๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

GRC & compliance automation

Compliance that maps itself.

Lavawall® reads your real posture and maps it to 70+ frameworks at once, generates the policies auditors expect, and collects evidence continuously, so "the auditor is asking" turns into a live compliance score instead of a lost weekend.

Start with the GRC WizardUnder a deadline?

70+ frameworks ยท generated policies ยท continuous evidence ยท PCI ASV

Watch the GRC walkthroughVideo coming soon

Does this sound like you?

Most organizations don't have one compliance obligation. They have a combination: a control framework or two, one or more privacy laws, and the rules for what they do. Here are a few, and yours will look different. That is the point, because almost nobody has just one.

A 12-person health-tech startup in BC

BC PIPA and PIPEDA for privacy; the BC E-Health Act if it touches a health information bank; PCI DSS for card payments; SOC 2 the moment a health authority asks; two breach clocks.

Six instruments, before twenty staff.

A Calgary accounting firm

Alberta PIPA and PIPEDA for client information; the CPA Canada cybersecurity expectations; FINTRAC when it handles client funds; SOC 2 if it runs any client-facing technology.

Five instruments.

A city of 40,000 in Iowa

The FBI CJIS Security Policy for policing; HIPAA once fire and EMS bill electronically; PCI DSS for utility and parking payments; AWIA for the water system; Iowa chapters 22, 21, and 715C; ADA Title II.

Eight instruments.

An Ontario medical-device company

PIPEDA, Ontario PHIPA, and HIPAA for privacy; FDA section 524B, Health Canada's guidance, and the lifecycle standards for device cybersecurity; SOC 2 or ISO 27001 for hospital IT.

Seven instruments (its quality system is a separate program).

A regulated investment broker in BC

BCFSA, CIRO cyber expectations, and CSA Staff Notice 33-322 from the sector regulators; FINTRAC for financial crime; BC PIPA and PIPEDA for privacy; SOC 2 if it runs client-facing technology.

Seven instruments.

A US SaaS company chasing enterprise deals

SOC 2 and often ISO 27001 for the sales cycle; CCPA and the growing list of US state privacy laws; the HIPAA Security Rule if a customer is in health care; PCI DSS if it takes payments.

Four to six instruments, climbing with each new state.

A US healthcare clinic

The HIPAA Security Rule and HITECH for patient data; state breach-notification laws; PCI DSS for co-pays and billing; and a business-associate agreement with every vendor that touches PHI.

Five instruments.

An MSP with forty clients

Every one of the above, times a book of business: a city, a clinic, a broker, and a manufacturer, each with a different obligation set, run from one console with per-tenant isolation and billing.

One platform, multi-tenant.

Not on this list? If you keep more than one framework, privacy law, or industry rule, whether you are an MSP running forty of these at once or a single business holding your own, you are exactly who Lavawall® is for. The question is never how big you are; it is how many obligations you carry.

From posture to proof

Map once, satisfy many

One control you turn on typically satisfies requirements across SOC 2, CIS, NIST, HIPAA and more at the same time. Compliance Wizard, assessments, and onboarding guide the way.

Policies & documents, generated

Policies, procedures, and a system description are generated and kept current, not copied from a stale template you'll have to defend.

Continuous, timestamped evidence

Patch logs, MFA status, access reviews, encryption state, and backup records are captured automatically, plus integrated PCI ASV scanning.

A live score and gap list

See exactly which controls are open and how to close them, prioritized, per framework, across every tenant.

SOC 2 note: a SOC 2 report is issued only by a licensed CPA firm. Lavawall/ThreeShield gets you audit-ready and works alongside your CPA auditor.

the live compliance score & gaps

The frameworks you need

When a client's questionnaire names a framework, it's already mapped.

A prospect asks for your SOC 2. An insurer wants CMMC 2.0. A hospital needs HIPAA and your Alberta clinic needs the AB HIA. Instead of starting each one from a blank page, Lavawall® maps your real posture to every framework at once, so the control you already turned on counts everywhere it applies.

Frameworks, standards, and regulations Lavawall® maps and evidences include:

The GRC Wizard showing which frameworks apply to your business and which it recommends

One turned-on control typically satisfies requirements across several of these at once. New frameworks are added regularly, and ThreeShield's CISSP/CISA team can scope any of them with you.

Open the full categorized framework directory →

Map my frameworks freeUnder a deadline?

One wizard. Your whole compliance program.

The GRC Wizard asks about your business in plain language, takes your industry and compliance requirements into account, and does the heavy lifting for you.

Built from the data you already collect

The wizard reads the security and IT data Lavawall® already gathers about your environment, so you are not re-entering what the platform can already see.

Policies and action plans, generated

It auto-generates the policies auditors expect and the action plans that tell you what to do next, matched to your industry and the frameworks you need to meet.

Plain language, start to finish

No jargon and no blank templates. Answer a few questions and the wizard turns your requirements into a working compliance program you can hand to an insurer, a client, or an auditor.

Start with the GRC Wizard →

The GRC Wizard asking about your business in plain language

The GRC & Resilience suite

The wizard builds on a full set of resilience tools, each one plain language, each one fed by the security and IT data you already collect.

Business Impact Assessment

Work out which systems and processes matter most, and what it costs you when they stop, in plain language.

Learn more →

Vendor Inventory

Keep a living list of the vendors and tools you rely on, so you know who touches your data and where your risk sits.

Learn more →

Continuity & incident plans

Generate the business-continuity and incident-response plans you need before something goes wrong, and keep them current.

