Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

CyberSecure Canada Readiness Checker

Go through each CAN/DGSI 104 requirement and mark where you stand. You get your status by clause group, whether you are closer to Level 1 or Level 2, and the gaps to close before the audit.

Where do you stand on each requirement?

Answer for how things are today. Requirements in clause 6 only apply if you have that environment (mobile work, cloud providers, a website, portable media, card payments, logs), so they can be marked not applicable.

Level 1 requirements met
0%
Not started
By clause group
Gaps to close
    CyberSecure Canada readiness, From $2,500 CAD
    Self-check, not an audit. The certificate is issued by an accredited certification body under the Standards Council of Canada programme, after it reviews your evidence. Requirement wording here is our own summary of CAN/DGSI 104 Rev 2 (2026) and ITSP.10.171, not the text of the standards.

    Questions

    What is the difference between Level 1 and Level 2?

    Level 1 is the core set every certified organization meets: leadership, training, a risk assessment, an incident response plan, patching, anti-malware, secure configuration, MFA, backups, firewalls and access control. Level 2 builds on it with controls for a more mature programme, such as EDR, phishing-resistant authentication for administrators, an asset register, network segmentation and supplier assurance.

    Who issues the CyberSecure Canada certificate?

    An accredited certification body, under the programme administered by the Standards Council of Canada. The standard is CAN/DGSI 104, published by the Digital Governance Standards Institute. We prepare you for the audit; we do not issue certificates.

    How does CPCSC Level 1 relate to CyberSecure Canada?

    CPCSC is the Canadian Program for Cyber Security Certification for defence suppliers, and Level 1 is an annual self-assessment against 13 requirements. Most of those requirements overlap with CyberSecure Canada, so one set of evidence can serve both.

    Is this checker free?

    Yes, free and no signup. Your answers stay in your browser.

    Not ready for a call yet?

    Get your gap list and the readiness notes

    Your results by email, then a few short notes from Jacob on getting certified without wasted effort. Unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    CyberSecure Canada Readiness

    Gap analysis, remediation and support through the accredited audit.

    Explore CyberSecure Canada Readiness →

    Go into the audit with every requirement evidenced.

    We run the gap analysis against Level 1 or Level 2, close the gaps with you, and support you through the audit by an accredited certification body. Defence suppliers can cover CPCSC Level 1 in the same engagement. From $2,500 CAD.

    See CyberSecure Canada readiness Book a call

    Want the full picture on CyberSecure Canada?

    This gives you the shape of the problem. The full picture is all 35 requirements of CyberSecure Canada, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free CyberSecure Canada assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.