Canadian certification body accredited by the Standards Council of Canada
Complade answer centre

Complade certification FAQs

Complade answers questions about its accreditation, ISO 27001, CyberSecure Canada, audits, pricing, nonconformities and the client portal.

01

Complade and accreditation

Is Complade an accredited ISO 27001 certification body?

Yes. Complade Canada Inc. is accredited by the Standards Council of Canada (SCC) to provide ISO/IEC 27001 and CyberSecure Canada management-system certification. Accreditation means an independent accreditation body has evaluated Complade's competence, impartiality and certification processes. Verify the current status in the official SCC directory and IAF CertSearch.

#is-complade-accredited

Who accredits Complade?

Complade is accredited by the Standards Council of Canada, Canada's national accreditation body. International recognition arrangements formerly operated through the International Accreditation Forum transitioned to Global Accreditation Cooperation Incorporated on January 1, 2026. The organization seeking certification is certified by Complade; it is not accredited by Complade.

#who-accredits-complade

Is Complade a Canadian company?

Yes. Complade Canada Inc. is a Canadian certification body headquartered at 2 Simcoe Street South, Suite 300, Oshawa, Ontario. Complade provides certification services across Canada in English and French, with remote ISO/IEC 27001 audits available to organizations worldwide subject to scope and audit feasibility.

#is-complade-canadian

Does Complade offer CyberSecure Canada certification?

Yes. Complade Canada Inc. conducts accredited certification audits for the CyberSecure Canada standard for eligible small and medium-sized organizations. The Standards Council of Canada accredits Complade for this certification programme. Organizations can verify Complade in the official SCC directory, review the certification process and apply through the Complade Audit Portal.

#who-provides-cybersecure-canada

Does Complade only certify small companies?

No. Organizations of different sizes use Complade for independent assurance. ISO/IEC 27001 clients include the largest Canadian global aviation software company, headquartered in Saint John, New Brunswick; Ontario’s largest credit union; and Toronto’s largest independent medical laboratory services provider. CyberSecure Canada clients include Canada’s largest medical group purchasing organization, Alberta’s largest independent trucking company, and Canada’s largest museum technology services provider, based in Belleville, Ontario. More than 50% of Ontario community development organizations have been certified through Complade. IT service providers in British Columbia, Alberta, Ontario, Quebec and New Brunswick also work with Complade. The audit plan and duration depend on each organization’s scope and complexity.

#client-sizes

Are certificates issued by Complade internationally recognized?

Complade's SCC-accredited ISO/IEC 27001 certifications benefit from the applicable multilateral recognition framework. On January 1, 2026, Global Accreditation Cooperation Incorporated assumed the operational roles previously held by IAF and ILAC and established the Global ACI Multilateral Recognition Arrangement. Recognition depends on the certificate, Complade's accredited scope and the applicable signatory scope and transition arrangements. Clients and stakeholders should verify Complade and individual certification records using official sources.

#international-recognition

Does Complade guarantee international acceptance of its ISO 27001 certificates?

Yes. Complade guarantees the accredited status of a valid SCC-accredited ISO/IEC 27001 certificate issued by Complade within its accredited scope across the 107 countries and economies covered by the applicable international recognition framework. If such a certificate is rejected solely because Complade's SCC accreditation is not recognized in one of those countries or economies, Complade will refund 100% of the certification fees paid to Complade for that certificate. The guarantee does not apply when rejection results from an expired, suspended or withdrawn certificate; a scope that does not cover the required activities; requirements outside ISO/IEC 27001; or a contract, tender, regulator or customer that requires a specifically named certification body. A claim must include written evidence identifying accreditation recognition as the sole reason for rejection.

#international-acceptance-guarantee

Is a Complade certificate as accredited and accepted as one issued by TÜV, BSI, SGS, PwC or KPMG?

