The control set

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

This is the control set we assess Canadian organisations against. We publish it so you can see exactly what is being asked of you before you engage us, and so you can work through it yourself if you would rather not.

What this is, and what it is not

Thirty-six governance controls, not a certification

Canada Cyber-Safe is not an accredited certification body and this is not a certification scheme. It is the set of questions we work through, the evidence we ask to see, and what each control relates to in Canadian law.

It sits above the technical baseline rather than replacing it. For technical controls we reference the Canadian Centre for Cyber Security’s Baseline Cyber Security Controls for Small and Medium Organizations (v1.2), which is the Government of Canada’s own standard for organisations under 499 people. There is no sense in us inventing a competing one.

Version 1.0 · August 2026 · Reviewed at least annually against changes in Canadian law.

A

Accountability and ownership

4 controls
A1

One named individual is accountable for cyber security and privacy.

Evidence A role description, contract clause or board minute that names them.

PIPEDA Principle 1 · Law 25 privacy officer

A2

The board, owner or executive receives a cyber and privacy report at a stated cadence.

Evidence Two consecutive board packs or sets of minutes showing it actually happened.

A3

Decision authority is defined for security decisions that disrupt the business.

Evidence A written statement of who can authorise emergency patching, isolating a system or taking a service offline, including out of hours.

A4

Cyber and privacy work has an identified budget.

Evidence A budget line or extract. It may be small. It may not be undefined.

B

What matters and what could hurt

4 controls
B1

There is a written list of the systems and data whose loss or exposure would materially damage the business.

Evidence The list, dated, reviewed within twelve months. Most organisations have never written this down, which is why every risk looks the same size.

B2

A risk register exists, with named owners and review dates.

Evidence The register.

B3

Risks that have been accepted are recorded, with who accepted them and when.

Evidence Register entries showing an acceptance decision, not a blank status column.

B4

There is an inventory of systems that hold personal information.

Evidence The inventory.

PIPEDA Principle 7

C

Privacy obligations

5 controls
C1

A breach register records every privacy breach, including those judged not to create a real risk of significant harm, and is kept for at least two years.

Evidence The register itself.

PIPEDA breach records

C2

A documented process determines whether a breach creates a real risk of significant harm.

Evidence The process, and a worked example if a breach has occurred.

PIPEDA

C3

A privacy notice states what is collected, why, how long it is kept and how to complain.

Evidence The published notice.

PIPEDA Principles 2, 8 and 10

C4

Retention periods are defined and actually enforced.

Evidence A retention schedule plus evidence that deletion has happened. A published period nobody executes is worse than none.

PIPEDA Principle 5

C5

Where the personal information of Quebec residents is handled, Law 25 obligations are identified and assigned.

Evidence A dated assessment note.

Law 25

D

Technical baseline

4 controls
D1

The organisation can evidence its position against the CCCS Baseline Cyber Security Controls.

Evidence A completed, dated baseline self-assessment. We assess governance. This is the technical floor beneath it and we do not restate it.

CCCS Baseline v1.2

D2

Multi-factor authentication is enforced on email, remote access and administrative accounts.

Evidence Configuration evidence, or a signed attestation from whoever administers it.

CCCS BC.5.1, BC.9.3, BC.10.5

D3

Backups exist, are protected from the systems they protect, and a restore has been tested in the last twelve months.

Evidence The restore test record. An untested backup is a hope, not a control.

CCCS BC.7.1, BC.7.2

D4

Patching is managed and exceptions are recorded.

Evidence A patch status report, and the list of what cannot be patched with the reason why.

CCCS BC.2.1, BC.2.2

E

Third parties and supply chain

4 controls
E1

There is an inventory of third parties with access to systems or personal information.

Evidence The inventory.

E2

Due diligence is carried out before contracting, proportionate to risk and criticality.

Evidence Completed reviews for the most critical suppliers.

OSFI B-10 where applicable

E3

Third parties are reviewed on an ongoing basis, not only at onboarding.

Evidence Dated review records from after the contract start.

OSFI B-10 where applicable

E4

Where a supplier subcontracts, the organisation knows who the subcontractor is.

Evidence A contract clause requiring disclosure, or a supplier attestation naming them.

F

AI deployment governance

5 controls
F1

There is an inventory of AI tools and features in use, including those switched on inside products you already own.

Evidence The inventory, dated. The features nobody decided to adopt are the ones that catch people out.

F2

AI deployments are reviewed before they go live, against a defined set of questions.

Evidence Completed pre-deployment reviews.

F3

What each AI system can reach is documented and deliberately scoped.

Evidence A record of the data and permissions each system inherits.

F4

Decisions made exclusively by automated processing are identified, and where they concern individuals the required information is given.

Evidence A register of automated decisions, and the notice provided to people.

Law 25 s.12.1

F5

Human oversight is defined for each AI system that affects people.

Evidence A named reviewer who is in a position to change the answer, and the route for someone to ask.

Law 25 s.12.1

G

Incident readiness

4 controls
G1

A written incident response plan exists, with contact details that are current.

Evidence The plan, with a review date inside twelve months.

CCCS BC.1.1, BC.1.2

G2

The plan names who decides, including out of hours and when that person is unavailable.

Evidence The named roles and the escalation path.

G3

The plan has been exercised in the last twelve months.

Evidence An exercise record, including what did not work.

G4

There is a defined route to breach notification decisions, including the Privacy Commissioner and affected individuals.

Evidence The decision path, and who signs it off.

PIPEDA

H

People

3 controls
H1

Security and privacy awareness training is delivered and completion is recorded.

Evidence Completion records, not a purchase order for a training platform.

CCCS BC.6.1

H2

Access is removed promptly when someone leaves or changes role.

Evidence A sample of recent leavers showing the date access ended.

CCCS BC.12.3

H3

People know how to report something suspicious, and are not penalised for reporting it.

Evidence The reporting route, and evidence it has been used.

I

Evidence and review

3 controls
I1

Evidence for these controls is held in one place and can be retrieved.

Evidence The repository, and someone who can find things in it.

I2

The control set is reviewed at least annually against changes in Canadian law.

Evidence A dated review note.

I3

The organisation can produce a dated summary for a customer, an insurer or a regulator on request.

Evidence The most recent summary. This is the point of all of it.

Work through it with us

Most organisations find they can evidence about a third of this on the first pass. That is normal, and it is a more useful starting point than a score. An independent assessment against this set is typically $6,000–$9,000 depending on scope, and the first conversation costs nothing.

Talk to us about an assessmentSee all services

French Version »