13 essential controls
A recognizable control set covering incident response, patching, authentication, security software, users, data, devices, networks, providers, websites, access, and media.
Turn Canada's practical cybersecurity baseline into continuously operated controls and defensible evidence for independent certification.
View the control mappingWhere we contribute
CyberSecure Canada is a voluntary federal certification program built on Canada's baseline cybersecurity controls for small and medium organizations. Network Box can implement and continuously operate much of the technical security layer, but an accredited certification body, rather than Network Box or the client's MSP, determines whether the organization meets the applicable certification requirements.
Certification status
Reviewed September 2, 2026An SCC-accredited certification body evaluates the organization's implementation. Successful organizations may use the CyberSecure Canada certification mark for a two-year certification period, subject to the current program and display rules.
Standards Council of Canada: CyberSecure Canada ↗A practical Canadian baseline
CyberSecure Canada is attainable for many MSP customers because it focuses on practical safeguards. Certification readiness still requires clear scope, assigned ownership, recurring operation, and evidence, not just purchased technology.
A recognizable control set covering incident response, patching, authentication, security software, users, data, devices, networks, providers, websites, access, and media.
The National Standard of Canada formalizes and expands the baseline into auditable requirements with levels and edition-specific criteria.
An accredited certification body reviews implementation and evidence; Network Box provides readiness support and managed-control records.
The certification mark is valid for two years, so controls and evidence must remain operational after the initial assessment.
Current national standard
Current CAN/DGSI 104 editions organize the baseline into a broader conformity-assessment structure. These areas reinforce why readiness cannot be reduced to a technical checklist.
| Framework area | Network Box contribution | Relevant services | Coverage |
|---|---|---|---|
| Security reporting and service reviews inform oversight, while executive direction and resources remain organization-owned. | Supporting | ||
Detailed mapping2 mapping notes Leadership must direct, support, resource, and continually improve the cybersecurity program. Network Box contributionSupportingNetwork Box provides threat trends, service performance, incident summaries, risk findings, and remediation recommendations for management review. Certified organization responsibilityClient responsibilityApprove the program, establish priorities, allocate resources, resolve risk decisions, and remain accountable for cybersecurity outcomes. | |||
| Defined managed-service roles and escalation paths support a complete responsibility model. | Partial | ||
Detailed mapping2 mapping notes Every cybersecurity activity and item of evidence needs an accountable owner with appropriate authority and competence. Network Box contributionPartialNetwork Box documents responsibilities, operational contacts, escalation paths, and the activities performed within the contracted service scope. Certified organization responsibilityClient responsibilityAssign internal leadership, control, and evidence owners; document responsibilities across the organization, MSP, Network Box, users, and other providers. | |||
| Vulnerability, threat, incident, architecture, and exposure information provides strong technical inputs to risk analysis. | Partial | ||
Detailed mapping2 mapping notes The organization must understand its assets, information value, threats, vulnerabilities, likelihood, impact, and treatment decisions. Network Box contributionPartialNetwork Box supplies current technical findings, observed attack activity, incident trends, architecture information, and managed-control performance data. Certified organization responsibilityClient responsibilityDefine scope and methodology, assess business impact and residual risk, approve treatment or acceptance, assign owners, and update the assessment after material changes. | |||
| Segmentation, monitoring, access protection, and vulnerability management can protect payment and finance environments. | Supporting | ||
Detailed mapping2 mapping notes Payment and financial systems require explicit protection against unauthorized access, manipulation, theft, and service disruption. Network Box contributionSupportingNetwork Box can isolate systems, control network paths, monitor activity, identify weaknesses, and support investigation within the managed scope. Certified organization responsibilityClient responsibilityInventory systems and data flows, govern terminals and applications, reconcile transactions, manage vendor access, and satisfy PCI DSS, banking, accounting, privacy, or contractual obligations where applicable. | |||
| Centralized logs, source monitoring, correlation, investigation, escalation, and retention options create recurring operational evidence. | Strong | ||
Detailed mapping2 mapping notes Security-relevant activity must be recorded, protected, reviewed, investigated, and retained so suspicious behavior and control operation can be demonstrated. Network Box contributionStrongNetwork Box centralizes supported telemetry, monitors source health, correlates activity, investigates alerts, escalates incidents, and provides dashboards and records. Certified organization responsibilityClient responsibilityIdentify every required source and event, enable complete logging, maintain time synchronization and attribution, protect and retain records, and cover systems outside Network Box scope. | |||
These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.
