ThreeShield runs compliance assessments and implementations across 70+ frameworks, covering Canadian regulations such as Alberta HIA and Bill C-8 CCSPA and global standards such as HIPAA, SOC 2, PCI DSS, CMMC, and ISO 27001. Every engagement includes Lavawall® continuous monitoring.
Every compliance framework page explains all three options. Choose the level that fits your team's capacity.
Use Lavawall®'s GRC module to monitor your compliance posture against any supported framework continuously. Automated evidence collection, live compliance scoring, and AI-generated reports. Ideal for lean IT departments and MSPs with internal security capacity.
Learn About Lavawall®Lavawall® platform plus CISSP/CISA guidance: gap assessment, prioritized remediation roadmap, policy development support, and quarterly review calls. MSP partners can white-label and deliver this to their clients.
Get Supported EngagementThreeShield manages the full compliance program: initial scoping, a formal CISSP/CISA-executed assessment, ongoing monitoring, and annual reassessment. Our findings methodology (typically 200+ findings) comes from government and Fortune 50 experience.
Book AssessmentCanada's Critical Cyber Systems Protection Act. Mandatory for telecom, banking, nuclear, pipelines, and transportation.
Up to $15M/day penaltiesHIA compliance for Alberta healthcare custodians: physicians, PCNs, pharmacists, and health tech affiliates.
The BC E-Health Act, BC PIPA, and health-sector privacy for BC healthcare organizations.
Canada's federal private-sector privacy law and its pending update: mandatory breach notification and security safeguards.
Affects all Canadian businessesCybersecurity framework for accounting firms and CPA-regulated entities. Backed by audits for Fortune 50, government, and fintech clients.
For Ontario government entities, municipalities, hospitals, school boards, and critical infrastructure.
Canadian Investment Regulatory Organization cybersecurity guidance for registered dealers and advisors.
BC Financial Services Authority technology risk expectations for BC credit unions, insurers, and financial planners.
Alberta's Personal Information Protection Act for private-sector organizations, with mandatory breach reporting to the Commissioner.
Quebec's modernized privacy law: consent, breach reporting, and data-transfer rules for anyone handling Quebec residents' data.
Fines up to $25M or 4% of worldwide turnoverThe Canadian Centre for Cyber Security's baseline cyber security controls for small and medium organizations.
Technology and cyber risk management expectations for federally regulated banks, insurers, and financial institutions.
Critical Infrastructure Protection for North American bulk electric system operators in Canada and the US.
Security Rule, Privacy Rule, and Breach Notification. Applies to Canadian Business Associates of US healthcare entities.
Canadian companies often overlookedAICPA Trust Services Criteria. The de facto security attestation for SaaS companies and service organizations.
Enterprise deal requirementPayment card security for merchants and service providers. All SAQ types, A through D.
Mandatory for US DoD contractors. Canadian companies in NORAD/NATO/DND supply chain increasingly affected.
Contract eligibility requirementIG1, IG2, and IG3. A prioritized, practical cybersecurity framework and the baseline for most cyber insurance requirements.
Lower insurance premiumsGovern, Identify, Protect, Detect, Respond, Recover. Global standard for cybersecurity risk governance.
International ISMS standard. Required for European market access, government procurement, and enterprise supply chains.
General Data Protection Regulation. Applies to any organization processing EU residents' data, including Canadian companies with EU customers.
Up to €20M / 4% global revenueNetwork & Information Security Directive 2. Mandatory for 18 critical sectors across the EU. 24-hour early warning + 72-hour detailed notification.
Expanded from 7 to 18 sectorsNCSC-backed certification required for UK government contracts. Five foundational controls. Delivered through ThreeShield Information Security Ltd (UK).
Required for UK public sector contractsVoluntary, vendor-neutral framework for governing, mapping, measuring, and managing risks of AI systems across their lifecycle.
The certifiable international standard for an Artificial Intelligence Management System, and the AI equivalent of ISO 27001.
Readiness for the EU AI Act across the deployer, provider, and GPAI model provider roles.
Technical security controls for applications that integrate large language models, including prompt injection, sensitive information disclosure, and supply chain risks.
Readiness for Canadian AI rules, based on the federal Directive on Automated Decision-Making, Quebec Law 25, and Ontario Bill 194.
Protecting Controlled Unclassified Information in Nonfederal Systems
A certifiable framework that harmonizes ISO 27001, NIST, PCI DSS, HIPAA, and 40+ other standards into a single assessment.
The FTC's Standards for Safeguarding Customer Information (16 CFR 314), revised 2023, for non-bank financial institutions.
Financial privacy and safeguards requirements for US financial institutions.
New York Department of Financial Services Cybersecurity Regulation (23 NYCRR 500), amended 2023.
California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
Sarbanes-Oxley Act of 2002: the US federal law requiring publicly traded companies to maintain internal controls over financial reporting (ICFR).
Cyber security requirements for US pipeline and energy operators.
UK General Data Protection Regulation (retained EU law post-Brexit) together with the Data Protection Act 2018.
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, in effect since 17 January 2025 for EU financial entities and their critical ICT providers.
Regulation (EU) 2024/2847, in force since 10 December 2024: mandatory cybersecurity requirements for products with digital elements sold in the EU.
Canada's official cyber security certification program for defence and government suppliers, managed by Public Services and Procurement Canada (PSPC).
FINTRAC requirements under the PCMLTFA for money services businesses, banks, credit unions, securities dealers, casinos, and other reporting entities.
British Columbia's private sector privacy law, the Personal Information Protection Act (PIPA).
British Columbia's Freedom of Information and Protection of Privacy Act (FIPPA/FOIPPA) for BC public bodies.
The Canadian equivalent of Sarbanes-Oxley, implemented through National Instrument 52-109 (Certification of Disclosure in Issuers' Annual and Interim Filings).
The Canadian Securities Administrators' current cybersecurity expectations for registered firms, published 15 July 2026 after a review of 73 firms.
The cyber and physical security expectations that fall on Canadian oil, gas, and pipeline operators.
Baseline cyber security for Canadian small and medium organizations.
ISACA COBIT 2019 framework for governance and management of enterprise information and technology.
ITIL 4 framework for IT service management.
Australian Privacy Act 1988 including the Australian Privacy Principles (APPs).
The Australian Signals Directorate (ASD) Essential Eight Maturity Model: eight prioritized mitigation strategies to protect internet-connected IT networks.
ThreeShield's free compliance scoping call identifies which frameworks your business is obligated to follow, which are worth pursuing for business development, and what your highest-priority gaps are. No commitment required.
Book Free Compliance Scoping CallAlso see our Training Programs for staff and executive cybersecurity education