The sector's security needs
Why seek independent assurance?
For software as a service (SaaS), artificial intelligence (AI) and other technology providers, security responsibilities extend across development, hosting and support. Cloud procurement guidance from the Canadian Cyber Centre identifies secure development, access management, incident response and data handling as matters buyers should address in their contracts.
Read the sector sourceChoosing a certification
Information security management
ISO/IEC 27001
ISO/IEC 27001 provides a framework for managing information security as your product, infrastructure, workforce and customer obligations change. Certification can support procurement where buyers require an independently assessed management system. The scope should make clear which products and supporting activities are included.
ISO/IEC 27001 certification processBaseline cybersecurity requirements
CyberSecure Canada
CyberSecure Canada is an option for providers whose customers need evidence of baseline cybersecurity practices. It can support Canadian supplier assessments without presenting the product itself as certified.
CyberSecure Canada certification processWhen do both make sense?
A provider may need ISO/IEC 27001 for one market and CyberSecure Canada for another customer's procurement requirements. Existing controls and records may support both assessments. Neither certificate automatically grants the other, and two certificates are not necessary for every provider.
Complade considers whether audit activities can be coordinated during application review. Audit time and fees are confirmed in the proposal.
Examples from the Complade Certification Registry
Open each record to check the standard, status and scope. These examples are not endorsements of the organizations' products or services.
Define your scope
Application review starts with your activities and responsibilities. Be ready to answer these questions:
- Which products, hosting environments and support activities are included?
- What information do you process, and which suppliers can access it?
- What evidence do your target customers actually require?
Sources and Complade's role
The sources explain sector concerns. Their connection to the certifications discussed is Complade's analysis; these organizations do not endorse Complade or necessarily require these certifications.
Complade provides independent certification audits. We do not provide implementation consulting, readiness consulting or internal audits. Certification concerns conformity with the applicable requirements within a defined scope; it does not guarantee the absence of incidents.
Verify Complade's accreditation · Understand the audit process