Control mapping
Open any control to see its intent, Network Box's contribution, and the work that remains with the certified organization and its MSP. The exact audit criteria must be confirmed against the applicable CAN/DGSI 104 edition and level.
| Framework area | Network Box contribution | Relevant services | Coverage |
|---|---|---|---|
| 24/7 monitoring, investigation, escalation, supported containment, and incident records help turn a written plan into an operational capability. | Partial | ||
Detailed mapping2 mapping notes Prepare to detect, respond to, communicate, and recover from incidents of varying severity, with clear owners and external contacts. Network Box contributionPartialThe SOC monitors and validates events, prioritizes alerts, investigates available telemetry, escalates through agreed contacts, supports containment using managed controls, and documents actions and timelines. Certified organization responsibilityClient responsibilityMaintain and test the enterprise incident response plan; define authority, legal and privacy notification, communications, evidence preservation, insurance, business continuity, recovery, and events beyond Network Box visibility. | |||
| Vulnerability Management identifies and prioritizes missing patches while Network Box maintains supported systems in its managed scope. | Partial | ||
Detailed mapping2 mapping notes Keep operating systems, applications, firmware, and security tools current through automatic updates or a documented vulnerability and patch-management process. Network Box contributionPartialNetwork Box maintains supported software in its managed services, identifies missing patches and exposed weaknesses in subscribed scans, prioritizes remediation, tracks trends, and can validate correction. Certified organization responsibilityClient responsibilityInventory and patch endpoints, servers, applications, firmware, cloud resources, mobile devices, and other systems outside Network Box management; test changes, replace unsupported technology, document exceptions, and verify deployment. | |||
| Layered managed security prevents, detects, investigates, and responds to malicious software and communications. | Strong | ||
Detailed mapping2 mapping notes Use active, current, automatically updating security software and local firewalls across applicable systems. Network Box contributionStrongManaged antimalware, UTM, IDS/IPS, secure web and email controls, endpoint detection, threat intelligence, automated blocking, investigation, and response provide continuously operated protection. Certified organization responsibilityClient responsibilityEnsure complete coverage across every endpoint, server, mobile device, cloud workload, and other system; keep protections enabled, govern exclusions, prevent unauthorized disabling, and remediate alerts. | |||
| Standardized managed configurations, controlled changes, and continuous monitoring support secure device operation. | Partial | ||
Detailed mapping2 mapping notes Change defaults, remove unnecessary features and accounts, enable relevant protections, and maintain secure configuration standards. Network Box contributionPartialNetwork Box hardens subscribed services, restricts administrative access, manages supported updates, documents changes, and continuously monitors managed security components. Certified organization responsibilityClient responsibilityCreate standards and securely configure endpoints, servers, applications, cloud systems, network equipment, mobile and IoT devices, local firewalls, accounts, and features outside the managed scope; review exceptions. | |||
| MFA-supported VPN, directory integration, controlled administration, authentication telemetry, and alerting protect managed access paths. | Partial | ||
Detailed mapping2 mapping notes Use strong authentication, especially MFA for important, privileged, financial, cloud, and remote-access accounts, and govern password practices. Network Box contributionPartialNetwork Box supports MFA and directory integration for applicable VPN access, uses controlled managed-service administration, records authentication activity, and can correlate suspicious access in SIEM. Certified organization responsibilityClient responsibilityOwn identity lifecycle, unique accounts, MFA coverage, password and password-manager policy, privileged and service accounts, access reviews, compromised-credential response, and authentication for all other systems. | |||
| Training and phishing simulations help employees recognize and report common attacks. | Partial | ||
Detailed mapping2 mapping notes Give personnel practical, recurring education on phishing, credentials, malware, acceptable use, data handling, and incident reporting. Network Box contributionPartialNetwork Box can administer awareness campaigns and phishing simulations, provide reminders and targeted education, and report completion and user-risk results. Certified organization responsibilityClient responsibilitySet policy and frequency, train everyone in scope at onboarding and recurrently, tailor content to roles and threats, address non-completion and repeated failures, and retain evidence. | |||
| Secure connectivity and protective monitoring support data protection, while backups and encryption at rest remain client-operated controls. | Supporting | ||
