Skip to main content
By Region

Compliance is local. CISGuard deploys where you operate.

Five regional landing pages covering the regulators, sovereignty constraints, and deployment patterns that matter for your jurisdiction.

Choose Your Region

Five jurisdictions, one platform.

US

United States

A single CIS benchmark scan produces evidence for NIST 800-53, FedRAMP Moderate/High, CMMC Level 2, SOC 2 Type II, HIPAA, and CCPA, with air-gapped support for federal classified environments.

Read deep-dive →
California

California, United States

CISGuard generates the technical-controls evidence California AG enforcement actions and class-action defenses rely on: continuous CIS benchmark posture, drift detection, and CCPA/CPRA-ready artifacts.

Read deep-dive →
New York

New York State, United States

CISGuard generates the technical-controls evidence New York Department of Financial Services examiners expect under 23 NYCRR 500: continuously, with the audit-ready Framework Coverage Reports the November 2023 amendments effectively mandate.

Read deep-dive →
Texas

Texas, United States

Texas Data Privacy and Security Act (TDPSA), HIPAA, PCI-DSS, NIST 800-53, FedRAMP, SOC 2, and CMMC compliance automated for Texas enterprises in tech, energy, healthcare, and aerospace.

Read deep-dive →
Virginia

Commonwealth of Virginia, United States

FedRAMP, CMMC Level 2, NIST 800-53, NIST 800-171, Virginia CDPA, HIPAA, and SOC 2 compliance automated for the federal contractor, GovTech, and BFSI tenants of Northern Virginia and Hampton Roads.

Read deep-dive →
Massachusetts

Commonwealth of Massachusetts, United States

HIPAA, HITRUST CSF, Massachusetts 201 CMR 17, SOC 2, FDA 21 CFR Part 11, FedRAMP, and CMMC compliance automated for Massachusetts biotech, BFSI, defense, and higher-education tenants.

Read deep-dive →
Washington

State of Washington, United States

My Health My Data Act, Washington Privacy Act, HIPAA, SOC 2, FedRAMP, ITAR, and CMMC compliance automated for Washington tech, healthcare, aerospace, and cloud-services tenants.

Read deep-dive →
Illinois

State of Illinois, United States

Illinois BIPA, IL Personal Information Protection Act, SOX, NYDFS-equivalent insurance frameworks, HIPAA, SOC 2, NIST 800-53, and CFTC Reg AT compliance automated for Illinois BFSI, insurance, manufacturing, and healthcare tenants.

Read deep-dive →
Colorado

State of Colorado, United States

Colorado Privacy Act, HIPAA, FedRAMP, NIST 800-171, CMMC, ITAR, and SOC 2 compliance automated for Colorado aerospace, defense, tech, healthcare, and energy tenants.

Read deep-dive →
San Francisco SoMa

SoMa (South of Market), San Francisco

CCPA / CPRA, SOC 2 Type II, ISO 27001, HIPAA, PCI-DSS, NYDFS, and GDPR compliance automated for the SaaS unicorns, fintech, and AI scaleups concentrated across SoMa, the Financial District, and Mission.

Read deep-dive →
SF Mission Bay

Mission Bay, San Francisco

HIPAA, HITRUST CSF, FDA 21 CFR Part 11, CCPA / CPRA, SOC 2, ISO 27001, and GDPR compliance automated for the biotech, clinical-research, and life-sciences tenants of UCSF Mission Bay and the adjacent biopharma cluster.

Read deep-dive →
Palo Alto

Palo Alto, Silicon Valley

CCPA / CPRA, SOC 2 Type II, ISO 27001, FedRAMP, NIST 800-171, HIPAA, and GDPR compliance automated for the late-stage VC, Stanford-adjacent research, and enterprise software tenants of Palo Alto and Sand Hill Road.

Read deep-dive →
Mountain View

Mountain View, Silicon Valley

CCPA / CPRA, SOC 2, ISO 27001, FedRAMP, NIST 800-53, HIPAA, and GDPR compliance automated for the Google, LinkedIn, NASA Ames, and Silicon Valley enterprise tenants of Mountain View.

Read deep-dive →
Cupertino

Cupertino, Silicon Valley

CCPA / CPRA, SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR, and ITAR-aligned compliance automated for the Apple-anchored ecosystem, supplier network, and Silicon Valley operators of Cupertino and Sunnyvale-adjacent.

Read deep-dive →
NYC Financial District

Financial District (FiDi), Manhattan, New York

NYDFS 23 NYCRR 500, SEC Reg SCI, FINRA, SOX, GLBA, HIPAA, NIST 800-53, and SOC 2 compliance automated for the BFSI HQs and capital-markets infrastructure of Lower Manhattan.

Read deep-dive →
NYC Midtown

Midtown Manhattan, New York

NYDFS 23 NYCRR 500, SOX, GLBA, HIPAA, SOC 2, ISO 27001, CCPA / CPRA, and GDPR compliance automated for the media, advertising, consulting, insurance, and corporate-services tenants of Midtown Manhattan.

