Our Insights
Insights and resources
We provide practical articles, regulatory analyses, and guides on cybersecurity, governance, risk and compliance, security architecture, and OT resilience, including CMMC, CPCSC, and industrial security, for complex organizations.

Writing a System Security Plan (SSP) assessors can follow
A useful SSP is not a policy summary. It is a controlled, evidence-based description of the system, its security boundary, and how applicable requirements are implemented in practice.

Securing operational technology without stopping production
Operational technology (OT) controls physical processes, production equipment, and safety functions. Security measures must reduce cyber risk without introducing unacceptable operational or safety risks.

CMMC Phase II suspended: what the pause means for readiness, certification and False Claims Act risk
The government paused the contractual phase-in of Phase II certification requirements. It did not repeal the CMMC program, suspend FAR or DFARS safeguarding clauses.

Navigating CMMC 2.0 and CPCSC: a strategic guide for defence SMEs
These two programs are important for Canadian suppliers in North American supply chains. While CMMC and CPCSC share similar objectives, they are separate programs with different reference standards, assessment methods, and contractual requirements.

Which CMMC level applies to your contracts?
Your required CMMC level is based on the solicitation or contract and the type of information your systems process, store, or transmit. Company size, industry reputation, or informal guidance do not determine your CMMC level.

Evidence that stands up to an assessor
Assessors need sufficient evidence to confirm that a requirement is implemented, applied throughout the defined scope, and functioning as intended.

CPCSC Level 1 is here: what Canadian suppliers should do now
CPCSC Level 1 has been available since April 2026 and may be required for certain defence contracts starting in summer 2026. Suppliers should prepare in advance to avoid last-minute compliance issues.

Where the Controlled Goods Program meets cybersecurity
Controlled goods obligations and cyber certification can apply to the same work, but they answer different compliance questions. A coordinated approach reduces duplication without treating the programs as interchangeable.

The real cost of getting your assessment boundary wrong
A boundary defines more than a network perimeter. It determines which assets, people, facilities, service providers, controls, and evidence become part of the assessment.

CMMC Phase II suspended: what the pause means for readiness, certification and False Claims Act risk
The government paused the contractual phase-in of Phase II certification requirements. It did not repeal the CMMC program, suspend FAR or DFARS safeguarding clauses.

Which CMMC level applies to your contracts?
Your required CMMC level is based on the solicitation or contract and the type of information your systems process, store, or transmit. Company size, industry reputation, or informal guidance do not determine your CMMC level.

Navigating CMMC 2.0 and CPCSC: a strategic guide for defence SMEs
These two programs are important for Canadian suppliers in North American supply chains. While CMMC and CPCSC share similar objectives, they are separate programs with different reference standards, assessment methods, and contractual requirements.

CPCSC Level 1 is here: what Canadian suppliers should do now
CPCSC Level 1 has been available since April 2026 and may be required for certain defence contracts starting in summer 2026. Suppliers should prepare in advance to avoid last-minute compliance issues.

The real cost of getting your assessment boundary wrong
A boundary defines more than a network perimeter. It determines which assets, people, facilities, service providers, controls, and evidence become part of the assessment.

Securing operational technology without stopping production
Operational technology (OT) controls physical processes, production equipment, and safety functions. Security measures must reduce cyber risk without introducing unacceptable operational or safety risks.

Writing a System Security Plan (SSP) assessors can follow
A useful SSP is not a policy summary. It is a controlled, evidence-based description of the system, its security boundary, and how applicable requirements are implemented in practice.

Evidence that stands up to an assessor
Assessors need sufficient evidence to confirm that a requirement is implemented, applied throughout the defined scope, and functioning as intended.

Where the Controlled Goods Program meets cybersecurity
Controlled goods obligations and cyber certification can apply to the same work, but they answer different compliance questions. A coordinated approach reduces duplication without treating the programs as interchangeable.