COMPLIANCE FRAMEWORKS

Every Framework.
One End-to-End Partner.

ThreeShield delivers compliance assessments and implementations across 50+ compliance frameworks - from Canadian-specific regulations like Alberta HIA and Bill C-8 CCSPA to global standards like HIPAA, SOC 2, PCI DSS, CMMC, and ISO 27001. Every engagement includes Lavawall® continuous monitoring.

Three Engagement Models for Every Framework

Every compliance framework page explains all three options. Choose the level that fits your team's capacity.

Self-Serve

DIY via Lavawall®

Use Lavawall®'s GRC module to monitor your compliance posture against any supported framework continuously. Automated evidence collection, live compliance scoring, and AI-generated reports. Ideal for lean IT departments and MSPs with internal security capacity.

Learn About Lavawall®
Recommended for MSPs & Lean IT

Supported by Experts

Lavawall® platform plus CISSP/CISA guidance - gap assessment, prioritized remediation roadmap, policy development support, and quarterly review calls. MSP partners can white-label and deliver this to their clients.

Get Supported Engagement
Fully Managed

Done-for-You

ThreeShield manages the full compliance program - from initial scoping to formal CISSP/CISA-executed assessment to ongoing monitoring and annual reassessment. findings methodology (typically 200+ findings) from government and Fortune 50 experience.

Book Assessment

Canadian-Specific Frameworks

Federal · NEW

Bill C-8 / CCSPA

Canada's Critical Cyber Systems Protection Act. Mandatory for telecom, banking, nuclear, pipelines, and transportation.

Up to $15M/day penalties
Alberta Healthcare

Alberta Health Information Act

HIA compliance for Alberta healthcare custodians - physicians, PCNs, pharmacists, health tech affiliates.

BC Healthcare / Privacy

BC PIPA & Health Privacy

BC Personal Information Protection Act and health sector privacy for BC healthcare organizations.

Federal Privacy

PIPEDA / Bill C-27 (CPPA)

Canada's federal private-sector privacy law and its pending update - mandatory breach notification, security safeguards.

Affects all Canadian businesses
Professional Services

CPA Canada Cybersecurity

Cybersecurity framework for accounting firms and CPA-regulated entities. Backed by audits for Fortune 50, government, and fintech clients.

Ontario Public Sector

Ontario Cybersecurity Framework

For Ontario government entities, municipalities, hospitals, school boards, and critical infrastructure.

Investment Dealers

CIRO / IIROC

Canadian Investment Regulatory Organization cybersecurity guidance for registered dealers and advisors.

BC Financial Services

BCFSA

BC Financial Services Authority technology risk expectations for BC credit unions, insurers, and financial planners.

Alberta Privacy

Alberta PIPA

Alberta's Personal Information Protection Act for private-sector organizations, with mandatory breach reporting to the Commissioner.

Quebec Privacy

Quebec Law 25 (Loi 25)

Quebec's modernized privacy law - consent, breach reporting, and data-transfer rules for anyone handling Quebec residents' data.

Fines up to $25M or 4% of worldwide turnover
Federal · CCCS

CCCS Baseline Controls

The Canadian Centre for Cyber Security's baseline cyber security controls for small and medium organizations.

Federally Regulated Finance

OSFI B-13

Technology and cyber risk management expectations for federally regulated banks, insurers, and financial institutions.

Energy / Utilities

NERC CIP

Critical Infrastructure Protection for North American bulk electric system operators - Canada and US.

Global & US Frameworks

European & UK Frameworks

Artificial Intelligence Governance

US Financial, Privacy & Sector

More European & UK Frameworks

More Canadian Frameworks

IT Governance & Service Management

Asia-Pacific

Not Sure Which Frameworks Apply to You?

ThreeShield's free compliance scoping call identifies which frameworks your business is obligated to follow, which are worth pursuing for business development, and what your highest-priority gaps are. No commitment required.

Book Free Compliance Scoping Call

Also see our Training Programs for staff and executive cybersecurity education