SCC-accredited ISO/IEC 27001 and CyberSecure Canada certification. Get an instant estimate and manage your application online.
CompladeFRLog in to Complade Portal
Menu
About Complade

Who we are and why we exist

Complade is an SCC-accredited Canadian certification body created to provide informed assurance about information risks and controls.

Our mission

To provide organizations and their stakeholders with informed assurance about information security risks and controls.

Our vision

A secure and resilient digitally enabled economy for our families.

Impartiality: our core principle

Integrity lies at the heart of our operations. We believe in a certification and audit process free from undue influence or bias. Our impartiality policy ensures every organization, regardless of size or stature, receives a fair, consistent, and transparent evaluation.

Accreditation

The SCC Accreditation Symbol is an official symbol of the Standards Council of Canada and is used under licence.

Complade Canada Inc. is a certification body accredited by the Standards Council of Canada under the Management Systems Accreditation Program. SCC participates in the applicable International Accreditation Forum multilateral recognition arrangements.

Complade's accreditation scope is based on ISO/IEC 17021-1:2015 and ISO/IEC 27006-1:2024, with applicable IAF mandatory documents including IAF MD 4:2023.

Accreditation status and scope should be verified using Complade's current IAF CertSearch record and SCC accreditation directory entry.

Verify our accreditation

View Complade’s official SCC and IAF CertSearch records.

External sources

Complade in recognized industry sources

Read independent SCC coverage of Complade and accreditation, plus Complade’s ISO 27001 analysis published by the Cloud Security Alliance.

Independent featureStandards Council of Canada (SCC)

How accreditation helps Complade build trust

An SCC feature about Complade and the role accreditation plays in building trust in certification services.

Read the source
Independent featureStandards Council of Canada (SCC)

Accreditation: a trusted ally for small business success

SCC explains how accredited services help small and medium-sized businesses build trust, access markets and grow.

Read the source
Complade thought leadershipCloud Security Alliance

Let’s go back to the basics: how ISO 27001 certification works

An analysis of ISO 27001 certification and cloud security written by Yehia (Ian) Ahmed of Complade and published by the Cloud Security Alliance.

Read the source
Why Complade

Why does Complade exist?

Organizations exist as they represent the most cost-effective method known for organizing resources to create value.

On October 13, 1994, Netscape Navigator was launched, allowing non-technical users to access the internet. Two years later, Compaq developed a business plan on how to utilize the internet through the browser, coining the term "Cloud". Cloud computing is when organizations use the browser and the internet to run their operations, like when using Outlook, Gmail, or QuickBooks Online.

Fast forward to 2024, over 5 billion people use the internet. Cloud computing is prevalent in more than 90% of the world's organizations. This means that 90% of organizations produce value for their stakeholders using tools connected to the internet, creating a dependency on Cloud providers like Microsoft for Outlook, Google for Gmail, and Intuit for QuickBooks Online. But these are not the only Cloud providers.

Cloud computing, or the use of internet and browser-enabled devices, encompasses various levels. For instance, an organization creating software for a doctor's office typically relies on cloud providers like Google Cloud, Microsoft Azure, or Amazon AWS for services and storage. In contrast, larger companies might opt to host these services on their own servers, managed by VMware with Windows as the operating system. Each segment of this supply chain presents unique risks that require effective management through controls, a process known as Cybersecurity Management. It's important to note that terms such as 'cyber', 'internet', 'IT', 'digital', and 'cloud' are often used interchangeably in this context.

For this economic system to function effectively, informed trust in the supply chain is essential. This is where impartial assurance providers play a crucial role, informing stakeholders about the status of an organization's information risks and controls. However, the assurance process often becomes complex and ineffective. Instances where schools, hospitals, financial systems, retailers, and others have their cloud resources held for ransom – reminiscent of old-age piracy – occur despite these organizations having assurance processes in place, such as ISO 27001 certification or SOC 2 attestations. Unfortunately, these can sometimes provide a false sense of assurance to stakeholders. Complade is an organization on a mission to rectify this issue.

Cybersecurity and data privacy standards are developed by the community to streamline processes, similar to the metric standard or Generally Accepted Accounting Principles (GAAP). When organizations utilize, implement, and get "certified" in standards like NIST CSF, ISO 27001, or CyberSecure Canada, yet still fail to protect their resources, the issue does not lie with the standard itself. Rather, it's due to a broken assurance process that leads to a false sense of assurance. This results in negative consequences such as complacency, apathy, and negligence among its stakeholders. Complade is an organization dedicated to resolving this challenge.

To help organizations' stakeholders obtain informed assurance that information risks and controls are balanced. Most organizations now depend on interconnected cloud and technology supply chains to create and deliver value. Those supply chains span data centres, fibre networks, software, and multiple service providers, making assurance too complex to manage through individual suppliers or disconnected spreadsheets and document templates.

Complade's objective is to provide stakeholders with informed assurance. We specialize in cybersecurity assurance, including assessments, testing, certification, attestation, and audits. By improving assurance processes, technology, and methods, we aim to build trust across the supply chains that support the economy.

Complade uses a transparent, repeatable audit model grounded in established standards. The objective is consistent, evidence-based assurance built on three pillars:

01

1. People

Complade reduces unnecessary auditor variation by requiring transparent, standardized methods and clear objectives based on recognized standards.

Complade audit teams have experience with cloud and AI-enabled technologies. They combine collaborative interviews and document reviews with direct observation, data analysis, and technical testing. The process focuses on evidence, systemic causes, and effective corrective action.

02

2. Technology

Complade uses transparent, near-real-time reporting during Stage 1 and Stage 2 audits so auditees can understand findings and supporting evidence as the audit progresses.

03

3. Process

Complade uses a structured, risk-informed certification programme with published pricing assumptions and a repeatable audit and verification cycle. The process is grounded in recognized requirements and informed by relevant threat models and technical evidence.

We'd like to invite you to discover the efficiency of Complade's assurance and cybersecurity certification process for your organization. Contact us.

The name

While at it. Here is what Complade means:

Complade = Compliance + Lade

Compliance:
the state or fact of according with rules or standards.
Lade:
to put cargo on a ship.