// frameworks
Standards and frameworks
Security standards, compliance frameworks, and laws that apply in Canada or reach Canadian organizations through customers, contracts, and foreign law. Each page explains what it requires, how it is assessed, and where to get help.
// 6 pages
Canadian privacy and cyber law
Federal and provincial laws that set privacy and security duties.
Alberta PIPA
Alberta's Personal Information Protection Act governs how private-sector organizations in the province handle personal information. Organizations must notify the Information and Privacy Commissioner without unreasonable delay when a breach creates a real risk of significant harm.
BC PIPA
British Columbia's Personal Information Protection Act sets consent, access, and security rules for private-sector organizations in the province. As of October 2026 it has no mandatory breach notification, although the OIPC strongly recommends reporting breaches that pose a risk of significant harm.
CCSPA
The Critical Cyber Systems Protection Act became law on June 15, 2026 as Part 2 of Bill C-8 but is not yet in force. Once operators are designated, they will need cyber security programs, supply chain risk controls, and incident reports to CSE within 72 hours.
PHIPA
PHIPA is Ontario's health privacy law for hospitals, clinicians, pharmacies, and other health information custodians. Custodians must notify patients of privacy breaches, report certain breaches to the IPC, and file annual breach statistics, and the IPC can impose administrative penalties.
PIPEDA
PIPEDA is Canada's federal private-sector privacy law, built on 10 fair information principles. Since November 1, 2018, organizations must report breaches that pose a real risk of significant harm to the OPC, notify the people affected, and keep a record of every breach.
Quebec Law 25
Law 25 rewrote Quebec's private-sector privacy law in 3 phases from 2022 to 2024. Enterprises must name a person in charge of personal information, report confidentiality incidents, keep an incident register, and run privacy impact assessments, with fines of up to $25 million or 4% of turnover.
// 4 pages
Canadian certification programs
Government programs that certify suppliers or cloud services.
CGP
PSPC's registration and security program for organizations that handle controlled defence goods and technical data in Canada. It covers personnel security assessments, security plans, records, breach reporting, and inspections, with few cyber-specific rules.
CPCSC
Canada's cyber security certification for defence suppliers, with 3 levels based on ITSP.10.171, a Canadian version of NIST SP 800-171. Level 1 self-assessment started in 2026, and third-party Level 2 assessments are planned from spring 2027.
CyberSecure Canada
A voluntary Canadian certification for small and medium organizations against the national baseline cyber security standard, CAN/DGSI 104. ISED left the program in 2023, and SCC-accredited certification bodies still certify.
GC cloud Protected B
The control profiles, assessment program, and guardrails that govern how federal departments use cloud services for Protected B information, and what cloud and SaaS vendors must show to be assessed by the Cyber Centre.
// 3 pages
Canadian government guidance
Control sets and guidance from the Canadian Centre for Cyber Security.
CCCS baseline controls
The Cyber Centre's free list of 13 baseline controls for organizations with fewer than 500 employees, chosen to deliver most of the protection for a modest effort. Version 1.2 dates from 2020 and underpins the CAN/DGSI 104 standard.
CCCS Top 10
The Cyber Centre's list of 10 priority IT security actions, from defending Internet gateways and patching to admin privilege control and application allow lists. ITSM.10.089 was published in September 2021.
ITSG-33
The Cyber Centre's lifecycle approach to IT security risk management for federal systems, with a control catalogue based on NIST SP 800-53. Its catalogue, Protected B profile, and departmental annex were replaced in 2026 by the ITSP.10.033 and ITSP.10.036 series.
// 7 pages
Canadian sector regulators
Rules for banks, insurers, investment dealers, and energy operators.
AMF ICT guideline
The AMF's expectations for how Quebec insurers, financial services cooperatives, and trust and deposit institutions manage technology and cyber risk. Since April 23, 2025 a separate regulation also requires incident policies, 24-hour incident reports to the AMF, and an incident register.
CIRO cyber reporting
CIRO requires investment dealers to report cybersecurity incidents within 3 days of discovery and to file an investigation report within 30 days. Consolidated CIRO Rules now under consultation would extend the duty to mutual fund dealers.
CSA Z246.1
CSA Group's standard for security management programs at Canadian oil and gas facilities, covering physical and cyber security. The current CSA Z246.1:21 edition was reaffirmed in 2026, and the Canada Energy Regulator requires federally regulated pipelines to follow it.
NERC CIP
NERC's cyber and physical security standards for the bulk electric system, from asset categorization to supply chain risk and network monitoring. They're mandatory in 8 Canadian provinces, each of which adopts and enforces them through its own regulator.
OSFI B-10
OSFI's guideline on managing risk from vendors, cloud providers, and other third parties, in effect since May 1, 2024. It sets 6 outcomes and 11 principles, and its security, audit, and incident terms flow down to suppliers of Canadian banks and insurers.
OSFI B-13
OSFI's guideline on technology and cyber risk for federally regulated banks, insurers, and trust and loan companies, in effect since January 1, 2024. It sets 17 principles in 3 domains covering governance, technology operations and resilience, and cyber security.
OSFI E-21
OSFI's guideline on operational risk and operational resilience for federally regulated financial institutions. Published August 22, 2024, it was fully in effect by September 1, 2026, with the most important operations identified, mapped, and given tolerances for disruption.
// 8 pages
International standards
ISO and IEC standards, most with third-party certification.
IEC 62443
The ISA/IEC 62443 series sets security requirements for industrial automation and control systems across asset owners, service providers, and product suppliers. It uses zones, conduits, and security levels, and certification is available for products, systems, and development processes.
