Skip to content
CyberTECTDigital operations control
Frameworks & official guidance

Go directly to the source behind better digital-risk decisions.

This library connects Ontario small businesses, professional offices and community organizations to the official cybersecurity, AI governance, continuity and digital-governance material most relevant to practical operations.

Start with outcomes, priorities and controls that fit the organization.

These resources help leadership organize cybersecurity risk, identify practical safeguards and connect day-to-day controls to wider governance and resilience objectives.

Canada · Small organizationsOfficial guidance

Canadian Centre for Cyber Security Baseline Controls

A Canadian starting point designed for small and medium organizations seeking proportionate improvements in cyber resilience.

  • Incident planning, authentication and awareness
  • Backups, cloud services and access control
  • Security priorities scaled for smaller organizations
Open the official Cyber Centre guidance
Canada · National standardEdition 1.1

CAN/DGSI 104 — Baseline Cyber Security Controls

A Canadian national standard specifying a minimum cybersecurity control set for small and medium organizations.

  • Published in 2021, reaffirmed in 2024 and revised in 2026
  • Designed for organizations with fewer than 500 employees
  • Conformity assessment is available through the current programme
Open the official CAN/DGSI 104 page
NIST · Cross-sectorVoluntary framework

NIST Cybersecurity Framework 2.0

A flexible outcomes-based framework organized around Govern, Identify, Protect, Detect, Respond and Recover.

  • Common language for leadership and providers
  • Supports profiles, prioritization and risk communication
  • Applicable across sectors and organization sizes
Open the official NIST CSF 2.0 resource centre
NIST · Small businessQuick-start guide

NIST SP 1300 — CSF 2.0 Small Business Quick-Start Guide

A shorter introduction for organizations with modest or no formal cybersecurity program.

  • Organized around the six CSF functions
  • Practical questions and actions to consider
  • Supplements rather than replaces CSF 2.0
Open NIST SP 1300
CIS · ImplementationVoluntary controls

CIS Critical Security Controls v8.1

A prioritized set of safeguards for defending systems and networks against common attacks.

  • Practical implementation groups
  • Detailed safeguards and mappings
  • Useful after leadership priorities are established
Open the official CIS Controls v8.1 page
ISO · Information securityPaid standard

ISO/IEC 27001:2022

The international requirements standard for establishing, implementing, maintaining and improving an information security management system.

  • Management-system approach to information risk
  • Applicable across organization sizes and sectors
  • Official overview is public; the full standard is generally purchased
Open the official ISO/IEC 27001 page

Choosing between them: Canadian baseline controls and NIST's small-business guide are usually easier entry points for a smaller organization. NIST CSF 2.0 supports wider risk governance, CIS adds implementation detail, and ISO/IEC 27001 is appropriate when an organization needs a formal information-security management system or certification pathway.

Use AI deliberately, with ownership, information rules and human accountability.

These sources support responsible deployment, risk identification, approved-use decisions and management oversight without treating every small organization as an AI developer.

Canada · SME deploymentOfficial toolkit

ISED Toolkit for SMEs Deploying AI

Canadian guidance for small and medium enterprises adopting AI securely, responsibly and in alignment with trustworthy-AI principles.

  • Focuses on organizations deploying AI
  • Addresses risk identification and supplier choices
  • Connects SMEs to international and Canadian resources
Open the official ISED SME AI toolkit
NIST · AI riskVoluntary framework

NIST AI Risk Management Framework 1.0

A cross-sector framework for incorporating trustworthiness considerations into the design, development, deployment and use of AI systems.

  • Organized around Govern, Map, Measure and Manage
  • Supports lifecycle risk discussion
  • NIST is revising the framework, so version status should be checked
Open the official NIST AI RMF page
NIST · Generative AICompanion profile

NIST AI 600-1 — Generative AI Profile

A companion resource to AI RMF 1.0 focused on risks and actions associated with generative AI.

