We advise organizations across 5 regions against 22 named regimes. This page sets out each one, what it asks of a firm like ours, what we do about it for ourselves, and the work we do for clients under it. Our own position is generated from the control register, so it changes when the practice changes.
What we claim, and what we do not
•We can be lawful and defensible in every country where we trade, and we are.
•No firm can hold every certification in every country, and any provider claiming otherwise should be checked.
•We hold no SOC 2 report, no ISO 27001 certificate, and no CMMC certification today. Each has a written program and a date.
•Where a country requires a local entity, local representation, or data that cannot leave its borders, we say so and work with local counsel rather than pretending the problem away.
•Every claim on a buyer page is generated from our control register, so it changes when the practice changes rather than when the marketing changes.
North America
Our home market and the source of most federal and state contracting work. Registration and contract clauses drive most of the obligation.
Federal contracting requirements, including FAR and DFARS clauses
in place
United States federal and subcontract work
What it requires
Accurate registration and representations, safeguarding of any federal contract information, and flow down of clauses to subcontractors.
Our own position
Registration facts are held in one approved record and written into every bid automatically. Subcontractor terms carry the same confidentiality and handling obligations we accept.
What we do for clients
Readiness assessment, control implementation, and evidence preparation for contract obligations.
NIST SP 800-171 and CMMC Level 2
triggered by contract
Contracts involving controlled unclassified information
What it requires
Implementation of the practice set and an assessment before award.
Our own position
Practices are mapped and scheduled. The program is deliberately held until a contract actually brings controlled information to us, and we hold no certification today.
What we do for clients
Gap assessment, system security plan, and assessment preparation.
State privacy and breach notification laws
in place
All fifty states, with California, Virginia, Colorado, Texas, and others leading
What it requires
Notification inside a defined window and honouring individual rights.
Our own position
Our own notification route and timing is written down and rehearsed, and we hold a very small amount of personal data by design.
What we do for clients
Multi state notification playbooks and rights handling procedures.
Sector rules, including HIPAA, GLBA, and the Safeguards Rule
in place
Health, financial services, and higher education clients
What it requires
A written program, a named responsible individual, vendor oversight, and incident response.
Our own position
We act as a service provider and sign the appropriate agreements. We do not hold health records.
What we do for clients
Written programs, qualified individual support, vendor oversight, and incident response.
Canadian federal privacy law, PIPEDA and provincial equivalents
in place
Canada
What it requires
Accountability, consent, and breach reporting to the regulator and individuals.
Our own position
Handled under the same data minimization and notification approach.
What we do for clients
Privacy program design and cross border transfer assessment.
Europe, the United Kingdom, and the wider EMEA region
The densest regulatory environment we work in, and the one clients most often need help translating into practice.
GDPR and the UK GDPR
in place
European Union and the United Kingdom
What it requires
Lawful basis, records of processing, data subject rights, transfer safeguards, and seventy two hour breach notification.
Our own position
We process a small, documented set of personal data, act as a processor on engagements, offer the standard contractual clauses with a transfer assessment, and can meet the notification window.
What we do for clients
Program build, records of processing, impact assessments, and transfer work.
NIS2
in place
European Union essential and important entities, and their suppliers
What it requires
Risk management measures, supply chain security, incident reporting inside twenty four and seventy two hour stages, and management accountability.
Our own position
We are not an in scope entity, and we answer supplier security requirements from in scope clients directly from our control register.
What we do for clients
Scoping, measure implementation, reporting playbooks, and board briefing.
DORA
in place
European financial entities and their information technology providers
What it requires
Resilience testing, register of information, incident classification, and contractual terms for providers.
Our own position
Where we serve a financial entity we accept the required contractual terms and appear in the client register of information.
What we do for clients
Resilience program, register support, and third party contract remediation.
The EU AI Act
in place
European Union, phased obligations
What it requires
Transparency, risk classification, and human oversight where a system is higher risk.
Our own position
Our own automated jobs are inventoried with their purpose, their limits, and the decisions a person keeps. No automated job makes a decision about a person.
What we do for clients
System inventory, classification, and governance design.
