The Digital Governance Council has released its "Practical Guide to Using CAN/DGSI 104 to Support CPCSC Level 1 Readiness."
The guidance is geared towards Canadian companies and clarifies how various cybersecurity requirements relate and prepare for defence supply-chain opportunities. It has been described as a "comprehensive crosswalk" between the CAN/DGSI 104, a National Standard of Canada for baseline cybersecurity, and Level 1 of the Canadian Program for Cyber Security Certification, which is the federal government’s cybersecurity certification program for defence suppliers.
The guidance outlines where current controls may support CPCSC Level 1 requirements, where increased specificity or evidence is necessary, and where more requirements must be met. It focuses on 17 control areas that include authentication, access control, patch management, malware protection, network security, external systems, portable media, logging, risk management, and physical security.
The council has released the guide as Canadian suppliers increasingly find themselves in local and global markets with dissimilar cybersecurity expectations. While CPCSC, CAN/DGSI 104 and the U.S. Cybersecurity Maturity Model Certification all aim to enhance cyber hygiene, cyber risk management, and sensitive information protection, all vary in structure and purpose.
“Cybersecurity is increasingly a condition of participating in strategic supply chains,” said Keith Jansa, DGC’s CEO, in a statement. “For Canadian companies, particularly SMEs, the opportunity is to build on the cybersecurity work they have already done.”
CAN/DGSI 104 sets practical criteria for small and medium-sized organizations in areas like governance, risk management, access control, patching, incident response, and secure configuration. Meanwhile, the Standards Council of Canada is the accreditation body of the CPCSC; the Canadian Centre for Cyber Security provides cybersecurity expertise for the program.
Under the SCC conformity assessment program CyberSecure Canada, the council accredits conformity assessment bodies to grant CAN/DGSI 104 certification. DGC CyberReady is a validation and verification program centered on implementation and readiness that independently evaluates the implementation of cybersecurity requirements.
DGC’s CyberDefence Ready Validation & Verification Program narrows its approach to CPCSC Level 1 for organizations seeking participation in defence supply chains. Program participants have their cybersecurity practices independently assessed against CPCSC Level 1 requirements. They also obtain a verification statement that could support internal readiness, supply-chain due diligence, partner discussions, and preparation of evidence for certification or procurement processes.
Nonetheless, CyberReady or CyberDefence Ready verification is not a replacement for CPCSC self-assessment, certification, contractual submissions, or Government of Canada acceptance requirements.
“Certification provides formal recognition against defined requirements. Verification provides independent evidence of implementation and readiness. Making those relationships clearer can make it easier for Canadian companies to demonstrate trusted cybersecurity across customers, markets and supply chains,” Jansa said.
Public Services and Procurement Canada oversees the CPCSC, which is led with National Defence. CPCSC Level 1 debuted in April and has been incorporated into certain defence contracts over the summer.

