Federal cybersecurity certificationCanada

CyberSecure Canada / CAN/DGSI 104 Readiness

Turn Canada's practical cybersecurity baseline into continuously operated controls and defensible evidence for independent certification.

View the control mapping

Where we contribute

A managed security layer within a broader compliance program.

CyberSecure Canada is a voluntary federal certification program built on Canada's baseline cybersecurity controls for small and medium organizations. Network Box can implement and continuously operate much of the technical security layer, but an accredited certification body, rather than Network Box or the client's MSP, determines whether the organization meets the applicable certification requirements.

Certification status

Reviewed September 2, 2026

CyberSecure Canada is a certification, not a self-issued compliance claim.

An SCC-accredited certification body evaluates the organization's implementation. Successful organizations may use the CyberSecure Canada certification mark for a two-year certification period, subject to the current program and display rules.

Standards Council of Canada: CyberSecure Canada ↗
  • The program is voluntary and designed primarily for Canadian small and medium organizations.
  • The familiar program baseline contains 13 cybersecurity controls developed by the Canadian Centre for Cyber Security.
  • The national standard originated as CAN/CIOSC 104:2021 and is now maintained as CAN/DGSI 104.
  • CAN/DGSI 104 was revised again in July 2026; applicants should confirm the applicable edition, level, transition dates, and audit criteria with their certification body.
  • Organizations with 500 or more employees, high-impact information, critical infrastructure, or more advanced threats should evaluate more comprehensive safeguards.

A practical Canadian baseline

From 13 essential controls to a certifiable operating program

CyberSecure Canada is attainable for many MSP customers because it focuses on practical safeguards. Certification readiness still requires clear scope, assigned ownership, recurring operation, and evidence, not just purchased technology.

Baseline

13 essential controls

A recognizable control set covering incident response, patching, authentication, security software, users, data, devices, networks, providers, websites, access, and media.

Standard

CAN/DGSI 104

The National Standard of Canada formalizes and expands the baseline into auditable requirements with levels and edition-specific criteria.

Assessment

Independent certification

An accredited certification body reviews implementation and evidence; Network Box provides readiness support and managed-control records.

Lifecycle

Two-year mark

The certification mark is valid for two years, so controls and evidence must remain operational after the initial assessment.

Current national standard

Five areas made explicit beyond the original 13-control checklist

Current CAN/DGSI 104 editions organize the baseline into a broader conformity-assessment structure. These areas reinforce why readiness cannot be reduced to a technical checklist.

Select a framework area to explore its detailed control mapping.
Framework areaNetwork Box contributionRelevant servicesCoverage
Security reporting and service reviews inform oversight, while executive direction and resources remain organization-owned.
Security reportingService reviews24/7 SOC
Supporting
Defined managed-service roles and escalation paths support a complete responsibility model.
Service documentationEscalation proceduresSecurity reporting
Partial
Vulnerability, threat, incident, architecture, and exposure information provides strong technical inputs to risk analysis.
Vulnerability ManagementThreat intelligenceSIEMSecurity reporting
Partial
Segmentation, monitoring, access protection, and vulnerability management can protect payment and finance environments.
Network segmentationUTM+SIEMNBX: MDR, EDR, XDRVulnerability Management
Supporting
Centralized logs, source monitoring, correlation, investigation, escalation, and retention options create recurring operational evidence.
SIEMNBX: MDR, EDR, XDR24/7 SOCSecurity reporting
Strong

These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.

Control mapping

The 13 baseline controls and Network Box support

Open any control to see its intent, Network Box's contribution, and the work that remains with the certified organization and its MSP. The exact audit criteria must be confirmed against the applicable CAN/DGSI 104 edition and level.

Authoritative sourceCyberSecure Canada program information ↗
Select a framework area to explore its detailed control mapping.
Framework areaNetwork Box contributionRelevant servicesCoverage
24/7 monitoring, investigation, escalation, supported containment, and incident records help turn a written plan into an operational capability.
SIEMNBX: MDR, EDR, XDR24/7 SOCIncident response support
Partial
Vulnerability Management identifies and prioritizes missing patches while Network Box maintains supported systems in its managed scope.
Vulnerability ManagementManaged platform operationsSecurity reporting
Partial
Layered managed security prevents, detects, investigates, and responds to malicious software and communications.
UTM+IDS/IPSSecure Web GatewayManaged Cloud Email SecurityNBX: MDR, EDR, XDR
Strong
Standardized managed configurations, controlled changes, and continuous monitoring support secure device operation.
UTM+Edge DefenseSecure SD-WANManaged change control
Partial
MFA-supported VPN, directory integration, controlled administration, authentication telemetry, and alerting protect managed access paths.
VPNMFA/TOTP supportDirectory integrationSIEM24/7 SOC
Partial
Training and phishing simulations help employees recognize and report common attacks.
Security Awareness TrainingPhishing simulationsCampaign reporting
Partial
Secure connectivity and protective monitoring support data protection, while backups and encryption at rest remain client-operated controls.
VPNSecure SD-WANNetwork segmentationNBX: MDR, EDR, XDR
Supporting
Secure remote access, web protection, endpoint telemetry, and continuous monitoring reduce risk for distributed users.
VPNSecure Web GatewayNBX: MDR, EDR, XDRManaged Cloud Email Security
Partial
Managed firewalls, UTM, intrusion prevention, segmentation, SD-WAN, secure remote access, and 24/7 monitoring form a continuously operated perimeter.
Edge DefenseUTM+IDS/IPSSecure SD-WANVPN24/7 SOC
Strong
Protected cloud connections, integrated monitoring, documented service scope, and provider evidence support third-party oversight.
Cloud telemetry monitoringManaged Cloud Email SecuritySecure connectivityService documentation
Partial
WAF, vulnerability assessment, attack detection, virtual patching, and SOC response protect public web applications and APIs.
WAFVulnerability ManagementPenetration TestingSIEM24/7 SOC
Strong
Network policy, segmentation, VPN, supported identity integration, and access monitoring restrict and observe managed paths.
Network segmentationUTM+VPNDirectory integrationSIEM
Partial
Endpoint and network monitoring may detect selected removable-media activity or subsequent malicious communications, but governance remains client-owned.
NBX: MDR, EDR, XDRNetwork monitoring
Supporting

These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.

