Home / Governance / Compliance Frameworks
Compliance

Which rules apply to you?

Almost every business answers to at least one of these. Here's what each one is, in plain English, and how we help.

PCI DSS v4.0.1

You take card payments

Applies to every merchant that accepts cards. We handle scoping, SAQ selection, and remediation. Full PCI DSS services →

HIPAA

You handle health information

Practices and business associates need a documented security program. We deliver the risk analysis, policies, and safeguards — sized for independent practices.

NY SHIELD Act

You hold New Yorkers' private data

New York requires "reasonable" safeguards from any business holding NY residents' data — employees count. We turn "reasonable" into a documented program.

PIPEDAQuébec Law 25CASL

You serve Canadian customers

Cross-border business comes with Canadian obligations — PIPEDA, Québec's Law 25, and CASL. We fold these into one privacy program that covers both sides of the river.

NIST CSF 2.0NIST 800-171CMMC

You want a real security program — or you sell to the DoD

NIST CSF 2.0 anchors every program we build. For defense contractors near Fort Drum, we support NIST 800-171 and CMMC readiness.

One program, many frameworks

Build once, comply many times

These frameworks overlap heavily. A single well-built program — risk assessment, policies, access control, backup, incident response, training — satisfies the core of all of them, on both sides of the border. That's why we anchor everything to NIST CSF 2.0 instead of building a separate binder for each acronym.

Not sure which frameworks apply?

Fifteen minutes on the phone will sort it out. No charge, no obligation.

Talk to Northern Computers