Sentrix

Services · Compliance

CAN/DGSI 104 certification support (CyberSecure Canada)

The Canadian standard built for SMEs (CyberSecure Canada): choosing Level 1 or 2, closing the gaps and preparing for the audit. We prepare; we do not certify.

Why this matters

ISO 27001 isn't always the right first step. CAN/DGSI 104 exists precisely because most SMEs need a proportional, credible certification, not the cost and timeline of a framework built for a different scale.

ISO 27001 is out of reach

A corporate client requires a recognized cyber certification, but ISO 27001 is out of budget or out of timeline.

Questionnaires keep piling up

You regularly fill out client security questionnaires and want a certification that answers the essentials once and for all.

Insurers want more than a form

Your cyber insurer is starting to ask for more than a questionnaire: they want a formal certification or attestation.

The two Canadian programs get confused

CAN/DGSI 104 (CyberSecure Canada) and CPCSC (the program for Defence suppliers) are not the same thing; we clarify which applies to you.

What sets this apart

Controls that are lived, not just documented. MFA that exists on paper but isn't enabled on critical accounts is not a control. We implement the required technical controls with your IT team or MSP, then run a formal internal audit before the certification audit, the outside look that self-audits miss.

  • Identity and access management: MFA, role-based access, strong password policies.
  • Endpoint and network security: malware protection, firewalls, monitoring.
  • Backup and recovery: secure backups with regular restoration testing.
  • A formal internal audit run before your certification audit.

Sample gap findings

Illustrative examples; they do not describe a specific client.

  • High: multi-factor authentication is not enabled on all privileged and remote accounts. Action: turn on MFA and enforce role-based access before the certification audit.
  • Medium: backup jobs complete successfully, but restoration has never been tested end to end. Action: run and document a full restore test ahead of the internal audit.
  • Medium: endpoint protection is deployed, but not monitored centrally across all devices. Action: centralize endpoint monitoring and document coverage for the evidence file.
  • Low: an incident response plan exists but has never been rehearsed with the team. Action: run a tabletop exercise and document lessons learned before the audit.

What is CAN/DGSI 104 and CyberSecure Canada?

CAN/DGSI 104 is a Canadian national standard published by the Digital Governance Standards Institute (part of the Digital Governance Council). It establishes a practical baseline of cybersecurity controls specifically designed for organizations without a dedicated security team. According to the text of the standard, it specifies 18 main controls (55 sub-controls), spread across domains such as governance, risk assessment, technical protection, training, backups and incident response.

This standard is the foundation of the CyberSecure Canada program: implementing CAN/DGSI 104's controls is how an organization earns certification, issued by a third-party certification body accredited by the Standards Council of Canada (SCC) under ISO/IEC 17021-1. According to the program, certification is valid for two years.

The current version is CAN/DGSI 104:2021 / Rev 1:2024, which notably clarified the distinction between Level 1 and Level 2 across several domains (training, risk assessment, incident response plan, secure configuration, backups, and cloud/outsourced IT services). The CAN/DGSI 104 framework page summarizes the standard.

Level 1 or Level 2: which should you aim for?

The standard provides two levels of requirements. The right choice depends on your current maturity, your customers and your contractual obligations, not a sales preference.

Level 1: fundamental baseline

A cybersecurity baseline ideal for an SME structuring its security for the first time. The audit is generally lighter (mainly documentary review). It is often the right starting point to build solid foundations.

Level 2: strengthened posture

Level 2 requirements add to Level 1's as your organization gains maturity. It is generally required when your customers or the federal government ask for more robust assurance. The audit includes a deeper verification of implementation.

Sometimes the best strategy is to aim for Level 1 now, then Level 2 at the next cycle. We help you decide.

Preparing without certifying: our independence commitment

This rule protects the value of your certification: whoever supports you should not be the one who certifies you. We structure your process, implement controls and prepare you for the audit, but the certification body remains a third party accredited by the Standards Council of Canada, chosen by you. We can present you with several accredited options, with no commercial relationship with any of them.

Who this support is for

CAN/DGSI 104 was designed for small and medium Canadian organizations across all sectors that depend on technology to operate and manage their data.

