See the whole path
An unofficial list of the approvals and duties a GC digital service has to pass
The official checkpoints a Government of Canada digital service can meet, by topic, with what brings each one into scope and what the business owner personally has to do about it. One appendix lists what is already built and can be reused. A second follows one invented service from its first sign of trouble to the day it is replaced, meeting the checkpoints in the order that service met them.
1.What this page covers
The official checkpoints only: the formal approvals, reviews, sign-offs and standing duties that come from Government of Canada instruments. Each one gets what it is, what pulls it into scope, and what the business owner personally has to do. It does not cover how to do the work inside each step, which is what the phase and sub-phase pages are for. Read it as the list to check your own service against.
2.How to use this page
- To find out what applies to your service, read the tables. There is one table per topic, and a row for each official instrument a Government of Canada digital service can meet. Start with the topics that match what your service does, read down the scope column, and rule out what does not apply to you.
- To get a feel for the order and the people, read Appendix B. It follows one invented service from the first sign of trouble to the day it is replaced, showing what its director general does at each step and who answers. It is a worked example of one route through these tables, and no two services take the same one.
- To understand a single instrument properly, follow it to its thread page. Security, privacy, accessibility and procurement each have a page of their own in the guide that explains the reasoning. This page is the index; the thread pages carry the explanation.
3.Nearly everything here varies
The checkpoints themselves are real and they are set out in Government of Canada instruments. Almost everything around them is not fixed. Which ones apply depends on what the service does and how much is being spent. Who chairs a board, what a department's thresholds are, who signs, and how each step is run in practice differ from one department to the next.
Timing varies most of all. Nothing here says how long a step takes, because that depends on the department's capacity, the queue in front of you, and what else is happening that year. Where a duration is given, treat it as one team's experience rather than a planning figure, and confirm it against your own department.
The order varies too. The sequence a service meets these checkpoints in follows the route it takes: buying a finished product, contracting a team, running an agile procurement and building in-house all rearrange them, and some fall away entirely.
4.Glossary
Four things the tables name without giving them a row of their own.
- Departmental investment plan
- The department's list of planned investments, approved by the deputy head. A project has to be on it before it can proceed.
- Capacity class (OPMCA)
- The department's approved project-management capacity, set by an Organizational Project Management Capacity Assessment. If the PCRA level is above it, or the project's value exceeds the department's delegated limit, the project needs Treasury Board approval.
- Contract Security Program
- PSPC screening of the supplier's organization and personnel when the contract involves protected or classified information.
- Personal Information Bank
- The registered description of the personal information the service holds, published in the department's Info Source listing. Created alongside the Privacy Impact Assessment.
5.The official things a service has to do
Split into twelve topics so a reader can go straight to the ones that apply. Every topic opens with what matters most about it, then a table of its instruments. Nothing here is specific to one department or one kind of service.
One table per topic below, and every instrument in them takes two rows. The top row says what brings it into scope, what you personally have to do about it, and who does the rest. The row underneath says what the thing is, and when in the service's life it comes up.
One caution. Which sub-phase an instrument belongs to is this guide's own judgement, because no Government of Canada source uses these phase names. Where a placement follows a real deadline in the instrument, the row says so. Where it does not, the row says that too.
What the tags mean
- CheckFind out whether it applies to this service at all.
- GatherHand over the business judgement only the service team holds. Someone else writes it up.
- FillThe thing is actually produced.
- Sign or acceptA named person puts their name to it, or receives someone else's result and decides what to do about it.
- SubmitSent, filed, registered or published where the rule says.
- Keep currentThe service changed, or the clock came round. Re-run it, re-test it, or refresh the record.
- Close outFormally ended, disposed of, or marked retired.
The one tag that changes whether a row applies to you
- Only ifThis instrument does not apply to every service. The scope column says what brings it into scope. An instrument with no tag applies to all of them.
What kind of thing each one is
- AssessmentWork that ends in a judgement: how bad, how likely, how critical.
- AuthorizationPermission to proceed, signed by a named person who accepts the risk.
- ReviewA board or committee looks at the work and decides.
- SubmissionA document sent up for a decision, usually about money or authority.
- RegisterA record the service is entered in and kept current.
- PlanArrangements written down in advance and tested.
- Standing dutyA standard the service has to meet for as long as it runs.
- FilingSomething sent or published, on a cycle or when an event triggers it.
