Home/ CAN/DGSI 104 Certification
Services · Compliance

CAN/DGSI 104 certification support (CyberSecure Canada)

The Canadian standard built for SMEs. Without the pitfalls. Sentrix helps you choose the right level (1 or 2), close your gaps, and prepare for the certification audit — with effort proportional to your size, and keeping verification independent: we prepare, we do not certify.

What is CAN/DGSI 104 and CyberSecure Canada?

CAN/DGSI 104 is a Canadian national standard published by the Digital Governance Standards Institute (part of the Digital Governance Council). It establishes a practical baseline of cybersecurity controls specifically designed for organizations without a dedicated security team. The standard specifies 18 main controls (55 sub-controls), spread across domains such as governance, risk assessment, technical protection, training, backups, and incident response.

This standard is the foundation of the CyberSecure Canada program: implementing CAN/DGSI 104’s controls is how an organization earns certification, issued by a third-party certification body accredited by the Standards Council of Canada (SCC) under ISO/IEC 17021-1.

The current version is CAN/DGSI 104:2021 / Rev 1:2024, which notably clarified the distinction between Level 1 and Level 2 across several domains (training, risk assessment, incident response plan, secure configuration, backups, and cloud/outsourced IT services).

18 main controls

(55 sub-controls)

2 levels

Level 1 (baseline) and Level 2 (strengthened posture).

Built for SMEs

Proportional to your size.

Third-party certified

Accredited by the SCC (ISO/IEC 17021-1).

Valid 2 years

With maintenance over the cycle.

Current version

CAN/DGSI 104:2021 / Rev 1:2024

Level 1 or Level 2: which should you aim for?

The standard provides two levels of requirements. The right choice depends on your current maturity, your customers, and your contractual obligations — not a sales preference.

Level 1 — Fundamental baseline

A cybersecurity baseline ideal for an SME structuring its security for the first time. The audit is generally lighter (mainly documentary review). It is often the right starting point to build solid foundations.

Level 2 — Strengthened posture

Level 2 requirements add to Level 1’s as your organization gains maturity. It is generally required when your customers or the federal government ask for more robust assurance. The audit includes a deeper verification of implementation.

Sometimes the best strategy is to aim for Level 1 now, then Level 2 at the next cycle. We help you decide.

Preparing without certifying: our independence commitment

This rule protects the value of your certification: whoever supports you should not be the one who certifies you. We structure your process, implement controls, and prepare you for the audit — but the certification body remains a third party accredited by the Standards Council of Canada, chosen by you. We can present you with several accredited options, with no commercial relationship with any of them.

Who this support is for

CAN/DGSI 104 was designed for small and medium Canadian organizations across all sectors that depend on technology to operate and manage their data.

  • Canadian SMEs who want a cyber certification sized to them, without aiming for ISO 27001 right away.
  • Companies receiving security questionnaires from corporate clients who want to answer with a federally recognized framework, without bearing the cost of ISO 27001.
  • Professional services providers (accountants, lawyers, consultants, agencies) who handle sensitive client information and want to demonstrate a measurable cyber posture.
  • Clinics, medical offices, and health organizations that hold sensitive information and want a pragmatic certification aligned with their maturity.
  • Organizations doing business with the federal government, or targeting tenders where CyberSecure Canada certification becomes an eligibility criterion.
  • SMEs considering ISO 27001 in the medium term looking for a concrete first step — Level 2 is a logical launching pad.

Is this the right time for you?

If you recognize your situation in any of the following, this support is designed for you.

  • A corporate client requires a recognized cyber certification, but ISO 27001 is out of budget or out of timeline.
  • You regularly fill out client security questionnaires and want a certification that answers the essentials once and for all.
  • You are torn between Level 1 and Level 2 and want an outside opinion to decide, not a salesperson pushing the pricier option.
  • You saw “CyberSecure Canada” in a tender or federal contract and want to understand what is actually being asked.
  • Your cyber insurer is starting to ask for more than a questionnaire: they want a formal certification or attestation.
  • You are already compliant with Law 25 and want to leverage that work to get CAN/DGSI 104 without starting from scratch.
  • You want a certification valid for two years, with effort proportional to your size — not a project that monopolizes the organization for months.
  • You are mixing up CAN/DGSI 104 (CyberSecure Canada) with CPCSC (the program for Defence suppliers) and want to know which applies to you.

What the standard covers: a defence-in-depth approach

CAN/DGSI 104 promotes a defence-in-depth approach: multiple layers of protection working together to cover people, devices, accounts, networks, and data. The controls group around the following domains:

Governance and security policies

Clear policies defining acceptable use, password requirements, and incident procedures.

Asset inventory

A register of the devices, systems, applications, and data in your environment.

Identity and access management

Role-based access, multi-factor authentication, and strong password policies.

Endpoint security

Malware protection, encryption, and monitoring of workstations and mobile devices.

Patch and vulnerability management

Regular updates of systems and applications.

Email security

Filtering, anti-phishing, attachment scanning, and domain authentication.

Training and awareness

Programs to help staff recognize phishing and social engineering.

Backup and recovery

Secure backups and regular restoration testing.

Network security

Firewalls, secure remote access, and network activity monitoring.

Threat monitoring and detection

Logging and detection of suspicious activity for a rapid response.

Incident response plan

A clear process to detect, report, contain, and resolve incidents.

Cloud and outsourced IT security

Secure configuration and monitoring of cloud services and providers.

