home / frameworks / controlled-goods-program

// Canadian certification programs

Controlled Goods Program

PSPC's registration and security program for organizations that handle controlled defence goods and technical data in Canada. It covers personnel security assessments, security plans, records, breach reporting, and inspections, with few cyber-specific rules.

Canada (federal)

Overview

The Controlled Goods Program (CGP) is a domestic industrial security program run by Public Services and Procurement Canada (PSPC). It rests on the Defence Production Act and the Controlled Goods Regulations. Anyone who examines, possesses, or transfers controlled goods in Canada must register with the program unless an exemption or exclusion applies. Controlled goods include many military and strategic items. Technical data counts too. Registration is valid for up to five years, and PSPC says a complete application can take up to 32 business days to process.

Each registered organization appoints a designated official. That person runs security assessments of officers, directors, and employees who need access, at least every five years, to judge the risk that they could transfer controlled goods to someone who isn't registered or exempt. The organization keeps a security plan, trains staff, briefs visitors, keeps records of controlled goods for the life of the registration plus five years, and reports security breaches to the program within three days of discovering them. CGP inspectors check compliance on site or by telephone.

On cyber security, the program is thin. PSPC's security plan guideline notes that controlled goods can take the form of electronic data, but neither the guideline nor the regulations set technical IT controls such as encryption, network segmentation, or logging. In practice, firms protect controlled technical data through the access control and breach procedures in their security plan, plus whatever cyber terms their contracts impose. For defence contracts, those terms increasingly come from the separate Canadian Program for Cyber Security Certification (CPCSC). Companies handling US-origin technical data may also face US export rules.

Who it applies to in Canada

Companies and individuals in Canada that examine, possess, or transfer controlled goods or controlled technical data listed in the schedule to the Defence Production Act, including subcontractors in defence supply chains.

It's a federal registration and security regime run by PSPC, and it's a condition of handling many US and Canadian defence articles and technical data. Registration is often needed before a firm can bid on or perform defence work.

Controls at a glance

The Controlled Goods Regulations set duties around registration, people, security planning, records, and reporting, and PSPC organizes them as 8 compliance steps.

Registration

  • Register before examining, possessing, or transferring controlled goods
  • Appoint an authorized individual and designated officials
  • Disclose ownership and business details
  • Renew before the registration expires, at most every five years
  • Report changes to the program

Personnel security assessments

  • Assess officers, directors, and employees needing access
  • Review criminal, residency, employment, and travel history
  • Repeat assessments at least every five years
  • Refer high-risk cases to the Minister
  • Verify temporary workers, students, and visitors

Exemptions and exclusions

  • Confirm exemptions for eligible US ITAR-registered staff
  • Handle visiting US government officials
  • Apply for temporary worker or visitor exemptions
  • Keep proof of exemptions

Security plan

  • Identify the company and its sites
  • Describe the security organization and responsibilities
  • Set procedures to receive, keep, and transfer goods
  • Set breach reporting and investigation procedures
  • Cover physical and electronic forms of controlled goods

Training and briefings

  • Train staff on initial access
  • Give annual refresher training
  • Brief visitors before access

Records, breaches, and inspections

  • Keep records of controlled goods for registration plus five years
  • Keep security assessment records two years after access ends
  • Report security breaches within three days
  • Give inspectors access to the plan and records
  • Fix issues found in follow-up inspections

Certification and assessment

Registered organizations undergo compliance inspections on site, or by telephone if they don't hold controlled goods on site, plus follow-up and close-out inspections. Inspectors review the security plan, records of transfers and disposal, and personnel security assessments.

Dates to know

2016-06-22
Latest amendment to the Controlled Goods Regulations

Resources

Official texts and free tools for CGP. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Controlled Goods Regulations (SOR/2001-32), Justice Laws Website
  2. Controlled Goods Program roadmap, Public Services and Procurement Canada
  3. Guideline for developing a security plan, Public Services and Procurement Canada
  4. Compliance inspections, Public Services and Procurement Canada