Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

CyberSecure Canada Certification: Level 1 vs Level 2, the 2026 Revision and How to Prepare

Direct answer: CyberSecure Canada is the federal certification for small and medium Canadian organizations, audited against the national baseline standard, CAN/DGSI 104. You pick Level 1 or Level 2, prepare your controls and evidence, and an accredited certification body under the Standards Council of Canada programme audits you and issues the certificate, which is valid for two years. Most of the cost and effort sits in readiness, not in the audit fee.

What CyberSecure Canada actually is

The programme was launched by Innovation, Science and Economic Development Canada in 2019 as a voluntary certification aimed at small and medium organizations. The government information sheet describes the shape that still holds: you implement a defined set of baseline security controls, work with a certification body accredited by the Standards Council of Canada (SCC), get audited, and receive a certificate valid for two years along with the CyberSecure Canada mark you can display. The SCC now administers the programme and accredits the certification bodies that do the audits.

The standard behind it is CAN/DGSI 104, Baseline Cyber Security Controls for Small and Medium Organizations, published by the Digital Governance Standards Institute. It grew out of the Canadian Centre for Cyber Security baseline controls, which is why buyers still talk about "the 13 controls". The current standard is organized differently from that list, and it is worth understanding the difference before you start, because the audit is against the standard, not against the marketing summary.

It was written for organizations below enterprise scale. The Cyber Centre baseline it descends from was written for organizations with fewer than 499 employees, and the controls assume a business that runs on a small IT team or a managed service provider rather than a security department.

Who asks for it, and why

There is no general federal procurement rule that requires CyberSecure Canada certification. Demand is buyer driven. It shows up in supplier questionnaires from larger Canadian companies, public sector and municipal buyers, insurers, and supply chains where a prime contractor wants evidence that its smaller suppliers have done the basics. It is also a credible first certification for a company that is not yet ready for ISO 27001 or a SOC 2 report, because the scope is narrower and the controls are concrete.

Before you start, ask the buyer who raised it what they will accept. Some want the certificate specifically. Some will take a SOC 2 report or an ISO 27001 certificate in its place. Some only want to see that a baseline exists. The answer decides whether this is the right certification for you or a stepping stone to a different one.

How the standard is organized

CAN/DGSI 104 groups its requirements into three parts. Our clause-level summary, in our own words:

  • Organizational controls (clause 4). Leadership commits to the programme (4.1), a named senior leader is accountable (4.2), employees are trained (4.3), and a cyber security risk assessment is carried out (4.4).
  • Baseline controls (clause 5). An incident response plan (5.1), patching (5.2), security software (5.3), secure configuration (5.4), strong authentication (5.5), backup and encryption (5.6), perimeter defences (5.7) and access control (5.8).
  • Controls for your operating environment (clause 6). Mobility (6.1), cloud and outsourced IT (6.2), websites (6.3), portable media (6.4), point of sale and financial systems (6.5), and log management (6.6). These apply where the environment exists. A company with no card terminals does not build a payment control.

Within each clause, requirements are tagged Level 1 or Level 2. That structure is what the certification body walks through, so it is also the structure your evidence should follow.

Level 1 vs Level 2

Level 1 is the floor every certified organization meets. In practice it means a signed policy and a named accountable leader, onboarding and annual training with completion records, a completed risk assessment, a written and tested incident response plan with a hard copy, automatic patching with documented exceptions, anti-malware on every device, secure device configuration, multi-factor authentication and a clear password rule, offsite and tested backups, firewalls and secured Wi-Fi, least-privilege access with separate admin accounts, and the environment controls that apply to you.

Level 2 adds the controls a more mature programme runs. The ones that change the work most, in our reading:

  • A formal risk process: an asset register, documented exclusions, risk acceptance signed by the accountable leader, recorded security spending and staffing, and an annual review of the controls.
  • Regular vulnerability assessments, not only patching.
  • Endpoint detection and response rather than anti-malware alone.
  • A company password manager and phishing-resistant authentication, such as security keys or passkeys, for administrator accounts.
  • Layered network protection: DNS filtering, host firewalls, VPN with MFA, segmentation, and authenticated and filtered email.
  • Centralized authentication, managed mobile devices, formal assessment of cloud and outsourced providers with independent assurance on file, website risks fixed against a defined verification level, and a log management policy.

Pick the level your buyers expect, not the one that sounds better. If nobody has asked for Level 2, Level 1 earned honestly is a stronger position than Level 2 attempted on a team that cannot yet run EDR or a vulnerability programme.

Not sure how far off you are? Answer the readiness checker against each clause at Level 1 or Level 2 and see where the gaps sit before you talk to anyone. CyberSecure Canada readiness checker

What changed in the 2026 revision

The standard has been revised twice since the 2021 edition. The first revision, published in December 2024, clarified the line between Level 1 and Level 2 in areas such as training, risk assessment, incident response, secure configuration, backups and cloud. The second revision was announced by the Digital Governance Council on 2 July 2026. The publicly announced changes include clearer Level 1 and Level 2 expectations for patching, security software, authentication, perimeter and cloud, a new informative annex on evaluating outsourced providers, and guidance on phishing-resistant authentication, EDR and XDR, vulnerability assessments, AI-enabled social engineering and cloud provider assurance.

