RequirementsBase — MCP-native regulatory gap-analysis agent
An MCP-native gap-analysis agent that connects to a client's Jira/Confluence/live systems, maps current state against regulation-derived requirements, and produces a done-vs-gap coverage scorecard spanning BOTH software controls and policy/procedure controls, plus a prioritised remediation backlog. Unique edge: auto-translating raw law/regulation text into buildable requirements.
RequirementsBase — Competitive Market Research (GRC / compliance-automation / control-mapping)
Research date: 2026-07-01. Method: fan-out web search + site fetches across 13 named vendors plus the RegTech "raw law -> requirements" category. See contributions for search methodology and per-source citations.
The core finding
Decompose the pitch into three claims; crowding is uneven:
- "Done-vs-gap scorecard + Jira remediation loop" — FULLY SOLVED / SATURATED. Do not lead with this.
- "Extract structured obligations from raw regulatory text" — SOLVED / CROWDED, concentrated in FS RegTech. Table stakes, not an edge.
- "MCP-native agent -> live Jira/Confluence/running systems -> done-vs-gap across BOTH software AND policy controls, driven by freshly translated raw law" — GENUINE WHITE SPACE. Nobody closes this full chain. RegTech players stop at the policy/document layer ("done" = a PDF/attestation/library entry); SOC2/GRC tools that read live systems start from pre-built framework checklists, not translated raw law, and treat policy controls as manual attestation.
Tier 1 — SOC2/ISO automation crowd (security-first, framework-driven)
- Vanta (vanta.com): 35+ frameworks, mostly security/privacy; FS-relevant = DORA, APRA CPS 234, PCI; no SEC/FINRA. 400+ integrations, 1,200+ hourly automated tests. Native Jira, auto-creates tickets from failing tests. ~$10K-$80K/yr. Weakness: framework-template-driven, no raw-law ingestion, policy controls manual.
- Drata (drata.com): 40+ frameworks; FS-labeled = PCI/DORA/FFIEC/SOX ITGC/NYDFS, no APRA/SEC/FINRA. 300+ integrations. Native Jira write, auto-opens tickets on Not Ready/Failed. ~$7.5K-$100K/yr (avg ~$34K). Weakness: templates only, policy manual.
- Secureframe (secureframe.com): 30+ frameworks; FS = PCI/DORA/NYDFS 500/FTC Safeguards/SOX ITGC. 300+ integrations, ComplyAI remediation code fixes. Jira bidirectional BUT auto-ticket-creation "not supported yet" (manual/bulk). ~$7.5K-$80K/yr. Weakest of tier on backlog claim.
- Sprinto (sprinto.com): security/privacy only; DORA shallow (~100 SCF controls, "disqualifying" for EU FS). Strong auto-pull (300+ systems). Jira not one-click (20-40 eng hrs). ~$6K-$25K/yr. Startups/mid-market.
- Thoropass (thoropass.com, ex-Laika): compliance automation bundled with in-house CPA audit. Security/privacy; DORA not first-class. 100+ integrations + First Pass AI, then human auditors. ~$20K-$60K/yr bundled. Edge is the human audit, not automation.
Tier 2 — Enterprise GRC/IRM incumbents (regulation-heavy)
- Archer / Archer IRM (archerirm.com): CLOSEST direct competitor to core edge. "Archer Evolv" reg-intel engine: 4,500+ sources, 170 jurisdictions, 600+ changes/day, 526 compliance-trained AI models, ~95% obligation-extraction accuracy; names DORA/Basel/SEC/FINRA/EU AI Act; DORA Register-of-Information app + Obligations Catalog with citation traceability. Hybrid, assisted-manual assurance; CCM via partners. Jira+ServiceNow sync. ~$55K-$300K+/yr. Weakness: heavyweight/expensive/slow, self-attestation-leaning, not the engineering system-of-record.
- LogicGate Risk Cloud (logicgate.com): no-code GRC; covers both security + explicit FS (FINRA/SEC/OCC/OFAC/FFIEC/GLBA/NYDFS) BUT does NOT author content — relies on CUBE/Ascent/UCF connectors. Spark AI (Jan 2026) first-pass control testing, human-in-loop. Native bidirectional Jira. Quote-only enterprise. Weakness: no raw-law translation, third-party content lag/lock-in.
- ServiceNow IRM (servicenow.com): UCF-native (100K+ mandates, 10K+ common controls); Regulatory Change Management module; DORA supported. Continuous Authorization & Monitoring + CMDB. Auto-generates remediation tasks (own ITSM engine); Jira via Integration Hub. ~$40K-$100K+/yr. Weakness: content UCF-curated not law-derived; assumes data flows into Now Platform.
