This is the control set we assess Canadian organisations against. We publish it so you can see exactly what is being asked of you before you engage us, and so you can work through it yourself if you would rather not.
What this is, and what it is not
Thirty-six governance controls, not a certification
Canada Cyber-Safe is not an accredited certification body and this is not a certification scheme. It is the set of questions we work through, the evidence we ask to see, and what each control relates to in Canadian law.
It sits above the technical baseline rather than replacing it. For technical controls we reference the Canadian Centre for Cyber Security’s Baseline Cyber Security Controls for Small and Medium Organizations (v1.2), which is the Government of Canada’s own standard for organisations under 499 people. There is no sense in us inventing a competing one.
Version 1.0 · August 2026 · Reviewed at least annually against changes in Canadian law.
Accountability and ownership
4 controlsOne named individual is accountable for cyber security and privacy.
Evidence A role description, contract clause or board minute that names them.
PIPEDA Principle 1 · Law 25 privacy officer
The board, owner or executive receives a cyber and privacy report at a stated cadence.
Evidence Two consecutive board packs or sets of minutes showing it actually happened.
Decision authority is defined for security decisions that disrupt the business.
Evidence A written statement of who can authorise emergency patching, isolating a system or taking a service offline, including out of hours.
Cyber and privacy work has an identified budget.
Evidence A budget line or extract. It may be small. It may not be undefined.
What matters and what could hurt
4 controlsThere is a written list of the systems and data whose loss or exposure would materially damage the business.
Evidence The list, dated, reviewed within twelve months. Most organisations have never written this down, which is why every risk looks the same size.
A risk register exists, with named owners and review dates.
Evidence The register.
Risks that have been accepted are recorded, with who accepted them and when.
Evidence Register entries showing an acceptance decision, not a blank status column.
There is an inventory of systems that hold personal information.
Evidence The inventory.
PIPEDA Principle 7
Privacy obligations
5 controlsA breach register records every privacy breach, including those judged not to create a real risk of significant harm, and is kept for at least two years.
Evidence The register itself.
PIPEDA breach records
A documented process determines whether a breach creates a real risk of significant harm.
Evidence The process, and a worked example if a breach has occurred.
PIPEDA
A privacy notice states what is collected, why, how long it is kept and how to complain.
Evidence The published notice.
PIPEDA Principles 2, 8 and 10
Retention periods are defined and actually enforced.
Evidence A retention schedule plus evidence that deletion has happened. A published period nobody executes is worse than none.
PIPEDA Principle 5
Where the personal information of Quebec residents is handled, Law 25 obligations are identified and assigned.
Evidence A dated assessment note.
Law 25
Technical baseline
4 controlsThe organisation can evidence its position against the CCCS Baseline Cyber Security Controls.
Evidence A completed, dated baseline self-assessment. We assess governance. This is the technical floor beneath it and we do not restate it.
CCCS Baseline v1.2
Multi-factor authentication is enforced on email, remote access and administrative accounts.
Evidence Configuration evidence, or a signed attestation from whoever administers it.
CCCS BC.5.1, BC.9.3, BC.10.5
Backups exist, are protected from the systems they protect, and a restore has been tested in the last twelve months.
Evidence The restore test record. An untested backup is a hope, not a control.
CCCS BC.7.1, BC.7.2
Patching is managed and exceptions are recorded.
Evidence A patch status report, and the list of what cannot be patched with the reason why.
CCCS BC.2.1, BC.2.2
Third parties and supply chain
4 controlsThere is an inventory of third parties with access to systems or personal information.
Evidence The inventory.
Due diligence is carried out before contracting, proportionate to risk and criticality.
Evidence Completed reviews for the most critical suppliers.
OSFI B-10 where applicable
Third parties are reviewed on an ongoing basis, not only at onboarding.
Evidence Dated review records from after the contract start.
OSFI B-10 where applicable
Where a supplier subcontracts, the organisation knows who the subcontractor is.
Evidence A contract clause requiring disclosure, or a supplier attestation naming them.
AI deployment governance
5 controlsThere is an inventory of AI tools and features in use, including those switched on inside products you already own.
Evidence The inventory, dated. The features nobody decided to adopt are the ones that catch people out.
AI deployments are reviewed before they go live, against a defined set of questions.
Evidence Completed pre-deployment reviews.
What each AI system can reach is documented and deliberately scoped.
Evidence A record of the data and permissions each system inherits.
Decisions made exclusively by automated processing are identified, and where they concern individuals the required information is given.
Evidence A register of automated decisions, and the notice provided to people.
Law 25 s.12.1
Human oversight is defined for each AI system that affects people.
Evidence A named reviewer who is in a position to change the answer, and the route for someone to ask.
Law 25 s.12.1
Incident readiness
4 controlsA written incident response plan exists, with contact details that are current.
Evidence The plan, with a review date inside twelve months.
CCCS BC.1.1, BC.1.2
The plan names who decides, including out of hours and when that person is unavailable.
Evidence The named roles and the escalation path.
The plan has been exercised in the last twelve months.
Evidence An exercise record, including what did not work.
There is a defined route to breach notification decisions, including the Privacy Commissioner and affected individuals.
Evidence The decision path, and who signs it off.
PIPEDA
People
3 controlsSecurity and privacy awareness training is delivered and completion is recorded.
Evidence Completion records, not a purchase order for a training platform.
CCCS BC.6.1
Access is removed promptly when someone leaves or changes role.
Evidence A sample of recent leavers showing the date access ended.
CCCS BC.12.3
People know how to report something suspicious, and are not penalised for reporting it.
Evidence The reporting route, and evidence it has been used.
Evidence and review
3 controlsEvidence for these controls is held in one place and can be retrieved.
Evidence The repository, and someone who can find things in it.
The control set is reviewed at least annually against changes in Canadian law.
Evidence A dated review note.
The organisation can produce a dated summary for a customer, an insurer or a regulator on request.
Evidence The most recent summary. This is the point of all of it.
Work through it with us
Most organisations find they can evidence about a third of this on the first pass. That is normal, and it is a more useful starting point than a score. An independent assessment against this set is typically $6,000–$9,000 depending on scope, and the first conversation costs nothing.