Governance & Compliance

From "we think we're secure" to "here's the documentation."

Regulators, card processors, and cyber insurers no longer accept good intentions. Northern Computers builds the governance layer — written policies, risk assessments, and evidence — anchored to NIST CSF 2.0 and mapped to the frameworks your business actually answers to.

NIST CSF 2.0 PCI DSS v4.0.1 HIPAA NY SHIELD Act NIST 800-171 CMMC PIPEDA Québec Law 25
The practice

Four ways in

Governance isn't one product — it's a discipline. Start where the pressure is.

Compliance Frameworks

Plain-English guidance on PCI DSS, HIPAA, and the NY SHIELD Act: what applies to you, what it requires, and what it takes to get there. Start here if a processor, regulator, or insurer just asked you a question you couldn't answer.

Explore frameworks →

Governance Policy Suite

A 20+ document information security policy program, anchored to NIST CSF 2.0 and written for your organization — covering everything from acceptable use to incident response to vendor management.

See the suite →

PCI DSS Services

Scoping, SAQ selection, gap assessment, remediation, and ongoing compliance for merchants — from a single card terminal to multi-location retail.

PCI DSS details →

Risk & Advisory

Executive-level security leadership on a fractional basis: risk assessments, board reporting, insurance application support, and a standing advisor who knows your environment.

Advisory services →
Why it matters now

The cost of "we'll get to it"

Three forces converged on small businesses at once: cyber insurance carriers began denying claims when attested controls weren't in place, PCI DSS v4.0.1 raised the bar for every merchant, and New York's SHIELD Act made "reasonable safeguards" a legal obligation for any business holding New Yorkers' private data. And here on the border, a fourth applies: any business serving Canadian customers answers to Canada's federal privacy law, PIPEDA — with Québec's Law 25 adding stricter rules for Québec residents' data.

None of this requires enterprise budgets. It requires a program: honest assessment, written policies, controls that match them, and evidence that accumulates. That's what we build.

How an engagement starts

  • Discovery call — what you handle, who's asking, what's due
  • Gap review against the frameworks that apply
  • Prioritized roadmap with honest effort estimates
  • Build, remediate, and document — at your pace

What would an auditor find tomorrow?

Find out from us first. A gap review is confidential, plain-English, and pressure-free.

Talk to Northern Computers