SECURITY · RISK · COMPLIANCE · CANADA

Canada is rebuilding its defence and critical infrastructure economy. New security and compliance obligations come with it.

We prepare organizations for the security and compliance requirements now attached to Canadian defence work, critical infrastructure operations, and AI adoption: CPCSC, ITSP.10.171, the Critical Cyber Systems Protection Act, and ISO/IEC 42001, with evidence an assessor will accept.

CPCSC Level 1 entered select defence contracts summer 2026
Critical Cyber Systems Protection Act: Royal Assent June 15, 2026
CCSPAIn forceRoyal Assent June 15, 2026
CPCSC Level 1In contractsselect contracts, summer 2026
CPCSC Level 2Expectedselect contracts, spring 2027
AI legislationSignaledconsultation closed July 2026

Where do you sit?

Pick your situation. You get the obligation, the clock, and the first step. Five situations cover most of the Canadian economy, statutes and customer contracts alike.

The obligation

CPCSC clauses in federal defence contracts. Requirements flow down from primes to subcontractors, so they reach you even when Canada is not your direct customer.

The clock

Level 1 is mandatory in select contracts now. Level 2, with 98 controls and external assessment, is expected in select contracts spring 2027.

First step

Run the free Level 1 readiness check against the self assessment criteria. Five minutes, and the report shows what an assessor would ask next.

The obligation

The Critical Cyber Systems Protection Act: a cyber security program, supply chain duties, incident reporting, and binding directions for designated operators in finance, telecommunications, energy, and transportation.

The clock

In force since June 15, 2026. Designation starts a 90 day program clock, and incident reporting will be capped near 72 hours.

First step

Check your readiness against the four duties of the Act before your class appears in the schedule.

The obligation

The governance the national AI strategy expects and the signaled legislation will formalize: policy, risk assessment, oversight, and records. Applies to AI you buy as much as AI you build.

The clock

AI for All live since June 4, 2026. The transparency consultation closed July 2026, and legislation is signaled behind it.

First step

Inventory your AI, then run the ISO/IEC 42001 readiness assessment to see what a working management system would take.

The obligation

No statute, but the same controls arrive by contract: security questionnaires, audit clauses, and flow down requirements from enterprise and government customers. This is how most Canadian businesses meet this economy.

The clock

Set by your sales pipeline. Usually it is the deal that is waiting on your answers.

First step

A readiness assessment against ISO 27001 or CyberSecure Canada, sized to what your customers actually ask for rather than the whole catalog.

The obligation

Probably at least one of the above. Most Canadian organizations sit under something here, through contracts if not statutes, and the overlap is where money gets wasted.

The clock

Cheap to find out now. Expensive to find out inside a bid, a customer review, or an incident.

First step

A discovery call. Twenty minutes, and you leave with a straight answer about what applies and what does not.

Three practice lines

Each practice owns a defined set of obligations, a client process, and the evidence it produces. If none of the three fits you exactly, the same requirements usually reach you through your customers; the finder above routes you.

PRACTICE 01

Defence & Government Supplier Security

For companies entering or growing in the defence supply chain under Build, Partner, Buy.

  • CPCSC Level 1 readiness and attestation support
  • ITSP.10.171 control implementation
  • Level 2 preparation and evidence programs
  • Contract security requirements interpretation
  • Supply chain security flow down
View the practice →
Buying now: Level 1 clauses live in contracts
PRACTICE 02

Critical Infrastructure Cyber Governance

For operators in finance, telecommunications, energy, and transportation facing the Critical Cyber Systems Protection Act and board scrutiny.

  • CCSPA readiness and gap assessment
  • Cyber security program design, the 90 day artifact
  • Incident reporting readiness
  • Resilience planning per Cyber Centre guidance
  • Third party and supply chain risk
View the practice →
Seed now: designation orders set the clock
PRACTICE 03

AI Governance & Technology Risk

For organizations adopting AI under the national strategy and preparing for the legislation behind it.

  • ISO/IEC 42001 readiness
  • AI governance frameworks and policy
  • AI risk and impact assessment
  • Responsible AI controls and evidence
  • Technology governance for boards
View the practice →
Growing: strategy live, legislation signaled

One process, seven steps

Every practice runs the same seven step shape. Only the obligation set changes.

01

Triage

Read the contracts, legislation, or adoption plans that apply, and their dates.

02

Scope

The smallest defensible boundary of systems, people, and locations.

03

Assess

Gap assessment against the control set your obligation names.

04

Build

Remediation sequenced by deadline. Your team implements; we verify.

05

Evidence

A record behind every control, assembled as the work happens.

06

Attest or Certify

Enter the assessment prepared, with nothing improvised.

07

Maintain

Renewal clocks and obligation changes tracked between assessments.

Ready to begin?

Tell us which obligation you are facing, a contract clause, a designation risk, or an AI adoption plan, and we'll schedule a discovery call.

Canada
Typically respond within 24 hours

Request a Discovery Call

We'll review your requirements and schedule a consultation.

We typically respond within 24 hours

Request Received

Thank you. We'll be in touch within 24 hours to schedule your discovery call.

ascio Assistant
Ask about our services & standards
Static assistant. No APIs. No data sent.
Welcome to ascio.
We prepare organizations for defence contract security requirements, critical infrastructure obligations under CCSPA, and AI governance readiness in Canada.

How can I assist you today?