Home / Governance / Compliance Frameworks
Compliance

Which rules apply to you?

Almost every business answers to at least one of these. Here's what each one is, in plain English, and how we help.

PCI DSS v4.0.1

You take card payments

The Payment Card Industry Data Security Standard applies to every merchant that accepts cards — the corner shop and the five-location chain alike. We handle scoping, SAQ selection, segmentation, remediation, and the annual attestation cycle. Full PCI DSS services →

HIPAA

You handle health information

Medical and dental practices, behavioral health, and their business associates must protect patient data with a documented security program. We deliver the required risk analysis, policies, training, and technical safeguards — sized for independent practices, not hospital systems.

NY SHIELD Act

You hold New Yorkers' private data

New York's SHIELD Act requires "reasonable" administrative, technical, and physical safeguards from virtually every business holding private information of NY residents — employees count. We translate "reasonable" into a concrete, documented program.

PIPEDAQuébec Law 25CASL

You serve Canadian customers

Twenty minutes from the border, cross-border commerce is everyday business — and it comes with Canadian obligations. PIPEDA, Canada's federal private-sector privacy law, governs how you collect, use, and safeguard Canadians' personal information, including mandatory breach reporting. Québec's Law 25 layers on stricter consent and privacy-impact requirements for Québec residents' data, and CASL regulates commercial email and texts to Canadian recipients. We fold these into your privacy program so one set of policies covers both sides of the river.

NIST CSF 2.0NIST 800-171CMMC

You want a real security program — or you sell to the DoD

NIST CSF 2.0 is the backbone we anchor every governance program to. For defense contractors and suppliers near Fort Drum, we support NIST 800-171 alignment and CMMC readiness, with certified practitioner expertise in-house.

One program, many frameworks

Build once, comply many times

These frameworks overlap heavily. A single well-built program — risk assessment, policy suite, access control, backup, incident response, training — satisfies the core of all of them, on both sides of the border: PIPEDA's safeguarding and breach-notification duties map cleanly onto the same controls SHIELD and HIPAA already demand. That's why we anchor everything to NIST CSF 2.0 and map outward, instead of building a separate binder for each acronym.

Not sure which frameworks apply?

Fifteen minutes on the phone will sort it out. No charge, no obligation.

Talk to Northern Computers