Detailed mapping2 mapping notes Back up essential systems and information, protect copies from attack, test recovery, and encrypt sensitive data in storage and transit. Network Box contributionSupportingVPN and secure connectivity protect traffic on managed paths; segmentation, access controls, monitoring, and response can help shield backup infrastructure from unauthorized activity. Certified organization responsibilityClient responsibilityDefine recovery objectives and backup frequency; maintain independent, protected, encrypted, and where appropriate offline copies; manage keys; monitor jobs; test integrity and restoration; and encrypt sensitive data at rest and across all relevant paths. | |||
| Secure remote access, web protection, endpoint telemetry, and continuous monitoring reduce risk for distributed users. | Partial | ||
Detailed mapping2 mapping notes Choose and govern a mobile-device ownership model, protect business data, control applications, encrypt devices, and secure remote connectivity. Network Box contributionPartialNetwork Box can protect remote traffic and web and email use, monitor supported endpoints, detect threats, and provide secure VPN access to corporate resources. Certified organization responsibilityClient responsibilityOwn BYOD or corporate-device policy, mobile-device management, application controls, data separation, device encryption and locks, updates, remote wipe, public Wi-Fi and travel rules, loss response, and disposal. | |||
| Managed firewalls, UTM, intrusion prevention, segmentation, SD-WAN, secure remote access, and 24/7 monitoring form a continuously operated perimeter. | Strong | ||
Detailed mapping2 mapping notes Protect every Internet and third-party boundary, isolate exposed systems, filter malicious traffic, secure remote access and Wi-Fi, and protect email and DNS paths. Network Box contributionStrongNetwork Box manages firewall and UTM policy, IDS/IPS, segmentation, VPN, SD-WAN, secure web and email controls, DNS-related protections, threat updates, logging, and SOC monitoring within scope. Certified organization responsibilityClient responsibilityIdentify and diagram every connection and location; approve and review rules; secure Wi-Fi, guest networks, remote work, domains, email authentication, local host firewalls, and any technology or bypass paths outside the managed boundary. | |||
| Protected cloud connections, integrated monitoring, documented service scope, and provider evidence support third-party oversight. | Partial | ||
Detailed mapping2 mapping notes Assess providers before use, define security responsibilities and contract terms, secure administrative access and connectivity, and monitor outsourced services. Network Box contributionPartialNetwork Box documents its services and responsibilities, protects connections, can monitor integrated cloud and identity telemetry, manages selected cloud security controls, and provides operational and available assurance information. Certified organization responsibilityClient responsibilityPerform risk-based due diligence; review provider reports; govern contracts, data location, access, incidents, continuity, deletion, exit, and downstream providers; enforce cloud-admin MFA; securely configure services; and monitor providers. | |||
| WAF, vulnerability assessment, attack detection, virtual patching, and SOC response protect public web applications and APIs. | Strong | ||
Detailed mapping2 mapping notes Protect websites and sensitive information through secure design, HTTPS, current components, strong administration, vulnerability management, and suitable application testing. Network Box contributionStrongNetwork Box WAF, scanning, IDS/IPS, virtual-patching capabilities, telemetry, and SOC monitoring detect and block attacks and support investigation and response. Certified organization responsibilityClient responsibilityInventory websites and APIs; own secure design and development; patch servers, frameworks, plugins, and dependencies; manage certificates, DNS, hosting, code, credentials, data, and pipelines; address OWASP risks and remediate findings. | |||
| Network policy, segmentation, VPN, supported identity integration, and access monitoring restrict and observe managed paths. | Partial | ||
Detailed mapping2 mapping notes Apply least privilege, separate administrative activity, promptly change or remove access, and use centralized authorization where appropriate. Network Box contributionPartialNetwork Box enforces managed firewall, segmentation, and VPN policy; supports selected identity integrations; restricts service administration; and monitors access telemetry for suspicious behavior. Certified organization responsibilityClient responsibilityProvision, approve, review, modify, and terminate access across applications, data, cloud, endpoints, privileged and service accounts; define business roles, segregation of duties, emergency access, and complete identity governance. | |||
| Endpoint and network monitoring may detect selected removable-media activity or subsequent malicious communications, but governance remains client-owned. | Supporting | ||
Detailed mapping2 mapping notes Minimize removable-media use and tightly govern approved, encrypted, inventoried devices through their complete lifecycle. Network Box contributionSupportingWhere the endpoint platform and service scope provide telemetry, Network Box may detect selected media activity or malware and can restrict or investigate malicious network communications. Certified organization responsibilityClient responsibilityAuthorize company-owned media, inventory and encrypt it, restrict connection and transfer, scan devices, train users, report loss, prohibit unmanaged media, and sanitize or physically destroy media before disposal. | |||
These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.
