GRC & compliance automation
Compliance that maps itself.
Lavawall® reads your real posture and maps it to 70+ frameworks at once, generates the policies auditors expect, and collects evidence continuously, so "the auditor is asking" turns into a live compliance score instead of a lost weekend.
Start with the GRC WizardUnder a deadline?
70+ frameworks ยท generated policies ยท continuous evidence ยท PCI ASV
Does this sound like you?
Most organizations don't have one compliance obligation. They have a combination: a control framework or two, one or more privacy laws, and the rules for what they do. Here are a few, and yours will look different. That is the point, because almost nobody has just one.
A 12-person health-tech startup in BC
BC PIPA and PIPEDA for privacy; the BC E-Health Act if it touches a health information bank; PCI DSS for card payments; SOC 2 the moment a health authority asks; two breach clocks.
Six instruments, before twenty staff.
A Calgary accounting firm
Alberta PIPA and PIPEDA for client information; the CPA Canada cybersecurity expectations; FINTRAC when it handles client funds; SOC 2 if it runs any client-facing technology.
Five instruments.
A city of 40,000 in Iowa
The FBI CJIS Security Policy for policing; HIPAA once fire and EMS bill electronically; PCI DSS for utility and parking payments; AWIA for the water system; Iowa chapters 22, 21, and 715C; ADA Title II.
Eight instruments.
An Ontario medical-device company
PIPEDA, Ontario PHIPA, and HIPAA for privacy; FDA section 524B, Health Canada's guidance, and the lifecycle standards for device cybersecurity; SOC 2 or ISO 27001 for hospital IT.
Seven instruments (its quality system is a separate program).
A regulated investment broker in BC
BCFSA, CIRO cyber expectations, and CSA Staff Notice 33-322 from the sector regulators; FINTRAC for financial crime; BC PIPA and PIPEDA for privacy; SOC 2 if it runs client-facing technology.
Seven instruments.
A US SaaS company chasing enterprise deals
SOC 2 and often ISO 27001 for the sales cycle; CCPA and the growing list of US state privacy laws; the HIPAA Security Rule if a customer is in health care; PCI DSS if it takes payments.
Four to six instruments, climbing with each new state.
A US healthcare clinic
The HIPAA Security Rule and HITECH for patient data; state breach-notification laws; PCI DSS for co-pays and billing; and a business-associate agreement with every vendor that touches PHI.
Five instruments.
An MSP with forty clients
Every one of the above, times a book of business: a city, a clinic, a broker, and a manufacturer, each with a different obligation set, run from one console with per-tenant isolation and billing.
One platform, multi-tenant.
Not on this list? If you keep more than one framework, privacy law, or industry rule, whether you are an MSP running forty of these at once or a single business holding your own, you are exactly who Lavawall® is for. The question is never how big you are; it is how many obligations you carry.
From posture to proof
Map once, satisfy many
One control you turn on typically satisfies requirements across SOC 2, CIS, NIST, HIPAA and more at the same time. Compliance Wizard, assessments, and onboarding guide the way.
Policies & documents, generated
Policies, procedures, and a system description are generated and kept current, not copied from a stale template you'll have to defend.
Continuous, timestamped evidence
Patch logs, MFA status, access reviews, encryption state, and backup records are captured automatically, plus integrated PCI ASV scanning.
A live score and gap list
See exactly which controls are open and how to close them, prioritized, per framework, across every tenant.
SOC 2 note: a SOC 2 report is issued only by a licensed CPA firm. Lavawall/ThreeShield gets you audit-ready and works alongside your CPA auditor.

The frameworks you need
When a client's questionnaire names a framework, it's already mapped.
A prospect asks for your SOC 2. An insurer wants CMMC 2.0. A hospital needs HIPAA and your Alberta clinic needs the AB HIA. Instead of starting each one from a blank page, Lavawall® maps your real posture to every framework at once, so the control you already turned on counts everywhere it applies.