Yes, when comparing valid ISO/IEC 27001 certificates issued within the applicable accredited scopes. Complade and every other certification body issuing accredited management-system certificates must be accredited by a competent accreditation body for the certification activities concerned. Complade is accredited by the Standards Council of Canada, Canada's national accreditation body, for ISO/IEC 27001 and CyberSecure Canada certification. This is not a lesser or secondary form of accreditation. In Canada, Complade, TÜV SÜD America and the specific SCC-listed legal entities operating under major professional-services brands such as PwC and KPMG are assessed by SCC under the same applicable management-systems accreditation programme and requirements. Other BSI, SGS or TÜV entities may instead be accredited by UKAS or another recognized national accreditation body. Within the relevant accredited and multilateral-recognition scopes, Complade's ISO/IEC 27001 certificates have the same accredited status and recognition; company size, price and brand awareness do not create a higher tier of accredited certificate. The exact legal entity, accredited scope and individual certificate should always be verified, and a separate contract or regulation may expressly require a named provider.

#large-certification-bodies

Why does Complade not have a heavy LinkedIn presence?

Complade prioritizes certification delivery, auditor competence, its client portal and publication of process, pricing and audit resources. Social-media activity is not evidence of accreditation or certification competence. Prospects should verify Complade through the official SCC directory, IAF CertSearch, its published policies and its certificate registry.

#linkedin-presence

Can Complade certify an organization based in France or another country?

Yes. Complade accepts ISO/IEC 27001 applications from organizations outside Canada, including France. Complade Canada Inc. is the certification body issuing the certificate under its applicable SCC-accredited scope. Remote audits in English or French are available subject to scope, audit feasibility and team availability. Provide the legal entity, countries, sites and intended scope so Complade can confirm eligibility and any restrictions.

#international-applicants
02

Choosing a certification

Is ISO 27001 or CyberSecure Canada better for my organization?

ISO/IEC 27001 is an internationally used information security management-system standard and is often selected when customers, contracts or international markets require it. CyberSecure Canada is Canada's national baseline cybersecurity certification for small and medium organizations. The better fit depends on customer requirements, market, scope and security maturity; some organizations pursue both.

#iso-or-cybersecure

Can we obtain ISO 27001 and CyberSecure Canada certification together?

Yes. An organization may pursue both certifications. Complade reviews the intended scopes and audit requirements before confirming whether activities can be coordinated. Requirements and certification decisions remain specific to each standard.

#both-certifications

Does ISO 27001 certification satisfy Government of Canada or Protected A requirements?

Not automatically. ISO/IEC 27001 certification and requirements such as ITSP.10.171 have different purposes and assessment criteria. A crosswalk, assessment or remediation plan can support preparation, but the contracting authority determines the requirements for a particular procurement. Check the tender’s required standard, scope, information classification and assessment conditions. Complade can audit the agreed ISO 27001 scope; certification does not guarantee government-contract eligibility.

#government-procurement

Can the certification scope cover our SaaS platform or AI services?

Yes, the proposed management-system scope can cover the design, development, hosting, operation and support of specified services, together with the relevant people, processes, locations and suppliers. Complade reviews the boundaries and dependencies before accepting the scope. ISO/IEC 27001 certifies the information security management system, not a product’s performance, AI accuracy or legal compliance. Discuss comparable scope wording with the certification team; client audit information is not shared without authorization.

#scope-product
03

Timing and readiness

What is the timeline for ISO 27001 certification with Complade?

For an audit-ready small organization, approximately six weeks is the fastest ISO/IEC 27001 scenario published by Complade. Actual timing depends on scope, complexity, readiness, document availability, auditor and client schedules, and the time needed to resolve nonconformities. CyberSecure Canada timing is also confirmed after the application and scope review.

#how-long

Is there a minimum operating period before Stage 2?

Complade does not impose a fixed number of months that a management system must operate before Stage 2. The applicable requirements must be established and implemented for the defined scope, and sufficient evidence must be available for audit. For ISO/IEC 27001, this includes the internal audit and management review requirements. Stage 2 proceeds after the lead auditor concludes that the organization is ready to advance.

#minimum-operating-period

After we sign the agreement, when will the auditors start reviewing our submission?

