home / frameworks / cybersecure-canada

// Canadian certification programs

CyberSecure Canada certification and CAN/DGSI 104

A voluntary Canadian certification for small and medium organizations against the national baseline cyber security standard, CAN/DGSI 104. ISED left the program in 2023, and SCC-accredited certification bodies still certify.

CanadaVoluntary

Overview

CyberSecure Canada was created by Innovation, Science and Economic Development Canada (ISED) as a voluntary certification for small and medium organizations. Its goal was to raise the cyber security baseline of Canadian businesses with fewer than 500 employees and give customers a recognizable mark. Nobody has to hold it. Certification is against a National Standard of Canada, Baseline cyber security controls for small and medium organizations, first published as CAN/CIOSC 104:2021. The CIO Strategy Council has since become the Digital Governance Council, and the standard now carries the designation CAN/DGSI 104:2021 / Rev 1:2024.

The program changed hands in 2023. ISED says that as of March 31, 2023, it's no longer the program authority for CyberSecure Canada, and it sends readers to the Standards Council of Canada (SCC) for current information. SCC still runs a CyberSecure Canada accreditation program for certification bodies, based on ISO/IEC 17021-1. It withdrew its separate CyberSecure Canada requirements and guidance document on June 13, 2025, as redundant after updates to the standard. So the scheme still exists. It's smaller and less visible than it was under ISED, and organizations should confirm a certification body's accreditation in the SCC directory before engaging one.

The Digital Governance Standards Institute maintains the standard and offers it free. Its product page lists Edition 1.1, first published in 2021, reaffirmed in 2024, with revisions scheduled for 2026. The 2024 revision clarified the split between Level 1 requirements for smaller organizations and Level 2 requirements for more mature ones. The Digital Governance Council also runs its own CyberReady validation program, which is separate from SCC-accredited certification. Defence suppliers also have CPCSC to consider.

Who it applies to in Canada

Small and medium organizations in Canada, generally those with fewer than 500 employees, that want independent certification of a baseline set of cyber security controls.

It's a made-in-Canada certification built on a National Standard of Canada and on the Cyber Centre's baseline controls. Some Canadian buyers and supply chains accept it as evidence of basic cyber hygiene for smaller suppliers.

Controls at a glance

CAN/DGSI 104 starts with organizational controls on scope, risk, and leadership, then sets technical and process controls that grew out of the Cyber Centre's 13 baseline controls, with Level 1 and Level 2 tiers.

Organizational controls

  • Define which systems and sites are in scope
  • Assess potential harm to information and systems
  • Identify the main threats the organization faces
  • Name someone responsible for cyber security
  • Commit to ongoing improvement

Incident response and recovery

  • Keep an incident response plan
  • Include recovery procedures
  • Back up important data
  • Encrypt backups and keep copies offsite

Patching and malware protection

  • Turn on automatic updates where possible
  • Patch operating systems and applications promptly
  • Run up-to-date anti-malware on devices
  • Use host firewalls

Secure configuration and authentication

  • Change default passwords and settings
  • Disable unneeded features and services
  • Use strong passwords or passphrases
  • Use multi-factor authentication for important accounts

People and training

  • Give staff cyber security awareness training
  • Cover phishing and social engineering
  • Match training depth to the chosen level

Devices, network, and access

  • Secure mobile devices used for work
  • Protect the network perimeter and Wi-Fi
  • Grant users only the access they need
  • Control portable media

Cloud, outsourced IT, and websites

  • Choose cloud providers with security attestations
  • Use secure cloud services
  • Secure public-facing websites

Certification and assessment

The organization implements the CAN/DGSI 104 controls for its chosen level and scope, then a certification body accredited by SCC under ISO/IEC 17021-1 audits it and issues the certificate. Check the SCC directory of accredited organizations to confirm a body's current accreditation.

Dates to know

2023-03-31
ISED ceases to be program authority for CyberSecure Canada
2025-06-13
SCC withdraws its CyberSecure Canada requirements and guidance document as redundant

Resources

Official texts and free tools for CyberSecure Canada. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. CyberSecure Canada, Innovation, Science and Economic Development Canada
  2. CAN/DGSI 104, Baseline cyber security controls for small and medium organizations, Digital Governance Council
  3. Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Security