Our Insights

Insights and resources

We provide practical articles, regulatory analyses, and guides on cybersecurity, governance, risk and compliance, security architecture, and OT resilience, including CMMC, CPCSC, and industrial security, for complex organizations.

CPCSC

Navigating CMMC 2.0 and CPCSC: a strategic guide for defence SMEs

These two programs are important for Canadian suppliers in North American supply chains. While CMMC and CPCSC share similar objectives, they are separate programs with different reference standards, assessment methods, and contractual requirements.

CMMC

Which CMMC level applies to your contracts?

Your required CMMC level is based on the solicitation or contract and the type of information your systems process, store, or transmit. Company size, industry reputation, or informal guidance do not determine your CMMC level.

GRC

Evidence that stands up to an assessor

Assessors need sufficient evidence to confirm that a requirement is implemented, applied throughout the defined scope, and functioning as intended.

CGP

Where the Controlled Goods Program meets cybersecurity

Controlled goods obligations and cyber certification can apply to the same work, but they answer different compliance questions. A coordinated approach reduces duplication without treating the programs as interchangeable.

CMMC

Which CMMC level applies to your contracts?

Your required CMMC level is based on the solicitation or contract and the type of information your systems process, store, or transmit. Company size, industry reputation, or informal guidance do not determine your CMMC level.

CPCSC

Navigating CMMC 2.0 and CPCSC: a strategic guide for defence SMEs

These two programs are important for Canadian suppliers in North American supply chains. While CMMC and CPCSC share similar objectives, they are separate programs with different reference standards, assessment methods, and contractual requirements.

GRC

Evidence that stands up to an assessor

Assessors need sufficient evidence to confirm that a requirement is implemented, applied throughout the defined scope, and functioning as intended.

CGP

Where the Controlled Goods Program meets cybersecurity

Controlled goods obligations and cyber certification can apply to the same work, but they answer different compliance questions. A coordinated approach reduces duplication without treating the programs as interchangeable.