💡 Articles published on this website summarize publicly available information, industry research and educational materials.
Security and Compliance Certifications
| Certification | Type | Issuing Body | Scope | Renewal / Maintenance | Canadian Recognition |
|---|---|---|---|---|---|
| ISO 27001 | Organizational | Accredited CB (via ISO) | Information security management system | 3-year cycle; annual surveillance audits | Widely recognized across sectors |
| SOC 2 Type II | Attestation Report | Licensed CPA Firm | Service organization controls | Annual audit period | Expected by enterprise customers of cloud services |
| Common Criteria (EAL) | Product | National accredited labs (CSE in Canada) | IT product security evaluation | Per product version; maintenance evaluation for updates | Required for government and defence procurement |
| PCI DSS v4.0 | Organizational / System | Qualified Security Assessor (QSA) | Payment card data handling environments | Annual assessment | Mandatory for payment card acceptance and processing |
| CSA STAR | Cloud Provider | Cloud Security Alliance | Cloud security controls (based on CCM) | Annual re-attestation or certification | Referenced in cloud procurement evaluations |
Professional Certifications in Compliance and Security
| Certification | Issuing Body | Domain | Experience Requirement | CPE Requirement | Canadian Relevance |
|---|---|---|---|---|---|
| CISSP | (ISC)² | Information security management | 5 years in 2+ CBK domains | 120 CPE over 3 years | High — widely required for security leadership roles |
| CISM | ISACA | Information security management | 5 years in information security management | 120 CPE over 3 years | High — valued in regulated industries |
| CISA | ISACA | IT audit, control, assurance | 5 years in IT auditing | 120 CPE over 3 years | High — standard for IT audit and compliance roles |
| CIPP/C | IAPP | Canadian privacy law | None (exam-based) | 20 CPE per year | Specific to Canadian privacy practice |
| CRISC | ISACA | IT risk management | 3 years in IT risk management | 120 CPE over 3 years | High — valued for risk-focused compliance roles |
| ISO 27001 Lead Auditor | Various (PECB, BSI, etc.) | ISMS audit | Varies by provider | CPD requirements vary | Relevant for compliance and audit roles |