CyberSecure Canada: are you ready?
CyberSecure Canada is the federal certification program for small and medium organizations. Our free check shows which of its 13 control areas we can see from outside, and what you'll need to show an auditor yourself.
The 13 control areas
The program is based on the national standard CAN/DGSI 104:2021 (Rev 2024), which builds on the Canadian Centre for Cyber Security's baseline controls. In plain terms:
- Have an incident response plan.
- Keep operating systems and applications patched, automatically where possible.
- Run security software.
- Configure devices securely.
- Use strong authentication, including two-factor where you can.
- Train staff in security awareness.
- Back up and encrypt data.
- Secure mobile devices.
- Put basic perimeter defences in place, including DMARC on your email domain.
- Secure your cloud and outsourced IT services.
- Secure your websites.
- Control who has access to what.
- Secure portable media like USB drives.
What our check covers
From outside, we can check two parts: DMARC and SPF on your email domain (part of control 9) andyour website's encryption and browser security settings (a small, visible part of control 11). Everything else (plans, training, backups, device settings, access control) can only be shown with your own evidence. Verified users see a readiness view in their report, area by area.