Read deep-dive →
Boston Kendall Square

Kendall Square, Cambridge / Boston

HIPAA, HITRUST CSF, FDA 21 CFR Part 11, Massachusetts 201 CMR 17, GDPR, SOC 2, and ISO 27001 compliance automated for the biotech, clinical-research, MIT, and gene-therapy tenants of Kendall Square.

Read deep-dive →
Boston Route 128

Route 128 Corridor (Burlington / Waltham / Lexington), Greater Boston

NIST 800-171, CMMC Level 2 / 3, FedRAMP, ITAR, NIST 800-53, HIPAA, HITRUST, SOC 2, and Massachusetts 201 CMR 17 compliance automated for the defense-electronics, federal-research, and enterprise-tech tenants of the Route 128 ring.

Read deep-dive →
Austin

Austin, Texas

TDPSA, HIPAA, SOC 2, ISO 27001, PCI-DSS, NIST 800-171, CMMC, and CCPA / CPRA compliance automated for the Tesla, Apple, Oracle, Dell, AMD, and SaaS-scaleup tenants of Austin.

Read deep-dive →
Seattle Downtown

Seattle Downtown / South Lake Union, Washington

My Health My Data Act, SOC 2, ISO 27001, FedRAMP, HIPAA, NIST 800-53, and CCPA / CPRA compliance automated for the Amazon, Expedia, Zillow, Tableau, and SaaS-scaleup tenants of Seattle Downtown and South Lake Union.

Read deep-dive →
Bellevue

Bellevue, Washington (Eastside)

My Health My Data Act, SOC 2, ISO 27001, FedRAMP, HIPAA, NIST 800-53, and PCI-DSS compliance automated for the Microsoft Bellevue, T-Mobile US, Concur, Smartsheet, and Eastside enterprise-tech tenants.

Read deep-dive →
Tysons Corner

Tysons Corner, Virginia

FedRAMP, CMMC L2 / L3, NIST 800-53, NIST 800-171, ITAR, NYDFS, SOX, HIPAA, and SOC 2 compliance automated for the federal contractor, GovTech, BFSI, and consulting tenants of Tysons Corner.

Read deep-dive →
Reston

Reston, Virginia

FedRAMP, CMMC L2 / L3, NIST 800-53, NIST 800-171, ITAR, HIPAA, SOC 2, and ISO 27001 compliance automated for the SAIC, Leidos, HPE Federal, Volkswagen Group of America, and federal-IT tenants of Reston.

Read deep-dive →
Research Triangle Park

Research Triangle Park (RTP), North Carolina

HIPAA, HITRUST, SOC 2, ISO 27001, FedRAMP, NIST 800-53, PCI-DSS, and FDA 21 CFR Part 11 compliance automated for the IBM RTP, SAS Institute, Cisco RTP, Lenovo, IQVIA, and biotech tenants of the Research Triangle.

Read deep-dive →
Florida

Florida, United States

CISGuard produces the reasonable-measures evidence the Florida Information Protection Act requires and the technical-safeguards record that supports Florida Digital Bill of Rights obligations, from continuous CIS benchmark scanning.

Read deep-dive →
New Jersey

New Jersey, United States

CISGuard produces the reasonable-security evidence the New Jersey Data Privacy Act requires and aligns day-to-day hardening with the defensive guidance NJCCIC publishes for New Jersey organizations.

Read deep-dive →
Pennsylvania

Commonwealth of Pennsylvania, United States

CISGuard gives Pennsylvania organizations the continuous CIS benchmark posture that shortens breach determination timelines under the Breach of Personal Information Notification Act and evidences security programs for auditors and regulators.

Read deep-dive →
Ohio

Ohio, United States

Ohio grants a litigation safe harbor to organizations whose cybersecurity program reasonably conforms to recognized frameworks, and the CIS Controls are on the list. CISGuard produces the continuous conformity evidence that makes the defense credible.

Read deep-dive →
Georgia

Georgia, United States

Georgia is the payments capital of the United States, and its state agencies run on Georgia Technology Authority security standards. CISGuard turns continuous CIS benchmark scanning into PCI-DSS, NIST, and breach-readiness evidence from a single platform.

Read deep-dive →
Michigan

Michigan, United States

Michigan spans healthcare systems under HIPAA and MDHHS oversight, an automotive supply chain facing TISAX assessments, and the Michigan Identity Theft Protection Act. CISGuard feeds all three from continuous CIS benchmark scanning.

Read deep-dive →
North Carolina

North Carolina, United States

North Carolina pairs one of the largest banking centers in the United States with statewide security standards from NCDIT and the NC Identity Theft Protection Act. CISGuard produces continuous CIS benchmark evidence for all three audiences.

Read deep-dive →
Arizona

Arizona, United States

Arizona's breach notification statute runs on a tight clock, and the Arizona Department of Homeland Security sets the security bar for state government. CISGuard supplies the continuous CIS benchmark evidence both regimes reward.

