CyberSecure Canada Certification Guide

In short

CyberSecure Canada is the federal cybersecurity certification for organizations with 1 to 499 employees, assessed against the CCCS 13 baseline controls and administered by the Standards Council of Canada since March 2023. Certification is valid for two years. This guide is maintained by Fusion Computing, a Canadian, CISSP-led managed IT and cybersecurity provider, and covers who qualifies, the 13 controls, cost drivers, and a step-by-step path to the mark.

What is CyberSecure Canada?

CyberSecure Canada is the federal government’s cybersecurity certification program for small and medium organizations. It is built around the Baseline Cyber Security Controls for Small and Medium Organizations published by the Canadian Centre for Cyber Security (CCCS), part of the Communications Security Establishment (CSE). Since March 31, 2023, the program has been administered by the Standards Council of Canada (SCC), which took over from Innovation, Science and Economic Development Canada (ISED). The SCC accredits the certification bodies that assess and certify organizations, under ISO/IEC 17021-1, the international standard for bodies that audit and certify management systems. Many older articles still name ISED as the program authority; if a site tells you to apply through ISED, it is out of date.

CyberSecure Canada at a glance Detail
Who it is for Canadian organizations with 1 to 499 employees
Certified against CCCS Baseline Cyber Security Controls v1.2: 13 baseline controls plus 5 organizational controls
Program administrator Standards Council of Canada (since March 31, 2023; formerly ISED)
Who audits you An SCC-accredited certification body (accredited under ISO/IEC 17021-1)
Validity 2 years, then re-certification
Biggest cost driver Closing control gaps before the audit: tested backups, MFA everywhere, incident response plan, patching

Who it is for

The program is designed for organizations with roughly 1 to 499 employees, the SMB segment that holds valuable data but rarely has an enterprise security team. Certification is voluntary, but it is increasingly valuable when bidding for government and enterprise contracts, applying for cyber insurance, or simply demonstrating diligence to customers.

About 1 in 6 Canadian businesses (16%) were impacted by a cybersecurity incident in 2023, and national spending on recovery from incidents doubled in two years, from roughly $600 million in 2021 to $1.2 billion in 2023. Source: Statistics Canada, Impact of cybercrime on Canadian businesses, October 2024.

The 13 baseline controls

Certification is assessed against 13 baseline control areas, including: an incident response plan, automatic patching, security configuration, strong user authentication (including MFA), employee awareness training, backups and recovery, secure mobility, perimeter defences, malware protection, secure cloud and outsourced IT, secure websites, access control, and secure portable media handling. In the CCCS document these are numbered BC.1.1 through BC.13.2, and they sit alongside 5 organizational controls (OC.1 through OC.5.4) that scope the program to your size and risk profile. Our readiness matrix breaks each one down with required evidence.

The CCCS designed the baseline controls around an explicit 80/20 rule: small and medium organizations should get roughly 80% of the security benefit from 20% of the effort of a full enterprise framework. Source: CCCS, Baseline Cyber Security Controls for Small and Medium Organizations, v1.2.

Get the CyberSecure Canada Readiness Matrix

This guide explains the program. The matrix breaks down all 13 baseline controls with the evidence a certification body looks for, so you can self-assess before you apply.

Open the controls matrix →

How certification works

The path is straightforward in shape: (1) implement the 13 baseline controls; (2) engage an accredited certification body; (3) undergo assessment of your controls and evidence; (4) on success, you are certified and may display the CyberSecure Canada certification mark. Certification is valid for two years, after which you re-certify, which keeps the program honest as your environment and the threat landscape change.

Certification bodies are accredited by the Standards Council of Canada under ISO/IEC 17021-1, and a CyberSecure Canada certification is valid for 2 years before re-certification. The SCC has administered the program since March 31, 2023. Source: Standards Council of Canada; ISED program notice.