ISO 22301
ISO 22301 sets requirements for a business continuity management system that helps an organization keep delivering its most important products and services during a disruption. The 2019 edition, amended in 2024, is current while ISO works on a revision.
ISO 27001
ISO/IEC 27001 sets the requirements for an information security management system (ISMS) that an accredited body can certify. It pairs risk-based management clauses with a reference list of 93 Annex A controls.
ISO 27002
ISO/IEC 27002 gives guidance for the 93 information security controls listed in ISO/IEC 27001 Annex A. Each control has a purpose, implementation guidance, and optional attributes for sorting and mapping.
ISO 27017
ISO/IEC 27017 adds cloud-specific guidance and extra controls to the ISO/IEC 27002 control set for cloud providers and customers. The second edition was published in July 2026 and replaces the 2015 edition.
ISO 27018
ISO/IEC 27018 sets out controls and guidance for public cloud providers that process personal information for their customers. The third edition, published in August 2025, aligns with ISO/IEC 27002:2022 and adds a new Annex B.
ISO 27701
ISO/IEC 27701 sets requirements for a privacy information management system (PIMS) for PII controllers and processors. The 2025 edition is a standalone standard, so it no longer has to be certified as an extension of ISO/IEC 27001.
ISO 42001
ISO/IEC 42001 sets requirements for an artificial intelligence management system (AIMS) covering the responsible development, provision, and use of AI. It pairs management system clauses with 38 reference controls and can be certified by an accredited body.
// 7 pages
Industry frameworks and attestations
Payment, cloud, health, and automotive schemes customers ask for.
CIS Controls
The CIS Critical Security Controls are 18 prioritized controls with 153 safeguards, sorted into 3 implementation groups. CIS also publishes the CIS Benchmarks, free secure configuration guides for common products.
CSA STAR
CSA STAR is the Cloud Security Alliance's assurance program for cloud providers, built on the Cloud Controls Matrix. Providers can post a self-assessment (Level 1) or add an independent SOC 2 or ISO 27001 based audit (Level 2) to a public registry.
HITRUST
HITRUST maintains the HITRUST CSF, a certifiable framework that maps more than 70 standards and regulations, including HIPAA. Its e1, i1, and r2 assessments, performed by authorized external assessors, are widely requested by US health care buyers.
PCI DSS
PCI DSS sets 12 requirements for protecting payment card data, published by the PCI Security Standards Council. Version 4.0.1 is the only active version, and all of its requirements have been mandatory since March 31, 2025.
SOC 2
SOC 2 is an independent CPA report on whether a service organization's controls meet the AICPA Trust Services Criteria for security and, if chosen, availability, processing integrity, confidentiality, and privacy. Customers use it to judge vendor risk.
Swift CSP
The Swift Customer Security Programme requires every Swift user to attest each year against the Customer Security Controls Framework. CSCF v2026 has 32 controls, 26 of them mandatory, and each attestation must be backed by an independent assessment.
TISAX
TISAX is the automotive industry's system for assessing suppliers against the VDA ISA catalogue and sharing the results. Assessments by ENX-accredited audit providers produce TISAX labels that are valid for 3 years.
// 6 pages
U.S. frameworks that reach Canada
U.S. federal frameworks Canadian suppliers meet through contracts.
CMMC
CMMC is the U.S. Department of Defense program that verifies whether defence contractors protect FCI and CUI. It has 3 levels, with self-assessment, third-party C3PAO, or government assessment, and is being phased into contracts since November 10, 2025.
FedRAMP
FedRAMP is the U.S. government program that assesses and certifies cloud services for use by federal agencies. In 2026 it replaced impact levels with Certification Classes A to D and made its automated FedRAMP 20x path generally available.
HIPAA
The HIPAA Security Rule requires U.S. health organizations and their business associates to protect electronic protected health information with administrative, physical, and technical safeguards. A stricter update proposed in January 2025 is not yet final.
NIST 800-171
NIST SP 800-171 sets security requirements for protecting U.S. Controlled Unclassified Information held by contractors and other nonfederal organizations. Rev. 3 has 97 requirements in 17 families, while U.S. defence contracts and CMMC still use the 110 requirements of Rev. 2.
NIST 800-53
NIST SP 800-53 Rev. 5 is the U.S. federal catalogue of security and privacy controls, organized into 20 families. SP 800-53B selects controls into Low, Moderate, High, and privacy baselines that agencies and FedRAMP use.
NIST CSF
The NIST Cybersecurity Framework 2.0 is a voluntary, outcome-based framework that organizes cybersecurity into 6 functions, 22 categories, and 106 subcategories. Organizations use it to describe their current and target posture and plan improvements.
// 4 pages
Foreign laws with Canadian reach
EU laws that apply to Canadian organizations serving the EU.
DORA
The EU regulation on ICT risk for the financial sector, applicable since January 17, 2025. It covers risk management, incident reporting, resilience testing, and third-party risk, and puts designated ICT providers under direct EU oversight.
EU AI Act
The EU's risk-based law on artificial intelligence, applying in stages since February 2, 2025. It bans some practices, regulates high-risk systems and general-purpose AI models, and reaches Canadian providers whose AI is used in the EU.
GDPR
The EU's data protection law applies to Canadian companies that offer goods or services to people in the EU or monitor them. It requires lawful processing, data subject rights, security, 72-hour breach notice, and in many cases an EU representative.
NIS2
The EU directive that sets cybersecurity risk-management and incident reporting duties for entities in 18 sectors. Canadian firms meet it through EU customers' supply-chain demands, and some digital providers fall directly under it.