Coverage
Canadian cybersecurity and privacy coverage included in this version.
The page is written for security leaders, privacy owners, founders, operators, and CISOs who need a practical first pass before calling counsel, preparing a board briefing, or answering customer diligence. It does not try to replace legal review. It helps you ask sharper questions before the meeting.
PIPEDA, BC PIPA, Alberta PIPA, and Quebec Law 25
The questionnaire checks for federal PIPEDA signals and then separates the province-specific laws: British Columbia's BC PIPA, Alberta PIPA, and Quebec Law 25. It also calls out when more than one privacy law may need validation because data crosses borders, vendors are involved, or the company is federally regulated.
Privacy breach reporting and health privacy
The tool flags privacy breach reporting, breach recordkeeping, regulator notice paths, and provincial health privacy analysis when personal, employee, health, biometric, government ID, or youth information is selected.
Bill C-8 and Critical Cyber Systems Protection Act readiness
The critical infrastructure signals cover Bill C-8, the Critical Cyber Systems Protection Act, designated operators, critical cyber systems, cyber program duties, incident reporting, and vendor risk flow-down for suppliers to critical infrastructure.
Canadian Program for Cyber Security Certification (CPCSC)
The defence and specified government information signals flag CPCSC and the need to confirm whether Level 1 certification or other cyber clauses appear in select defence contracts.
CASL, OSFI Guideline B-13, CIRO, PCI DSS, and sector obligations
The questionnaire separates anti-spam and software consent requirements, federally regulated financial institution expectations, investment dealer incident reporting, card payment requirements, and energy or operational technology signals.
CCCS Baseline Cyber Security Controls
Every result includes the CCCS Baseline Cyber Security Controls as a recommended baseline so smaller teams still leave with a practical control starting point while they validate stricter requirements.