Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Mainframe Compliance

2025 Mainframe Compliance Countdown: Regulatory Changes

The DOJ final rule, FISMA updates, CJIS 5.9.4 and the proposed HIPAA Security Rule changes all land in 2025. Mainframes are now held to the same standard as cloud.

EJ Pappas

By EJ PappasField Chief Technology Officer and Managing Director of Strategic Accounts at PKWARE

Share on social media

In 2025, the regulatory spotlight on data privacy has never been more intense. Meanwhile, mainframes have become the center of focus.

First, organizations continue to modernize their security and privacy infrastructure. In doing so, they increasingly realize that legacy environments must meet the same rigorous standards as cloud and distributed systems. Mainframes are the clearest example. Therefore enterprise and public sector IT leaders face a path that requires immediate, strategic action. A wave of new federal and state mandates is arriving, and many carry near-term deadlines and significant penalties for non-compliance.

The Regulatory Landscape: What’s Changing in 2025

Several major federal rules are reshaping data security obligations this year. Moreover, each has implications for mainframe environments.

DOJ Final Rule (Effective April 8, 2025)

This landmark regulation prohibits bulk transfers of sensitive U.S. personal and government-related data to foreign adversaries. Therefore U.S. entities must implement data classification and export controls, including on mainframes. By October 6, 2025, organizations must have enforcement-ready audit and reporting programs in place. Otherwise they risk civil or criminal penalties.

FISMA 2025 Updates

The Federal Information Security Modernization Act now mandates continuous cybersecurity planning. In addition, it requires risk-based classification and data inventories. Those apply to all federal systems and contractors, including systems running on IBM Z or similar platforms.

CJIS Security Policy (v5.9.4)

Any mainframe system processing criminal justice data must enforce encryption, access auditing, and classification controls. In addition, those controls must stay consistent with FBI CJIS standards.

Proposed HIPAA Security Rule Changes

These upgrades are expected to be finalized this year. Specifically, they require multifactor authentication (MFA), encryption, data flow mapping, and vendor oversight for systems handling ePHI. Many of those systems still rely on mainframes in healthcare and government.

The Rise of State-Level Privacy Laws

Eight new state laws are now in effect. For example, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, and Maryland all have them. Moreover, each carries an expansive definition of sensitive personal data. That definition includes race, religion, biometric, genetic, health, sexual orientation, and geolocation data.

These laws introduce:

  • Explicit consent requirements
  • Data minimization mandates
  • Consumer rights for access, deletion, and portability

Therefore mainframes must now tag, filter, and restrict sensitive data to comply with these jurisdictional rules. Furthermore, systems must respond to data subject requests. That capability is not typically native to mainframes.

What This Means for Mainframe Owners

The message is clear. Treat mainframes as first-class citizens in your data privacy and security architecture. In other words, there are no longer “data at rest” exceptions for the mainframe. Organizations must understand what data exists on the platform as diligently as they do for any cloud repository or database. In short, knowing what the data is, where it is going, and how it is consumed is now critical for regulatory compliance.

Key imperatives include:

  1. Implement Data Classification at Scale: Identify and tag sensitive data categories, including health, financial, biometric, and government-related data, on legacy formats and record structures.
  2. Enforce Export Controls: Ensure mechanisms block unauthorized transfers of regulated data, whether through third-party vendors, employment transitions, or cross-border exports.
  3. Maintain Inventories and Flow Maps: Understand what data resides where, how it moves, and which systems touch it. This is essential for both FISMA and HIPAA compliance.
  4. Enable Consent Management and Consumer Rights: Prepare workflows for access, deletion, and portability requests. That includes datasets nobody designed for dynamic interaction.
  5. Strengthen Controls: MFA, encryption, audit logging, and vendor monitoring must now extend into environments that have historically operated in silos.

Powering Mainframe Compliance at Scale

At PKWARE, we recognize that most mainframes were never exposed to this level of scrutiny. However, that does not make compliance optional.

Our solutions bridge the gap between legacy limitations and modern regulatory demands:

  • Automated discovery and classification of sensitive data across structured and unstructured formats
  • Persistent encryption and policy enforcement, even across air-gapped systems and data exchanges
  • Export control enforcement and audit readiness aligned with DOJ, FISMA, CJIS, and HIPAA requirements
  • Support for consumer rights compliance across jurisdictional boundaries, even for mainframe data

In 2025, no system gets a free pass. Instead, your mainframe must meet the same regulatory demands as today’s cloud and SaaS platforms.

Because enforcement deadlines are fast approaching, IT and security leaders must act swiftly. Mainframe compliance is not just about keeping pace. Rather, it is about leading the way in securing the data that matters most.

Finally, PKWARE is here to help you make that happen, intelligently, efficiently, and in full compliance.

Learn more about PK Protect for z/OS

EJ Pappas

EJ Pappas

Field Chief Technology Officer and Managing Director of Strategic Accounts at PKWARE

As the Field Chief Technology Officer and Managing Director of Strategic Accounts at PKWARE, I bring over 25 years of experience in exceeding revenue targets, building customer relationships, and leading teams. I am responsible for bridging the gap between technology and business strategy while engaging directly with customers and partners. I focus on developing a collaborative approach to dealing with customers’ Use Cases and problems. I serve as a trusted advisor to the PKWARE policy-driven data protection offerings product and technology and work to make customers successful. Additionally, I executively manage PKWARE's top eight customers worldwide, based on annual contract value (ACV).

My mission is to help enterprises reduce their risk from breaches and optimize their IT operations by prioritizing and managing sensitive data anywhere it is used, shared, and stored. I partner with key stakeholders and decision-makers to understand their challenges and needs and deliver customized solutions that address their pain points and goals.