Complade normally introduces the assigned audit team within hours after the agreement is signed. The client can then access the Stage 1 evidence list and begin uploading documents in the portal. Once the complete required Stage 1 document set has been uploaded and payment received, Complade's service target is for the auditor to complete the initial review within three business days or less, subject to the completeness of the submission and any clarification required.

#auditor-start-time

How soon can Stage 2 be scheduled after Stage 1?

There is no fixed waiting period between Stage 1 and Stage 2. Stage 2 can be planned after the lead auditor concludes that the management system is ready to proceed. Complade normally shares the Stage 2 audit plan within three business days or less after Stage 1 is completed. Audit dates depend on the availability of the client team and qualified auditors; in some cases, Stage 2 can begin within a week, but this timing is not guaranteed.

#stage-2-scheduling

What evidence does a cloud-based company need for CyberSecure Canada?

Prepare evidence against the applicable CAN/DGSI 104 requirements, including responsibilities, incident response, updates, protective software, secure configuration, authentication, employee awareness, backups, encryption, access controls, supplier arrangements and other applicable controls. Cloud hosting does not remove your own responsibilities. Provide the evidence requested in the portal and explain any exclusions. Planned penetration tests or privacy assessments should be coordinated with the audit schedule; a planned activity is not evidence that it has been completed.

#cyber-evidence

What evidence should be ready before Stage 1 and Stage 2?

For ISO/IEC 27001 Stage 1, prepare the defined scope, information security policy, risk assessment and treatment approach, Statement of Applicability, objectives and relevant documented information, including internal audit and management review records. Stage 2 needs sufficient evidence that the system and applicable controls are implemented and effective, such as access reviews, incident records where applicable, training, monitoring and corrective actions. There is no universal minimum number of months, but blank templates are not evidence of completed activities. Readiness is assessed for the actual scope.

#stage-readiness
04

Audit process

What is the difference between Stage 1 and Stage 2?

Stage 1 reviews the management system's scope, documented information and readiness for the implementation audit. Stage 2 evaluates whether the management system and applicable controls are implemented and operating effectively in practice through interviews, records, sampling, observation and technical evidence.

#stage-1-stage-2

What happens if the audit identifies a nonconformity?

The audit report identifies the applicable requirement, evidence and finding. The organization responds with correction, root-cause analysis and a corrective-action plan, with supporting evidence as required. Complade reviews the response before closure. Certification can proceed when applicable requirements are met and required nonconformities are resolved; an identified nonconformity does not automatically mean certification is refused.

#nonconformities

How does Complade keep audits objective and consistent?

Complade uses defined audit criteria, evidence-based evaluation and controlled review methods. Conclusions are tied to applicable requirements and recorded evidence rather than personal auditor preferences. A qualified person independent of the audit delivery reviews the recommendation before the certification decision.

#audit-method

How many audit days are required, and how are they calculated?

Complade determines audit time using the applicable ISO/IEC 27006-1 requirements and the confirmed certification scope. Factors include the number of people in scope, activities, locations, outsourced functions, technical and cloud complexity, and other scope-specific conditions. Total audit time includes both Stage 1 and Stage 2; the scheduled Stage 2 meetings are only part of the total person-days. The lead auditor finalizes the detailed Stage 2 plan after completing Stage 1.

#audit-days

How is the lead auditor selected, and what qualifications do Complade auditors have?

Complade assigns the lead auditor and any audit-team members after confirming the scope and agreement. Selection considers competence for the certification standard and technical activities, audit language, location where relevant, availability and impartiality. Auditor competence is evaluated against applicable ISO/IEC 17021-1 and ISO/IEC 27006-1 requirements, and the Standards Council of Canada assesses Complade's accredited certification programme. The assigned team must also satisfy impartiality requirements, including the applicable restriction on prior ISMS-related relationships with the client. The exact team is introduced to the client after assignment. You can request relevant experience with SaaS, cloud or AI services and confirm the assigned auditor’s location and working hours. A Canadian certification body does not imply that every auditor is based in Canada.

#lead-auditor

Can I speak with a Complade lead auditor instead of a sales representative?

