// frameworks

Standards and frameworks

Security standards, compliance frameworks, and laws that apply in Canada or reach Canadian organizations through customers, contracts, and foreign law. Each page explains what it requires, how it is assessed, and where to get help.

// 6 pages

Canadian privacy and cyber law

Federal and provincial laws that set privacy and security duties.

Alberta

Alberta PIPA

Alberta's Personal Information Protection Act governs how private-sector organizations in the province handle personal information. Organizations must notify the Information and Privacy Commissioner without unreasonable delay when a breach creates a real risk of significant harm.

British Columbia

BC PIPA

British Columbia's Personal Information Protection Act sets consent, access, and security rules for private-sector organizations in the province. As of October 2026 it has no mandatory breach notification, although the OIPC strongly recommends reporting breaches that pose a risk of significant harm.

Canada (federal)

CCSPA

The Critical Cyber Systems Protection Act became law on June 15, 2026 as Part 2 of Bill C-8 but is not yet in force. Once operators are designated, they will need cyber security programs, supply chain risk controls, and incident reports to CSE within 72 hours.

Ontario

PHIPA

PHIPA is Ontario's health privacy law for hospitals, clinicians, pharmacies, and other health information custodians. Custodians must notify patients of privacy breaches, report certain breaches to the IPC, and file annual breach statistics, and the IPC can impose administrative penalties.

Canada (federal)

PIPEDA

PIPEDA is Canada's federal private-sector privacy law, built on 10 fair information principles. Since November 1, 2018, organizations must report breaches that pose a real risk of significant harm to the OPC, notify the people affected, and keep a record of every breach.

Quebec

Quebec Law 25

Law 25 rewrote Quebec's private-sector privacy law in 3 phases from 2022 to 2024. Enterprises must name a person in charge of personal information, report confidentiality incidents, keep an incident register, and run privacy impact assessments, with fines of up to $25 million or 4% of turnover.

// 7 pages

Canadian sector regulators

Rules for banks, insurers, investment dealers, and energy operators.

Quebec

AMF ICT guideline

The AMF's expectations for how Quebec insurers, financial services cooperatives, and trust and deposit institutions manage technology and cyber risk. Since April 23, 2025 a separate regulation also requires incident policies, 24-hour incident reports to the AMF, and an incident register.

Canada (national self-regulatory organization)

CIRO cyber reporting

CIRO requires investment dealers to report cybersecurity incidents within 3 days of discovery and to file an investigation report within 30 days. Consolidated CIRO Rules now under consultation would extend the duty to mutual fund dealers.

Canada

CSA Z246.1

CSA Group's standard for security management programs at Canadian oil and gas facilities, covering physical and cyber security. The current CSA Z246.1:21 edition was reaffirmed in 2026, and the Canada Energy Regulator requires federally regulated pipelines to follow it.

North America (mandatory in 8 Canadian provinces through provincial law)

NERC CIP

NERC's cyber and physical security standards for the bulk electric system, from asset categorization to supply chain risk and network monitoring. They're mandatory in 8 Canadian provinces, each of which adopts and enforces them through its own regulator.

Canada (federal)

OSFI B-10

OSFI's guideline on managing risk from vendors, cloud providers, and other third parties, in effect since May 1, 2024. It sets 6 outcomes and 11 principles, and its security, audit, and incident terms flow down to suppliers of Canadian banks and insurers.

Canada (federal)

OSFI B-13

OSFI's guideline on technology and cyber risk for federally regulated banks, insurers, and trust and loan companies, in effect since January 1, 2024. It sets 17 principles in 3 domains covering governance, technology operations and resilience, and cyber security.

Canada (federal)

OSFI E-21

OSFI's guideline on operational risk and operational resilience for federally regulated financial institutions. Published August 22, 2024, it was fully in effect by September 1, 2026, with the most important operations identified, mapped, and given tolerances for disruption.

// 8 pages

International standards

ISO and IEC standards, most with third-party certification.

International

IEC 62443

The ISA/IEC 62443 series sets security requirements for industrial automation and control systems across asset owners, service providers, and product suppliers. It uses zones, conduits, and security levels, and certification is available for products, systems, and development processes.

International

ISO 22301

ISO 22301 sets requirements for a business continuity management system that helps an organization keep delivering its most important products and services during a disruption. The 2019 edition, amended in 2024, is current while ISO works on a revision.

International · Hub

ISO 27001

ISO/IEC 27001 sets the requirements for an information security management system (ISMS) that an accredited body can certify. It pairs risk-based management clauses with a reference list of 93 Annex A controls.

