Official sources, guides, and tools to support your CAN/DGSI:104 implementation and cybersecurity program.
Use these resources to understand the framework, assess your readiness, and begin implementing the controls.
A complete introduction to CAN/DGSI:104: what it is, who it applies to, the protection model, and all controls and requirements explained.
Read OverviewAn interactive checklist covering all CAN/DGSI:104 control areas. Check items off to track your progress and identify gaps. Also available as a fillable PDF.
A structured questionnaire for assessing the cybersecurity posture of your third-party vendors and suppliers against CAN/DGSI:104 controls.
⬇ Download PDFPlain-language explanations of every CAN/DGSI:104 control: risks addressed, key practices, and how organizations implement each one.
View ControlsStep-by-step guidance for implementing CAN/DGSI:104, including a typical implementation timeline and common challenges.
Read GuideA free 21-question self-assessment aligned with the official Annex B of CAN/DGSI:104. Receive a personalized score and recommendations.
Take AssessmentAn overview of the Government of Canada's national cybersecurity certification program and how it relates to CAN/DGSI:104.
Learn MoreThe authoritative sources for CAN/DGSI:104, CyberSecure Canada, and Canadian cybersecurity guidance.
The Digital Governance Council (DGC) is the standards body responsible for CAN/DGSI:104. The DGC developed the framework in collaboration with Canadian cybersecurity experts and industry stakeholders.
Visit Digital Governance Council ↗The CyberSecure Canada information page hosted by Innovation, Science and Economic Development Canada (ISED). Since March 2023 the program itself has been administered by the Standards Council of Canada; this page explains the program and directs new applicants to the SCC.
Visit CyberSecure Canada ↗The SCC has administered CyberSecure Canada certification since March 2023 and accredits the certification bodies that assess organizations against CAN/DGSI:104.
Visit SCC Program Page ↗An independent validation of your cybersecurity practices against CAN/DGSI:104, launched in February 2025. A lighter-weight alternative to full certification and a practical readiness step.
Learn About CyberReady ↗Canada's cybersecurity certification for defence suppliers. Level 1 was introduced in April 2026 and requirements will progressively appear in defence contracts.
Visit CPCSC Overview ↗Canada's national technical authority on cybersecurity. The CCCS provides threat intelligence, guidance, and resources to help Canadian organizations protect themselves from cyber threats.
Visit Cyber Centre ↗Guidance on Canadian privacy laws including PIPEDA (Personal Information Protection and Electronic Documents Act) and how cybersecurity relates to privacy obligations for Canadian businesses.
Visit OPC ↗Doing business in Quebec? Cybersecurity and privacy compliance go hand in hand. Our companion guide explains Law 25, Quebec's privacy law, in the same plain language: obligations, penalties, a checklist, and a free self-assessment.
Visit law25.ca ↗Other widely referenced cybersecurity frameworks and standards that organizations may encounter as their security programs mature.
| Framework | Developed By | Focus | Best Suited For |
|---|---|---|---|
| CAN/DGSI:104 | Digital Governance Council (Canada) | Baseline cybersecurity controls for SMBs | Canadian small and medium businesses |
| NIST Cybersecurity Framework (CSF) | NIST (United States) | Risk-based cybersecurity management | Government agencies and larger enterprises |
| ISO/IEC 27001 | ISO / IEC | Information security management system | Enterprises seeking international certification |
| SOC 2 | AICPA (United States) | Service organization controls for data handling | Technology companies and service providers |
| CIS Controls | Center for Internet Security | Prioritized security controls and best practices | Organizations of all sizes seeking actionable guidance |
Note: Many organizations begin with CAN/DGSI:104 as a practical baseline and expand their program over time toward more comprehensive frameworks. Starting with foundational controls is the most impactful first step for most small and medium businesses.
The CCCS publishes free, practical cybersecurity guidance for Canadian organizations. Key publications relevant to CAN/DGSI:104 include:
The CCCS's prioritized list of security actions that organizations should implement to protect against common cyber threats. Closely aligned with many CAN/DGSI:104 controls.
Read Guidance ↗Guidance for Canadian organizations on preventing, responding to, and recovering from ransomware attacks, one of the most significant threats facing businesses today.
Read Playbook ↗CCCS guidance specifically designed for small and medium organizations on establishing a cybersecurity baseline, complementary to the CAN/DGSI:104 framework.
Read Baseline ↗Implementing cybersecurity controls can be challenging without the right expertise. These resources can help.
Managed security services providers (MSPs) offer ongoing security monitoring, endpoint protection, email security, and other services aligned with CAN/DGSI:104 controls, without requiring an in-house security team.
A professional gap assessment evaluates your current controls against the CAN/DGSI:104 framework and provides a prioritized remediation roadmap tailored to your organization.
Employee training platforms provide cybersecurity awareness courses and phishing simulations to address one of the most critical and most human control areas in the framework.
MTech Cyber specializes in helping Canadian small and medium businesses implement cybersecurity controls aligned with the CAN/DGSI:104 framework. Services include managed security, endpoint protection, email security, 24/7 SOC monitoring, and employee awareness training.
Visit MTech Cyber ↗Before diving into implementation, understand where your organization stands today. Our free 21-question assessment evaluates your practices against the CAN/DGSI:104 framework and provides personalized recommendations.