CyberSecure Canada: CAN/DGSI 104

CyberSecure Canada is a voluntary Canadian certification program for small and medium organizations. Its current technical baseline is CAN/DGSI 104, Baseline Cyber Security Controls for Small and Medium Organizations, in the second revision of the first edition published on 2 July 2026. The Digital Governance Standards Institute (DGSI) maintains the standard. The Standards Council of Canada (SCC) accredits the bodies that certify organizations. ISED has not been the program authority since 31 March 2023.

Current reference

The program name remains CyberSecure Canada. The associated National Standard of Canada is numbered CAN/DGSI 104:2021. It was first published as CAN/CIOSC 104:2021 by the CIO Strategy Council, then under the CAN/DGSI designation after the standards body was renamed.

The edition currently published by DGSI is the second revision of the first edition (2 July 2026). It succeeds CAN/DGSI 104:2021 / Rev 1:2024. It mainly clarifies Level 1 versus Level 2 requirements (automatic patching, security software, authentication, perimeter defences, cloud and outsourced IT) and adds an informative annex for evaluating service providers.

For certification or recertification, ask the SCC-accredited certification body which edition it will audit. SCC accreditation bulletin 2025-14 still pointed to Rev 1:2024; some bodies may still be transitioning to the 2026 revision.

CyberSecure Canada program (SCC)

Who it is for

The standard targets small and medium organizations, typically with fewer than 500 employees. Larger organizations can use it as a starting point, but they must judge whether their context requires more.

It is not equivalent to ISO 27001, SOC 2 or PCI DSS. Organizations that handle personal, financial or sensitive information, that have high availability needs, or that supply critical infrastructure or military sectors will often need additional controls.

What the baseline covers

CAN/DGSI 104 specifies a minimum set of cyber security controls, with distinct Level 1 (baseline) and Level 2 (higher maturity) expectations. Typical program themes include governance and security policy, awareness, risk assessment, incident response, patching and secure configuration, security software, authentication, backups, access control, mobile devices, perimeter defences, websites, cloud services and outsourced IT.

The 2026 revision also clarifies phishing-resistant authentication, endpoint detection (EDR/XDR), vulnerability assessments and awareness of AI-enabled social engineering. These are scope clarifications, not a change in philosophy: the program remains a pragmatic SMB baseline.

How to get certified

Organizations are not certified by SCC. They are certified by a certification body accredited for the CyberSecure Canada program. The process is voluntary. The certificate attests that the baseline is in place; it does not replace ISO 27001 certification or a sector requirement such as CPCSC.

  1. Confirm scope and level

    Decide whether the SMB baseline matches what your customers and tenders actually ask for, then whether you are aiming at Level 1 or Level 2. More exposed organizations (sensitive data, high availability, defence) often need to go beyond CAN/DGSI 104.

  2. Map the gaps

    Compare current policies, evidence and practices with CAN/DGSI 104. Frequent gaps include governance, risk analysis, logging, tested backups and oversight of cloud providers.

  3. Implement controls and evidence

    Assign owners, document what the target level requires, and keep evidence that controls work, not only that they are written down.

  4. Choose an accredited body

    Confirm the certification body appears in the SCC accreditation directory for CyberSecure Canada, then agree audit scope and timing.

  5. Complete the audit and maintain the baseline

    Close findings, obtain the certificate, then plan recertification. A major change (cloud, merger, new payment environment) may require a review before expiry.

Difference from CPCSC

CyberSecure Canada targets SMBs across all sectors with a generalist baseline. CPCSC (Canadian Program for Cyber Security Certification) addresses defence suppliers and builds on ITSP.10.171, a significantly higher requirement level.

The two efforts can complement each other. They are not interchangeable: a CyberSecure Canada certificate does not by itself demonstrate CPCSC conformity.

How Certi360 can help

Certi360 helps Quebec SMBs turn CAN/DGSI 104 into an action plan: gaps, evidence, ownership and preparation for an accredited-body audit. We do not issue the certificate; we prepare the file so the audit looks at controls that actually operate.

If customers also ask for ISO 27001, Bill 25 or CPCSC, we frame what overlaps and what must stay distinct, so the program is not oversized.

Request a free assessment ← All standards