English
CANADIAN CYBERSECURITY STANDARD

Make CAN/DGSI 104 practical for your business.

CAN/DGSI 104 gives Canadian small and medium organisations a clear baseline for cybersecurity.

Sample Readiness Snapshot
38%

Most SMBs already have some controls in place.

12
control areas
2
implementation levels
1
clear action plan
0
guesswork
Built For Canadian SMBs
Managed Implementation Support
Practical, Prioritized Roadmap
What is CAN/DGSI:104?

Canada's first dedicated SMB cybersecurity standard

Developed by the Digital Government Security Institute (DGSI) in collaboration with the Canadian Centre for Cyber Security (CCCS), CAN/DGSI:104 establishes a clear, practical framework.

Unlike enterprise-focused standards such as ISO 27001, CAN/DGSI:104 is built for organisations with 5 to 500 employees.

Adherence is currently voluntary, but is increasingly expected by insurers, government contractors, and supply chains.

🏒
Built for 5–500 employees
Sized and scoped for real SMB operations β€” not stripped-down enterprise frameworks.
πŸ‡¨πŸ‡¦
Canada-specific requirements
Addresses PIPEDA alignment and critical infrastructure considerations unique to Canadian businesses.
πŸ”—
Maps to NIST CSF 2.0
Aligns with globally recognized security controls so your posture is defensible internationally.
πŸ“‹
Insurer & contractor ready
Increasingly expected in supply chains, government contracting, and cyber insurance applications.
The Framework

The standard organises cybersecurity controls across five functional domains, each with tiered maturity levels.

01
Identify
Develop a clear inventory of your assets, data, and systems.
Asset Management
02
Protect
Implement safeguards to ensure delivery of critical services.
Access Control
03
Detect
Develop and implement activities to identify cybersecurity events.
Monitoring
04
Respond
Develop and implement activities to take action on detected incidents.
Incident Response
05
Recover
Develop and implement activities to restore services after an incident.
Resilience
Who It Applies To

Built for every Canadian SMB sector

CAN/DGSI:104 applies across industries.

πŸ₯
Healthcare & Clinics
Patient records, medical devices, and billing systems require the highest care.
βš–οΈ
Legal & Accounting
Professional firms handling confidential client data face strong compliance expectations.
πŸ—οΈ
Construction & Trades
Increasingly targeted via subcontractor networks and payment fraud.
πŸ›’
Retail & eCommerce
POS systems, payment processors, and customer data require protection.
🏭
Manufacturing
Supply chain requirements increasingly include cybersecurity certifications.
πŸ›οΈ
Government Vendors
Federal and provincial procurement mandates CAN/DGSI:104 alignment.
Free Resources

Start your CAN/DGSI:104 readiness assessment today

Our team built a practical, plain-language assessment template. Our team built a practical, plain-language assessment β€” available as a downloadable template or as a guided online assessment.

  • Plain-language assessment template β€” no jargon
  • Maps to all five CAN/DGSI:104 pillars
  • Identify gaps and prioritise what to fix first
  • Download free or complete online β€” no strings attached
πŸ“‹

Get Your Free Assessment Template

Takes 2 minutes Β· No credit card required

πŸ”’ No spam. Your data is never shared.

Why ALCIT

We make Canadian cybersecurity simple for SMBs

We're not a generic IT provider. Cybersecurity for Canadian small and medium businesses is everything we do.

Canadian-First Expertise
Our team holds Canadian cybersecurity certifications and understands the specific regulatory environment.
Built for SMBs
Our programs are sized, priced, and designed for businesses with 5–500 employees.
Framework-Guided Approach
Every engagement is anchored to CAN/DGSI:104 giving you a defensible security posture.
24/7 SOC Monitoring
Our Canadian Security Operations Centre watches for threats around the clock.