  • Cross-sector generative-AI risk profile
  • Useful for tool, use-case and vendor reviews
  • Supports governance beyond simple acceptable-use rules
Open the official NIST Generative AI Profile
Canada · Privacy regulatorsJoint principles

Principles for Responsible, Trustworthy and Privacy-Protective Generative AI

Joint Canadian privacy-regulator principles for organizations developing, providing or using generative AI.

  • Accountability and lawful authority
  • Data minimization, safeguards and transparency
  • Individual rights and meaningful human review
Open the official Canadian privacy-regulator principles
ISO · AI managementPaid standard

ISO/IEC 42001:2023

The international requirements standard for an artificial intelligence management system used by organizations that develop, provide or use AI-enabled products and services.

  • Policies, objectives and accountable processes
  • Risk and opportunity management
  • Continual improvement across AI use
Open the official ISO/IEC 42001 page

Plan for the organization to keep operating when people, systems or providers are unavailable.

Continuity and incident response overlap, but they are not identical. These sources help organizations define priorities, responsibilities, response actions, recovery paths and testing.

ISO · ContinuityPaid standard

ISO 22301:2019

The international requirements standard for a business continuity management system.

  • Roles, priorities and documented continuity processes
  • Exercises, review and continual improvement
  • Formal management-system and certification pathway
Open the official ISO 22301 page
Canada · ContinuityOfficial guidance

Developing Your Business Continuity Plan

Canadian Cyber Centre guidance for identifying critical operations, dependencies, recovery procedures, roles and plan testing.

  • Business-impact and priority thinking
  • People, assets, suppliers and alternate resources
  • Testing and regular maintenance
Open the official Cyber Centre continuity guidance
NIST · Incident responseCurrent publication

NIST SP 800-61 Revision 3

Current NIST incident-response recommendations integrated with Cybersecurity Framework 2.0 risk-management outcomes.

  • Preparation across Govern, Identify and Protect
  • Detection, response and recovery integration
  • Supersedes Revision 2
Open NIST SP 800-61 Rev. 3
Canada · RansomwareOfficial playbook

Canadian Cyber Centre Ransomware Playbook

Operational guidance for preparing for, responding to and recovering from ransomware incidents.

  • Backups and recovery priorities
  • Incident roles and communications
  • Supplier and operational dependencies
Open the official ransomware playbook

Some programs are optional. Others apply only when a contract or sector brings them into scope.

Do not treat a voluntary framework as law or assume a procurement requirement applies to every business. Scope must be established before anyone claims compliance, readiness or certification.

01 · VOLUNTARY

CyberSecure Canada

A Canadian certification program based on baseline controls. Certification requires the current program process and does not result from a normal CyberTECT review.

02 · CONTRACT-DRIVEN

CPCSC Level 1

Available since April 2026 and introduced into select defence contracts beginning in summer 2026. Level 1 uses an annual self-assessment against 13 controls.

03 · EVIDENCE

Keep proof

Policies alone do not establish implementation. Account lists, access reviews, training records, configurations and test evidence may be required.

04 · BOUNDARIES

Confirm scope

Certification, legal compliance, contractual requirements and framework alignment are different conclusions and should never be used interchangeably.

Frameworks inform the work. They do not replace evidence or professional judgment.

CyberTECT uses authoritative sources to structure questions, identify reasonable outcomes and explain why a control matters. An engagement is scoped to the organization and does not become a certification audit merely because a framework informed the method.

Reference

An official publication supports a recommendation, definition or practical control objective.

Alignment

Selected work may be mapped to relevant outcomes without claiming complete implementation of the framework.

Validation

Evidence is reviewed or tested to determine what is actually true in the organization.

Information and authoritative sources last reviewed: July 2026. Frameworks, standards and government programs change. CyberTECT reviews the official source before relying on edition-specific or requirement-specific details.

Need help choosing the right starting point?

CyberTECT can connect the business question to the smallest appropriate framework, review or validation without turning a practical problem into an unnecessary enterprise program.