# Reggy > Regulatory compliance software and system of record for mid-market and enterprise companies in Norway, the Nordics and the EU, covering ISO management standards, GDPR, NIS2, the EU AI Act and the Norwegian Transparency Act in a single platform. Reggy provides an execution layer for cross-domain governance: structural policies, controls and evidence held in one place rather than spread across spreadsheets and per-framework tools. It is designed to be run by a company's existing finance, legal or operations team rather than requiring a dedicated compliance specialist, and initial setup takes three to five hours. Customers include Telenor, Aker, Mainstream Renewable Power and Aberdeen. Pricing starts at €2,500/year, covering all employees, with no implementation fee. Primary markets are Norway and the wider Nordics, with EU/EEA coverage. Resources are published in English and in Norwegian Bokmål. Reggy is not an audit or certification body, not a law firm, and does not issue ISO or SOC 2 certificates; it supports the preparation, operation and evidencing of those programmes. Certification itself is granted by an accredited external auditor. Formerly branded Fortifai. Last updated: 2026-08-19. ## Platform - [Reggy](https://reggy.co/): Product overview — the governance execution layer, its scope across frameworks, and how policies and controls are structured. - [Pricing](https://reggy.co/pricing): Plan tiers, what each includes, per-employee coverage and implementation costs. - [FAQ](https://reggy.co/faq): Answers on onboarding, day-to-day workflows, platform capabilities and limits. - [Book a consultation](https://reggy.co/meetings): Scheduling page for a call about company-specific regulatory requirements. ## Compliance framework guides - [Norwegian Transparency Act](https://reggy.co/resources/norwegian-transparency-act): Who the Act applies to, the due diligence obligation, the 30 June annual reporting deadline, and the three-week window for responding to public information requests. - [NIS2](https://reggy.co/resources/nis2-compliance-for-growing-companies): Scope and sector coverage under the EU cybersecurity directive, national transposition, management accountability, and incident reporting duties. - [EU AI Act](https://reggy.co/resources/the-eu-ai-act): Risk tiers, obligations for providers versus deployers, the phased application dates, and governance responsibilities at leadership level. - [GDPR](https://reggy.co/resources/gdpr-for-mid-market-companies): Core obligations for mid-market companies, recent enforcement trends, and the documentation gaps commonly found in organisations that implemented GDPR once in 2018 and left it there. - [ISO 27001](https://reggy.co/resources/what-is-iso-27001): What the information security management standard requires, the Annex A controls, the Stage 1 and Stage 2 audit process, and cost components. Sets out a fast-tracked path reaching audit readiness in 30 to 60 days. - [ISO 9001](https://reggy.co/resources/iso-9001-for-growing-companies): Quality management system requirements, how the standard maps onto growing companies without a formal QA function, and a certification path measured in weeks rather than months. - [ISO 14001](https://reggy.co/resources/iso-14001-for-tech-and-hardware-companies): Environmental management for technology, SaaS and hardware companies, including energy use, e-waste and supply chain emissions. - [ISO 45001](https://reggy.co/resources/iso-45001-for-tech-and-digital-companies): Occupational health and safety management applied to digital workplaces — mental health, remote and hybrid work, ergonomics and contractor safety. - [ISO 37001](https://reggy.co/resources/iso-37001-the-anti-bribery-standard): Requirements of the international anti-bribery management standard and where it fits alongside existing financial controls. - [ISO 42001](https://reggy.co/resources/iso-42001-the-ai-governance-standard): The AI management system standard — scope, control areas, and its relationship to the EU AI Act. - [SOC 2](https://reggy.co/resources/soc-2-certification): Trust services criteria, Type I versus Type II reports, audit process, cost drivers and timelines. Norwegian Bokmål translations of each guide above are published under https://reggy.co/resources/. ## ESG and governance analysis - [10 facts about VSME](https://reggy.co/blogs/10-important-facts-about-vsme-every-sme-should-know): EFRAG's voluntary sustainability reporting standard for SMEs and what it asks for. - [Is ESG dead?](https://reggy.co/blogs/is-esg-dead): Changes to CSRD scope and what they mean for companies that were preparing to report. - [Proportional ESG compliance](https://reggy.co/blogs/esg-compliance-is-achievable-for-everyone): Meeting ESG reporting expectations without enterprise-scale spend. - [Governance debt](https://reggy.co/blogs/governance-debt-the-risk-cfos-dont-measure): Framework for identifying accumulated, unmeasured compliance risk on a balance sheet. - [The many types of governance](https://reggy.co/blogs/the-many-types-of-governance): Why governance responsibilities fragment across functions and what that costs. - [Why governance feels hard for SMBs](https://reggy.co/blogs/why-governance-feels-so-hard-for-smbs): Sources of reporting overload in smaller organisations. ## Optional - [Our story](https://reggy.co/our-story): Founder background and why the platform was built. - [Two types of CFO](https://reggy.co/blogs/two-types-of-cfos-and-who-fortifai-is-built-for): How compliance priorities differ between established and growth-stage finance leaders. - [Resources for compliance officers](https://reggy.co/email-signup-have): Sign-up for companies with a dedicated compliance function. - [Resources without a compliance officer](https://reggy.co/email-signup-dont-have): Sign-up for companies where compliance sits with an existing team.