  • Canadian SMEs who want a cyber certification sized to them, without aiming for ISO 27001 right away.
  • Companies receiving security questionnaires from corporate clients who want to answer with a federally recognized framework, without bearing the cost of ISO 27001.
  • Professional services providers (accountants, lawyers, consultants, agencies) who handle sensitive client information and want to demonstrate a measurable cyber posture.
  • Clinics, medical offices and health organizations that hold sensitive information and want a pragmatic certification aligned with their maturity.
  • Organizations doing business with the federal government, or targeting tenders where CyberSecure Canada certification becomes an eligibility criterion.
  • SMEs considering ISO 27001 in the medium term looking for a concrete first step; Level 2 is a logical launching pad.

Is this the right time for you?

If you recognize your situation in any of the following, this support is designed for you.

  • A corporate client requires a recognized cyber certification, but ISO 27001 is out of budget or out of timeline.
  • You regularly fill out client security questionnaires and want a certification that answers the essentials once and for all.
  • You are torn between Level 1 and Level 2 and want an outside opinion to decide, not a salesperson pushing the pricier option.
  • You saw "CyberSecure Canada" in a tender or federal contract and want to understand what is actually being asked.
  • Your cyber insurer is starting to ask for more than a questionnaire: they want a formal certification or attestation.
  • You are already compliant with Law 25 and want to leverage that work to get CAN/DGSI 104 without starting from scratch.
  • You want a certification valid for two years, with effort proportional to your size, not a project that monopolizes the organization for months.
  • You are mixing up CAN/DGSI 104 (CyberSecure Canada) with CPCSC (the program for Defence suppliers) and want to know which applies to you.

What the standard covers: a defence-in-depth approach

CAN/DGSI 104 promotes a defence-in-depth approach: multiple layers of protection working together to cover people, devices, accounts, networks and data. The controls group around the following domains:

  • Governance and security policies: clear policies defining acceptable use, password requirements and incident procedures.
  • Asset inventory: a register of the devices, systems, applications and data in your environment.
  • Identity and access management: role-based access, multi-factor authentication and strong password policies.
  • Endpoint security: malware protection, encryption and monitoring of workstations and mobile devices.
  • Patch and vulnerability management: regular updates of systems and applications.
  • Email security: filtering, anti-phishing, attachment scanning and domain authentication.
  • Training and awareness: programs to help staff recognize phishing and social engineering.
  • Backup and recovery: secure backups and regular restoration testing.
  • Network security: firewalls, secure remote access and network activity monitoring.
  • Threat monitoring and detection: logging and detection of suspicious activity for a rapid response.
  • Incident response plan: a clear process to detect, report, contain and resolve incidents.
  • Cloud and outsourced IT security: secure configuration and monitoring of cloud services and providers.

Thematic grouping of the standard's 18 controls (55 sub-controls), presented for readability; the official enumeration is found in the text of CAN/DGSI 104:2021 / Rev 1:2024.

What you get

A clear level recommendation

A Level 1 or Level 2 choice justified by your operational reality, your clients and your contractual obligations, not a sales preference.

A full gap analysis

A comparison of your current posture against the requirements of the chosen level, with an action plan prioritized by risk.

The required policies and procedures

The documents and records required by the standard, written and adapted to your reality, not generic copy-pasted templates.

Implementation of missing controls

Working with your IT team or MSP, putting in place the required technical controls: multi-factor authentication, tested backups, access management, monitoring.

A documented internal audit

An internal audit conducted before the certification audit, to avoid unpleasant surprises on the day (a prerequisite, notably for Level 2).

An organized evidence file

Your documents structured to the certification body's expectations, ready in the right place, not a scramble on audit day.

Support during the audit

Support during the audit conducted by the accredited body of your choice: preparing teams, translating questions, managing any non-conformities.

A two-year maintenance plan

Monitoring changes to the standard, preparing recertification, and adjusting as your environment evolves (new systems, employees, contracts).

Our approach, step by step

A rigorous, transparent approach, proportional to your size.

