Independent assessment and certification for information security, AI governance, and cybersecurity.
Laws create obligations. Standards provide the management system. Certification provides independent evidence. This is the map.
The scope of accreditation applied for covers the certifications most relevant to technology organizations. For standards beyond those listed, contact us.
Third-party certification of your ISMS. Risk-based approach to protecting information assets through governance, controls, and continuous improvement. Annex A controls span organizational, people, physical, and technological domains.
Certification for organizations developing, providing, or using AI. Governance, risk management, lifecycle controls, responsible AI, and monitoring. First certifiable international AI standard.
Government of Canada baseline cybersecurity for SMEs, certified against CAN/DGSI 104:2021 / Rev 1:2024 at Level 1 or Level 2. The requirement areas cover leadership, accountability, cyber security training, risk assessment, incident response, patching, security software, secure configuration, strong user authentication, backup and encryption, perimeter defences, access control and authorization, secure mobility, secure cloud and outsourced IT services, secure websites, secure portable media, point of sale and financial systems, and security log management.
Searchable reference across the Canadian technology regulatory landscape. Our chatbot can answer detailed questions on any item listed.
What AICT certifies. AICT offers management system certification to ISO/IEC 27001, ISO/IEC 42001 and CyberSecure Canada only (see Programs). Every other entry in this library is reference material to help you place those programs in context; AICT does not certify against it.
Information Security Management System. Risk-based controls, governance, and continuous improvement. Three-year certification cycle.
AI Management System. Governance, risk, lifecycle controls, responsible AI, and monitoring. First certifiable AI standard.
Government of Canada SME cybersecurity certification against CAN/DGSI 104:2021 / Rev 1:2024, Level 1 or Level 2. Certification through SCC accredited certification bodies.
Governs private-sector commercial activities. Consent, safeguards, breach notification, accountability. Applies where no substantially similar provincial law exists.
BC PIPA, Alberta PIPA, and Quebec Law 25. Each substantially similar to PIPEDA for intra-provincial activities. Law 25 adds enhanced breach rules and mandatory PIAs.
Artificial Intelligence and Data Act (AIDA) and the AI and Data Companion Regulation (AIMS) under Bill C-27. Would regulate high-impact AI systems. Not yet enacted. Maps to ISO 42001.
Privacy information management extension to 27001. Maps controls to PIPEDA and GDPR requirements.
Cloud security controls (27017) and cloud PII protection (27018). Both extend 27002 for cloud environments.
Control implementation guidance (27002) and risk management processes (27005). Supporting standards for 27001 certification.
Business continuity management (22301) and IT service management (20000-1). Additional management system standards for technology organizations.
Federal public-sector privacy. Collection, use, disclosure constraints for government institutions. Access and correction rights.
Identify, Protect, Detect, Respond, Recover. Voluntary framework. Maps to ISO 27001 controls.
AI risk management (Govern, Map, Measure, Manage) and international AI governance principles. Voluntary reference frameworks.
Attestation report based on Trust Services Criteria. Issued by CPA firms. Not a certification. Primarily North American.
Risk-based AI regulation. Prohibited, high-risk, limited, minimal categories. International reference point for AI governance.
Prioritized security controls by maturity (CIS) and IT governance framework (COBIT). Complementary to management system standards.
Structured, transparent, independent. Click each stage to read what happens, from the first enquiry to the end of certification.
Structural separation between assessment and decision functions. Two-year cooling-off period for prior consulting relationships. AICT's two Directors also hold roles in a related advisory corporation, Ascio Consultancy Incorporated, operating as ascio and as Unlock Solutions, and AICT does not certify any organization that corporation advised within the preceding two years. Conflict-of-interest screening on every engagement.
Certification decisions are made by a Certification Decision Maker who did not take part in the audit, on the audit report, the evidence of corrective action and the recommendation of the audit team. This separation is a non-negotiable accreditation requirement.
AICT does not provide consulting, implementation, or advisory services. This separation is a structural requirement of ISO/IEC 17021-1, not a policy choice.
Formal processes with defined timelines, independent review, and escalation paths. Open to any person or organization. Submit complaints to complaints@aictglobalservices.com or appeals to appeals@aictglobalservices.com.
AICT has not yet issued any certificate: no certificate is issued before the Standards Council of Canada grants accreditation. Once certificates are issued, this register lists each certified organization with its standard, scope, certificate number and status, and is updated on issuance, suspension or withdrawal.
Access AICT's public disclosure documents. These policies are maintained as part of our quality management system.
Whether exploring certification for the first time or looking for a technology-focused alternative, we will help you understand scope, timeline, and requirements.