Appropriate use
The Canadian Centre for Cyber Security designed these controls primarily for organizations with fewer than 500 employees and information whose compromise would cause no more than medium injury. Larger, critical-infrastructure, regulated, defence-supply-chain, or higher-risk organizations may need more comprehensive frameworks and sector-specific obligations. CyberSecure Canada also does not by itself establish PIPEDA or provincial privacy-law compliance.
Certification path
Treat certification as an operating cycle rather than a one-time technology purchase.
Select an SCC-accredited certification body and confirm eligibility, edition, level, audit method, evidence expectations, cost, transition rules, and certification cycle.
Inventory people, locations, systems, data, cloud services, providers, websites, mobile devices, and exclusions; assign a responsible owner for every control and record.
Compare actual policies, processes, technology, and evidence with every applicable requirement, then correct deficiencies and document accepted risks.
Run recurring controls long enough to demonstrate they work, review exceptions, test response and recovery, and preserve complete evidence populations.
Provide policies, records, interviews, demonstrations, and corrective actions to the certification body. Network Box can supply agreed technical evidence but does not make the decision.
Monitor changes and risk, address findings, retain evidence, use the mark accurately, and prepare for the next certification cycle.
Assessment evidence
Available evidence depends on deployed services, configured log sources, agreed scope, format, and retention period.
Coverage key
Network Box can directly deliver and operate a substantial part of this technical outcome when the relevant services are in scope.
Network Box contributes meaningful controls, but the requirement also depends on the client's systems, configuration, people, or processes.
Network Box provides useful security operations or evidence, but does not satisfy the requirement by itself.
This area primarily remains with the MSP and client, their assessors, or other qualified parties.
Shared responsibility
The organization owns certification scope, leadership accountability, risk decisions, policies, complete asset and identity governance, client-operated controls, evidence, corrective actions, and the application and independent audit.
CyberSecure Canada FAQ
Turn Canada's practical cybersecurity baseline into continuously operated controls and defensible evidence for independent certification.
Network Box USA can operate managed technical safeguards, monitor the subscribed environment, investigate and escalate security activity, maintain managed configurations, and produce service evidence that may support applicable CyberSecure Canada requirements.
No. A managed security service can contribute controls, operations, and evidence, but it cannot guarantee compliance or replace the organization's governance, complete scope, legal interpretation, assessment, or formal certification and attestation work.
Use the mapping as a scoping and evidence-planning aid. Each row explains the requirement, the potential Network Box contribution, available evidence, the coverage level, and the work that remains with the organization.
Depending on the deployed services and agreed retention, evidence may include managed configurations, logs, alerts, incident records, vulnerability findings, change records, service reports, and recurring operational reviews. The assessor determines whether evidence is sufficient.
The organization owns certification scope, leadership accountability, risk decisions, policies, complete asset and identity governance, client-operated controls, evidence, corrective actions, and the application and independent audit.
The information in this Compliance Center is provided for general informational purposes and does not constitute legal, regulatory, audit, or certification advice. Requirements vary by organization, jurisdiction, contract, data, and system scope. Network Box services can support selected technical and operational safeguards but do not by themselves establish compliance, certification, or attestation. Each organization remains responsible for determining its obligations, defining scope, implementing governance and non-technical controls, and obtaining advice or assessment from qualified legal, compliance, audit, or certification professionals.
Security stack review