  1. Assessment and level selection. We determine which level is right for you by examining your business context, contractual obligations and current maturity. Sometimes the right answer is to aim for Level 1 now and Level 2 at the next cycle.
  2. Gap analysis. We map your current posture against the requirements of the chosen level: what is already in place and documentable, what is missing, what needs realigning. Deliverable: a prioritized gap report and a clear recommendation on the achievable timeline.
  3. Control implementation. We implement missing controls with your IT team or MSP, guided by one principle: every control must be lived, not just documented. MFA that exists on paper but is not enabled on critical accounts is not a control. The NIST CSF framework helps prioritize by real impact.
  4. Documentation and internal audit. We write the required policies, procedures and records, then conduct a formal internal audit before the certification audit, an outside look that reveals blind spots self-audits miss. This is often where unsupported efforts go off track.
  5. Audit support and maintenance. We support you during the audit conducted by the SCC-accredited certification body you chose. Then, over the two-year cycle, we remain available to prepare recertification and adjust the setup as your environment evolves, without locking you into a recurring contract.

Why aim for CyberSecure Canada certification

  • Certification at the scale of your SME: effort proportional to your size and resources, without the cost of ISO 27001.
  • A response to market expectations: answer client security questionnaires, supply chain requirements and cyber insurer requests with a recognized framework.
  • Better cyber resilience: concretely reduce the risk of ransomware, phishing and data leaks through a proven baseline of controls.
  • A scalable base: CAN/DGSI 104 shares principles with ISO 27001 and the NIST CSF; Level 2 is a natural launching pad toward a more advanced certification.
  • The trust of your clients and partners: demonstrate a measurable security posture, a differentiator in sectors where trust matters.

Why trust Sentrix with your CAN/DGSI 104 journey

Independence preserved

We prepare; we do not certify. The choice of accredited certification body remains yours, with no commercial relationship on our part.

An honest level recommendation

We recommend the level that is right for your organization, based on your real needs, not the highest invoice.

Controls that are lived, not just documented

We implement controls that are genuinely in place and operational, with the NIST CSF as support to prioritize by real impact.

Proportional effort

An approach calibrated for an SME, that does not monopolize your organization and stays maintainable over the two-year cycle.

Where CAN/DGSI 104 fits

A proportional standard, built to connect to bigger frameworks later. CAN/DGSI 104 shares principles with ISO 27001 and the NIST CSF, and existing Law 25 work can reduce your gaps. When a client requires ISO 27001, ISO 27001 certification support takes over; for Defence suppliers, CPCSC is the program that applies. The standard's technical controls map to our endpoint and server protection and data protection services.

Let's talk about your CAN/DGSI 104 journey.

Whether a client is asking, you're weighing your options, or just want to check your readiness, a first conversation costs nothing and helps determine the right level and achievable timeline.

Contact us

Frequently asked questions

Is CAN/DGSI 104 the same as CPCSC?
No. CAN/DGSI 104 (CyberSecure Canada) is a national certification mainly aimed at SMEs, published by the Digital Governance Standards Institute. CPCSC (Canadian Program for Cyber Security Certification) specifically targets defence sector suppliers and rests on a different standard (ITSP.10.171, aligned with NIST SP 800-171). We quickly clarify which one applies to you.
Is this equivalent to ISO 27001?
No. CAN/DGSI 104 shares principles with ISO 27001 and the NIST CSF but remains a lighter standard, designed for organizations without a dedicated security team. It is generally not accepted as a substitute for ISO 27001 in international contracts. If your client explicitly requires ISO 27001, that is the certification to pursue; Level 2 is often a launching pad toward it.
How do you choose between Level 1 and Level 2?
Based on your current maturity, your clients and your contractual obligations, not a sales preference. Level 1 is a baseline, with a generally lighter audit (mainly documentary review); Level 2 adds requirements for more robust assurance and a deeper verification of implementation. Sometimes the right answer is to aim for Level 1 now, then Level 2 at the next cycle.
Is it mandatory, and how long is the certification valid?
The standard is not a regulatory requirement in itself, but it is increasingly becoming a de facto requirement: corporate clients, public sector contracts, cyber insurers and supply chain partners are asking for it more and more. According to the CyberSecure Canada program, certification is valid for two years; we remain available to prepare recertification and maintain the setup in between.
Who issues the certification?
A third-party certification body accredited by the Standards Council of Canada (SCC) under ISO/IEC 17021-1. We prepare you, implement the controls with your IT team or MSP, run the internal audit and support you during the audit, but we do not issue the certification. The choice of accredited body remains yours, with no commercial relationship on our side.

Let's talk about your compliance program.

Last updated: 2026-09-17