Canadian certification body accredited by the Standards Council of Canada
All sectors

Independent certification

Technology Services

Your customers give you access to their systems. Certification gives them evidence to consider before they do.

IT support, managed services and cybersecurity consulting

The sector's security needs

Why seek independent assurance?

An information technology (IT) provider may hold administrator access, manage backups or respond to incidents for several customers. Buyers need to understand how that access is controlled and who is responsible when something goes wrong. The Canadian Cyber Centre identifies provider assessments, access control, incident response and recovery as areas customers should examine.

Read the sector source

Choosing a certification

Information security management

ISO/IEC 27001

ISO/IEC 27001 suits providers that need a consistent way to manage information security across staff, subcontractors, customer environments and changing services. The audit assesses the information security management system within the agreed scope. The resulting certificate can support customers evaluating how you manage their information security risks.

ISO/IEC 27001 certification process

Baseline cybersecurity requirements

CyberSecure Canada

CyberSecure Canada can help a provider demonstrate that its own baseline cybersecurity practices have been independently assessed. It is relevant when a Canadian customer asks for evidence of those practices during supplier review. Providing technical expertise does not, by itself, demonstrate how your own organization operates.

CyberSecure Canada certification process

When do both make sense?

Both may be useful when customers ask for different certifications. Some evidence can be relevant to both audits, but each has its own requirements and certification decision. Confirm the customer's requirement before taking on a second certification.

Complade considers whether audit activities can be coordinated during application review. Audit time and fees are confirmed in the proposal.

Examples from the Complade Certification Registry

Open each record to check the standard, status and scope. These examples are not endorsements of the organizations' products or services.

Define your scope

Application review starts with your activities and responsibilities. Be ready to answer these questions:

  • Which services and customer access arrangements are in scope?
  • Who controls privileged accounts, subcontractor access and incident response?
  • Does a customer require a particular certification?

Estimate the cost and apply

Review the calculator's assumptions. The firm price and audit time are confirmed after review of your scope and the required information.

Estimate pricingStart a non-binding applicationReview audit resources

Sources and Complade's role

The sources explain sector concerns. Their connection to the certifications discussed is Complade's analysis; these organizations do not endorse Complade or necessarily require these certifications.

Complade provides independent certification audits. We do not provide implementation consulting, readiness consulting or internal audits. Certification concerns conformity with the applicable requirements within a defined scope; it does not guarantee the absence of incidents.

Verify Complade's accreditation · Understand the audit process