What is CyberSecure Canada?
CyberSecure Canada is a certification programme for baseline cybersecurity practices. It is intended to help small and medium-sized organizations demonstrate that they meet defined security requirements within their certification scope.
A defined cybersecurity baseline
The programme uses CAN/DGSI 104, a Canadian national standard covering baseline cybersecurity controls. DGSI means Digital Governance Standards Institute. Earlier records may use the CAN/CIOSC designation, referring to the CIO Strategy Council.
The approach is more prescriptive than ISO 27001: the applicable baseline requirements set the assessment criteria. Preparation includes operational practices, responsibilities, staff awareness and evidence, as well as technical safeguards.
Can we skip a requirement if we think our risk is low?
You cannot simply omit an applicable requirement because you prefer another approach or consider the risk acceptable. Applicability and any permitted exceptions must follow the relevant standard and certification scheme, with supporting justification.
A headline category is not a single test. For example, providing some staff training does not by itself demonstrate that every applicable awareness requirement has been met. The audit examines the required coverage and the evidence.
Are there only 13 controls?
The original programme was commonly described through 13 control categories. That shorthand is not a complete checklist for every edition of CAN/DGSI 104. Our detailed guide identifies the edition covered and separates individual requirements from examples of implementation and evidence.
The Digital Governance Council announced a further revision in July 2026. Publication of a revised standard does not by itself confirm its adoption within a certification programme or a certification body’s accredited scope. Complade confirms the applicable edition and transition arrangements during application review.
Do ISO 27001 or SOC 2 remove the need for this audit?
No. Existing work may provide relevant evidence, but it must be assessed against the CyberSecure Canada requirements and your proposed scope. An ISO 27001 certificate or SOC 2 (System and Organization Controls 2) report is not an automatic substitute.
Where both certifications are useful, an organization can reuse relevant records and coordinate preparation. The assessment criteria and certification decisions remain specific to each programme.
What should we prepare?
Define which organization, services and locations are included. Identify the people involved, the systems that support the work and the responsibilities of cloud and other service providers. Then check the applicable requirements against what is actually in place.
Keep evidence that practices are operating. Depending on the requirement, this may include training records, configurations, access reviews, backup test results or incident response records. The detailed guide provides examples; the examples are not a substitute for the standard.
How does certification differ from preparation?
Your organization is responsible for implementing and maintaining its security practices. Complade independently assesses conformity and makes a certification decision. Complade does not provide client-specific implementation consulting or internal audits.
Use the service page for the application, audit stages and pricing. Use the audit preparation guide to understand requirements and evidence. Any later surveillance or renewal obligations are set out in the certification agreement.
When is CyberSecure Canada a useful choice?
It can be appropriate when a Canadian customer, funder or business partner asks for this certification, or when a smaller organization wants independent assessment against a defined cybersecurity baseline. Confirm the exact requirement with the party requesting it.
Choose ISO 27001 when the requirement is for that management system certificate. Consider both where different stakeholders need each form of assurance and the benefit justifies maintaining both.
From understanding to audit preparation
Sources and reference documents
This guide provides general explanations. The applicable standard and programme rules remain the basis for certification.