5.1Security
These four run in order, and each one feeds the next. The categorization decides how large the set of security controls has to be. The threat and risk assessment looks at what could still go wrong once those controls are in place. The Authority to Operate is the signature that lets the service run in production, and for a service that lives inside one department the person who signs it is usually the business owner.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| Security categorization Assessment source | Every service. Three separate requirements point at the same standard: for assets, for information, and for services and activities. The service-level one is part of the business impact analysis requirement. | Makes the judgement about how bad it would be if this information leaked, if someone changed it, or if the service stopped, judging the three separately. | The departmental security team assigns the category, ideally with legal and the access to information and privacy office in the room. |
| What it isA rating of how much injury would follow a leak, an unwanted change to the information, or an outage. It is set on four levels, from low to very high, and the result decides how large a set of security controls the build has to meet.When it comes upDiscovery Gather · Alpha Fill · Growth Keep current · Maturity Keep current | |||
| Threat and risk assessment (TRA) Assessment source also | The activity applies to all information systems that support departmental programs, services or activities. No dollar figure, no user count, no risk score. A standalone report is a different matter: producing one is neither recommended nor required, and the results are meant to go into the ordinary design documents. | Approves the work plan before the assessment starts, and states in advance how much left-over risk is acceptable. Supplies what the service is worth to the business and what it depends on. Accepts or refuses the left-over risk at the end. | A security practitioner works with the system designers during design; a security assessor, often a contractor, assesses the built system. The business owner sits on the assessment team as the program authority. |
| What it isThe exercise that lists what could go wrong, ranks each one by how likely it is and how much damage it would do, and states the risk left over once the safeguards are in place. It covers deliberate, accidental and natural threats alike, so it is wider than a cybersecurity exercise.When it comes upAlpha Gather, Fill · Beta Fill · Growth Keep current · Maturity Keep current | |||
| Physical security assessment and Authority to Occupy Facility (ATOF) Only if Authorization | Only if the service touches physical space: new accommodation, hardware in people's hands, kiosks, or software that operates doors, gates, lighting or heating. A cloud-hosted service with no hardware usually stays clear of it. | Says whether the service touches physical space at all, early enough for the answer to reach the solicitation. | Departmental physical security, using the Royal Canadian Mounted Police (RCMP) assessment guide. |
| What it isThe second security track, running in parallel and covering buildings, equipment and physical space. It uses the same harmonized method as the systems assessment, run by different people and ending in a different signature.When it comes upAlpha Check · Beta Fill, Sign or accept | |||
| Security assessment and authorization, ending in the Authority to Operate (SA&A, ATO) Authorization source | Every information system, before operations commence. Each department defines its own documented practice for how it is done, which is why identical systems get different treatment in different departments. | Gets the conditions for authorization in writing before the design starts, from the departmental security plan or from the authorizer directly. Reads the package and decides: authorize, authorize with conditions, or refuse. | The information technology security team assembles the package; a security assessor, often independent, does the assessment. |
| What it isThe formal permission for the service to run in production. Someone with the authority reads what the security work found, accepts the risk that is left, and signs. For a departmental system that signer is normally the business owner.When it comes upDiscovery Gather, Sign or accept · Alpha Sign or accept · Beta Sign or accept · Growth Keep current, Sign or accept · Maturity Keep current · Sunset Close out | |||
5.2Continuity and incidents
This is about how long the service can be unavailable before it matters, and who is told when something goes wrong. Every service is worth asking the question, because the answer decides whether anything else here applies. The formal requirement for a business impact analysis is narrower than that: it reaches services supporting something critical to the health, safety, security or economic well-being of Canadians, or to the functioning of government. A continuity plan follows only where the analysis marks the service critical. The recovery numbers are worth settling early, because a four-hour limit and a two-week one lead to different designs and different costs.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| Business impact analysis (BIA) Assessment | Every service should answer the question, because the answer is what decides whether anything further is owed. The directive's formal requirement is narrower. It reaches only the services and activities that support the availability of what is critical to the health, safety, security or economic well-being of Canadians, or to the effective functioning of government. Large departments are separately measured on holding an up-to-date analysis for every external and internal enterprise service. | Makes the judgement about who is harmed if the service stops, how fast that harm escalates, and what the service depends on. | The departmental business continuity management specialist, who is also the person responsible for identifying which services are critical. |
| What it isThe exercise that decides how critical the service is, and produces four numbers with it: maximum allowable downtime, minimum service level, recovery time objective and recovery point objective.When it comes upAlpha Gather · Beta Gather · Stabilization Keep current · Growth Keep current · Maturity Keep current | |||
