Skip to content
CyberTECTDigital operations control
All resources

The Digital Governance Council: A Practical Guide to Canadian Digital Standards

Canada has standards, readiness tools and assurance pathways for cybersecurity, AI governance, data and digital sovereignty. This guide explains what the Digital Governance Council offers and where organizations can begin.

Canada is talking more seriously about digital sovereignty, cybersecurity, responsible artificial intelligence and the need to build domestic digital capability. Organizations also need something concrete: standards they can apply, evidence they can retain, and credible ways to demonstrate that their practices are operating as intended.

The Digital Governance Council is helping build that practical layer.

What this guide clarifies

DGC develops Canadian digital-governance standards and provides readiness and assurance pathways. This guide explains what its principal resources do, how they differ from government certification programs, and where a Canadian organization can begin.

What does the Digital Governance Council do?

DGC is a Canadian not-for-profit, member-led organization that brings together participants from government, industry, technology, professional services, research and the non-profit sector. Its work includes coordinating cross-sector initiatives, developing digital-governance standards, and offering assessment, validation and verification pathways.

DGC describes its model through four connected functions:

  1. Convene: Bring Canadian leaders and specialists together around shared digital challenges.
  2. Coordinate: Organize cross-sector initiatives and practical projects.
  3. Codify: Develop standards through the Digital Governance Standards Institute.
  4. Confirm: Assess, validate or verify whether organizations have implemented recognized requirements.

The Digital Governance Standards Institute is an accredited standards development body within DGC. Its catalogue covers cybersecurity, artificial intelligence, data governance, privacy, digital identity, biometrics, digital skills and other areas of digital governance. Published standards are available to download and implement without a purchase fee.

DGC is not a government department or regulator, and its standards are generally voluntary. Voluntary standards can nevertheless become commercially important when they are referenced in contracts, procurement requirements, customer due diligence, insurance reviews or other assurance programs.

The Canadian pathways are related, but they are not the same thing

The language around standards, readiness, validation and certification can become confusing quickly. These distinctions matter.

Resource or program What it is What it is not
CAN/DGSI 104 A Canadian standard specifying baseline cybersecurity controls for small and medium-sized organizations. It is not, by itself, certification or proof that an organization has implemented the controls.
CyberReady DGC validation or verification against CAN/DGSI 104. Successful organizations receive a statement and associated Trustmark. It is not the federal CyberSecure Canada certification program.
CyberSecure Canada A federal certification program designed to help small and medium-sized organizations demonstrate baseline cybersecurity practices. It is not a DGC program and should not be confused with CyberReady.
CPCSC The Government of Canada’s cyber security certification program for defence-related contracting and supply chains. Level 1 became available in April 2026. It is not CAN/DGSI 104 or CyberReady. Although it aligns with the American CMMC program, it is Canada’s own certification system.
DGC practical guide for CAN/DGSI 104 and CPCSC Level 1 A free resource mapping areas of CAN/DGSI 104 to CPCSC Level 1 readiness and possible evidence reuse. It is not official CPCSC direction and does not replace contract clauses, CanadaBuys instructions or Government of Canada requirements.
CyberDefence Ready A DGC independent validation or verification review against CPCSC Level 1 requirements. It is not official CPCSC certification.
123 AuditPrep A preparation tool for organizing policies, control implementation and evidence for supported requirements. It is not an audit result, validation, verification or certification.

An organization needs to know whether it is using a standard for internal improvement, preparing for a customer or procurement requirement, seeking independent verification, or pursuing a formal certification program. Those goals require different evidence and different authorities.

A useful starting point for Canadian small and medium-sized organizations

For many Canadian SMEs, CAN/DGSI 104 is a practical place to begin.

The standard sets out baseline cybersecurity controls for organizations that typically have fewer than 500 employees. It gives owners and managers a structured way to examine governance, access, protection, monitoring, response and recovery without assuming the organization has a large security department.

The value is not in downloading a standard and placing it in a policy folder. The value comes from connecting each requirement to four things:

  1. Responsibility: Who owns the control?
  2. Implementation: What process or technical measure is operating?
  3. Evidence: What record demonstrates that it is being followed?
  4. Review: How will the organization know when the control needs to change?

This evidence-focused approach is central to DGC’s current cyber-resilience work. Organizations may already have many necessary safeguards, but often struggle to define them consistently, document the process and retain evidence that can be reused across customer, procurement and assurance requests.