Frameworks, standards, and regulations Lavawall® maps and evidences include:

Security & governance
- CIS Controls v8 8.1
- Canadian Program for Cyber Security Certification (CPCSC) 1.0
- NIST Cybersecurity Framework (NIST CSF) 2.0
- NIST SP 800-171 r3
- Canadian Centre for Cyber Security Guidance 2024
- COBIT 2019 2019
- ITIL 4 4
- Ontario Cyber Security Framework 2024
- ISO/IEC 27001 2022
- Sarbanes-Oxley Act (SOX) 2002
- C-SOX (Canadian Securities NI 52-109) 2023
- EU NIS2 Directive 2024
- CMMC v2.0
- UK Cyber Essentials 2025
- EU Cyber Resilience Act (CRA) 2024
- SOC 2 2024
- IEC 81001-5-1 Health Software Security Life Cycle 2021
- ANSI/AAMI SW96 Medical Device Security Risk Management 2023
- HSCC Medical Device and Health IT Joint Security Plan v2.0 (March 2024)
- Canadian Cyber Essentials 2024
- Australian Essential Eight 2024
- Ontario Personal Health Information Protection Act (PHIPA) 2004, as amended
Privacy
Payment card
Energy & critical infrastructure
Government & public sector
- NIST SP 800-53 - Security and Privacy Controls Rev. 5
- FBI CJIS Security Policy 6.1
- FBI CJIS Security Policy 5.9.5 (Pre-Modernization) 5.9.5
- Alberta Protection of Privacy Act (POPA) / Access to Information Act (AITA) 2025
- Ontario MFIPPA - Municipal Freedom of Information and Protection of Privacy Act (as amended by Bill 194) 2024 amendments
- Iowa Public Sector Information Obligations 2026
- IRS Publication 1075 - Federal Tax Information 2024
- US Water & Wastewater Cyber Security (AWIA) 2026
- ADA Title II - Web and Mobile Accessibility 2024 Final Rule
- GovRAMP (formerly StateRAMP) - Cloud Vendor Assurance 2026
Healthcare
AI governance
Financial services
- FTC Safeguards Rule 2023
- GLBA โ Gramm-Leach-Bliley Act 2023
- NYDFS Cybersecurity Regulation 2023
- FINTRAC / PCMLTFA 2024
- EU DORA 2025
- BC Financial Services Authority Security Guidance 2024
- CPA Canada Cybersecurity Framework 2024
- CIRO Cybersecurity Program - Dealer Members 2026
- CSA Staff Notice 33-322 - Registered Firm Cybersecurity 15 July 2026
One turned-on control typically satisfies requirements across several of these at once. New frameworks are added regularly, and ThreeShield's CISSP/CISA team can scope any of them with you.
One wizard. Your whole compliance program.
The GRC Wizard asks about your business in plain language, takes your industry and compliance requirements into account, and does the heavy lifting for you.
Built from the data you already collect
The wizard reads the security and IT data Lavawall® already gathers about your environment, so you are not re-entering what the platform can already see.
Policies and action plans, generated
It auto-generates the policies auditors expect and the action plans that tell you what to do next, matched to your industry and the frameworks you need to meet.
Plain language, start to finish
No jargon and no blank templates. Answer a few questions and the wizard turns your requirements into a working compliance program you can hand to an insurer, a client, or an auditor.

The GRC & Resilience suite
The wizard builds on a full set of resilience tools, each one plain language, each one fed by the security and IT data you already collect.
Business Impact Assessment
Work out which systems and processes matter most, and what it costs you when they stop, in plain language.
Learn more →Vendor Inventory
Keep a living list of the vendors and tools you rely on, so you know who touches your data and where your risk sits.
Learn more →Continuity & incident plans
Generate the business-continuity and incident-response plans you need before something goes wrong, and keep them current.
Learn more →Stakeholder questionnaires
Send and track the security and privacy questionnaires clients, insurers, and partners ask you to fill in.
Learn more →Trust Centre
Give clients and prospects a single page that shows your security posture, so you answer the same questions once.
Learn more →AI governance
Set the guardrails and policies for how your team uses AI, and show that you have them in place.
Learn more →Industry policy packs
Ready-made privacy, acceptable-use, AI, and client-consent documents for your industry, in Canadian and US variants.
Learn more →Controls that test themselves
Most GRC tools hand you a list of controls and ask you to attest to each one by hand, over and over. Lavawall works the other way around. It reads the live configuration and the user issues it already sees across Microsoft 365, Google Workspace, macOS, Windows, Linux, and more, and fills in the matching controls for you. A misconfiguration or a risky user setting does not just raise an alert, it updates the control it maps to.
The result is evidence that is collected from the system that runs the control, not typed into a questionnaire and hoped to be true. When the posture changes, the control changes with it, so what an auditor sees is what is actually in place today.
