Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

ISO 27001 · Public sector & education

ISO 27001 Readiness for Public Agencies & Crown Corporations

Privacy Horizon prepares Crown corporations and public agencies for ISO 27001 certification by building on the ISO/IEC 27002 foundation Ontario's GO-ITS 25.0 already expects of provincial agencies, so work you have already done becomes the scaffolding for a certificate rather than a parallel project. Boards raise it when a lender, insurer or commercial partner wants independent assurance, or when a commercial Crown's RFPs start scoring for it directly.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

Where GO-ITS 25.0 already gives your ISMS a head start

An ISO 27001 information security management system asks you to govern risk formally across people, systems and vendors; for an Ontario agency working from GO-ITS 25.0, much of that governance already exists and mainly needs organizing into the standard's structure.

Controls you're already assessed against

GO-ITS 25.0's requirements for MFA on sensitive processing, threat and risk assessments, pre-production testing and centralized logging map onto Annex A directly, so a gap assessment starts from real coverage, not zero.

Program systems as the asset core

Claims, licensing, case-management and citizen-portal systems form the information assets an agency's ISMS scope statement has to name specifically, rather than describing security in the abstract.

The board and the MOU as governance

ISO 27001 requires visible top-management commitment and internal audit; for a board-governed body, that means writing the CEO's MOU accountability and the audit and risk committee's oversight into the management system rather than inventing new structures.

Vendor and central-provider relationships

Annex A's supplier controls must capture MFT vendors, SaaS platforms and dependencies on providers like Shared Services Canada, documenting assurance even where you cannot choose the provider.

OT scope for utilities and transit Crowns

Operators running SCADA face an early decision on whether operational technology sits inside the certification boundary or is carved out with compensating controls, a scoping call that shapes the whole engagement.

Regulatory map

Why certification fits this niche in particular

Few public-sector bodies can turn a security standard into a market-facing certificate the way agencies and Crown corporations can, because the framework their government already applies is built from the same standard ISO 27001 certifies against.

GO-ITS 25.0's ISO/IEC 27002 foundation

Ontario's baseline security standard is built on ISO/IEC 27002, which means an agency aligning with GO-ITS 25.0 is already working from ISO 27001's own control catalogue, not a competing framework.

Primary source →

The Agencies and Appointments Directive expects alignment

Ontario provincial agencies are expected to align with GO-ITS 25.0 under this directive; certification demonstrates that alignment with evidence an external auditor has tested, not a self-assessment nobody outside IT reads.

Primary source →

FIPPA's safeguards duty wants proof, not intent

Ontario's designated agencies have carried a statutory safeguards duty since the middle of 2025, and a certified ISMS is documented evidence that safeguards were assessed and operated, the exact record an IPC review asks for.

Primary source →

Commercial Crowns answering to markets as well as ministries

Utilities, insurers and lottery corporations run under board governance and an MOU with a minister, but they also answer to lenders, reinsurers and commercial counterparties who read a certificate faster than a government directive.

Positioning ahead of CCSPA designation

With the Critical Cyber Systems Protection Act now law following Bill C-8's mid-2026 Royal Assent, a future designated operator will need a documented cyber-security program, and a certified management system gives a Crown utility or transport body a considerable head start on building one.

Primary source →

What goes wrong

What the certification risk assessment surfaces in agencies

ISO 27001's mandatory risk assessment tends to formalize exactly the exposures Canadian public bodies have already been breached through, which is why the process rarely feels theoretical once it starts.

  • A central-provider dependency nobody had documented

    Global Affairs Canada's incident began in VPN infrastructure operated by Shared Services Canada; a proper asset and supplier inventory forces an agency to name that dependency before an auditor, or an attacker, finds it first.

    Source →

  • File-transfer tooling outside the register

    Nova Scotia's MOVEit breach reached about 100,000 people through a single file-transfer platform, and the kind of asset and supplier inventory ISO 27001 requires is built specifically to catch tools like it before an advisory does.

    Source →

  • Legacy systems carrying decades of records

    An intruder sat undetected inside Toronto Public Library's aging systems for two full months; the asset inventory and lifecycle controls an ISMS demands exist precisely to catch equipment nobody has looked at in years.

    Source →

  • Subcontractor access no one had inventoried

    The IPC's PowerSchool investigation examined how far subcontractor access can extend past the named vendor, precisely the question Annex A's supplier-relationship controls require an ISMS to answer.

    Source →

Our iso 27001 for public agencies & crown corporations

What certification preparation includes for your body

Our specialists lead the engagement and the IS3WARE platform automates the documentation load, so your program and IT teams contribute judgment rather than paperwork.