| Business continuity plan (BCP) Only if Plan | Only if the business impact analysis marks the service critical, meaning disruption would cause a high or very high degree of injury. One department reads that as needing to recover to minimum service levels within 72 hours. | Supplies the recovery steps and the workarounds, then tests them. Asks the coordinator where this service appears in the departmental plan, and with what downtime limit. | The departmental or branch business continuity coordinator drafts it on the departmental template. |
| What it isThe written arrangements for keeping a critical service delivering at a minimum acceptable level during a disruption, and recovering it afterwards. There is one plan for the department, and this service either has its own section in that plan or is covered by several.When it comes upBeta Gather · Stabilization Keep current · Maturity Keep current | |||
| Information technology continuity management Plan source | All information systems. Recovery strategies are set in accordance with the department's business continuity requirements, so the recovery targets come down from the business impact analysis and this is where they get met. | Confirms the restore has been tested at least once before launch, and that the build meets the recovery target set by the business impact analysis. | The team running the service, with information technology operations and the hosting provider. |
| What it isThe service team's own recovery arrangements: how this system gets back up, in what order its parts are restored, and proof from testing that the restore works. The departmental business continuity plan belongs to the department; this is the part the team owns.When it comes upBeta Fill · Stabilization Keep current · Maturity Keep current | |||
| Cyber security event response and reporting Plan source | Every service. Departmental plans and procedures for responding to cyber events must operate in accordance with the Government of Canada Cyber Security Event Management Plan, and security events are reported under the security event reporting standard. | Knows before launch who to call and how fast, and passes an incident to them as soon as the team spots one. | The departmental security operations function sets the escalation route, with the designated official for cyber security. The service team detects, contains and supplies the facts. |
| What it isThe duty to have a way of spotting, containing and reporting a cyber incident before one happens, and to report it up the government-wide chain when it does. The government-wide plan sets who is told, in what order, and how an event escalates into a coordinated response.When it comes upBeta Fill · Stabilization Keep current · Growth Keep current · Maturity Keep current | |||
| Material privacy breach report Only if Filing | Only when a breach involving personal information is judged material, on sensitivity of the information, number of people affected, and whether it is a systemic problem. A cyber incident touching personal information can trigger both this and the cyber reporting route at once. | Tells the privacy office immediately what happened and what information was involved. | The access to information and privacy office assesses materiality and prepares the report. |
| What it isThe report a department must make when personal information is lost, accessed or disclosed in a way that could reasonably be expected to cause serious injury. It goes to the Office of the Privacy Commissioner of Canada and to the Treasury Board of Canada Secretariat, and the people affected are notified.When it comes upBeta Check · Stabilization Submit · Growth Keep current | |||
5.3Privacy and automated decisions
The checklist comes first, and it is worth completing even where the answer is that no assessment is needed, because having asked is itself part of the requirement. The automated-decision half applies only if the service decides something about a person without someone making the call, including scoring and ranking. A service can acquire that later, when a feature is added to save time, so it is worth looking again whenever the service changes.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| Privacy checklist and privacy impact assessment (PIA) Only if Assessment source | Triggers are broad. A new or substantially modified program that creates, collects, uses, discloses, retains or disposes of personal information brings it into scope. So does using it for an administrative purpose, contracting the program out or transferring it, bringing in a third party, changing the technology that processes it, or automating a decision. No dollar or user-count threshold. | Completes the checklist, even where the answer turns out to be no. Says what personal information the service will use and which decisions about people it will be used to make. | The program area drafts it on the Treasury Board template; the access to information and privacy office reviews, iterates and owns the instrument. |
| What it isA structured look at what personal information the service collects, why it is allowed to, where it flows, how long it is kept, and what could happen to people if it goes wrong. A mandatory checklist comes first, and it decides whether a full assessment, a lighter privacy protocol, or neither is needed.When it comes upDiscovery Check · Alpha Gather · Beta Fill, Submit · Growth Keep current · Maturity Keep currentThe stand-alone Directive on Privacy Impact Assessment was rescinded on 9 October 2024. The live instrument is Appendix C of the Directive on Privacy Practices. | |||
| Algorithmic impact assessment (AIA) Only if Assessment source also | Only if the service makes or supports an automated decision about a person: scoring, ranking, recommending, or auto-approving. A later efficiency feature can trigger it without anyone noticing. | Fills in the questionnaire, answering from how the program works and what the decision does to people. | The department completes it itself, normally the program team with support from the data or chief information officer function. |