What it costs, and what it returns

The largest cost is usually not the assessment fee but the work of closing control gaps before you apply. For most SMBs the highest-effort items are tested backups, organization-wide MFA, a real incident response plan, and consistent patching. The return is concrete: a recognized federal mark, smoother cyber-insurance underwriting, and a credible answer to the security questionnaires that now accompany most B2B and government deals.

Most SMBs we take through CyberSecure Canada stumble on the same three controls: backups that have never been restore-tested, MFA that covers email but not admin accounts, and an incident response plan that exists on paper only. Close those three first and the formal audit becomes a confirmation, not a discovery.

Mike Pearlstein, CISSP, Founder and CEO, Fusion Computing

How to get certified: a roadmap

  1. Self-assess. Run the readiness matrix against the 13 controls and mark each red/yellow/green.
  2. Close the gaps. Prioritize MFA, backups, patching, and an incident response plan.
  3. Gather evidence. Certification is evidence-based, screenshots, policies, logs, and test results.
  4. Engage an accredited certification body and complete the assessment.
  5. Maintain it. Keep controls current and re-certify before the two-year mark.

CyberSecure Canada in context

CyberSecure Canada is the most accessible on-ramp to a recognized security posture for an SMB, and it maps cleanly onto CIS Controls v8.1. Organizations in regulated sectors will layer it with sector rules, PHIPA for health, OSFI B-13 for federally regulated finance, but the baseline controls are the common foundation underneath all of them. It is also a different program from CPCSC, the Canadian Program for Cyber Security Certification, which applies to defence suppliers; if you sell into Department of National Defence supply chains, you will eventually need CPCSC rather than (or on top of) CyberSecure Canada.

Frequently asked questions

What is CyberSecure Canada?

CyberSecure Canada is the federal cybersecurity certification program for small and medium organizations, based on the Canadian Centre for Cyber Security’s Baseline Cyber Security Controls. Accredited certification bodies, overseen by the Standards Council of Canada, assess and certify organizations against 13 baseline control areas.

How long does CyberSecure Canada certification last?

Certification is valid for two years from the date it is issued. Before the two-year mark you re-engage an accredited certification body and re-certify against the current version of the baseline controls, which keeps the mark meaningful as your environment and the threat landscape change. Budget the renewal like the first assessment: gathering fresh evidence is the bulk of the work.

Who is eligible for CyberSecure Canada certification?

The program targets small and medium organizations of roughly 1 to 499 employees, in any sector. Certification is voluntary, and there is no revenue threshold or industry restriction. It is increasingly valuable for winning government and enterprise contracts, securing cyber insurance, and demonstrating diligence to customers, which is why professional services, construction, and healthcare-adjacent SMBs are common applicants.

What are the 13 baseline controls?

They cover incident response planning, automatic patching, secure configuration, strong user authentication including MFA, awareness training, backups and recovery, secure mobility, perimeter defences, malware protection, secure cloud/outsourced IT, secure websites, access control, and secure portable media. Our readiness matrix details the evidence required for each.

How much does CyberSecure Canada certification cost?

The assessment fee is usually smaller than the cost of closing control gaps beforehand. For most SMBs the highest-effort items are tested backups, organization-wide MFA, an incident response plan, and consistent patching. The payoff is a recognized federal mark and easier insurance and procurement.

How do I get CyberSecure Canada certified?

Implement the 13 baseline controls, gather the supporting evidence, engage an accredited certification body, and pass the assessment. Running our CyberSecure Canada readiness matrix first lets you self-assess and close gaps so the formal assessment is a confirmation rather than a surprise.

About this guide

This guide is maintained by Mike Pearlstein, CISSP, Founder and CEO of Fusion Computing Limited, a Canadian managed IT and cybersecurity provider and Microsoft Solutions Partner. It is reviewed as legislation and program requirements change. Definitions are written for business leaders, not lawyers, for a legal opinion on your specific obligations, consult qualified counsel.

Want a second opinion on where your organization actually stands? We will review your current controls against this framework in plain language, no jargon, no obligation.

Book a 30-minute consult

Updated