Framework · CAN/DGSI 104
CAN/DGSI 104: the cybersecurity baseline for Canadian SMEs
Canada's baseline cyber security controls standard for SMEs: 18 main controls, 55 sub-controls, two levels, and the CyberSecure Canada certification program.
CAN/DGSI 104:2021 Rev 1:2024, the standard behind the CyberSecure Canada program, is the baseline cybersecurity controls standard published by the Digital Governance Standards Institute (DGSI) under the Standards Council of Canada. It specifies 18 main controls (55 sub-controls) across two levels, designed for organizations without a dedicated security team: low-burden, affordable, and sector-neutral.
Key facts
- 18 main controls: 55 sub-controls, across two levels.
- Rev 1:2024: latest revision of the standard, released in December 2024.
- 2 levels: Level 1 baseline and Level 2 strengthened posture, across all Canadian industries.
- CyberSecure Canada: the national certification program built on the standard, with accredited certification bodies.
What CAN/DGSI 104 requires
The 18 main controls address the most impactful foundational protections for SMEs: patching, authentication, backups, access control, incident response, and employee awareness.
- Patch management: automated OS and application updates across all devices
- Strong authentication: multi-factor authentication for privileged and remote access
- Data backup and recovery: encrypted backups tested regularly and stored offsite
- Access control: least-privilege access, authorization reviews, user lifecycle management
- Incident response plan: documented procedures for detection, containment, notification, and recovery
- Employee awareness training: regular cybersecurity awareness for all staff, tracked and documented
What Sentrix provides for CAN/DGSI 104
18 controls pre-built
All 18 main controls are pre-built in Sentrix with evidence connectors for patching, MFA, backup status, access reviews, and training completion records.
CyberSecure Canada certification readiness
Sentrix generates your evidence package formatted for submission to an accredited certification body under Innovation, Science and Economic Development Canada.
SME-sized implementation
CAN/DGSI 104 is designed to be achievable without a dedicated security team. Sentrix provides guided remediation workflows and plain-language evidence collection.
2024 revision ready
Sentrix mappings reflect CAN/DGSI 104:2021 Rev 1:2024. Framework updates are reflected in your control library without manual rework.
Crosswalks
- NIST CSF 2.0: CAN/DGSI 104 controls map to the CSF functions; an organization adopting the standard as its baseline satisfies a significant portion of the Protect and Detect functions.
- CIS Controls: crosswalk included for organizations following both.
- CPCSC: for SMEs that also supply the defence supply chain.
- Law 25 and PIPEDA: the standard's safeguards support personal information protection obligations.
Further reading
The Sentrix CAN/DGSI 104 certification support service covers dossier preparation. Public sector solution.
See your 18-control coverage against your real infrastructure.
Frequently asked questions
- What is CAN/DGSI 104?
- CAN/DGSI 104:2021 Rev 1:2024 is the baseline cybersecurity controls standard for small and medium organizations, published by the Digital Governance Standards Institute (DGSI) under the Standards Council of Canada. It specifies 18 main controls and 55 sub-controls across two levels, designed for organizations without a dedicated security team: low-burden, affordable, and sector-neutral. It is the standard behind the CyberSecure Canada program.
- What are the two levels of CAN/DGSI 104?
- Level 1 is the baseline: the most impactful foundational protections for an SME, including patch management, strong authentication, backups, access control, an incident response plan and employee awareness. Level 2 is a strengthened posture. Both levels remain low-burden and sector-neutral across all Canadian industries.
- How does it relate to CyberSecure Canada?
- CyberSecure Canada is the national certification program built on CAN/DGSI 104. Certification is issued by an accredited certification body under Innovation, Science and Economic Development Canada. Sentrix generates the evidence package formatted for submission to that body and maps the 18 controls to NIST CSF and CIS Controls for organizations pursuing several frameworks.
Related pages
Framework · NIST CSF 2.0
NIST CSF 2.0: the risk framework your board understands
The NIST Cybersecurity Framework, version 2.0 of 2024: six outcome-based functions, including the new Govern function, that layer on top of your standards.
Framework · CPCSC
CPCSC: self-assessment, third party, National Defence
Canadian Program for Cyber Security Certification for defence suppliers: Levels 1, 2 and 3, ITSP.10.171 controls, accredited assessment and a crosswalk to CMMC.
Framework · Law 25
Law 25: PIAs, incidents, access and portability, documented
Québec's private-sector privacy law, in full force since September 2023: privacy impact assessments, confidentiality incidents, access rights and portability.
Framework · PIPEDA
PIPEDA: ten principles, enforceable obligations
Canada's federal private-sector privacy law: ten fair information principles, breach reporting to the Privacy Commissioner and the bridge to GDPR adequacy.
Let's talk about your compliance program.
Last updated: 2026-09-17