| What it isA scored questionnaire about how much an automated decision could affect a person's rights, health or economic interests, or the ongoing sustainability of an ecosystem. The score sets what the service then owes on explanation, human involvement, testing and recourse.When it comes upAlpha Check · Beta Fill, Submit · Growth Keep current · Maturity Keep current | |||
5.4Accessibility
Two related duties. A supplier's conformance report exists only if you are buying something, and it describes one version of their product. The department's own conformance is about the service as people meet it, so a good report from a supplier is a starting point and not the finish. Two deadlines set when the service itself has to conform: web pages created or updated on or after 5 December 2027, and mobile applications, digital documents and the conformity assessment used in buying from 5 December 2028.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| Accessibility conformance report (ACR) Only if Assessment source also | Only when buying. An in-house build has no supplier and no report; the equivalent duty is the department's own conformance assessment against the standard. | Says which clauses of the standard the service has to meet, so they go into the solicitation, then reads the supplier's report and checks its claims against the product. | The supplier, through a third party or a qualified in-house accessibility expert. |
| What it isA supplier's written statement of how far their product meets the accessibility standard, clause by clause, with the gaps named. It is a claim to be tested.When it comes upAlpha Gather · Beta Sign or accept · Maturity Keep current | |||
| Accessibility conformance and the accessibility statement Standing duty source | By 5 December 2027, every web page, public-facing and employee-facing, created or updated on or after that date, plus the published statement. Mobile applications, digital documents, and the procurement conformity assessment follow on 5 December 2028. Legally the duty sits on the department through its deputy head. | Includes the people most likely to be excluded in the research, books the testing early, and funds the fixes. | The service team, testing with people with disabilities. Automated checkers catch only a fraction of the barriers. |
| What it isConformance of the service itself to the Canadian accessibility standard for information and communication technology, plus a published statement that names what does not conform, what the alternatives are, and when the gaps close.When it comes upAlpha Gather · Beta Fill, Submit · Growth Keep current · Maturity Keep current | |||
5.5Official languages
This applies to every service the public can use online. It has no form, no board and nothing to file, which is why it is often noticed late. Two things help: design and test in both languages from the first prototype, and put the requirement in the contract where a supplier is involved, because French added afterwards is priced as a change.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| Service in both official languages Standing duty | Every service the public can use online. The trigger is being an automated system accessible to the public, under section 11(b) of the Official Languages Regulations, with Official Languages Act section 24(1)(b) as the enabling hook. Geographic reach is a different test that covers correspondence and telephone, so a service is not exempt for serving one region. How bilingual web content is published is set by subsection 6.6.4.1 of the Directive on Official Languages for Communications and Services. | Funds and schedules both languages from the first prototype, and tests with francophone users. | The service team builds it bilingual; the departmental official languages champion or adviser sets the obligations; communications owns the content standards. |
| What it isThe duty to offer and deliver the service in English and French at the same time and to the same standard. For a digital service that covers the interface, the content, notifications, error messages, and the human support behind it, so a translated afterthought does not meet it.When it comes upDiscovery Check · Alpha Gather · Beta Fill, Submit · Growth Keep current · Maturity Keep currentBill C-13 changed language-of-work duties with effect from 20 June 2025, so anything written before that date may be out of date on the work side. | |||
| Official languages in what you buy Only if Standing duty | Whenever a supplier delivers, hosts or supports any part of a service that reaches the public, or produces content on the department's behalf. Guidance is set through a contracting policy notice. | States the bilingual requirement in the statement of work before the solicitation goes out. Left out, French becomes a priced contract amendment later. | The contracting authority writes the clauses into the solicitation and the contract. |
| What it isThe obligation to write official languages requirements into the contract, so the supplier is contractually bound to deliver both languages.When it comes upAlpha Gather · Beta Sign or accept · Maturity Keep current | |||
5.6Approvals and money
These decide how much of the rest of the list applies to you. Two different measures are at work and they are easy to mix up. The project's complexity score, compared with the department's approved capacity class, decides whether the Treasury Board has to approve it. Separate investment thresholds decide whether a concept case is needed. Most projects are under both and stay inside the department.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| Concept case Only if Submission source also | Mandatory for digitally enabled projects where the department is willing to invest at least: $2.5 million with no approved capacity class or class 1; $5 million at class 2; $10 million at class 3; $15 million for National Defence; $25 million at class 4. | Writes the problem and the rough size from Discovery's evidence, then takes it up for approval. | The department, approved at assistant deputy minister level or above. |
| What it isA short, early write-up of the problem and the rough size of the investment, produced before a business case and before any solution is chosen.When it comes upDiscovery Check, Fill, Submit | |||