Bring your own auditor
An audit gets slow and expensive when the auditor works at arm's length, asking for screenshots and waiting on emailed evidence. Lavawall gives your external auditor a direct, controlled way in: they access the GRC, review the controls and the evidence behind them, evaluate your posture, and sign off, all inside the same system. Less back and forth, a shorter engagement, and a lower bill.
You are not locked to one firm, either. Bring the auditor you already trust, or have ThreeShield's CISSP- and CISA-credentialled team run the examination with you.
The documents Lavawall writes for you
Lavawall® uses data you already have, led by your Business Impact Assessment, and writes each of these in plain language, auto-filled from your records rather than typed from a blank page.
- Incident Response Plan · who does what, severity levels, and a first-hour checklist, with critical systems and vendors auto-filled from your BIA.
- Disaster Recovery Plan · recovery priorities, backup expectations, and restore order, auto-filled from your BIA recovery targets.
- Business Continuity Plan · the umbrella policy that keeps the business running and ties the other two plans together.
- Foreign Processing Disclosure · a Canadian outside-Canada privacy disclosure most compliance platforms do not generate, built from the services that move your data across the border.
- Data Flow Documentation · what information moves between your systems and how, mapped from the apps Lavawall detects.
- Privacy Policy addendum · your service providers, AI use, and international processing, written into one addendum.
- Industry Privacy Policy packs · ready-made privacy documents matched to your industry, in Canadian and US variants.
Want the audit run with you?
ThreeShield, the CISSP/CISA team that builds Lavawall® scopes the framework, operationalizes controls, and prepares you so the examination is fast and predictable.
Pricing, published
Almost nobody in this category publishes a number. Here is ours, beside how the rest of the category answers the question.
Lavawall® Complete
$89.50 /seat/year
Annual, two months free. A seat is the greater of your managed devices or your Microsoft 365 / Google Workspace licensed users, never both.
Starts at $2,240/year for the first 25 seats, and every compliance framework in the catalogue is included, along with the business-continuity module, your policies, and a Trust Centre.
No per-framework fee: the whole catalogue is in Complete. Volume discounts start at 51 seats.
The rest of the category
Quote only / book a call
Most GRC platforms publish no public price; you request a quote to find out. Lavawall lists its number here and on the pricing page.
A published number is the first thing a buyer can check.
Volume discount, by seat
| 1–50 seats | list price |
| 51–250 seats | 5% off |
| 251–1,000 seats | 10% off |
| 1,001–5,000 seats | 15% off |
| 5,001+ seats | 20% off |
A few scenarios
| Organization | Assumptions | Lavawall / year |
|---|---|---|
| 20-person BC health-tech | 25 seats (the minimum), every framework it needs included | $2,240 |
| 50-person services firm | 50 seats, every framework included | $4,475 |
| 250-seat organization | 250 seats at the 5% volume tier, every framework included | $21,256 |
Lavawall®’s number is on this page and on the pricing page; most of the category makes you ask for it.
For most of these buyers, though, the real alternative to Lavawall is not another compliance platform at all. It is a consultant at $15,000 to $40,000 and a spreadsheet, repeated every year, with nothing left behind between engagements. See the full pricing page for the calculator.
Common questions
- Who is Lavawall GRC for?
- Any organization whose compliance is a combination rather than a single framework: a health-tech startup, an accounting firm, a municipality, a medical-device manufacturer, an investment broker, or an MSP running all of these for its clients. The common thread is carrying more than one framework, privacy law, or industry rule at once.
- Is Lavawall only for MSPs?
- No. Lavawall is multi-tenant, so an MSP can run a whole book of clients from one console, and it works the same way for a single organization holding several obligations of its own.
- Which frameworks are supported?
- 70+, CIS v8.1, NIST CSF 2.0, NIST 800-171, SOC 2, HIPAA, PCI DSS (all SAQs), ISO 27001:2022, CMMC 2.0, Canada's CPCSC, PIPEDA, Alberta/BC health & privacy acts, Quebec Law 25, CPA Canada, OSFI, IIROC/CIRO, EU GDPR/NIS2/DORA, UK Cyber Essentials, and Australia's Essential Eight.
- Can Lavawall issue our SOC 2 report?
- No, only a licensed CPA firm can. Lavawall gets you audit-ready and works alongside your auditor.
- Do you include PCI ASV scanning?
- Yes, integrated Clone Systems PCI ASV scanning with missed-scan notifications and report inclusion.