For a company preparing now, the practical effects are these. Training has to cover AI-enabled impersonation, such as deepfake voice or synthetic email used for payment fraud. Level 2 expects EDR, regular vulnerability assessments and phishing-resistant admin authentication. Supplier assurance at Level 2 is stronger, so a register of important providers with their SOC 2 reports or certificates on file is now part of the job.

One caution. Certification bodies move to a new revision on their own schedule, and we could not find a published transition date. Ask your certification body which revision it will audit you against before you finalize scope. Preparing to the newer revision is rarely wasted, because its additions are controls a buyer will ask about anyway.

Free weekly email

Get The Compliance Brief every Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Who certifies you

Only a certification body accredited by the SCC for this programme can issue the certificate. We are not one, and no readiness firm should be both your preparer and your certifier on the same engagement. The SCC publishes its directory of accredited organizations, and that is the place to confirm a body's accreditation before you sign anything.

Certification bodies describe the process in broadly similar terms: an application and estimate, a first stage that reviews your documentation and evidence, a second stage that confirms the controls operate, corrective actions where needed, then a certification decision. The assessment is weighted towards documents and records, with interviews where the assessor needs clarification. That is why evidence quality decides most outcomes.

Questions worth asking any certification body: which revision of the standard do you audit against today; is the second stage remote, on site or either; what happens if you find a nonconformity, and how long do we have to correct it; what does recertification at two years involve; and do you or a related company also sell readiness or remediation services.

What drives the cost

There are two separate costs, and they are usually confused. The certification body charges for the audit. Readiness, which means building and evidencing the controls, is the larger cost for almost every organization, and it is driven by what you have today rather than by your headcount alone.

The drivers we see:

  • Level. Level 2 roughly doubles the number of things to evidence and adds tooling such as EDR and a vulnerability scanner.
  • Environment controls in scope. Websites, mobile devices, card terminals and outsourced IT each add a clause.
  • Starting point. A company that already has MFA everywhere, managed devices and backups it has restored from has a short list. One with shared admin accounts and no written incident plan has a long one.
  • Who runs IT. If a managed service provider operates your environment, much of the evidence lives in their tools, and their cooperation sets the pace.
  • Tests that must actually happen. An incident response exercise and a backup restore are both required, and both take a calendar slot with the right people in the room.

Our Phase 1 gap analysis for CyberSecure Canada is from $2,500. It assesses every clause at the level you choose and produces a ranked findings register. Remediation is scoped and priced from those findings, because nobody can honestly price the fixes before the gaps are known.

How to prepare

  1. Confirm the target. Which level, which revision, and whether the buyer who asked will accept it.
  2. Appoint the accountable leader in writing and get a short policy signed. Almost every other requirement points back to this person.
  3. Run the risk assessment honestly. The standard includes a risk questionnaire. Each "no" becomes a remediation item.
  4. Close the high-effort technical gaps first: MFA everywhere, separate admin accounts, managed patching, offsite and protected backups. These take longest to roll out and to show working.
  5. Write and test the incident response plan. A tabletop with the people named in the plan, with a record of what happened and what you changed.
  6. Restore from backup and keep the record. An untested backup is a claim, not evidence.
  7. Collect evidence clause by clause, each item dated and owned, in the order the certification body will review it.
  8. Book the certification body once the evidence exists, not before. Booking first creates a deadline without a plan.

How long this takes depends on what the gap analysis finds and on the certification body's schedule. A company with most of the technical controls in place mostly has documentation and testing to do. A company starting from shared passwords has a rollout to run first. After Phase 1 we give you a plan with a realistic range rather than a date we cannot control.

If you are a defence supplier, the CPCSC Level 1 self-assessment overlaps heavily with this work. We cover that separately in CPCSC Level 1 for defence suppliers.

Frequently asked questions

Is CyberSecure Canada the same as ISO 27001?

No. ISO 27001 certifies a management system you design around your own risks, with a broader scope and a heavier audit. CyberSecure Canada certifies a fixed baseline of controls for smaller organizations. The two overlap, and work done for one carries into the other, but a buyer who asked for ISO 27001 will not usually accept CyberSecure Canada in its place.

How long is the certificate valid?

Two years, after which you recertify. Treat the controls as continuous rather than as a project, because the recertification looks at whether they kept operating.

Can our managed service provider handle it?

Your provider can operate many of the controls and supply much of the evidence. Accountability stays with your organization, and the standard requires a named senior leader inside it. Ask your provider early what evidence they can export, because that often sets the pace.

Do we need Level 2?

Only if a buyer, insurer or contract asks for it, or your risk assessment says the Level 2 controls are warranted. Most organizations start at Level 1.

Preparing for CyberSecure Canada? We run the Phase 1 gap analysis against every clause at your level, then prepare you for the accredited certification body.

CyberSecure Canada readinessOr check your readiness first

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.