Tier 3 — Trust/audit-centric GRC
- OneTrust (onetrust.com): security/privacy-first, weak on US financial reg (only DORA; SOX = IT only; no SEC/FINRA). Graded 1-5 evidence-confidence. Jira task->ticket still Public Preview (2026). New $10K/yr minimum; enterprise $120K-$500K+. Weakness: templates not raw law, no US financial depth.
- Hyperproof (hyperproof.io): STRONGEST Tier-3 overlap. Dedicated fintech line (as templates): SOX/DORA/FINRA-gap/GLBA/FFIEC/PCI/NIS2 + 140+ templates. Hypersyncs (50+ systems) + Automated Controls Testing + CCM + control health score; 2026 AI gap-discovery agents. Native bidirectional Jira (+ADO/GitHub); gap-scan flags missing policy/procedure/technical controls. ~$12K-$100K/yr (median ~$40K). Weakness: curated templates, no raw-law translation, Jira bolt-on not MCP-native.
- AuditBoard — now "Optro" (rebranded 2026-03-09; auditboard.com -> optro.ai): SOX DNA ("SOXHUB"); SOX/ITGC/DORA/NYDFS 500/Basel op-risk/FFIEC/NIS2 + 30+ frameworks. RegComply module (Apr 2025, powered by CUBE) AI-maps obligations to controls; G2 #1 in Reg Change Mgmt. Intelligent Testing pulls from 150-200+ systems. Jira supported; backlog derives from audit findings not regulation-to-current-state gap. ~$30K-$150K+/yr, ~4-mo implementation. Weakness: CUBE-licensed content + human-in-loop, not MCP-native.
Category X — The actual "raw law -> requirements" competitors (the real fight)
- Ascent RegTech (ascentregtech.com): patented AI extracts each obligation from rulebooks as structured objects (MiFID II in 2.5 min). Genuine extraction but output = legal obligations, no Jira/dev done-vs-gap.
- CUBE (cube.global): "Automated Regulatory Intelligence," 750 jurisdictions; dominant consolidator — acquired Thomson Reuters Regulatory Intelligence (closed early 2026) + 4CRisk. Powers AuditBoard/others. No dev integration. Watch item: agentic APIs.
- Corlytics + Clausematch (corlytics.com): the ONLY incumbent explicitly doing obligation->control gap analysis + LLM remediation suggestions — but against policy documents, not live systems.
- Norm Ai (norm.ai, $48M, Citi/Bain/Blackstone/Vanguard): most technically ambitious "law-as-code" — regs into executable programs + LLM agents. But reviews artifacts/documents, no dev-system done-vs-gap, no build backlog. Best-funded threat if it pivots to systems verification.
- Regology / Reggi AI (regology.com): CLOSEST single vendor to "raw law -> controls/requirements generation"; AI agents "generate obligations, risks, controls, and policies" from tracked laws in 135+ countries. But maps to internal policies, no dev integration.
- 6clicks "Hailey" (6clicks.com): AI crosswalk/gap analysis, but maps to pre-existing framework libraries, not raw statute; no dev systems.
- UCF (unifiedcompliance.com) & SCF (securecontrolsframework.com): incumbent common-control backbones GRC tools license. UCF's patented NLP decomposing raw regulation into atomic mandates is PRIOR ART. Both static curated catalogs, no live systems.
Two consistent, exploitable blind spots across ALL incumbents
- Every incumbent is template/library-driven — none auto-translates arbitrary or newly-issued statute. Long tail (APRA CPS 230, novel jurisdictional/contractual obligations, fast-moving DORA RTS, SEC/FINRA conduct rules) is unserved.
- All are strong on machine-verifiable software controls, weak on policy/procedure controls (manual attestation). Scoring BOTH from live Confluence + Jira reads is real differentiation.
Threats to watch (ranked)
- Archer Evolv — only incumbent already doing raw-law->requirements at scale with deep FS content.
- Norm Ai — best-funded law-as-code; dangerous if it moves to live-systems verification.
- AuditBoard/Optro + Hyperproof — shipped agentic gap-discovery 2025-2026; AI-automation edge is a timing advantage only.
- CUBE — consolidating the reg-intel content layer.
Verdict
The durable moat is the SPECIFIC combination — raw-law-to-buildable-requirements translation feeding an MCP-native, live-systems done-vs-gap scorecard across software AND policy controls, with a prioritised build backlog. Each link exists somewhere; nobody has all four. "Regulation-derived requirement checked against a live Jira/codebase rather than a policy PDF" is the unoccupied position.
Loading comments...