Common questions about CAN/DGSI:104, CyberSecure Canada, and implementing cybersecurity controls in Canadian businesses.
CAN/DGSI:104 is a Canadian cybersecurity framework that outlines baseline security controls organizations should implement to protect systems and business data from cyber threats. It provides practical guidance for improving cybersecurity without requiring enterprise-level resources.
The framework focuses on foundational protections such as identity security, device protection, employee awareness training, system monitoring, and incident response planning.
CAN/DGSI:104 was developed by the Digital Governance Standards Institute (DGSI) through its Technical Committee 5 (TC 5) on Cyber Security, which brought together more than 170 experts in cybersecurity and related fields. The standard was approved by the Standards Council of Canada (SCC), the body that designates National Standards of Canada, and DGSI is an SCC-accredited standards development organization.
The framework is designed primarily for small and medium organizations operating in Canada. It is particularly useful for businesses that rely on digital systems and store customer or operational data.
Organizations in sectors such as professional services, healthcare, manufacturing, construction, retail, and technology often benefit from implementing the framework.
CAN/DGSI:104 aligns with many widely recognized cybersecurity frameworks but is designed to be more practical for smaller organizations.
| Framework | Primary Purpose | Typical Organizations | Complexity |
|---|---|---|---|
| CAN/DGSI:104 | Baseline cybersecurity controls | Small and medium businesses in Canada | Low to Moderate |
| CyberSecure Canada | Certification based on CAN/DGSI:104 | Canadian organizations seeking recognized certification | Moderate |
| NIST CSF | Risk management framework | Government agencies and larger enterprises | Moderate to High |
| ISO 27001 | International information security standard | Global enterprises and regulated industries | High |
CAN/DGSI:104 focuses on the most critical controls that organizations should implement to protect themselves from common threats. It emphasizes practical implementation rather than extensive documentation or complex governance structures.
Many organizations begin with a baseline framework such as CAN/DGSI:104 and expand their cybersecurity program over time. More advanced organizations may align their security practices with additional frameworks such as ISO 27001 or the NIST Cybersecurity Framework.
However, implementing foundational cybersecurity controls is often the most important first step for improving an organization's security posture. Starting with CAN/DGSI:104 gives organizations a practical, achievable baseline before progressing to more complex frameworks.
CAN/DGSI:104 represents a baseline level of cybersecurity protection. The framework focuses on foundational controls that significantly reduce cyber risk for most organizations.
It is designed to address common threats such as phishing attacks, ransomware, credential theft, and malware infections. While the framework improves cybersecurity maturity, it is not intended to replace more comprehensive enterprise frameworks such as ISO 27001 or NIST for organizations that require advanced protection.
The Digital Governance Standards Institute published the second revision of CAN/DGSI 104 on July 2, 2026. It refines terminology and strengthens several requirements, including phishing-resistant authentication, endpoint detection and response, vulnerability assessments, and cloud service security, and adds a new Annex D that maps the standard to other cybersecurity frameworks. The overall structure is unchanged: the same control sections and the Annex A, B, and C templates carry forward.
CyberSecure Canada certification is currently assessed against the previous revision (Rev 1:2024). If you are pursuing certification, confirm with your certification body which revision applies.
CAN/DGSI:104 itself is not a mandatory regulation. However, many organizations adopt the framework voluntarily to improve cybersecurity practices and support the CyberSecure Canada certification program.
Implementing these controls can also help organizations meet expectations from customers, partners, and insurers, making adoption increasingly common even without a formal regulatory requirement.
No. Organizations can use the framework to improve their cybersecurity practices even if they do not pursue formal certification. Many businesses adopt the controls simply to reduce cyber risk and strengthen their security posture.
Certification through CyberSecure Canada is optional and adds external validation and market recognition to an organization's security investments.
CAN/DGSI:104 and ISO 27001 both focus on improving cybersecurity, but they serve different purposes and audiences.
CAN/DGSI:104 provides a practical set of baseline security controls designed for small and medium organizations. It is focused on implementation and achievable by most businesses without specialized cybersecurity expertise.
ISO 27001 is an international information security management standard that requires formal governance processes, extensive documentation, and certification audits. It is typically adopted by larger organizations that need globally recognized certification or operate in regulated industries.
Organizations often use CAN/DGSI:104 as a starting point before potentially progressing to ISO 27001 as their security program matures.
