Canada is rebuilding its defence and critical infrastructure economy. New security and compliance obligations come with it.
We prepare organizations for the security and compliance requirements now attached to Canadian defence work, critical infrastructure operations, and AI adoption: CPCSC, ITSP.10.171, the Critical Cyber Systems Protection Act, and ISO/IEC 42001, with evidence an assessor will accept.
Where do you sit?
Pick your situation. You get the obligation, the clock, and the first step. Five situations cover most of the Canadian economy, statutes and customer contracts alike.
CPCSC clauses in federal defence contracts. Requirements flow down from primes to subcontractors, so they reach you even when Canada is not your direct customer.
Level 1 is mandatory in select contracts now. Level 2, with 98 controls and external assessment, is expected in select contracts spring 2027.
Run the free Level 1 readiness check against the self assessment criteria. Five minutes, and the report shows what an assessor would ask next.
The Critical Cyber Systems Protection Act: a cyber security program, supply chain duties, incident reporting, and binding directions for designated operators in finance, telecommunications, energy, and transportation.
In force since June 15, 2026. Designation starts a 90 day program clock, and incident reporting will be capped near 72 hours.
Check your readiness against the four duties of the Act before your class appears in the schedule.
The governance the national AI strategy expects and the signaled legislation will formalize: policy, risk assessment, oversight, and records. Applies to AI you buy as much as AI you build.
AI for All live since June 4, 2026. The transparency consultation closed July 2026, and legislation is signaled behind it.
Inventory your AI, then run the ISO/IEC 42001 readiness assessment to see what a working management system would take.
No statute, but the same controls arrive by contract: security questionnaires, audit clauses, and flow down requirements from enterprise and government customers. This is how most Canadian businesses meet this economy.
Set by your sales pipeline. Usually it is the deal that is waiting on your answers.
A readiness assessment against ISO 27001 or CyberSecure Canada, sized to what your customers actually ask for rather than the whole catalog.
Probably at least one of the above. Most Canadian organizations sit under something here, through contracts if not statutes, and the overlap is where money gets wasted.
Cheap to find out now. Expensive to find out inside a bid, a customer review, or an incident.
A discovery call. Twenty minutes, and you leave with a straight answer about what applies and what does not.
Three practice lines
Each practice owns a defined set of obligations, a client process, and the evidence it produces. If none of the three fits you exactly, the same requirements usually reach you through your customers; the finder above routes you.
Defence & Government Supplier Security
For companies entering or growing in the defence supply chain under Build, Partner, Buy.
- CPCSC Level 1 readiness and attestation support
- ITSP.10.171 control implementation
- Level 2 preparation and evidence programs
- Contract security requirements interpretation
- Supply chain security flow down
Critical Infrastructure Cyber Governance
For operators in finance, telecommunications, energy, and transportation facing the Critical Cyber Systems Protection Act and board scrutiny.
- CCSPA readiness and gap assessment
- Cyber security program design, the 90 day artifact
- Incident reporting readiness
- Resilience planning per Cyber Centre guidance
- Third party and supply chain risk
AI Governance & Technology Risk
For organizations adopting AI under the national strategy and preparing for the legislation behind it.
- ISO/IEC 42001 readiness
- AI governance frameworks and policy
- AI risk and impact assessment
- Responsible AI controls and evidence
- Technology governance for boards
One process, seven steps
Every practice runs the same seven step shape. Only the obligation set changes.
Triage
Read the contracts, legislation, or adoption plans that apply, and their dates.
Scope
The smallest defensible boundary of systems, people, and locations.
Assess
Gap assessment against the control set your obligation names.
Build
Remediation sequenced by deadline. Your team implements; we verify.
Evidence
A record behind every control, assembled as the work happens.
Attest or Certify
Enter the assessment prepared, with nothing improvised.
Maintain
Renewal clocks and obligation changes tracked between assessments.
Governance & Compliance Review
Latest developments in Canadian cybersecurity certification, AI governance, and regulatory compliance.
OpenAI Halts Its Largest Frontier Training Run After Internal Models Approach Critical Cyber Capability
The upcoming Astra model may reach the top cyber capability tier of OpenAI's Preparedness Framework, so the company paused its flagship training run, hardened research clusters, and added token level monitoring that raises inference costs by about 20%. AI capability is now a board level cyber risk, not a research topic.
Read more →Medusa Ransomware Tops 500 Victims as an Updated Federal Advisory Flags Exploits Used Before Public Disclosure
The updated CISA and FBI advisory reports more than 200 new victims in a year, heavy targeting of healthcare, and exploits in use up to a week before public disclosure. The defensive bar it sets: patch latency in days, monitored remote access tooling, and exercised response.
Read more →Anthropic Moves Toward Gigawatt Scale Canadian Compute, and the Governance Questions Arrive With It
Job postings for a Canadian compute lead and an Alberta community engagement manager point to a domestic frontier compute buildout, joining Microsoft, OpenAI, and Meta's Alberta plans. Data residency, energy planning, and social licence arrive with it.
Read more →Ready to begin?
Tell us which obligation you are facing, a contract clause, a designation risk, or an AI adoption plan, and we'll schedule a discovery call.
Request a Discovery Call
We'll review your requirements and schedule a consultation.
Request Received
Thank you. We'll be in touch within 24 hours to schedule your discovery call.