Thematic grouping of the standard’s 18 controls (55 sub-controls), presented for readability; the official enumeration is found in the text of CAN/DGSI 104:2021 / Rev 1:2024.

What you get

A clear level recommendation

A Level 1 or Level 2 choice justified by your operational reality, your clients, and your contractual obligations — not a sales preference.

A full gap analysis

A comparison of your current posture against the requirements of the chosen level, with an action plan prioritized by risk.

The required policies and procedures

The documents and records required by the standard, written and adapted to your reality — not generic copy-pasted templates.

Implementation of missing controls

Working with your IT team or MSP, putting in place the required technical controls: multi-factor authentication, tested backups, access management, monitoring, and more.

A documented internal audit

An internal audit conducted before the certification audit, to avoid unpleasant surprises on the day (a prerequisite, notably for Level 2).

An organized evidence file

Your documents structured to the certification body’s expectations, ready in the right place — not a scramble on audit day.

Support during the audit

Support during the audit conducted by the accredited body of your choice: preparing teams, translating questions, managing any non-conformities.

A 2-year maintenance plan

Monitoring changes to the standard, preparing recertification, and adjusting as your environment evolves (new systems, employees, contracts).

Our approach, step by step

A rigorous, transparent approach, proportional to your size.

1. Assessment and level selection
We determine which level is right for you by examining your business context, contractual obligations, and current maturity. Sometimes the right answer is to aim for Level 1 now and Level 2 at the next cycle.
2. Gap analysis
We map your current posture against the requirements of the chosen level: what is already in place and documentable, what is missing, what needs realigning. Deliverable: a prioritized gap report and a clear recommendation on the achievable timeline.
3. Control implementation
We implement missing controls with your IT team or MSP, guided by one principle: every control must be lived, not just documented. MFA that exists on paper but is not enabled on critical accounts is not a control. The NIST CSF framework helps prioritize by real impact.
4. Documentation and internal audit
We write the required policies, procedures, and records, then conduct a formal internal audit before the certification audit — an outside look that reveals blind spots self-audits miss. This is often where unsupported efforts go off track.
5. Audit support and maintenance
We support you during the audit conducted by the SCC-accredited certification body you chose. Then, over the two-year cycle, we remain available to prepare recertification and adjust the setup as your environment evolves — without locking you into a recurring contract.

Why aim for CAN/DGSI 104

  • Certification at the scale of your SME — effort proportional to your size and resources, without the cost of ISO 27001.
  • A response to market expectations — answer client security questionnaires, supply chain requirements, and cyber insurer requests with a recognized framework.
  • Better cyber resilience — concretely reduce the risk of ransomware, phishing, and data leaks through a proven baseline of controls.
  • A scalable base — CAN/DGSI 104 shares principles with ISO 27001 and the NIST CSF; Level 2 is a natural launching pad toward a more advanced certification.
  • The trust of your clients and partners — demonstrate a measurable security posture, a differentiator in sectors where trust matters.

Why trust Sentrix with your CAN/DGSI 104 journey

Independence preserved

We prepare, we do not certify. The choice of accredited certification body remains yours, with no commercial relationship on our part.

An honest level recommendation

We recommend the level that is right for your organization, based on your real needs — not the highest invoice.

Controls that are lived, not just documented

We implement controls that are genuinely in place and operational, with the NIST CSF as support to prioritize by real impact.

Proportional effort

An approach calibrated for an SME, that does not monopolize your organization and stays maintainable over the two-year cycle.

Frequently asked questions

Is CAN/DGSI 104 the same as CPCSC?
No. CAN/DGSI 104 / CyberSecure Canada is a national certification mainly aimed at SMEs. CPCSC (Canadian Program for Cyber Security Certification) specifically targets defence sector suppliers and rests on a different standard (ITSP.10.171 / NIST SP 800-171). We quickly clarify which one applies to you.
Is this equivalent to ISO 27001?
No. CAN/DGSI 104 shares principles with ISO 27001 but remains a lighter standard, designed for SMEs. It is generally not accepted as a substitute for ISO 27001 in international contracts. If your client explicitly requires ISO 27001, that is the certification to pursue.
Is it mandatory?
The standard is not a regulatory requirement in itself. But it is increasingly becoming a de facto requirement: corporate clients, public sector contracts, cyber insurers, and supply chain partners are asking for it more and more.
How do you choose between Level 1 and Level 2?
Based on your current maturity, your clients, and your contractual obligations. Level 1 is a baseline; Level 2 adds requirements for more robust assurance. We help you decide, and sometimes the right answer is a phased progression.
How long is the certification valid?
CAN/DGSI 104 certification is valid for two years. We remain available to prepare recertification and maintain the setup in between.
We already did the work for Law 25. Does that speed things up?
Yes. Some of the work done for Law 25 can be reused. The gap analysis identifies what is transferable and what remains to be done, so you don’t start from zero.
Can our MSP run our certification?
An MSP can contribute to technical implementation, but it is preferable to keep verification of implementation independent. We clarify roles from the start to preserve the credibility of the process.
Who issues the certification?
A third-party certification body accredited by the Standards Council of Canada (SCC) under ISO/IEC 17021-1. We prepare you and support you, but we do not issue the certification.
Will the standard change soon?
The current version is CAN/DGSI 104:2021 / Rev 1:2024, published by the Digital Governance Standards Institute. We track updates and build your program on the current version.

Let’s talk about your CAN/DGSI 104 journey.

Whether a client is asking, you’re weighing your options, or just want to check your readiness — a first conversation costs nothing and helps determine the right level and achievable timeline.