Mariners call it taking a fix: verifying that a ship remains on its intended course and, if it’s not, adjusting direction accordingly.
On July 13, the U.S. Department of Defense effectively took a fix when it suspended the second phase of its program to protect sensitive unclassified information. The requirements would have introduced mandatory third-party cybersecurity certification across much of the defence industrial base, though some contractors could still self-assess. Instead, the department ordered a 60-day review.
What the department did not suspend matters more. The current cybersecurity standard for defence suppliers remains the baseline; self-assessments remain in force and the obligation to safeguard sensitive defence information remains enforceable. The Pentagon has not paused cybersecurity; it has paused one way of proving it.
For Canada, which has based its own certification program on the American model, that distinction is important.
Cybersecurity is not the same as certification. Cybersecurity is the goal; certification is one way of ensuring it. Treat them as the same and you risk defending the means instead of the goal. The U.S. has paused. Canada should pause, too, before mandatory third-party certification becomes part of Canadian defence contracts.
Costly third-party certification
The U.S. decision did not emerge in isolation. In March, the Government Accountability Office identified a gap in the department’s planning. It had not assessed how it would manage external factors, including whether the private sector has sufficient capacity to assess cybersecurity. The Small Business Administration identified additional challenges, including the cost of third-party certification (priced at roughly US$205,000 per company above the cost of self-assessment). These findings were enough for the Pentagon to pause. Canada should follow that lead.
The Canadian government announced its own cybersecurity program for defence and federal security contractors in 2023. It was introduced to better protect sensitive defence information and preserve access for Canadian companies to the American defence supply chain. Given these objectives, building on the U.S. model, which appeared to offer significant benefits with relatively little downside, made sense.
What was far less apparent was that certification was not the difficult part. The American program is the result of more than a decade spent building the foundation on which certification depends. The U.S. has established laws and policies about how to classify information, which information requires protection, the cybersecurity standards companies must meet, the organizations to oversee the program and qualified assessors to verify these standards.
Canada’s challenge is therefore not simply developing a certification program. It is trying to re-create, in roughly three years, what the United States built over more than a decade, while at the same time preparing to make certification mandatory.
“Buy Canadian” won’t fix defence procurement until Ottawa defines “Canadian”
The consequences are already visible. Canada is still building the foundations that certification depends on. Before the United States introduced certification, it had already decided what information the program was designed to protect and built the policies and institutions to support it. Canada did not begin with this advantage. Instead, it introduced a new category called “specified information” without explaining how it fits within the security system Canada already had.
Nor has the government identified a single organization responsible for the program. The program’s own evaluation confirms that governance arrangements are still awaiting approval; risk-management tools are incomplete; no pilot contract has been identified; and partner departments have been given responsibilities without dedicated funding.
This is not a criticism of the officials who took up the task nor of the ministers who set it. It reflects the scale of the undertaking.
Beyond the design challenges, Canada has not published data showing how many suppliers will require certification, what it will cost or whether sufficient evaluators exist. For startup companies, even a fraction of the U.S. model’s compliance cost could deter their entry into the defence market. Because U.S. certification also applies to foreign suppliers, Canadian firms operating in both markets could pay twice.
Unresolved questions
The strategic environment that informed Canada’s cybersecurity certification in 2023 has also changed. The government has since created an agency to improve defence procurement and launched its own defence industrial strategy to attract Canadian suppliers. Sovereignty, small-business participation and readiness are now national objectives alongside cybersecurity. Ministers must therefore weigh not one risk, but many.
Cyber threats are only one component of Canada’s overall national risk. Mandatory third-party certification measures more than whether information is protected. It also measures documented policies, governance and administrative measures a business needs to demonstrate compliance. These require resources that small, innovative firms must often devote instead to building capacity and reaching commercial viability. Small- and medium-sized firms may already be safeguarding sensitive information, yet still lack what is needed to be third-party certified.
The result is a policy that is likely to exclude precisely the firms Canada’s defence strategy seeks to attract, delaying or denying innovative capabilities to sailors, soldiers, aviators and special forces operators. It also narrows the defence industrial base and weakens the strategy that depends on both. That is not risk reduced. It is risk increased.
It’s recommended that the government keep current certification standards in place, but hold off on mandatory third-party assessments set for next spring. By the end of 2026, it should determine and publish answers to unresolved questions, such as:
- How many companies will require certification?
- What will it cost?
- Are the program’s foundations solidly in place?
- Are there enough qualified assessors?
- How many small businesses will be affected?
- Does the program support Canada’s defence industrial strategy and help Canadian firms compete in allied defence markets?
Achieving Canada’s cybersecurity objectives
It’s also important that the federal government not make a major industrial decision on the assumption that Canadian certification will automatically be recognized in the United States. That has yet to be established.
The central question is whether Canada’s present program is the best fit for achieving the country’s cybersecurity objectives. If it is, ministers should determine whether mandatory certification should be part of it. If it is not, they should adopt a model best suited to Canada’s strategic objectives and security environment, as sovereign nations do. The current framework already gives ministers that flexibility. They should use it. And the decision should rest on a Canadian analysis — not the findings of the U.S. review.
It would be wise to take the lead of mariners. When indications suggest a ship could be heading into danger, the officer of the watch does not maintain direction and speed — and hope for the best. The ship is stopped, a fix is taken and, once the ship’s position is confirmed, the passage proceeds on the appropriate course.
The United States has stopped to take a fix on its defence cybersecurity provisions. Canada should do the same.