Yes. Prospective clients can book an introductory meeting with a Complade lead auditor to discuss the certification standard, intended scope, audit process, timing, delivery options and published pricing assumptions. Once an application and agreement are completed, the assigned lead auditor is introduced and audit-related meetings can be managed through the Complade portal. To protect impartiality, the auditor can explain requirements and the certification process but cannot design your management system, write policies, recommend specific controls or provide implementation consulting.

#meet-lead-auditor

Do Azure, AWS or Google certifications, SOC 2 reports or penetration tests replace our certification audit?

No. A cloud provider’s certificate covers its stated scope, not automatically your organization or application. Relevant supplier certificates, SOC 2 reports, penetration tests and privacy assessments can support audit evidence when their scope, date and findings are applicable. Complade still evaluates your responsibilities, management system and controls. Existing assurance may inform planning but does not guarantee fewer audit days or certification. SOC 2 is an attestation report, not ISO 27001 certification.

#cloud-existing-assurance
05

Audit delivery

Can the certification audit be conducted remotely?

Yes. Complade conducts remote audits and also offers hybrid or in-person delivery when appropriate. The delivery method is confirmed during application and audit planning based on the certification scope, activities, locations and ability to obtain sufficient audit evidence.

#remote-audit

Can Complade conduct the audit in French?

Yes. Complade provides certification audits in English and French. Select the audit language in the application so the estimate, auditor assignment and audit planning reflect the requested language.

#french-audit
06

Pricing

How much does an ISO 27001 Stage 1 audit cost?

Complade prices the complete initial certification audit rather than selling Stage 1 as a separate certification service. Published planning estimates include Stage 1, Stage 2, audit reports, processing, the independent certification decision and certificate issuance when requirements are met. ISO/IEC 27001 starts at CAD $1,900 for organizations with 1 to 10 people in scope under the published assumptions. Final pricing is confirmed after Complade reviews the application, scope and required audit time.

#cost

How can I get an official certification quotation from Complade?

Start at app.complade.com and complete the initial application to receive an instant planning estimate. If the estimate is suitable, continue with the detailed certification application by confirming the legal organization, requested certification, scope, in-scope personnel, activities, locations, audit language and delivery method. Complade reviews the completed scope and required audit time, then provides the official quotation and certification agreement through the portal. A complete, straightforward application can normally move from scope review to agreement and Stage 1 access within one business day. The online estimate is not the official quotation; the confirmed quotation and signed agreement are controlling.

#official-quote

What is included in the certification price?

The published initial-certification estimate covers the initial certification year: Stage 1, Stage 2, audit reports, processing, the certification decision and certificate issuance when requirements are met. It does not include later surveillance audits unless the official quotation expressly states otherwise. Applicable taxes, travel and accommodation for qualifying in-person audits, and stated language surcharges are excluded. The quotation and certification agreement are controlling for the confirmed scope.

#what-price-includes

Why is Complade's certification pricing lower than many Canadian, British and American certification bodies?

Complade's lower pricing comes from its operating model, not from reducing required audit work. Complade invested in a purpose-built portal and standardized processes that manage applications, scope information, agreements, evidence exchange, audit planning, audit notes, corrective actions, reports and certification records without repetitive PDF editing, fragmented email chains or unnecessary administrative hand-offs. This reduces administrative overhead that does not improve the audit itself. Pricing is therefore based mainly on the professional audit, technical-review and certification time required for the confirmed scope. Depending on the scope and audit language, published estimates generally correspond to approximately CAD $50 to $90 per hour of professional audit work. Technology does not remove required audit time, evidence gathering or independent certification review; it provides a more controlled evidence trail, consistent workflow and near-real-time client visibility. The official quotation remains controlling.

#why-lower-pricing

How much do surveillance audits cost?

Surveillance audits are priced separately from the initial certification unless the official quotation states otherwise. Under Complade's published pricing model, the planning estimate for each scheduled surveillance year is generally 50% of the initial certification price for the same confirmed scope. Scope changes, applicable programme requirements, taxes, travel and other stated exclusions may affect the final amount. The official quotation and contract clearly itemize the applicable fees.