Organizations preparing for federal defence-supplier requirements should also use the official CyberTECT CPCSC Level 1 guide alongside current Government of Canada instructions.

Canadian standards extend beyond cybersecurity

DGC’s work is broader than one cybersecurity baseline.

Responsible artificial intelligence

DGC’s responsible AI adoption initiative connects standards, education, implementation and assurance. CAN/DGSI 101 addresses minimum requirements for the ethical design and use of artificial intelligence by small and medium-sized organizations.

Digital sovereignty and economic security

The digital sovereignty and economic security initiative addresses the authority and dependencies surrounding data, cloud services, infrastructure, contracts and technology supply chains.

Digital sovereignty is not determined by server location alone. Organizations also need to understand who can access, alter, operate or withdraw the systems and data on which they depend.

Data, identity and digital trust

The wider DGSI standards catalogue includes work on data governance, privacy and access control, digital credentials, biometrics, health information, digital trust and other emerging issues. Organizations can use the catalogue to find published standards, follow work in development, and participate in technical committees or public reviews.

Supporting Canadian standards does not require Canada to isolate itself from international technology or global standards. DGC’s approach emphasizes Canadian capability while supporting interoperability and cooperation across borders. The objective is to ensure Canadian organizations have a meaningful role in defining the requirements that affect their technology, data and economic security.

Why standards literacy belongs in cybersecurity education

Cybersecurity education understandably gives significant attention to networks, systems, threats, tools and technical controls. Employers also need graduates who understand how those controls connect to governance, procurement, contracts, evidence and organizational accountability.

Canadian standards create opportunities for applied learning. Students can work through questions such as:

  • How does a written requirement become a technical or operational control?
  • What evidence demonstrates that the control is functioning?
  • Who should own and review it?
  • What is the difference between implementing a standard and being independently verified or formally certified?
  • How do Canadian procurement, sovereignty and supply-chain concerns change the risk discussion?

Working with an actual Canadian standard helps students see that cybersecurity is not only about finding and fixing technical weaknesses. It is also about establishing responsibilities, making defensible decisions and demonstrating that safeguards continue to operate.

That matters for large employers, but it is especially important for graduates who will support small businesses, municipalities, non-profits and rural organizations where the same person may need to translate between technology, management and service providers.

Where should an organization begin?

The right starting point depends on why the organization is looking at standards.

The goal does not have to be immediate certification. For many organizations, the first useful result is a clearer picture of responsibilities, gaps and evidence.

Why CyberTECT is publishing this resource

Canadian businesses and community organizations are often directed first to American frameworks, international standards or vendor-created checklists. Those resources can be valuable, but Canadian organizations should also know that Canadian standards, readiness tools and assurance pathways already exist.

CyberTECT’s role is not to replace the Digital Governance Council or speak on its behalf. As Ontario’s Rural & Small Business Digital Risk Partner, our role is to help make credible Canadian resources easier for small and rural organizations to find and understand.

For authoritative requirements, current program status and assessment options, always consult the Digital Governance Council, the Standards Council of Canada and the applicable Government of Canada program.

Frequently asked questions

Is the Digital Governance Council part of the Government of Canada?

No. DGC is a Canadian not-for-profit, member-led organization. Its Digital Governance Standards Institute is an accredited standards development body, and some DGSI publications are National Standards of Canada.

Are DGC standards mandatory?

They are generally voluntary unless a law, regulation, contract, procurement requirement or other program incorporates a standard or requires evidence against it.

Does following CAN/DGSI 104 make an organization certified?

No. Implementing a standard is different from undergoing validation, verification or certification. DGC offers CyberReady reviews against CAN/DGSI 104, while CyberSecure Canada is a separate federal certification program.

Does CyberDefence Ready provide CPCSC certification?

No. It provides an independent DGC review and statement against CPCSC Level 1 requirements. Organizations pursuing CPCSC must continue to follow official Government of Canada and procurement instructions.

Can small organizations use DGC standards without pursuing an assessment?

Yes. Published DGSI standards are available for organizations to download and implement. An organization can use a standard to structure internal improvement before deciding whether independent assessment is necessary.

Related CyberTECT resources

Official resources

Disclosure: The author has volunteered subject-matter expertise in support of Digital Governance Council conformity-assessment activities. DGC did not commission, review or endorse this article. CyberTECT does not issue DGC validations, verifications, Trustmarks or certifications.

Using this guidance

CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.

Discover more from Cybertect

Subscribe now to keep reading and get access to the full archive.

Continue reading