Appropriate use

A strong baseline, not a ceiling

The Canadian Centre for Cyber Security designed these controls primarily for organizations with fewer than 500 employees and information whose compromise would cause no more than medium injury. Larger, critical-infrastructure, regulated, defence-supply-chain, or higher-risk organizations may need more comprehensive frameworks and sector-specific obligations. CyberSecure Canada also does not by itself establish PIPEDA or provincial privacy-law compliance.

Certification path

Move from readiness to independent assessment

Treat certification as an operating cycle rather than a one-time technology purchase.

01

Confirm the certification basis

Select an SCC-accredited certification body and confirm eligibility, edition, level, audit method, evidence expectations, cost, transition rules, and certification cycle.

02

Define scope and ownership

Inventory people, locations, systems, data, cloud services, providers, websites, mobile devices, and exclusions; assign a responsible owner for every control and record.

03

Assess and remediate gaps

Compare actual policies, processes, technology, and evidence with every applicable requirement, then correct deficiencies and document accepted risks.

04

Operate and retain evidence

Run recurring controls long enough to demonstrate they work, review exceptions, test response and recovery, and preserve complete evidence populations.

05

Complete the independent audit

Provide policies, records, interviews, demonstrations, and corrective actions to the certification body. Network Box can supply agreed technical evidence but does not make the decision.

06

Maintain and recertify

Monitor changes and risk, address findings, retain evidence, use the mark accurately, and prepare for the next certification cycle.

Assessment evidence

Show that safeguards are operating.

Available evidence depends on deployed services, configured log sources, agreed scope, format, and retention period.

  1. 01Service descriptions, scope documents, responsibility assignments, and escalation contacts
  2. 02Managed device, protected endpoint, subscribed service, and connected log-source inventories
  3. 03Network diagrams and descriptions of boundaries, connections, remote access, and segmentation
  4. 04Firewall, VPN, SD-WAN, IDS/IPS, secure web, email, DNS-related, remote-access, and WAF policies
  5. 05Secure configurations, managed updates, change approvals, and implementation records
  6. 06Administrative access, authentication, directory integration, and MFA evidence for managed services
  7. 07Security-software coverage, health, update, detection, and exception information
  8. 08Vulnerability findings, patch priorities, remediation recommendations, trends, and validation rescans
  9. 09Centralized logs, source-health checks, time-synchronization information, searches, dashboards, and reports
  10. 10SOC alerts, analyst investigations, incident tickets, timelines, escalations, and supported containment actions
  11. 11WAF, malware, phishing, email, web, endpoint, identity, network, and application-security events
  12. 12Security-awareness participation, campaign results, completion records, and phishing-simulation metrics
  13. 13Service availability, health monitoring, restoration, and operational review information
  14. 14Exceptions, remediation tracking, management reporting, and continuous-improvement recommendations
  15. 15Available service-provider security, contractual, and independent-assurance information

Coverage key

What each label means.

Strong

Network Box can directly deliver and operate a substantial part of this technical outcome when the relevant services are in scope.

Partial

Network Box contributes meaningful controls, but the requirement also depends on the client's systems, configuration, people, or processes.

Supporting

Network Box provides useful security operations or evidence, but does not satisfy the requirement by itself.

Client responsibility

This area primarily remains with the MSP and client, their assessors, or other qualified parties.

Shared responsibility

Network Box helps operate the controls. The organization owns the compliance program.

The organization owns certification scope, leadership accountability, risk decisions, policies, complete asset and identity governance, client-operated controls, evidence, corrective actions, and the application and independent audit.

CyberSecure Canada FAQ

Questions about scope, evidence, and responsibility.

What is CyberSecure Canada?

Turn Canada's practical cybersecurity baseline into continuously operated controls and defensible evidence for independent certification.

How can Network Box USA support CyberSecure Canada?

Network Box USA can operate managed technical safeguards, monitor the subscribed environment, investigate and escalate security activity, maintain managed configurations, and produce service evidence that may support applicable CyberSecure Canada requirements.

Does using Network Box USA make an organization CyberSecure Canada compliant?

No. A managed security service can contribute controls, operations, and evidence, but it cannot guarantee compliance or replace the organization's governance, complete scope, legal interpretation, assessment, or formal certification and attestation work.

How should the CyberSecure Canada control mapping be used?

Use the mapping as a scoping and evidence-planning aid. Each row explains the requirement, the potential Network Box contribution, available evidence, the coverage level, and the work that remains with the organization.

What evidence may be available for a CyberSecure Canada assessment?

Depending on the deployed services and agreed retention, evidence may include managed configurations, logs, alerts, incident records, vulnerability findings, change records, service reports, and recurring operational reviews. The assessor determines whether evidence is sufficient.

What remains the organization's responsibility under CyberSecure Canada?

The organization owns certification scope, leadership accountability, risk decisions, policies, complete asset and identity governance, client-operated controls, evidence, corrective actions, and the application and independent audit.

Explore another frameworkReturn to the Compliance Center →

Security stack review

Map the technical foundation before the assessment starts.

Request a Security Stack Review