Baseline Controls News Resources Glossary About

Canadian Cybersecurity Assessment: What It Is and How to Start

Canadian Cybersecurity Assessment: What It Is and How to Start

A Canadian cybersecurity assessment is a structured way to evaluate your organization's security practices against the Government of Canada's recommended baseline. Unlike generic security checklists, it is tailored to Canadian businesses: aligned with federal guidance, grounded in Canadian regulatory context (PIPEDA, Quebec Law 25, the forthcoming Bill C-8), and focused on the threats that the Canadian Centre for Cyber Security (CCCS) has identified as most relevant to Canadian organizations.

Why Canadian businesses need a Canadian-specific assessment

The threat landscape facing Canadian organizations is not identical to the global average. Microsoft Threat Intelligence documented a financially motivated threat actor, Storm-2755, that specifically geo-targets Canadian users. The Canadian Anti-Fraud Centre recorded over CA$704 million in reported fraud losses in 2025, with investment fraud (CA$351 million), romance scams (over CA$63 million), and job fraud (over CA$50 million) leading the list. The CAFC estimates only 5 to 10 percent of fraud is reported, placing the true annual figure somewhere between CA$3.5 billion and CA$7 billion.

Meanwhile, a 2025 survey by the Insurance Bureau of Canada found that only 48 percent of Canadian SMB owners and decision-makers believed their business was vulnerable to a cyber attack or data breach. The gap between perceived risk and actual exposure is significant.

A Canadian cybersecurity assessment addresses this gap by measuring your organization against a Canadian standard: the 13 Baseline Cyber Security Controls published by the CCCS. These controls are designed specifically for organizations with fewer than 500 employees and apply the 80/20 rule, where a focused set of security measures delivers the majority of the protection.

What the 13 Baseline Controls cover

The Baseline Controls are published as ITSM.10.089 by the Canadian Centre for Cyber Security. They organize cybersecurity into 13 areas:

  1. Incident Response Planning (BC.1): having a documented plan for when an incident occurs
  2. Patch Management (BC.2): keeping software and operating systems up to date
  3. Anti-Malware (BC.3): endpoint protection against viruses and malicious software
  4. Secure Configuration (BC.4): setting up systems securely from the start
  5. Authentication (BC.5): verifying identity, including multi-factor authentication
  6. Security Awareness Training (BC.6): training employees to recognize threats
  7. Data Backup (BC.7): ensuring you can recover from data loss
  8. Mobile Device Security (BC.8): securing phones and tablets
  9. Network Security (BC.9): protecting your network perimeter
  10. Cloud Services Security (BC.10): securing cloud-based tools and data
  11. Web Application Security (BC.11): protecting public-facing websites
  12. Access Control (BC.12): managing who can access what
  13. Portable Media (BC.13): controlling USB drives and external storage

A comprehensive Canadian cybersecurity assessment evaluates your practices across all 13 areas and identifies where the gaps are.

What makes Cybersecurity Canada different

Cybersecurity Canada is a non-profit resource built specifically for Canadian businesses. The free assessment evaluates your organization against all 13 Baseline Controls, takes under 30 minutes, and produces a score, a letter grade, and prioritized recommendations. There is no signup, no email required, and no data collection: your answers remain entirely in your browser.

The assessment is based on the same Government of Canada standards that underpin the federal CyberSecure Canada certification programme. It is not a substitute for professional security consulting or a compliance audit, but it is a practical starting point for any Canadian SMB that wants to understand where it stands.

How to start your Canadian cybersecurity assessment

The process is straightforward:

  1. Set aside 30 minutes. The assessment includes 50 questions. You can pause and resume within 48 hours if needed.
  2. Involve the right people. If you have an IT administrator or managed service provider, have them available to answer technical questions. If you are unsure about a question, selecting "None" is the safest approach.
  3. Complete the assessment. Answer honestly about your current practices. The goal is to identify gaps, not to achieve a perfect score.
  4. Review your results. You will receive an overall score, a breakdown by control area, and specific recommendations for every question.
  5. Prioritize improvements. Focus first on the control areas flagged as highest risk. Even small improvements in authentication, patching, and backup practices can meaningfully reduce your exposure.

What happens after the assessment

The assessment produces a report you can download as a PDF or print. For guidance on interpreting and acting on your results, see How to Use Your Assessment Results.

What if I need a professional cybersecurity assessment in Canada?

The free cybersecurity assessment is a self-guided starting point, but some organizations need a documented, independently verified evaluation. Cyber Unit, the Canadian cybersecurity company that built and maintains Cybersecurity Canada, offers a Professional Security Assessment: analyst-led structured interviews with your team, hands-on review of your systems and configurations across 20+ security areas, and a written report with executive summary and prioritized roadmap. A findings walkthrough session is included, and the assessment is conducted remotely over Zoom or Teams. The free tool on this site remains free with no obligation.

If your organization is ready for a deeper understanding of the 13 Baseline Controls, our guide to Understanding Canada's Baseline Cyber Security Controls provides additional context on each control area, with links to the corresponding pillar pages and related posts.

Take the free assessment

The Cybersecurity Canada free assessment is available now. It takes under 30 minutes, runs entirely in your browser, and gives you a clear picture of where your organization stands against the Government of Canada's recommended security baseline.

Canadian cybersecurity starts with knowing where you are. The assessment is the first step.

Free Assessment

How prepared is your business?

Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.

Check Your Score

Frequently Asked Questions

What is a Canadian cybersecurity assessment?

A Canadian cybersecurity assessment is a structured evaluation of your organization's security posture against the Canadian Centre for Cyber Security's 13 Baseline Controls (ITSM.10.089). It identifies gaps in areas like incident response, patch management, authentication, and data backup, then provides prioritized recommendations based on Canadian federal guidance. Unlike generic security checklists, it is tailored to Canada's regulatory environment and the specific threats facing Canadian businesses.

Who should take a Canadian cybersecurity assessment?

The assessment is designed for Canadian small and medium businesses (SMBs) with fewer than 500 employees. Business owners, executives, IT managers, and operations leaders benefit from understanding where their organization stands relative to the Government of Canada's recommended baseline. Even organizations that outsource IT to a managed service provider should assess their practices, since the business remains accountable for its security posture.

How long does a cybersecurity assessment take?

A self-assessment against the 13 Baseline Controls typically takes under 30 minutes. The Cybersecurity Canada free assessment includes 50 questions covering all 13 control areas and can be completed in a single session. Progress is saved locally in your browser for up to 48 hours if you need to pause.

Is the Cybersecurity Canada assessment free?

Yes. The Cybersecurity Canada assessment is completely free, requires no signup or email, and collects no data. Your answers remain in your browser and are never transmitted. It is a community resource for Canadian businesses, operated by Cyber Unit Security Inc.

What do I receive after completing the assessment?

You receive an overall compliance score (percentage and letter grade), a breakdown by each of the 13 control areas, a list of your top risks, and specific recommendations for every question. The results can be downloaded as a PDF or printed for your records and for sharing with your team or IT provider.

Cite This Page

Suggested citation:

Cybersecurity Canada (2026). Canadian Cybersecurity Assessment: What It Is and How to Start. Retrieved from https://cybersecuritycanada.ca/news/posts/canadian-cybersecurity-assessment-what-it-is-and-how-to-start/

Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.

Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.

How does your organization measure up?

Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.

Take the Free Assessment