In 2025, the regulatory spotlight on data privacy has never been more intense. Meanwhile, mainframes have become the center of focus.
First, organizations continue to modernize their security and privacy infrastructure. In doing so, they increasingly realize that legacy environments must meet the same rigorous standards as cloud and distributed systems. Mainframes are the clearest example. Therefore enterprise and public sector IT leaders face a path that requires immediate, strategic action. A wave of new federal and state mandates is arriving, and many carry near-term deadlines and significant penalties for non-compliance.
The Regulatory Landscape: What’s Changing in 2025
Several major federal rules are reshaping data security obligations this year. Moreover, each has implications for mainframe environments.
DOJ Final Rule (Effective April 8, 2025)
This landmark regulation prohibits bulk transfers of sensitive U.S. personal and government-related data to foreign adversaries. Therefore U.S. entities must implement data classification and export controls, including on mainframes. By October 6, 2025, organizations must have enforcement-ready audit and reporting programs in place. Otherwise they risk civil or criminal penalties.
FISMA 2025 Updates
The Federal Information Security Modernization Act now mandates continuous cybersecurity planning. In addition, it requires risk-based classification and data inventories. Those apply to all federal systems and contractors, including systems running on IBM Z or similar platforms.
CJIS Security Policy (v5.9.4)
Any mainframe system processing criminal justice data must enforce encryption, access auditing, and classification controls. In addition, those controls must stay consistent with FBI CJIS standards.
Proposed HIPAA Security Rule Changes
These upgrades are expected to be finalized this year. Specifically, they require multifactor authentication (MFA), encryption, data flow mapping, and vendor oversight for systems handling ePHI. Many of those systems still rely on mainframes in healthcare and government.
The Rise of State-Level Privacy Laws
Eight new state laws are now in effect. For example, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, and Maryland all have them. Moreover, each carries an expansive definition of sensitive personal data. That definition includes race, religion, biometric, genetic, health, sexual orientation, and geolocation data.
These laws introduce:
- Explicit consent requirements
- Data minimization mandates
- Consumer rights for access, deletion, and portability
Therefore mainframes must now tag, filter, and restrict sensitive data to comply with these jurisdictional rules. Furthermore, systems must respond to data subject requests. That capability is not typically native to mainframes.
What This Means for Mainframe Owners
The message is clear. Treat mainframes as first-class citizens in your data privacy and security architecture. In other words, there are no longer “data at rest” exceptions for the mainframe. Organizations must understand what data exists on the platform as diligently as they do for any cloud repository or database. In short, knowing what the data is, where it is going, and how it is consumed is now critical for regulatory compliance.
Key imperatives include:
- Implement Data Classification at Scale: Identify and tag sensitive data categories, including health, financial, biometric, and government-related data, on legacy formats and record structures.
- Enforce Export Controls: Ensure mechanisms block unauthorized transfers of regulated data, whether through third-party vendors, employment transitions, or cross-border exports.
- Maintain Inventories and Flow Maps: Understand what data resides where, how it moves, and which systems touch it. This is essential for both FISMA and HIPAA compliance.
- Enable Consent Management and Consumer Rights: Prepare workflows for access, deletion, and portability requests. That includes datasets nobody designed for dynamic interaction.
- Strengthen Controls: MFA, encryption, audit logging, and vendor monitoring must now extend into environments that have historically operated in silos.
Powering Mainframe Compliance at Scale
At PKWARE, we recognize that most mainframes were never exposed to this level of scrutiny. However, that does not make compliance optional.
Our solutions bridge the gap between legacy limitations and modern regulatory demands:
- Automated discovery and classification of sensitive data across structured and unstructured formats
- Persistent encryption and policy enforcement, even across air-gapped systems and data exchanges
- Export control enforcement and audit readiness aligned with DOJ, FISMA, CJIS, and HIPAA requirements
- Support for consumer rights compliance across jurisdictional boundaries, even for mainframe data
In 2025, no system gets a free pass. Instead, your mainframe must meet the same regulatory demands as today’s cloud and SaaS platforms.
Because enforcement deadlines are fast approaching, IT and security leaders must act swiftly. Mainframe compliance is not just about keeping pace. Rather, it is about leading the way in securing the data that matters most.
Finally, PKWARE is here to help you make that happen, intelligently, efficiently, and in full compliance.
