CyberSecure Canada

Canada's national cybersecurity certification program, helping organizations demonstrate that they have implemented recognized security practices to protect systems, data, and operations.

Program Overview

What is CyberSecure Canada?

CyberSecure Canada is a national cybersecurity certification program supported by the Government of Canada. The program allows organizations to demonstrate that they have implemented recognized cybersecurity practices designed to protect their systems, data, and operations.

The certification is intended primarily for small and medium organizations that want to strengthen their cybersecurity posture and demonstrate responsible security practices to customers, partners, and suppliers.

Organizations that achieve certification can show that they meet a recognized baseline for cybersecurity protection.

🇨🇦

Government of Canada Supported

CyberSecure Canada is backed by Innovation, Science and Economic Development Canada (ISED) and helps Canadian businesses demonstrate cybersecurity readiness to customers, partners, and insurers.

Official Program Website ↗
Framework vs. Certification

CAN/DGSI:104 vs CyberSecure Canada

Understanding the relationship between the framework and the certification program.

📋

CAN/DGSI:104

The cybersecurity framework that defines the technical controls organizations should implement to protect their systems and data.

  • Defines cybersecurity requirements
  • 12 mandatory core controls (Sections 4 & 5), plus up to 6 environment-specific controls depending on how your organization operates
  • Practical and accessible for SMBs
  • Can be used without certification

Leads to

🏅

CyberSecure Canada

The certification program that allows organizations to demonstrate they have implemented the controls outlined in CAN/DGSI:104.

  • Recognized national certification
  • Assessed by accredited body
  • Demonstrates compliance publicly
  • Requires periodic reassessment

In simple terms: CAN/DGSI:104 defines what to implement. CyberSecure Canada is the certification that proves you've implemented it.

Who It's For

Who Should Get CyberSecure Canada Certification?

Certification is designed primarily for small and medium organizations that want to demonstrate strong cybersecurity practices.

🏢

Businesses Storing Sensitive Data

Companies that store customer data, financial records, or sensitive operational information benefit from demonstrating they protect that data responsibly.

🤝

Enterprise & Government Suppliers

Organizations working with larger enterprise clients or government organizations that require supply chain cybersecurity assurances.

🔗

Supply Chain Participants

Companies that must meet supply chain cybersecurity expectations from clients, procurement requirements, or industry standards.

💼

Service Providers

Organizations responsible for protecting client information: MSPs, professional services firms, and technology providers.

🛡️

Trust-Focused Organizations

Businesses that want to demonstrate a commitment to cybersecurity best practices and build trust with customers and partners.

📄

Insurance-Driven Organizations

Companies seeking to strengthen cyber insurance eligibility or demonstrate cybersecurity maturity to underwriters.

Even organizations that do not pursue certification can benefit from implementing the controls recommended in the framework to reduce cybersecurity risk. Certification adds external validation and market recognition to your security investments.

Business Value

Why Organizations Pursue Certification

Many organizations choose to pursue CyberSecure Canada certification to strengthen trust and demonstrate that they take cybersecurity seriously.

  • Demonstrating responsible cybersecurity practices to customers
  • Meeting cybersecurity expectations from larger clients or supply chain partners
  • Strengthening internal cybersecurity policies and procedures
  • Supporting cyber insurance requirements and eligibility
  • Reducing risk from common cyber threats
  • Formalizing security practices that already exist within the business

Is Certification Required?

CyberSecure Canada certification is voluntary. Organizations are not required to obtain certification in order to implement the cybersecurity controls outlined in CAN/DGSI:104.

Many businesses adopt these controls simply to improve their cybersecurity posture and reduce risk from cyber threats.

However, certification can provide additional assurance to customers, partners, and stakeholders that the organization follows recognized cybersecurity practices.

Certification Process

How CyberSecure Canada Certification Works

Organizations typically follow several steps to obtain CyberSecure Canada certification.

1

Implement the Required Security Controls

Organizations first implement the cybersecurity controls defined in the CAN/DGSI:104 framework. These controls focus on foundational protections such as:

  • Identity security and multi-factor authentication
  • Device protection and patch management
  • Email security and phishing protection
  • Security monitoring and threat detection
  • Employee awareness training
  • Incident response planning
View Implementation Guide

MTech Cyber can help you implement these controls as part of a managed cybersecurity program.

2

Choose Your Certification Path

Once the required controls are in place, organizations can pursue certification through one of two paths:

  • Self-attestation: For the foundational certification level, organizations can self-declare that they have implemented the required controls. This is the lighter-weight entry point into the program.
  • Third-party assessment: For a verified certification, organizations work with an accredited certification body authorized to conduct CyberSecure Canada assessments. The assessor reviews documentation and evaluates whether controls have been properly implemented.
3

Receive Certification

If the organization meets the certification requirements, it receives CyberSecure Canada certification. Certified organizations may promote their certification status to:

  • Demonstrate commitment to cybersecurity best practices
  • Signal trustworthiness to customers and partners
  • Support tender responses and supply chain requirements

Certification must be maintained through periodic reassessment to ensure that cybersecurity practices remain effective as threats evolve.

First Step

Getting Started

Organizations interested in improving their cybersecurity posture often begin by evaluating their existing security controls and identifying areas where improvements may be needed.

A cybersecurity readiness assessment can help determine how closely an organization's current practices align with the controls outlined in CAN/DGSI:104.

Once gaps are identified, organizations can develop a prioritized implementation plan to address the most important risks first, laying the groundwork for eventual CyberSecure Canada certification if desired.

Assess Your CAN/DGSI:104 Readiness

Review the Checklist

Evaluate your controls against the full CAN/DGSI:104 checklist.

🛡️

Explore the Controls

Understand what each control requires across all sections of the framework.

📋

Follow the Implementation Guide

Step-by-step guidance for implementing the framework.