Read deep-dive →
Tennessee

Tennessee, United States

The Tennessee Information Protection Act brings comprehensive privacy obligations to a state built on healthcare. CISGuard produces the continuous CIS benchmark evidence that TIPA's security expectations and HIPAA's technical safeguards both examine.

Read deep-dive →
Utah

Utah, United States

Utah pairs a cybersecurity affirmative defense that recognizes the CIS Controls with the Utah Consumer Privacy Act. CISGuard produces the continuous conformity evidence that makes the safe harbor defensible and the UCPA security obligation demonstrable.

Read deep-dive →
Connecticut

Connecticut, United States

Connecticut combines a comprehensive privacy law with a safe harbor statute that rewards CIS Controls conformity. CISGuard supplies the continuous CIS benchmark evidence both regimes examine, plus insurance-sector data security coverage.

Read deep-dive →
Maryland

Maryland, United States

Maryland pairs one of the strictest state privacy laws in the country with the densest federal-contractor corridor in it. CISGuard maps continuous CIS benchmark scanning to MODPA security expectations and NIST 800-171/CMMC evidence simultaneously.

Read deep-dive →
EU

European Union

CISGuard maps a single CIS benchmark scan to GDPR Article 32 technical measures, NIS2 risk-management requirements, DORA ICT controls, and TISAX assessment evidence, all within EU sovereign deployment.

Read deep-dive →
Germany

Federal Republic of Germany

CISGuard automates the technical-controls layer underpinning BSI IT-Grundschutz, the German NIS2 transposition law (NIS-2-Umsetzungsgesetz), TISAX automotive assessments, and DSGVO/BDSG technical measures, deployed entirely within German or EU sovereign infrastructure.

Read deep-dive →
France

French Republic

CISGuard automates the technical-controls layer underpinning HDS (Hébergeurs de Données de Santé), SecNumCloud-aligned deployments, the French NIS2 transposition, and CNIL technical-measures expectations, deployed within French or EU sovereign infrastructure.

Read deep-dive →
UK

United Kingdom of Great Britain and Northern Ireland

CISGuard automates the technical-controls layer underpinning Cyber Essentials, Cyber Essentials Plus, NIS Regulations 2018, UK GDPR, and the post-Brexit data-protection regime, deployed within UK or EU sovereign infrastructure.

Read deep-dive →
Spain

Kingdom of Spain

CISGuard automates the technical-controls layer underpinning ENS (Esquema Nacional de Seguridad), the Spanish NIS2 transposition, and AEPD/RGPD technical measures, covering ENS Categoría ALTA / MEDIA / BÁSICA from a single CIS scan.

Read deep-dive →
Italy

Italy

CISGuard generates the technical-controls evidence Italian regulators expect: continuous CIS benchmark posture mapped to ISO 27001 and NIST 800-53, with on-premises and air-gapped deployment that keeps every artifact inside Italy.

Read deep-dive →
Netherlands

The Netherlands

CISGuard turns continuous CIS benchmark scanning into the hardening evidence Dutch regulators and the BIO public-sector baseline expect, mapped to ISO 27001 and kept on infrastructure you control.

Read deep-dive →
Sweden

Sweden

CISGuard delivers continuous CIS benchmark evidence for Swedish essential entities, public-sector bodies, and GDPR-regulated organizations, mapped to ISO 27001 and deployable entirely inside Sweden.

Read deep-dive →
Poland

Poland

CISGuard gives entities under the Polish National Cybersecurity System continuous CIS benchmark evidence, mapped to ISO 27001 and NIST 800-53, deployable on-premises or air-gapped inside Poland.

Read deep-dive →
Ireland

Ireland

CISGuard gives Irish operations, including the EU headquarters of global technology companies, continuous CIS benchmark evidence for GDPR, NIS2, and ISO 27001, with deployment that keeps data in Ireland.

Read deep-dive →
Belgium

Kingdom of Belgium

CISGuard gives Belgian essential and important entities a continuously maintained CIS benchmark baseline: live technical evidence for NIS2 risk management measures, GDPR technical safeguards, and CCB CyberFundamentals conformity work.

Read deep-dive →
Austria

Republic of Austria

CISGuard gives Austrian enterprises, manufacturers, and public bodies a continuously maintained CIS benchmark baseline: live technical evidence for NIS2 risk management measures and GDPR technical safeguards under the Datenschutzbehörde.

Read deep-dive →
Switzerland

Swiss Confederation

CISGuard gives Swiss enterprises and financial institutions a continuously maintained CIS benchmark baseline: technical evidence for the revised Federal Act on Data Protection, FINMA supervisory expectations, and federal ICT minimum standards, with data that never leaves Switzerland.

Read deep-dive →
Luxembourg

Grand Duchy of Luxembourg

CISGuard gives Luxembourg's banks, fund administrators, and service providers a continuously maintained CIS benchmark baseline: technical evidence for CSSF supervisory expectations, DORA ICT risk management, NIS2, and GDPR from one scan.

Read deep-dive →