Digital sovereignty and economic security
Help Canadian organizations understand, govern and reduce dependencies that can shift control over data, operations and strategic capability.
Implementation and adoption
Each mission moves from executive dialogue into coordinated work, standards, implementation or verification as the opportunity matures.
Make sovereignty a practical governance discipline for technology, infrastructure, data and procurement decisions.
Hidden dependencies
Cloud, AI, data and platform choices can expose Canadian organizations to foreign laws, operational dependencies and loss of decision-making control.
Standards and executive coordination
DGC connects executive discussion, standards, implementation guidance and assurance so organizations can make informed choices.
Apply the standard
The next opportunity is to apply CAN/DGSI 100-8, document implementation lessons and develop sector-specific guidance and assurance.
Sovereignty is determined by operating choices, not by data location alone
Digital sovereignty cuts across cloud infrastructure, artificial intelligence, distributed technologies, data flows and critical systems.
Organizations need to understand who can access, operate, alter or withdraw the technologies and data on which they depend, including the effects of contracts, supply chains and foreign legal obligations.
- Unclear authority and control across technology supply chains
- Exposure to laws and operational decisions outside Canada
- Limited visibility into data lineage, access and transfer points
- Procurement decisions that do not account for strategic dependencies
Connect sovereignty policy to operational requirements
DGC provides a place to define the challenge, develop common requirements and support practical implementation.
Frame the strategic choices
Bring public and private executives together to examine sovereignty, economic security, infrastructure and market implications.
Connect policy and procurement
Link governance objectives with procurement, contracting, architecture, risk and investment decisions.
Maintain a Canadian standard
Develop and update CAN/DGSI 100-8 as a practical method for identifying assets, threats, foreign-jurisdiction risks and mitigation options.
Build implementation confidence
Develop guidance, assessments and assurance approaches that help organizations demonstrate how sovereignty obligations are managed.
A cross-sector mission
Sovereignty decisions affect both technology operators and the organizations that depend on them.
Government and procurement
Public institutions responsible for policy, procurement, digital services, national security and critical infrastructure.
Cloud and digital infrastructure
Cloud providers, data centres, network operators and organizations that design or operate shared infrastructure.
Regulated and critical sectors
Finance, energy, telecommunications, transportation, health, defence and other strategically important sectors.
Technology and AI
Developers, integrators and users of AI, software, data platforms, distributed systems and emerging technologies.
Legal and risk
Legal, privacy, cybersecurity, procurement and enterprise-risk leaders responsible for contracts and control boundaries.
Standards and assurance
Standards developers, auditors, assessors and conformity assessment bodies supporting implementation.
A practical standard is now available
DGC and DGSI have moved the issue from general debate toward a structured implementation method.
CAN/DGSI 100-8:2026
The second edition provides requirements and guidance for classifying digital assets, developing threat models, identifying jurisdictional risks and selecting mitigation options.
Economic statecraft
Executive Forum discussions connected digital sovereignty with standards, infrastructure, intellectual property, artificial intelligence and long-term competitiveness.
From requirements to practice
The next phase is to support organizations applying the standard across procurement, architecture, contracting and risk management.
Contribute to implementation and sector guidance
Organizations can apply the standard, share implementation lessons, contribute sector-specific scenarios and participate in the development of guidance, assessment methods and verification pathways.
Organizations making consequential technology and infrastructure decisions
This mission is relevant to public procurement, regulated industries, critical infrastructure, cloud and AI providers, legal and risk teams, standards experts and assurance bodies.