Where the Controlled Goods Program meets cybersecurity

Controlled goods obligations and cyber certification can apply to the same work, but they answer different compliance questions. A coordinated approach reduces duplication without treating the programs as interchangeable.

Key point: Controlled Goods Program registration does not satisfy CPCSC requirements, and CPCSC certification does not replace Controlled Goods Program obligations.

Two regimes, different purposes

The Controlled Goods Program (CGP) regulates who may examine, possess or transfer controlled goods and controlled technology in Canada. Registrants must appoint a designated official, conduct required personnel security assessments, maintain records, implement site-specific security plans and report security breaches.

The Canadian Program for Cyber Security Certification (CPCSC) focuses on how Specified Information (SI) identified in a contract is protected in non-government systems. Its scope includes the people, facilities, devices, applications, cloud services and other components that handle or protect that information.

The same technical drawing or specification may fall under both regimes when it is controlled technology and is also identified in a contract as Specified Information (SI). That overlap is not automatic: applicability must be confirmed from the Defence Production Act schedule, the organization’s CGP obligations, and the contract’s security clauses and handling instructions.

Where the obligations overlap

The programs are separate, but several operating practices can support both:

  • information and asset inventories that identify sensitive drawings, models, specifications and technical data;
  • access rules that connect personnel authorization, business need and system privileges;
  • training, visitor controls, record keeping and incident escalation procedures;
  • documented responsibilities for security, IT, engineering, operations and management; and
  • evidence showing that controls are applied in practice, not only described in policy.

A single industrial-security framework can therefore reduce duplicated processes. However, shared procedures should retain clear traceability to each program’s specific requirements, owners, records and reporting channels.

Build one operating model, not one compliance claim

1

Classify the information

Identify which files and technical data are controlled goods, Specified Information (SI), both or neither. Do not rely on filenames or markings alone.

2
 

Map where it moves

Include CAD and product-lifecycle systems, email, cloud platforms, removable media, paper records, supplier exchanges and any shop-floor or OT systems that receive the data.

3

Align access decisions

Confirm that personnel authorization under the CGP is matched by appropriate logical and physical access in the relevant systems and facilities.

4

Coordinate security plans

Align the CGP site security plan with cybersecurity policies, incident response, supplier management and evidence-retention processes, while preserving each program’s mandatory content.

5

Test the evidence

Verify that records, access reviews, training logs, system configurations and incident procedures support both compliance obligations and can be retrieved when requested.

Why this matters for defence and manufacturing suppliers

Treating controlled goods, cybersecurity and physical security as unrelated workstreams creates gaps between contracts, people, facilities and systems. Integrating governance gives leadership a clearer view of risk and reduces conflicting procedures. The objective is not to merge the regimes, but to operate them coherently.

Practical takeaway: Use one governance model and one information inventory, but maintain separate applicability decisions, evidence mappings and compliance records for the CGP and CPCSC.