Skip to content

Cybersecurity for
defence and aerospace

Certification support for Canadian defence suppliers, and independent refutation testing for aircraft and avionics, military or civilian.

A broader defence and security ecosystem

Canada is making a major, long-term investment in defence, security and national sovereignty. Tens of billions of dollars are committed to modernizing the Canadian Armed Forces, strengthening domestic industrial capacity and developing critical technologies in Canada.

The initiative reaches well beyond traditional military equipment. For organizations entering or expanding in this ecosystem, cybersecurity, supply-chain security and regulatory compliance are increasingly fundamental requirements for protecting sensitive information, intellectual property and critical defence capabilities.

  • Priority areas

    Cybersecurity, artificial intelligence, quantum technologies, secure digital infrastructure, space, autonomous systems, advanced sensing, critical minerals, advanced manufacturing and biomedical technologies.

  • Non-traditional sectors

    Software, cloud, telecommunications, life sciences, semiconductors and other dual-use technologies are also becoming part of Canada’s defence industrial base.

A rapidly evolving cybersecurity landscape

The pace and scale of Canada’s defence investment are reshaping the cybersecurity landscape just as quickly. New programs, technologies and supply-chain expectations are emerging faster than regulations, contractual requirements and technical standards can be defined and harmonized.

That creates real uncertainty for traditional defence suppliers, OEMs, systems integrators and In-Service Support providers, and for the commercial and dual-use technology companies now entering the ecosystem. Knowing which requirements apply, how they relate to one another and what level of cybersecurity maturity will be expected is difficult.

Build the foundation for what comes next

OKIOK helps organizations navigate this changing environment by translating emerging cybersecurity requirements into practical actions. We determine what applies, identify the gaps and set a clear roadmap toward compliance.

Beyond individual requirements, we raise an organization’s overall maturity and put a structured framework in place, aligned with recognized standards such as ISO/IEC 27001, NIST SP 800-53 and ITSG-33. That builds the governance, controls, processes and evidence needed to respond as new defence-sector requirements emerge. It also makes each future certification significantly easier to obtain and maintain.

Cybersecurity requirements are already here

For Canadian defence suppliers, CPCSC Level 1 is now in effect, linking cybersecurity certification requirements to Government of Canada defence contracts, while Levels 2 and 3 are still under development. For aircraft OEMs, avionics manufacturers and system integrators, civilian or military, established airworthiness cybersecurity standards increasingly bring security assurance and independent refutation testing into aircraft certification and major system changes.

CPCSC certification readiness

The Canadian Program for Cyber Security Certification is in effect now for organizations that bid on or perform Government of Canada defence contracts, the whole supply chain, not only prime contractors. The level you need is set contract by contract by the Government of Canada, and stated in the RFP and contract security clauses. OKIOK prepares you for certification and supports you through it; the certification decision rests with the accredited body or DND.

The three levels

  • Level 1Annual cybersecurity self-assessment. 13 controls drawn from ITSP.10.171.
  • Level 2External cybersecurity assessment by an accredited certification body every three years, plus an annual affirmation. 98 controls.
  • Level 3Cybersecurity assessment conducted by National Defence every three years, plus an annual affirmation. 200 controls.

Level 1 is currently available. Levels 2 and 3 are still under development. Once established, the required certification level will be determined on a contract-by-contract basis through a standardized cybersecurity risk assessment.

What OKIOK does

Understand what applies

  • Identification and interpretation of the cybersecurity obligations from ITSP.10.171 and other frameworks that apply to your context
  • Gap assessment against the control set for the level that applies to you

Close the gaps

  • A prioritized remediation roadmap
  • Policies, controls and evidence management fully customized for your environment

Demonstrate

  • Support through the Level 1 assessment, with support for Level 2 external and Level 3 DND assessments as those requirements become available
  • Support for annual affirmations and control upkeep between assessment cycles

At every stage

  • Strategic cybersecurity consulting for engineering, security and management teams

DO-356A / ED-203A airworthiness security testing

For OEMs, integrators and In-Service Support organizations, RTCA DO-356A and EUROCAE ED-203A Airworthiness Security Methods and Considerations are the accepted means of compliance with the cybersecurity airworthiness requirements of the FAA, EASA, Transport Canada Civil Aviation (TCCA) and the Airworthiness Authority (AA). OKIOK provides the independent testing required for meeting the refutation testing objectives at SAL2 and SAL3.

The three refutation objectives

  • O3.1Refutation analyses are performed to identify new vulnerabilities.
  • O3.2Refutation tests are performed to evaluate the exposure of vulnerabilities in the security environment and to challenge the vulnerability evaluation.
  • O3.3Refutation test plans are available; refutation test results cover the test plans and the tests performed.

What OKIOK does

Understand what applies

  • Identification and interpretation of the cybersecurity obligations from DO-356A / ED-203A, DO-326A / ED-202A and DO-355A / ED-204A that apply to your work
  • Gap assessment against the standards at the required SAL level

Close the gaps

  • A prioritized remediation roadmap

Demonstrate

  • Refutation testing of avionics components and systems to Security Assurance Levels SAL2 and SAL3
  • Offensive security testing of avionics systems and ancillary technologies to identify exploitable vulnerabilities and assess their resistance to realistic attack scenarios
  • Testing of legacy avionics technologies: ARINC 429, MIL-STD-1553B, RTOS systems
  • Preparation and presentation of a detailed test report covering attack vectors, impacts and severity, the test plans and the tests performed, as O3.3 requires

At every stage

  • Strategic cybersecurity consulting for engineering, security and management teams

A defence and aerospace offer backed by 40+ years of cybersecurity experience

Over the years, we have helped clients assess and improve their cybersecurity maturity and their compliance with the standards and frameworks that apply to them: assessing risk, testing systems, closing security gaps, and proving that their controls work.

ISO 9001:2015 certified by IntertekISO/IEC 27001:2022 certified by Insight AssuranceBureau de la sécurité privée (BSP) licence
  • Work under way in the defence ecosystem

    We are already delivering cybersecurity engagements across the defence and aerospace ecosystem, including for the Canadian Space Agency. We help organizations raise their cybersecurity maturity whether they are entering the sector, adapting to new requirements, or are established suppliers working to achieve or maintain compliance.

  • Decades of certification work

    Preparing organizations for NERC CIP, TGV, PCI DSS, ISO/IEC 27001 and SOC 2.

  • ISO 9001 and ISO/IEC 27001 certified, SOC 2 Type 2 for our SaaS solutions

    Our own compliance program keeps controls operating between assessments and evidence ready on demand.

  • 2,500+ penetration tests

    Refutation testing is a specialized penetration test, and that is the practice behind it.

  • Active in Canada’s defence and cybersecurity industry

    As a member of CADSI and In-Sec-M, OKIOK actively contributes to strengthening Canada’s defence industrial base, cyber resilience and sovereign cybersecurity capabilities.

Start from where you are

Know what applies. Know what’s missing. Know what to do next.

Send us a message

Only your email is required. Pick a subject, add a note, and send.

Incident in progress? Call the 24/7 line instead of waiting for a reply: +1 450 681-1681, extension 277