Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

CyberSecure Canada (CAN/DGSI 104)

CyberSecure Canada is a federal cybersecurity certification programme for small and medium organizations, run by the Government of Canada. It certifies organizations against CAN/DGSI 104, a national standard of baseline cyber security controls aimed at smaller businesses. The controls are deliberately foundational, covering areas such as patching, backups, access control, and incident response.

In practice

The baseline controls are a reasonable floor for a small company that has never formalised security: multi-factor authentication, patching, backups, and a basic incident plan. Meeting them genuinely is more valuable than the badge itself.

We treat it as a stepping stone. The same evidence that satisfies the baseline feeds directly into a later SOC 2 or ISO 27001 effort, so an organization expecting to need those eventually loses nothing by starting here.

// how traztech helps

traztech delivers CyberSecure Canada certification readiness for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

CyberSecure Canada tends to come up with smaller Canadian organizations that want a recognised mark without the weight of SOC 2 or ISO 27001. It is positioned as an achievable baseline rather than an enterprise-grade attestation. We prepare companies for it as CyberSecure Canada certification readiness.

The honest framing for buyers is that it demonstrates a baseline, not a mature programme. If your customers are asking for SOC 2 or ISO 27001, the certification will not substitute for them, though the control work overlaps and is rarely wasted.

CyberSecure Canada (CAN/DGSI 104): common questions

What standard does CyberSecure Canada use?

CAN/DGSI 104, a baseline set of cyber security controls for small and medium organizations developed through the Digital Governance Standards Institute. The controls are intentionally a starting point rather than an exhaustive framework.

Is it equivalent to SOC 2 or ISO 27001?

No. It is a lighter baseline aimed at smaller organizations. It can be a sensible first step, but enterprise buyers who ask for SOC 2 or ISO 27001 will still expect those.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.