Learn more →

Stakeholder questionnaires

Send and track the security and privacy questionnaires clients, insurers, and partners ask you to fill in.

Learn more →

Trust Centre

Give clients and prospects a single page that shows your security posture, so you answer the same questions once.

Learn more →

AI governance

Set the guardrails and policies for how your team uses AI, and show that you have them in place.

Learn more →

Industry policy packs

Ready-made privacy, acceptable-use, AI, and client-consent documents for your industry, in Canadian and US variants.

Learn more →

Controls that test themselves

Most GRC tools hand you a list of controls and ask you to attest to each one by hand, over and over. Lavawall works the other way around. It reads the live configuration and the user issues it already sees across Microsoft 365, Google Workspace, macOS, Windows, Linux, and more, and fills in the matching controls for you. A misconfiguration or a risky user setting does not just raise an alert, it updates the control it maps to.

The result is evidence that is collected from the system that runs the control, not typed into a questionnaire and hoped to be true. When the posture changes, the control changes with it, so what an auditor sees is what is actually in place today.

Bring your own auditor

An audit gets slow and expensive when the auditor works at arm's length, asking for screenshots and waiting on emailed evidence. Lavawall gives your external auditor a direct, controlled way in: they access the GRC, review the controls and the evidence behind them, evaluate your posture, and sign off, all inside the same system. Less back and forth, a shorter engagement, and a lower bill.

You are not locked to one firm, either. Bring the auditor you already trust, or have ThreeShield's CISSP- and CISA-credentialled team run the examination with you.

The documents Lavawall writes for you

Lavawall® uses data you already have, led by your Business Impact Assessment, and writes each of these in plain language, auto-filled from your records rather than typed from a blank page.

  • Incident Response Plan · who does what, severity levels, and a first-hour checklist, with critical systems and vendors auto-filled from your BIA.
  • Disaster Recovery Plan · recovery priorities, backup expectations, and restore order, auto-filled from your BIA recovery targets.
  • Business Continuity Plan · the umbrella policy that keeps the business running and ties the other two plans together.
  • Foreign Processing Disclosure · a Canadian outside-Canada privacy disclosure most compliance platforms do not generate, built from the services that move your data across the border.
  • Data Flow Documentation · what information moves between your systems and how, mapped from the apps Lavawall detects.
  • Privacy Policy addendum · your service providers, AI use, and international processing, written into one addendum.
  • Industry Privacy Policy packs · ready-made privacy documents matched to your industry, in Canadian and US variants.

Want the audit run with you?

ThreeShield, the CISSP/CISA team that builds Lavawall® scopes the framework, operationalizes controls, and prepares you so the examination is fast and predictable.

Pricing, published

Almost nobody in this category publishes a number. Here is ours, beside how the rest of the category answers the question.

Lavawall® Complete

$89.50 /seat/year

Annual, two months free. A seat is the greater of your managed devices or your Microsoft 365 / Google Workspace licensed users, never both.

Starts at $2,240/year for the first 25 seats, and every compliance framework in the catalogue is included, along with the business-continuity module, your policies, and a Trust Centre.

No per-framework fee: the whole catalogue is in Complete. Volume discounts start at 51 seats.

The rest of the category

Quote only / book a call

Most GRC platforms publish no public price; you request a quote to find out. Lavawall lists its number here and on the pricing page.

A published number is the first thing a buyer can check.

Volume discount, by seat

1–50 seatslist price
51–250 seats5% off
251–1,000 seats10% off
1,001–5,000 seats15% off
5,001+ seats20% off

A few scenarios

OrganizationAssumptionsLavawall / year
20-person BC health-tech 25 seats (the minimum), every framework it needs included $2,240
50-person services firm 50 seats, every framework included $4,475
250-seat organization 250 seats at the 5% volume tier, every framework included $21,256

Lavawall®’s number is on this page and on the pricing page; most of the category makes you ask for it.

For most of these buyers, though, the real alternative to Lavawall is not another compliance platform at all. It is a consultant at $15,000 to $40,000 and a spreadsheet, repeated every year, with nothing left behind between engagements. See the full pricing page for the calculator.

Common questions

Who is Lavawall GRC for?
Any organization whose compliance is a combination rather than a single framework: a health-tech startup, an accounting firm, a municipality, a medical-device manufacturer, an investment broker, or an MSP running all of these for its clients. The common thread is carrying more than one framework, privacy law, or industry rule at once.
Is Lavawall only for MSPs?
No. Lavawall is multi-tenant, so an MSP can run a whole book of clients from one console, and it works the same way for a single organization holding several obligations of its own.
Which frameworks are supported?
70+, CIS v8.1, NIST CSF 2.0, NIST 800-171, SOC 2, HIPAA, PCI DSS (all SAQs), ISO 27001:2022, CMMC 2.0, Canada's CPCSC, PIPEDA, Alberta/BC health & privacy acts, Quebec Law 25, CPA Canada, OSFI, IIROC/CIRO, EU GDPR/NIS2/DORA, UK Cyber Essentials, and Australia's Essential Eight.
Can Lavawall issue our SOC 2 report?
No, only a licensed CPA firm can. Lavawall gets you audit-ready and works alongside your auditor.
Do you include PCI ASV scanning?
Yes, integrated Clone Systems PCI ASV scanning with missed-scan notifications and report inclusion.

Start with the GRC WizardStart my free trial

Data residency: We place your data and our AI processing in the region your obligations require: Canada, the United States, Europe, or Australia. How data residency works →