A modern office building detail
  1. Scope and Statement of Applicability

    We define the certification boundary, decide how OT or subsidiary operations are treated, and draft the Statement of Applicability an auditor and your ministry will both read.

  2. Gap assessment mapped to GO-ITS 25.0

    Current controls are benchmarked against Annex A with your GO-ITS 25.0 posture as the starting point, producing a remediation plan the board can approve rather than a generic checklist.

  3. Control design and implementation

    We build the controls that close the gap alongside your IT team and central or MSP providers, while the platform assembles policies and captures operating evidence as changes go live.

  4. Management-system machinery sized to your body

    Risk methodology, internal audit and management review are set at a cadence a board-governed agency can sustain, folded into existing audit and risk committee meetings rather than added on top.

  5. Mock audit and certification support

    A rehearsal audit conditions your team before the real assessment, and we support you through the certification body's process to the certificate itself.

  6. Ongoing monitoring between cycles

    Continuous evidence capture and surveillance-audit preparation keep the certificate defensible year over year, so the program survives staff turnover and MOU renewal cycles.

How the engagement runs

From GO-ITS 25.0 to a certificate, in stages

The engagement follows the same three-stage model for every client, mapped here onto an agency's existing standard and governance.

  1. Step 1

    Map your baseline to Annex A

    We translate your GO-ITS 25.0 posture, or your province's equivalent, into the ISO 27001 control set, showing exactly where you already meet the standard.

  2. Step 2

    Gap assessment and costed plan

    The mapping produces a sequenced remediation plan with effort estimates, ready for the board or audit and risk committee to approve within the fiscal-year cycle.

  3. Step 3

    Design, implement and capture evidence

    Controls are built with your team while the platform assembles policies and evidence automatically, so certification work does not stall program delivery.

  4. Step 4

    Mock audit, then certification

    A rehearsal audit prepares your people, and we support you through the certification body's assessment stages to the attestation your board and ministry can cite.

What it costs

What ISO 27001 costs turn on for a public body

Certification cost turns heavily on your current coverage of GO-ITS 25.0 or your province's equivalent, whether scope includes OT or stays corporate-only, the complexity of your vendor and central-provider chain, and how the timeline fits your fiscal-year and board-approval calendar.

The certification body's own audit fees are separate and scale with scope and headcount, with surveillance audits recurring in later years. We quote a staged fee once we have seen your current posture and a systems list, rather than guessing at a figure first.

Public Agencies & Crown Corporations: ISO 27001 questions, answered

For most Ontario agencies, yes, precisely because GO-ITS 25.0 is already built on ISO/IEC 27002. Certification does not ask you to adopt a competing framework; it asks you to formalize the risk-assessment and continual-improvement layer around controls you already largely implement, then have an accredited body test the result. Agencies outside Ontario without a comparable baseline face a bigger lift.

Expect a defined scope statement covering your program systems and the network they sit on, a gap assessment that likely finds solid technical controls but thin documentation of risk methodology, internal audit and management review, and a management-system cadence built around quarterly or semi-annual cycles rather than a dedicated team. The IS3WARE platform carries much of the evidence-capture load, so a body this size does not need a compliance hire to sustain it.

Often, yes, and that is frequently the commercial reason a Crown corporation pursues it. Lenders, reinsurers, ministry procurement processes and enterprise counterparties increasingly accept ISO 27001 in place of a lengthy bespoke questionnaire, which shortens due diligence on both sides. Confirm what a specific RFP or partner actually requires first, since some still ask for scope details or supplementary evidence alongside the certificate.

Timeline depends on your starting point and chosen scope, and we will not put a number on it before seeing your posture against Annex A. Agencies already aligned with GO-ITS 25.0 typically move through design and implementation faster than organizations starting from nothing, because the control work is largely in place and effort shifts toward documentation, evidence and the management-system layer.

Not necessarily. Utilities and transit operators can often scope certification to the corporate network and program systems while carving out SCADA and control environments with a clearly documented boundary and compensating controls, provided the Statement of Applicability is honest about what sits outside it. Bringing OT into scope later, once corporate certification is established, is a common and defensible sequencing choice.

Certification is a management system, not a one-time document: expect ongoing internal audits, a management review folded into your audit and risk committee cadence, risk assessment as systems and vendors change, and a surveillance audit before recertification. Ownership usually sits with whoever already carries security or privacy accountability, supported by the platform's automated evidence capture so the certificate does not lapse between MOU renewals.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.