COMPLIANCE FRAMEWORKS

Every Framework.
One End-to-End Partner.

ThreeShield delivers compliance assessments and implementations across 16 major frameworks - from Canadian-specific regulations like Alberta HIA and Bill C-8 CCSPA to global standards like HIPAA, SOC 2, PCI DSS, CMMC, and ISO 27001. Every engagement includes Lavawall® continuous monitoring.

Three Engagement Models for Every Framework

Every compliance framework page explains all three options. Choose the level that fits your team's capacity.

Self-Serve

DIY via Lavawall®

Use Lavawall®'s GRC module to monitor your compliance posture against any supported framework continuously. Automated evidence collection, live compliance scoring, and AI-generated reports. Ideal for lean IT teams and MSPs with internal security capacity.

Learn About Lavawall®
Recommended for MSPs & Lean IT

Supported by Experts

Lavawall® platform plus CISSP/CISA guidance - gap assessment, prioritized remediation roadmap, policy development support, and quarterly review calls. MSP partners can white-label and deliver this to their clients.

Get Supported Engagement
Fully Managed

Done-for-You

ThreeShield manages the full compliance program - from initial scoping to formal CISSP/CISA-executed assessment to ongoing monitoring and annual reassessment. findings methodology (typically 200+ findings) from government and Fortune 50 experience.

Book Assessment

Canadian-Specific Frameworks

Global & US Frameworks

European & UK Frameworks

EU · In Force

EU GDPR

General Data Protection Regulation. Applies to any organization processing EU residents' data - including Canadian companies with EU customers.

⚠️ Up to €20M / 4% global revenue
EU · October 2024

EU NIS2 Directive

Network & Information Security Directive 2. Mandatory for 18 critical sectors across the EU. 24-hour early warning + 72-hour detailed notification.

Expanded from 7 to 18 sectors
🇬🇧 UK Government

UK Cyber Essentials & CE+

NCSC-backed certification required for UK government contracts. Five foundational controls. Delivered through ThreeShield Information Security Ltd (UK).

Required for UK public sector contracts

Not Sure Which Frameworks Apply to You?

ThreeShield's free compliance scoping call identifies which frameworks your business is obligated to follow, which are worth pursuing for business development, and what your highest-priority gaps are. No commitment required.

Book Free Compliance Scoping Call

Also see our Training Programs for staff and executive cybersecurity education