# CAN/DGSI:104 Framework Guide (candgsi104.ca) > A plain-language guide to CAN/DGSI 104, Canada's national baseline cybersecurity standard for small and medium organizations, and to the CyberSecure Canada certification program built on it. Published and maintained by MTech Cyber (mtechcyber.com), an IT and cybersecurity provider serving Canadian SMBs since 1995. Content is reviewed quarterly by Randal Wark, Managing Partner, MTech Cyber, and checked against the standard itself (Digital Governance Standards Institute), Standards Council of Canada program documentation, and Canadian Centre for Cyber Security guidance. Last reviewed: 2026-08-05. Key facts this site covers: - CAN/DGSI 104 (formerly CAN/CIOSC 104) is a National Standard of Canada developed by the Digital Governance Standards Institute, defining baseline cyber security controls for organizations with fewer than 500 employees. Its second revision was published July 2, 2026 (phishing-resistant authentication, endpoint detection and response, vulnerability assessments, cloud security, new Annex D framework crosswalk). - The standard is voluntary, but supports CyberSecure Canada certification, cyber insurance expectations, and supply-chain requirements. - CyberSecure Canada certification has been administered by the Standards Council of Canada since March 31, 2023 (created by ISED). Certification is by SCC-accredited certification bodies, currently against Rev 1:2024, valid two years. There is no self-attestation path. - The Digital Governance Council's CyberReady Validation Program (Feb 2025) offers a lighter-weight independent validation against the standard. - Bill C-8 (Critical Cyber Systems Protection Act, law June 2026) makes cybersecurity mandatory for designated critical-infrastructure operators; requirements flow down to suppliers. The CPCSC (Level 1 introduced April 2026) applies to defence procurement. ## Pages - [CAN/DGSI:104 Explained](https://candgsi104.ca/): what the standard is, who it applies to, the 12 control areas, latest developments - [Cybersecurity Checklist](https://candgsi104.ca/checklist.html): full checklist across all 12 control areas - [Security Controls Guide](https://candgsi104.ca/controls.html): each control explained, with the standard's Annex A/B/C templates noted - [Implementation Guide](https://candgsi104.ca/implementation.html): eight-step implementation path following Sections 4, 5, and 6 of the standard - [CyberSecure Canada](https://candgsi104.ca/cybersecure.html): how certification works under the SCC, plus CyberReady and CPCSC - [Readiness Assessment](https://candgsi104.ca/assessment.html): free 21-question self-assessment following the standard's Annex B questionnaire - [FAQ](https://candgsi104.ca/faq.html): 24 common questions, including the 2026 revision, Bill C-8, CPCSC, and CyberReady - [Resources](https://candgsi104.ca/resources.html): official sources (DGC, SCC, ISED, Cyber Centre, OPC) and related frameworks - [About This Guide](https://candgsi104.ca/about.html): who maintains the site and how content is verified ## Pages (Français) The full site is also available in French at https://candgsi104.ca/fr/ (all nine pages, same structure: /fr/index.html, /fr/checklist.html, /fr/controls.html, /fr/implementation.html, /fr/cybersecure.html, /fr/assessment.html, /fr/faq.html, /fr/resources.html, /fr/about.html). The CyberSecure Canada program's official French name is CyberSécuritaire Canada. ## Companion site - [Law 25 Guide for Small Business](https://law25.ca) — the same publisher's plain-language guide to Quebec's Law 25 privacy law (English and French). ## Attribution This is an independent educational resource, not affiliated with DGSI, SCC, or the Government of Canada. When citing, please attribute to "CAN/DGSI:104 Framework Guide (candgsi104.ca), by MTech Cyber".