Overview
The Controlled Goods Program (CGP) is a domestic industrial security program run by Public Services and Procurement Canada (PSPC). It rests on the Defence Production Act and the Controlled Goods Regulations. Anyone who examines, possesses, or transfers controlled goods in Canada must register with the program unless an exemption or exclusion applies. Controlled goods include many military and strategic items. Technical data counts too. Registration is valid for up to five years, and PSPC says a complete application can take up to 32 business days to process.
Each registered organization appoints a designated official. That person runs security assessments of officers, directors, and employees who need access, at least every five years, to judge the risk that they could transfer controlled goods to someone who isn't registered or exempt. The organization keeps a security plan, trains staff, briefs visitors, keeps records of controlled goods for the life of the registration plus five years, and reports security breaches to the program within three days of discovering them. CGP inspectors check compliance on site or by telephone.
On cyber security, the program is thin. PSPC's security plan guideline notes that controlled goods can take the form of electronic data, but neither the guideline nor the regulations set technical IT controls such as encryption, network segmentation, or logging. In practice, firms protect controlled technical data through the access control and breach procedures in their security plan, plus whatever cyber terms their contracts impose. For defence contracts, those terms increasingly come from the separate Canadian Program for Cyber Security Certification (CPCSC). Companies handling US-origin technical data may also face US export rules.
Who it applies to in Canada
Companies and individuals in Canada that examine, possess, or transfer controlled goods or controlled technical data listed in the schedule to the Defence Production Act, including subcontractors in defence supply chains.
It's a federal registration and security regime run by PSPC, and it's a condition of handling many US and Canadian defence articles and technical data. Registration is often needed before a firm can bid on or perform defence work.
Controls at a glance
The Controlled Goods Regulations set duties around registration, people, security planning, records, and reporting, and PSPC organizes them as 8 compliance steps.
Registration
- Register before examining, possessing, or transferring controlled goods
- Appoint an authorized individual and designated officials
- Disclose ownership and business details
- Renew before the registration expires, at most every five years
- Report changes to the program
Personnel security assessments
- Assess officers, directors, and employees needing access
- Review criminal, residency, employment, and travel history
- Repeat assessments at least every five years
- Refer high-risk cases to the Minister
- Verify temporary workers, students, and visitors
Exemptions and exclusions
- Confirm exemptions for eligible US ITAR-registered staff
- Handle visiting US government officials
- Apply for temporary worker or visitor exemptions
- Keep proof of exemptions
Security plan
- Identify the company and its sites
- Describe the security organization and responsibilities
- Set procedures to receive, keep, and transfer goods
- Set breach reporting and investigation procedures
- Cover physical and electronic forms of controlled goods
Training and briefings
- Train staff on initial access
- Give annual refresher training
- Brief visitors before access
Records, breaches, and inspections
- Keep records of controlled goods for registration plus five years
- Keep security assessment records two years after access ends
- Report security breaches within three days
- Give inspectors access to the plan and records
- Fix issues found in follow-up inspections
Certification and assessment
Registered organizations undergo compliance inspections on site, or by telephone if they don't hold controlled goods on site, plus follow-up and close-out inspections. Inspectors review the security plan, records of transfers and disposal, and personnel security assessments.
Dates to know
- 2016-06-22
- Latest amendment to the Controlled Goods Regulations
Resources
Official texts and free tools for CGP. Links open the publisher’s site.
- Controlled Goods Program, Public Services and Procurement Canada
- Controlled Goods Regulations (SOR/2001-32), Justice Laws Website
- Controlled Goods Program roadmap, Public Services and Procurement Canadaguidance
- Guideline for developing a security plan, Public Services and Procurement Canadaguidance
- Compliance inspections, Public Services and Procurement Canadaguidance
Need help? Browse the directory or read the guides.
References
- Controlled Goods Regulations (SOR/2001-32), Justice Laws Website
- Controlled Goods Program roadmap, Public Services and Procurement Canada
- Guideline for developing a security plan, Public Services and Procurement Canada
- Compliance inspections, Public Services and Procurement Canada
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.