Massachusetts Web Compliance Requirements

Massachusetts Regulation 201 CMR 17.00 sets the national standard for written information security programs (WISP). Web development stacks must implement server-level encryption, active firewall tracking, and granular access control matrices.

Massachusetts Regulation 201 CMR 17.00 sets the national standard for written information security programs (WISP). Web development stacks must implement server-level encryption, active firewall tracking, and granular access control matrices.

Statutory citation

Massachusetts Standards for Protection of Personal Information (201 CMR 17.00)

Technical focus

  • WISP documentation mapping
  • End-to-end data encryption
  • Firewall enforcement

Retention and scrubbing

Records retained for 4 Years. Data scrubbing standard: NIST SP 800-88 Secure Erase.

Metro areas served

Boston, Worcester, Springfield, Cambridge, Lowell