#surveillance-cost

How is the total cost of the three-year certification cycle calculated?

The three-year cost is built from the initial certification audit and the scheduled surveillance or recertification activities stated in the certification programme. Complade's online calculator provides a planning estimate, while the official quotation itemizes the fees that apply to the confirmed scope across the cycle. Changes in scope, headcount, sites, complexity or delivery requirements can change later audit time and cost.

#three-year-cycle-cost

When is payment required?

After accepting the official quotation, the client can sign the certification agreement and begin uploading Stage 1 documents in the portal as they become ready. Payment is required when the complete Stage 1 document set has been uploaded and the audit is ready to begin, in accordance with the invoice and signed agreement.

#payment-timing

Does completing the initial application commit us to purchasing certification?

The initial form provides information for an estimate and scope review; it is not the signed certification agreement. Review the terms presented when submitting the form. The official quotation and subsequent agreement set out the certification services and commercial obligations. You can ask for clarification before signing. After the agreement is accepted, documents can be uploaded before payment is due for the Stage 1 review.

#application-commitment

Is ISO 27001 recertification included in the initial three-year price?

Do not assume it is included. For comparison, request separate amounts for initial certification, the two surveillance audits during the cycle, and recertification before the certificate expires. Recertification starts the next certification cycle and is quoted according to the then-confirmed scope and audit requirements. It is not automatically priced at the surveillance rate.

#recertification-cost

Which taxes, travel costs or additional audit charges could apply?

Published estimates are in Canadian dollars and exclude applicable taxes. On-site travel and accommodation, changes to scope, additional sites or audit work beyond the agreed scope may affect the price. Ask the written quotation to identify corrective-action review allowances, any additional verification charges, certificate or registry fees, and how changes or annual price adjustments are handled. Do not assume a fixed annual increase or unlimited follow-up is included. The signed agreement governs the confirmed scope and charges.

#additional-fees

Does small-team pricing apply to a SaaS or AI company with contractors?

It may apply when the confirmed scope meets the published pricing assumptions. Include regular contractors and outsourced functions relevant to the scope, not just employees on payroll. A small headcount does not automatically mean low complexity. Multiple platforms, locations, cloud environments, sensitive data, integrations, delivery methods or language requirements may change the audit effort and estimate. Describe the full environment in the application.

#small-team-scope

What information is needed to prepare a formal certification quote?

Provide the legal entity and address, requested standard, proposed scope, services and products, people in scope including regular contractors, sites, cloud environments, outsourced activities, audit language and delivery preference. Include your readiness status, target dates, existing assurance reports and any restrictions on access to evidence. Complade reviews this information to establish audit effort; headcount alone does not determine the final quote. Detailed evidence is collected through the portal for Stage 1.

#quote-information

Can we receive a written quote before arranging a call?

Yes. Start with the published pricing and submit your scope through the portal, or send questions to Complade if you need clarification before applying. A call is not required to request written information. Ask for a breakdown of Stage 1 and Stage 2 audit time, planning, reporting, certification and registration fees, two surveillance audits, and recertification as a separate item. The official quotation and agreement confirm inclusions, exclusions and payment terms.

#written-quote-breakdown
07

Certification cycle

What happens after the initial certificate is issued?

Certification is maintained through scheduled surveillance audits. For ISO/IEC 27001, surveillance audits occur during Years 1 and 2, followed by recertification before the next three-year cycle. Surveillance verifies that the management system remains implemented, maintained and effective.

#surveillance

How can someone verify a certificate issued by Complade?

Use Complade's certificate-verification search to look up an organization by name or certificate number. Where applicable, the certification record can also be checked in IAF CertSearch. Certificate pages show the certified organization, standard, scope and validity dates.

#certificate-verification

Can we display the certificate or certification mark on our website?