For some organizations, yes. Bill C-8, the Critical Cyber Systems Protection Act, became law in June 2026. It imposes mandatory cybersecurity programs, incident reporting, and compliance obligations on designated operators in federally regulated sectors such as telecommunications, finance, energy, and transportation.
Most small businesses are not directly covered. Designated operators are expected to push security requirements down to their suppliers, though, so if you sell into these sectors, implementing CAN/DGSI:104 is a practical way to get ahead of those flow-down requirements.
The Canadian Program for Cyber Security Certification (CPCSC) is Canada's cybersecurity certification for defence procurement, comparable to the American CMMC program. Level 1 was introduced in April 2026, and certification requirements will progressively appear in defence contracts.
If your business sells into defence supply chains, directly or as a subcontractor, expect cybersecurity certification to become a condition of bidding. The Digital Governance Council also offers a CyberDefence Ready program to help defence-industrial and dual-use companies prepare, and the CAN/DGSI:104 controls are a strong foundation for it.
CyberReady is a validation program launched by the Digital Governance Council in February 2025. An independent reviewer evaluates your cybersecurity practices against CAN/DGSI:104 and issues a statement of validation.
It is a lighter-weight option than full CyberSecure Canada certification, and a good way to demonstrate progress to clients and insurers or to prepare for certification later.
Implementation timelines vary depending on the organization's existing cybersecurity practices and the number of gaps that need to be addressed.
Many organizations can establish foundational protections within a few months by focusing on key controls such as identity protection, device security, employee training, backup procedures, and system monitoring. More advanced controls may take additional time as security programs mature.
A typical implementation roadmap often looks like this:
The framework defines two levels of cybersecurity maturity:
Level 1: Foundational focuses on essential security practices. These controls are intended for organizations that are building their cybersecurity program or formalizing existing practices. Level 1 establishes essential protections such as patch management, employee training, backups, and basic access controls.
Level 2: Advanced builds on this foundation with more sophisticated security practices. These controls typically involve stronger monitoring, more formal security processes, and greater visibility into systems and activity across the environment.
Many organizations begin with Level 1 and expand toward Level 2 as their cybersecurity capabilities mature over time.
While all controls contribute to overall security, several protections significantly reduce risk and should be prioritized:
No. CAN/DGSI:104 was specifically designed so organizations can implement practical cybersecurity protections without needing a large internal security team.
Many businesses rely on a combination of internal IT staff, managed security services providers (MSPs), and security tools to implement the recommended controls. Managed detection and response (MDR) services can provide 24/7 security monitoring without requiring in-house expertise.
Small businesses are increasingly targeted by cybercriminals because they often lack strong security protections relative to larger organizations. Attackers know that smaller organizations may have fewer defences while still holding valuable data: customer records, financial information, and operational systems.
Cyber incidents can lead to operational disruption, financial loss, and exposure of sensitive information. Implementing baseline cybersecurity controls helps reduce these risks and improves an organization's ability to respond if an incident occurs.
Common threats that target Canadian businesses include:
These attacks frequently target user accounts, email systems, and vulnerable devices, all areas addressed by the CAN/DGSI:104 controls.
Ransomware attacks often succeed because organizations lack basic cybersecurity protections. CAN/DGSI:104 helps reduce ransomware risk by promoting controls such as:
A good starting point is evaluating your current cybersecurity protections. A readiness assessment can help identify which controls are already implemented and where improvements may be needed.
From there, organizations typically focus on strengthening identity security (MFA), protecting devices (endpoint security), improving email protection, and implementing reliable backups, as these controls address the most common attack methods used against businesses today.
Take the Free Readiness AssessmentOrganizations can measure their readiness by evaluating how well their existing practices align with the controls outlined in CAN/DGSI:104. Common approaches include:
Yes. The framework was specifically designed with small and medium organizations in mind. Rather than requiring complex enterprise security programs, CAN/DGSI:104 focuses on practical controls that most businesses can implement using existing IT tools and security services.
Many organizations already have some of these protections in place and only need to strengthen specific areas such as identity security, monitoring, or incident response planning.
Organizations that lack basic cybersecurity protections face significantly increased risk of cyber incidents such as ransomware attacks, data breaches, and operational disruption.
Cyber incidents can result in:
Implementing baseline cybersecurity controls helps reduce these risks and improves the organization's ability to respond and recover if an incident does occur.
Start with our free readiness assessment to understand your organization's cybersecurity posture, or explore our detailed guides for more information.