A plain-language guide to every requirement in Canada's national cybersecurity standard for small and medium organizations; organized by section with Level 1 and Level 2 requirements clearly explained.
Level 1: Foundational. Requirements every organization should implement first. No large IT team required.
Level 2: Advanced. Builds on Level 1. Intended for organizations growing their cybersecurity program. You must complete Level 1 before Level 2.
CAN/DGSI:104 organizes its requirements into three layers: organizational controls that set the foundation, baseline technical controls every organization should implement, and environment-specific controls that apply depending on how your business operates.
Requirements are split into two maturity levels. You don't have to do everything at once. Level 1 gets you started, and Level 2 builds on that as your program matures.
Before any technical controls can work, the organization needs the right structure in place. These four requirements establish who is responsible, what training is needed, and how risk is understood.
These are the fundamental protections the standard requires regardless of your industry or size. Think of them as the floor, not the ceiling.
These controls apply depending on your organization's environment. If you use mobile devices, run a website, accept payments, store data in the cloud, or use USB drives; these sections apply to you. Many small businesses will need several of these.
Many organizations already have some of these protections in place but may still have gaps. A cybersecurity assessment can help identify which controls are already implemented and where improvements are needed.
Assess Your CAN/DGSI:104 ReadinessNeed help implementing these controls? MTech Cyber specializes in CAN/DGSI:104 implementation for Canadian SMBs.
Take our free CAN/DGSI:104 Readiness Assessment and receive a personalized report on which controls you have in place and where improvements are needed.