ThreeShield delivers compliance assessments and implementations across 50+ compliance frameworks - from Canadian-specific regulations like Alberta HIA and Bill C-8 CCSPA to global standards like HIPAA, SOC 2, PCI DSS, CMMC, and ISO 27001. Every engagement includes Lavawall® continuous monitoring.
Every compliance framework page explains all three options. Choose the level that fits your team's capacity.
Use Lavawall®'s GRC module to monitor your compliance posture against any supported framework continuously. Automated evidence collection, live compliance scoring, and AI-generated reports. Ideal for lean IT departments and MSPs with internal security capacity.
Learn About Lavawall®Lavawall® platform plus CISSP/CISA guidance - gap assessment, prioritized remediation roadmap, policy development support, and quarterly review calls. MSP partners can white-label and deliver this to their clients.
Get Supported EngagementThreeShield manages the full compliance program - from initial scoping to formal CISSP/CISA-executed assessment to ongoing monitoring and annual reassessment. findings methodology (typically 200+ findings) from government and Fortune 50 experience.
Book AssessmentCanada's Critical Cyber Systems Protection Act. Mandatory for telecom, banking, nuclear, pipelines, and transportation.
Up to $15M/day penaltiesHIA compliance for Alberta healthcare custodians - physicians, PCNs, pharmacists, health tech affiliates.
BC Personal Information Protection Act and health sector privacy for BC healthcare organizations.
Canada's federal private-sector privacy law and its pending update - mandatory breach notification, security safeguards.
Affects all Canadian businessesCybersecurity framework for accounting firms and CPA-regulated entities. Backed by audits for Fortune 50, government, and fintech clients.
For Ontario government entities, municipalities, hospitals, school boards, and critical infrastructure.
Canadian Investment Regulatory Organization cybersecurity guidance for registered dealers and advisors.
BC Financial Services Authority technology risk expectations for BC credit unions, insurers, and financial planners.
Alberta's Personal Information Protection Act for private-sector organizations, with mandatory breach reporting to the Commissioner.
Quebec's modernized privacy law - consent, breach reporting, and data-transfer rules for anyone handling Quebec residents' data.
Fines up to $25M or 4% of worldwide turnoverThe Canadian Centre for Cyber Security's baseline cyber security controls for small and medium organizations.
Technology and cyber risk management expectations for federally regulated banks, insurers, and financial institutions.
Critical Infrastructure Protection for North American bulk electric system operators - Canada and US.
Security Rule, Privacy Rule, and Breach Notification. Applies to Canadian Business Associates of US healthcare entities.
Canadian companies often overlookedAICPA Trust Services Criteria. The de facto security attestation for SaaS companies and service organizations.
Enterprise deal requirementPayment card security for merchants and service providers. All SAQ types - A through D.
Mandatory for US DoD contractors. Canadian companies in NORAD/NATO/DND supply chain increasingly affected.
Contract eligibility requirementIG1, IG2, IG3. The most practical cybersecurity framework and the baseline for most cyber insurance requirements.
10-20% insurance savingsGovern, Identify, Protect, Detect, Respond, Recover. Global standard for cybersecurity risk governance.
International ISMS standard. Required for European market access, government procurement, and enterprise supply chains.
General Data Protection Regulation. Applies to any organization processing EU residents' data - including Canadian companies with EU customers.
Up to €20M / 4% global revenueNetwork & Information Security Directive 2. Mandatory for 18 critical sectors across the EU. 24-hour early warning + 72-hour detailed notification.
Expanded from 7 to 18 sectorsNCSC-backed certification required for UK government contracts. Five foundational controls. Delivered through ThreeShield Information Security Ltd (UK).
Required for UK public sector contractsVoluntary, vendor-neutral framework for governing, mapping, measuring, and managing risks of AI systems across their lifecycle.
The certifiable international standard for an Artificial Intelligence Management System - the AI equivalent of ISO 27001.
Readiness framework for the EU AI Act.
Technical security controls for applications that integrate large language models: prompt injection, sensitive information disclosure, supply chain,...
Canadian AI governance readiness based on the federal Directive on Automated Decision-Making (in force; mandatory for federal automated decision...
Protecting Controlled Unclassified Information in Nonfederal Systems
HITRUST Common Security Framework (CSF) v11 — a certifiable framework that provides organizations with a comprehensive, flexible, and efficient...
FTC Standards for Safeguarding Customer Information (16 CFR 314), revised 2023.
Gramm-Leach-Bliley Act (GLBA) financial privacy and safeguards requirements for US financial institutions.
New York Department of Financial Services Cybersecurity Regulation (23 NYCRR 500), amended 2023.
California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
Sarbanes-Oxley Act of 2002 — US federal law requiring publicly traded companies to maintain internal controls over financial reporting (ICFR).
Cyber security requirements for US pipeline and energy operators.
UK General Data Protection Regulation (retained EU law post-Brexit) together with the Data Protection Act 2018.
Digital Operational Resilience Act — Regulation (EU) 2022/2554, effective 17 January 2025.
Regulation (EU) 2024/2847 — Cyber Resilience Act, entered into force 10 December 2024.
The CPCSC is Canada's official cyber security certification program for defence and government suppliers, managed by Public Services and Procurement...
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) requirements under the Proceeds of Crime (Money Laundering) and Terrorist...
British Columbia Personal Information Protection Act (PIPA).
British Columbia Freedom of Information and Protection of Privacy Act (FIPPA/FOIPPA).
Canadian equivalent of Sarbanes-Oxley, implemented through National Instrument 52-109 — Certification of Disclosure in Issuers Annual and Interim Filings.
The Canadian Securities Administrators' current cybersecurity expectations for registered firms, published 15 July 2026 after a review of 73 firms.
The cyber and physical security expectations that fall on Canadian oil, gas, and pipeline operators.
Baseline cyber security for Canadian small and medium organizations
ISACA COBIT 2019 framework for governance and management of enterprise information and technology.
ITIL 4 framework for IT service management.
Australian Privacy Act 1988 including the Australian Privacy Principles (APPs).
Australian Signals Directorate (ASD) Essential Eight Maturity Model — eight prioritized mitigation strategies to protect internet-connected IT networks...
ThreeShield's free compliance scoping call identifies which frameworks your business is obligated to follow, which are worth pursuing for business development, and what your highest-priority gaps are. No commitment required.
Book Free Compliance Scoping CallAlso see our Training Programs for staff and executive cybersecurity education