POPIA and the NDPR, with the African Union Malabo Convention as context
in place
South Africa, Nigeria, and the wider continent
What it requires
Lawful processing, an information officer or equivalent, and regulator notification.
Our own position
Treated on the same basis as other privacy regimes we are subject to.
What we do for clients
Program build and regulator engagement support.
Regional data localization and sector rules across the Gulf and the Levant
in place
Saudi Arabia, the United Arab Emirates, and neighbouring markets
What it requires
National cyber security controls, hosting location rules, and sector regulator approval.
Our own position
We deliver remotely and never require client data to leave the client tenancy, which avoids most localization conflict outright.
What we do for clients
Control mapping to national frameworks and localization assessment.
Asia Pacific
Fast moving privacy law and strong sector supervision, especially in financial services.
Australian Privacy Act, the notifiable data breaches scheme, and the Essential Eight
in place
Australia
What it requires
Notification of eligible breaches and recognized hardening expectations.
Our own position
Notification route documented. Hardening measured against the same maturity model.
What we do for clients
Maturity uplift and notification readiness.
Singapore PDPA and the Monetary Authority technology risk guidelines
in place
Singapore
What it requires
Consent, protection obligations, and third party risk expectations.
Our own position
Met through the same processor terms and control register.
What we do for clients
Technology risk management and outsourcing assessment.
Japan APPI, Korea PIPA, and India DPDP
in place
Japan, South Korea, and India
What it requires
Consent, cross border transfer conditions, and breach reporting.
Our own position
Transfer positions are documented per engagement before any data is touched.
What we do for clients
Transfer assessment and local program alignment.
China PIPL, the Data Security Law, and the Cybersecurity Law
in place
Mainland China
What it requires
Localization for some data, a security assessment for export, and local representation.
Our own position
We do not export personal data out of mainland China, and any engagement touching it is scoped so that analysis stays inside the client environment.
What we do for clients
Scoping and export assessment support with local counsel in the lead.
Latin America
Privacy law modeled closely on the European approach, with active regulators.
LGPD
in place
Brazil
What it requires
Lawful basis, a data protection officer contact, and incident reporting.
Our own position
Handled under the same privacy program and contact route.
What we do for clients
Program build and reporting readiness.
Mexican federal privacy law and other national regimes
in place
Mexico, Chile, Colombia, Argentina, and neighbors
What it requires
Notice, rights handling, and security measures proportionate to the data.
Our own position
Same processor terms and notification route.
What we do for clients
Notice and rights handling design, plus security measure implementation.
Cross border and framework wide
What we hold for ourselves, everywhere, regardless of where a client sits.
ISO 27001 and ISO 27701
being strengthened
International
What it requires
A management system, a risk process, and audited controls.
Our own position
Our management system artifacts are being built to the clause structure on a written timeline. We hold no certificate and we say so on every buyer page.
What we do for clients
Management system build and certification readiness.
SOC 2
being strengthened
Buyer assurance, chiefly North America
What it requires
Controls operating over a period, examined by a licensed firm.
Our own position
Readiness program underway with a month by month plan. We hold no report and offer a signed management attestation in its place.
What we do for clients
Readiness, control implementation, and audit preparation.
NIST Cybersecurity Framework and NIST 800-53
in place
International, used as our translation layer
What it requires
A common control language across regimes.
Our own position
One control set is mapped outward to every framework we report against.
What we do for clients
Cross framework mapping so a client implements once and reports many times.
Export control, sanctions screening, and anti bribery law
in place
International, including the Foreign Corrupt Practices Act and the UK Bribery Act
What it requires
Screening of counterparties, refusal of restricted engagements, and no facilitation payments.
Our own position
Counterparty screening happens before engagement acceptance, and the refusal rule is absolute.
What we do for clients
Not applicable. This governs who we will work with.
Accessibility law, including the European Accessibility Act, Section 508, and WCAG
in place
International
What it requires
Digital services usable by people with disabilities.
Our own position
Public pages are built to the recognized guidance, a statement is published, and reduced motion and right to left reading are supported.
What we do for clients
Reviewing client facing security tooling for accessibility barriers.
Ask us about your own jurisdictions
Tell us where you operate and which regulators supervise you, and we will map the overlap so you implement one control set and report against all of them.