEBI and IRDAI in India, and MAS, CBUAE and APRA outside it. A group supervised by the RBI in India, the FCA in the United Kingdom and MAS in Singapore sets all three and reads one queue rather than holding three subscriptions and reconciling them by hand.
Can it tell us whether a circular applies to our entity?
It can narrow it a long way, and then it stops — deliberately. Items are scoped and prioritised against the profile you configure, and each one carries the entity types the instrument itself names: Scheduled Commercial Bank or NBFC under the RBI, Stock Broker or Registrar and Transfer Agent under SEBI, Major Payment Institution under MAS, Authorised Deposit-taking Institution under APRA. What we will not do is convert that into a determination that the instrument binds you. That is a legal question about your registration and your permissions, and it belongs to your compliance function and your advisers, not to a monitoring platform.
How is this different from subscribing to the regulators we care about?
A subscription gives you everything an authority publishes, and for most financial regulators the overwhelming majority of that is not about security at all. Here the non-cyber body is screened out deterministically before anything is analysed, individual CVE advisories are pushed back to vulnerability management where they belong, and what remains is asked whether it actually changes a rule. What reaches you is then structured rather than attached: the requirements, the entity types, the domains, binding or advisory, and the deadline the document itself states. The second difference is the record. The monitoring around it is dated, scoped and logged, which is the form an auditor asks for and the form an inbox cannot produce.
Which authorities do you track, and can you add one?
All 31 are named in the coverage table on this page — six in the United States, five at EU level, four in the United Kingdom, three in the UAE, two each in Singapore and Australia, eight in India, and the PCI Security Standards Council globally. Adding one is a registry entry and a resync rather than a release, so an authority you are supervised by that is missing is a request rather than a roadmap item. Ask and we will tell you what it would take and when.
Who else does this
Compared honestly
Where regulatory intelligence is concerned, the real alternatives are the broad digital-risk platforms:
All five vendors side by side · What the same coverage costs assembled from separate tools
See the estate your obligations actually apply to
One apex domain, two business days. The written snapshot carries what we found from outside, and the dated record of the monitoring that found it.