๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

GRC & compliance automation

Compliance that maps itself.

Lavawall® reads your real posture and maps it to 54 frameworks at once, generates the policies auditors expect, and collects evidence continuously, so "the auditor is asking" turns into a live compliance score instead of a lost weekend.

Start with the GRC WizardUnder a deadline?

54 frameworks ยท generated policies ยท continuous evidence ยท PCI ASV

Watch the GRC walkthroughVideo coming soon

From posture to proof

Map once, satisfy many

One control you turn on typically satisfies requirements across SOC 2, CIS, NIST, HIPAA and more at the same time. Compliance Wizard, assessments, and onboarding guide the way.

Policies & documents, generated

Policies, procedures, and a system description are generated and kept current, not copied from a stale template you'll have to defend.

Continuous, timestamped evidence

Patch logs, MFA status, access reviews, encryption state, and backup records are captured automatically, plus integrated PCI ASV scanning.

A live score and gap list

See exactly which controls are open and how to close them, prioritized, per framework, across every tenant.

SOC 2 note: a SOC 2 report is issued only by a licensed CPA firm. Lavawall/ThreeShield gets you audit-ready and works alongside your CPA auditor.

the live compliance score & gaps

The frameworks you need

When a client's questionnaire names a framework, it's already mapped.

A prospect asks for your SOC 2. An insurer wants CMMC 2.0. A hospital needs HIPAA and your Alberta clinic needs the AB HIA. Instead of starting each one from a blank page, Lavawall® maps your real posture to every framework at once, so the control you already turned on counts everywhere it applies.

Frameworks, standards, and regulations Lavawall® maps and evidences include:

The GRC Wizard showing which frameworks apply to your business and which it recommends

Security & governance

  • CIS Controls v8.1 (IG1โ€“IG3)
  • NIST Cybersecurity Framework 2.0
  • NIST SP 800-171 r3
  • ISO/IEC 27001:2022
  • SOC 2 (Type I & II)
  • CMMC 2.0 (Levels 1โ€“3)
  • CPCSC (Levels 1โ€“3)
  • Canadian Cyber Essentials 2024
  • CCCS Baseline Controls 2024
  • Ontario Cyber Security Framework
  • UK Cyber Essentials 2025
  • Australian Essential Eight
  • COBIT 2019
  • ITIL 4
  • EU Cyber Resilience Act
  • EU NIS2 Directive
  • Sarbanes-Oxley (SOX)
  • C-SOX (NI 52-109)

Privacy

  • Canadian PIPEDA
  • Quebec Law 25
  • Alberta PIPA
  • BC PIPA
  • BC FIPPA
  • EU GDPR
  • UK GDPR / DPA 2018
  • CCPA / CPRA
  • Australian Privacy Act 1988

Payment card

  • PCI DSS v4.0.1 โ€” SAQ A, A-EP, B, B-IP, C, C-VT, D

Energy

  • NERC CIP v7

Healthcare

  • HIPAA Security Rule
  • HITRUST CSF v11
  • Alberta Health Information Act (HIA)
  • BC E-Health Act

AI governance

  • NIST AI Risk Management Framework (+ GenAI Profile)
  • ISO/IEC 42001 (AI Management System)
  • EU AI Act readiness
  • OWASP Top 10 for LLM Applications
  • Canada AI Governance readiness

Financial services

  • CPA Canada Cybersecurity Framework
  • BC Financial Services Authority Guidance
  • EU DORA
  • IIROC / CIRO Best Practices
  • NYDFS 23 NYCRR 500
  • GLBA
  • FTC Safeguards Rule
  • FINTRAC / PCMLTFA

One turned-on control typically satisfies requirements across several of these at once. New frameworks are added regularly, and ThreeShield's CISSP/CISA team can scope any of them with you.

Map my frameworks freeUnder a deadline?

One wizard. Your whole compliance program.

The GRC Wizard asks about your business in plain language, takes your industry and compliance requirements into account, and does the heavy lifting for you.

Built from the data you already collect

The wizard reads the security and IT data Lavawall® already gathers about your environment, so you are not re-entering what the platform can already see.

Policies and action plans, generated

It auto-generates the policies auditors expect and the action plans that tell you what to do next, matched to your industry and the frameworks you need to meet.

Plain language, start to finish

No jargon and no blank templates. Answer a few questions and the wizard turns your requirements into a working compliance program you can hand to an insurer, a client, or an auditor.

Start with the GRC Wizard →

The GRC Wizard asking about your business in plain language

The GRC & Resilience suite

The wizard builds on a full set of resilience tools, each one plain language, each one fed by the security and IT data you already collect.

Business Impact Assessment

Work out which systems and processes matter most, and what it costs you when they stop, in plain language.

Learn more →

Vendor Inventory

Keep a living list of the vendors and tools you rely on, so you know who touches your data and where your risk sits.

Learn more →

Continuity & incident plans

Generate the business-continuity and incident-response plans you need before something goes wrong, and keep them current.

Learn more →

Stakeholder questionnaires

Send and track the security and privacy questionnaires clients, insurers, and partners ask you to fill in.

Learn more →

Trust Centre

Give clients and prospects a single page that shows your security posture, so you answer the same questions once.

Learn more →

AI governance

Set the guardrails and policies for how your team uses AI, and show that you have them in place.

Learn more →

Industry policy packs

Ready-made privacy, acceptable-use, AI, and client-consent documents for your industry, in Canadian and US variants.

Learn more →

The documents Lavawall writes for you

Lavawall® uses data you already have, led by your Business Impact Assessment, and writes each of these in plain language, auto-filled from your records rather than typed from a blank page.

  • Incident Response Plan · who does what, severity levels, and a first-hour checklist, with critical systems and vendors auto-filled from your BIA.
  • Disaster Recovery Plan · recovery priorities, backup expectations, and restore order, auto-filled from your BIA recovery targets.
  • Business Continuity Plan · the umbrella policy that keeps the business running and ties the other two plans together.
  • Foreign Processing Disclosure · a Canadian outside-Canada privacy disclosure most compliance platforms do not generate, built from the services that move your data across the border.
  • Data Flow Documentation · what information moves between your systems and how, mapped from the apps Lavawall detects.
  • Privacy Policy addendum · your service providers, AI use, and international processing, written into one addendum.
  • Industry Privacy Policy packs · ready-made privacy documents matched to your industry, in Canadian and US variants.

Want the audit run with you?

ThreeShield, the CISSP/CISA team that builds Lavawall® scopes the framework, operationalizes controls, and prepares you so the examination is fast and predictable.

Common questions

Which frameworks are supported?
54, CIS v8.1, NIST CSF 2.0, NIST 800-171, SOC 2, HIPAA, PCI DSS (all SAQs), ISO 27001:2022, CMMC 2.0, Canada's CPCSC, PIPEDA, Alberta/BC health & privacy acts, Quebec Law 25, CPA Canada, OSFI, IIROC/CIRO, EU GDPR/NIS2/DORA, UK Cyber Essentials, and Australia's Essential Eight.
Can Lavawall issue our SOC 2 report?
No, only a licensed CPA firm can. Lavawall gets you audit-ready and works alongside your auditor.
Do you include PCI ASV scanning?
Yes, integrated Clone Systems PCI ASV scanning with missed-scan notifications and report inclusion.

Start with the GRC WizardStart my free trial