After certification is granted, use only the certificate and marks you are authorized to use, following the applicable usage guidelines. Claims must match the certified legal entity, standard, scope and current status. Do not imply that a management-system certificate certifies a product or guarantees security. SCC and IAF accreditation marks have separate restrictions; receiving a certificate does not grant unrestricted use. Update or remove claims when the scope or certification status changes.

#certification-marks

How long is CyberSecure Canada certification valid, and what ongoing costs apply?

Use the validity dates on the issued certificate and the maintenance and renewal programme in your signed agreement. Do not assume that the ISO 27001 three-year cycle or its surveillance pricing also applies to CyberSecure Canada. Request a written breakdown of the initial assessment, any ongoing verification or annual charges, and renewal before accepting the quote. Maintain the applicable controls, notify Complade of relevant changes and arrange renewal before expiry.

#cyber-validity
08

Independence

Can Complade implement the standard, write our policies or provide templates?

No. Complade is an independent certification body and does not provide client-specific consulting, implementation, internal audits, policy writing or tailored templates. Complade can explain the certification process, audit criteria and findings without prescribing how the organization must implement or correct its management system.

#consulting

Does Complade offer a readiness discussion or gap-assessment consulting?

Complade can explain eligibility, the application, audit criteria, required evidence and timing before you apply. Stage 1 is part of certification and assesses readiness for Stage 2. Complade does not provide implementation consulting, write policies or conduct your internal audit. If you need tailored implementation or gap-remediation support, engage an independent provider and disclose that relationship in your application.

#readiness-discussion
09

Complade Audit Portal

What can clients do in the Complade Audit Portal?

Clients can submit applications, review estimates, sign agreements, upload Stage 1 evidence, communicate with the audit team, plan Stage 2, assign interview participants, follow evaluated audit points, manage corrective actions, access reports and receive certification records in one system.

#portal

Can the Complade Audit Portal import evidence from a GRC tool?

Yes. With the client's authorization, the Complade Audit Portal can pull selected evidence directly from Maple GRC. Connections for Vanta, Drata, Sprinto, ServiceNow GRC and OneTrust are coming soon and are not currently available. Clients may upload evidence directly in the portal instead. The audit team applies the same evaluation criteria regardless of the evidence source.

#grc-evidence-import

Can we use our own tools or AI to prepare evidence without buying a GRC subscription?

Yes. You can prepare and maintain evidence using your own tools and upload it through the Complade Audit Portal. Purchasing a separate GRC subscription is not a prerequisite. AI-assisted documents are assessed against the same criteria as other evidence: they must accurately describe your organization, be reviewed and approved where required, and be supported by implementation records. Generic policies or AI-generated text alone do not demonstrate that controls operate effectively. Your organization remains responsible for its management system.

#own-tools-ai
10

Other services

Why does Complade focus on ISO 27001 and CyberSecure Canada instead of ISO 9001, ISO 27701, ISO 42001 or SOC 2?

Complade deliberately specializes in information-security risk and assurance rather than offering a broad catalogue of unrelated certifications. Information security is foundational to digitally dependent organizations and directly intersects with privacy, AI governance, cloud services, operational resilience, supply-chain risk and customer trust. This focus allows Complade to invest deeply in specialist auditors, evidence-based audit methods, technical verification and the Complade Audit Portal for ISO/IEC 27001 and CyberSecure Canada. Complade does not currently offer ISO 9001, ISO/IEC 27701 or ISO/IEC 42001, but may add closely related standards where they strengthen this information-risk mission and can be delivered with the same rigour. SOC 2 follows a different attestation model rather than the ISO management-system certification model used by Complade.

#other-standards

Does Complade provide SOC 2 examinations, and why not?

No. Complade deliberately focuses on accredited information-security management-system certification through ISO/IEC 27001 and CyberSecure Canada. SOC 2 uses a different attestation model rather than the ISO management-system certification model. Organizations specifically requiring a SOC 2 report should engage a qualified provider for that form of attestation. Organizations seeking independent, accredited certification of their information-security management system can apply for ISO/IEC 27001 through Complade.

#soc-2
Still have a question?

Start an application or speak with Complade.