About

EU regulatory operations need
a better execution layer.

Thesis

Regulation is becoming an operating discipline.

RegAtlas turns mandatory, recurring regulatory obligations into reviewer-gated, evidence-backed workflows.

The next decade of EU regulation - DORA, NIS2, EU AI Act - moves the centre of gravity from documentation to operations. Registers must be running objects. Evidence must be linked. Reviews must be gated. Exports must be reproducible.

Most teams are asked to deliver this operating posture with tools designed for inventory or for narrative. The result is heroic effort with brittle outcomes - and a recurring dependence on advisory cycles to reassemble what should have been an operation.

RegAtlas exists to change the substrate. We're building a compliance operating system for EU regulatory execution - DORA-first, evidence-centred, reviewer-gated, private by architecture - with adjacent EU regimes on the same operating layer.

Mission

Turn fragmented regulatory work into structured operational workflows - for the EU, with the discipline it requires.

The people behind the system

Built by people who have carried the audit.

We build the system we wished we had when the supervisor's request landed on our desk.

JF

Joe Fancher

Co-founder · CTO

Twenty-plus years as a CISO and security-operations leader for regulated businesses, now focused on AI governance and evidence-centered operating systems.

MA

Marius van Aswegen

Co-founder · CEO

Senior ISO lead implementer and auditor - ISO 9001, 27001, 27701, and 42001 - with SOC 2, NIS2, PCI-DSS, and DORA delivery for regulated clients. Founder of cybercontrols.io.

AS

Arian Sheremeti

Co-founder · CPO

Principal GRC architect: ISO 27001 lead auditor and implementer, ISO 42001 lead auditor, CISM, CISA. Runs ISO certification, EU regulatory compliance, and assurance programs end to end.

What we don't claim

Boundaries we hold to, deliberately.

We don't provide legal advice

RegAtlas does not produce legal opinions or interpretive conclusions. Legal judgement stays with qualified counsel.

We don't replace auditors

Internal and external audit remain independent. RegAtlas produces the operating record that makes their work cleaner.

We don't guarantee compliance

Compliance is a function of the operating model and the people running it. RegAtlas structures the work - the obligations remain yours.

Operating principles

What we hold to.

01

DORA-first

We start where the regulation actually changes the operating model.

02

Workflow-centered

Operations, not modules. State and ownership are first-class.

03

Evidence-linked

Every claim traces to an artefact; every artefact to an obligation.

04

Reviewer-gated

Approval is a state machine, not a comment thread.

05

Private-first

Sensitive material stays where it should - operationally and legally.

Posture

Quiet, deliberate, and EU-grounded.

Built in the EU

We operate inside the regulatory geography we serve.

Domain over hype

Our reference points are supervisors and operators - not headlines.

Designed to last

An operating layer should outlive the regulation it was first shaped by.

Early Access

Request early access to RegAtlas.

We're talking to a small group of design partners building a more operational approach to EU regulatory execution.