International

ISO 27002

ISO/IEC 27002 gives guidance for the 93 information security controls listed in ISO/IEC 27001 Annex A. Each control has a purpose, implementation guidance, and optional attributes for sorting and mapping.

International

ISO 27017

ISO/IEC 27017 adds cloud-specific guidance and extra controls to the ISO/IEC 27002 control set for cloud providers and customers. The second edition was published in July 2026 and replaces the 2015 edition.

International

ISO 27018

ISO/IEC 27018 sets out controls and guidance for public cloud providers that process personal information for their customers. The third edition, published in August 2025, aligns with ISO/IEC 27002:2022 and adds a new Annex B.

International

ISO 27701

ISO/IEC 27701 sets requirements for a privacy information management system (PIMS) for PII controllers and processors. The 2025 edition is a standalone standard, so it no longer has to be certified as an extension of ISO/IEC 27001.

International

ISO 42001

ISO/IEC 42001 sets requirements for an artificial intelligence management system (AIMS) covering the responsible development, provision, and use of AI. It pairs management system clauses with 38 reference controls and can be certified by an accredited body.

// 7 pages

Industry frameworks and attestations

Payment, cloud, health, and automotive schemes customers ask for.

International

CIS Controls

The CIS Critical Security Controls are 18 prioritized controls with 153 safeguards, sorted into 3 implementation groups. CIS also publishes the CIS Benchmarks, free secure configuration guides for common products.

International

CSA STAR

CSA STAR is the Cloud Security Alliance's assurance program for cloud providers, built on the Cloud Controls Matrix. Providers can post a self-assessment (Level 1) or add an independent SOC 2 or ISO 27001 based audit (Level 2) to a public registry.

United States (used internationally)

HITRUST

HITRUST maintains the HITRUST CSF, a certifiable framework that maps more than 70 standards and regulations, including HIPAA. Its e1, i1, and r2 assessments, performed by authorized external assessors, are widely requested by US health care buyers.

International · Hub

PCI DSS

PCI DSS sets 12 requirements for protecting payment card data, published by the PCI Security Standards Council. Version 4.0.1 is the only active version, and all of its requirements have been mandatory since March 31, 2025.

United States (used internationally, including Canada) · Hub

SOC 2

SOC 2 is an independent CPA report on whether a service organization's controls meet the AICPA Trust Services Criteria for security and, if chosen, availability, processing integrity, confidentiality, and privacy. Customers use it to judge vendor risk.

International

Swift CSP

The Swift Customer Security Programme requires every Swift user to attest each year against the Customer Security Controls Framework. CSCF v2026 has 32 controls, 26 of them mandatory, and each attestation must be backed by an independent assessment.

International (German automotive industry)

TISAX

TISAX is the automotive industry's system for assessing suppliers against the VDA ISA catalogue and sharing the results. Assessments by ENX-accredited audit providers produce TISAX labels that are valid for 3 years.

// 6 pages

U.S. frameworks that reach Canada

U.S. federal frameworks Canadian suppliers meet through contracts.

United States · Hub

CMMC

CMMC is the U.S. Department of Defense program that verifies whether defence contractors protect FCI and CUI. It has 3 levels, with self-assessment, third-party C3PAO, or government assessment, and is being phased into contracts since November 10, 2025.

United States

FedRAMP

FedRAMP is the U.S. government program that assesses and certifies cloud services for use by federal agencies. In 2026 it replaced impact levels with Certification Classes A to D and made its automated FedRAMP 20x path generally available.

United States

HIPAA

The HIPAA Security Rule requires U.S. health organizations and their business associates to protect electronic protected health information with administrative, physical, and technical safeguards. A stricter update proposed in January 2025 is not yet final.

United States

NIST 800-171

NIST SP 800-171 sets security requirements for protecting U.S. Controlled Unclassified Information held by contractors and other nonfederal organizations. Rev. 3 has 97 requirements in 17 families, while U.S. defence contracts and CMMC still use the 110 requirements of Rev. 2.

United States (used internationally)

NIST 800-53

NIST SP 800-53 Rev. 5 is the U.S. federal catalogue of security and privacy controls, organized into 20 families. SP 800-53B selects controls into Low, Moderate, High, and privacy baselines that agencies and FedRAMP use.

United States (used internationally) · Hub

NIST CSF

The NIST Cybersecurity Framework 2.0 is a voluntary, outcome-based framework that organizes cybersecurity into 6 functions, 22 categories, and 106 subcategories. Organizations use it to describe their current and target posture and plan improvements.