| Project complexity and risk assessment (PCRA) Only if Assessment source | Required at: $2.5 million with no approved capacity class or class 0; $5 million at class 1; $10 million at class 2; $25 million at class 3; $50 million at class 4, all tax included. Note this ladder differs from the architecture review board ladder as written. | Answers the business-risk questions, including how ready the organization actually is to adopt the thing. | The departmental project management office authors it; the project sponsor is responsible for ensuring it is completed; the deputy head is responsible for its accuracy. |
| What it isA 64-question scoring tool that rates a project from level 1, sustaining, to level 4, transformational. The score decides who is allowed to approve the project: the minister, or the Treasury Board.When it comes upDiscovery Check, Gather, Fill · Growth Keep current | |||
| Departmental architecture review board (DARB) Review source | All departmental digital initiatives. Two carve-outs: small departments and agencies, meaning reference levels under $300 million a year or so designated, are exempt; and Agents of Parliament are exempt. | Presents the direction, bringing the reuse scan Discovery produced. | The board reviews. The chief information officer's architecture team books the slot and prepares the material. |
| What it isThe department's own board, which reviews a digital initiative's design against the government-wide architecture framework: look for something that already exists before buying or building, open standards, data, security and privacy.When it comes upAlpha Submit, Sign or accept · Growth Keep current | |||
| Government of Canada Enterprise Architecture Review Board (GC EARB) Only if Review source | Any one of these is enough. The department is willing to invest $2.5 million with no class or class 1, $5 million at class 2, $10 million at class 3, $15 million for National Defence, $25 million at class 4. Or the initiative involves emerging technologies. Or it needs an exception under the directive. Or it is categorized at Protected B or below and uses a deployment model other than public cloud. Or it extends or creates custom support to stop a technology becoming unsupported. Or the Chief Information Officer of Canada directs it. | Checks all six triggers, since a small initiative can qualify on emerging technology or hosting alone, then supplies the material for the departmental chief information officer's submission. | The departmental chief information officer submits; the project team usually attends. |
| What it isThe government-wide architecture board, co-chaired by the Chief Technology Officer of Canada and the Chief Technology Officer of Shared Services Canada. Six separate triggers can send an initiative to it, and the size of the investment is only one of them.When it comes upAlpha Check, Submit | |||
| Treasury Board submission Only if Submission source | When the project's complexity level exceeds the department's approved capacity class, or the department has no class and the project is over $2.5 million. Plus all programmes. Plus procurement or real property above their own approval limits. | Supplies what the service is for, what it will cost, and what benefits it promises. Those promises are tracked after approval. | The department writes it; the chief financial officer attests. |
| What it isThe formal request to the Treasury Board for authority and money when the project is beyond what the minister can approve alone. It commits the department to specific benefits.When it comes upDiscovery Check · Alpha Fill, Submit | |||
| Benefits realization plan and project close-out report Only if Submission source | Universal for anything that counts as a project under the projects and programmes directive, with no dollar trigger. Baseline reporting to the Office of the Comptroller General starts at $25 million. | Names the benefits when the money is sought, then supplies the delivery record at close-out. | The project sponsor and the departmental project office. |
| What it isThe written statement of what good this project is supposed to do, and the later report confirming what was actually delivered and whether the promised benefits arrived.When it comes upDiscovery Fill · Stabilization Submit · Maturity Keep current | |||
5.7Contracts and suppliers
All three apply only when you are buying, and all three run on the procurement timetable, which makes them earlier than they look. The check list and the screening apply where a supplier will handle sensitive information: the check list has to be settled before the solicitation goes out, because the security clauses in the solicitation come from it, and clearing a supplier's people can take longer than the competition itself. The 5% target for contracts awarded to Indigenous businesses is the department's to meet, and the one moment a business owner can affect it is before the solicitation is written.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| Security Requirements Check List (SRCL, form TBS/SCT 350-103) Only if Submission source | Only where the supplier or its people will access Protected or Classified information or assets, enter restricted sites, or connect electronically to departmental systems, which includes any access to personal information the department holds. Where there are no security requirements, no check list is produced and the department certifies that instead. | Drafts the check list from the statement of work, saying what the supplier will do and touch, and signs the project authority block. A vague description produces clauses that block the work. | The departmental security officer advises on the levels. Public Services and Procurement Canada's Contract Security Program reviews it and derives the clauses. |
| What it isA short form that states, for one contract, exactly what security the supplier and its people need: what level of information they will touch, what screening each role needs, and whether the company may hold government information at its own offices.When it comes upDiscovery Check · Alpha Fill · Beta Sign or accept, Submit · Growth Keep current · Maturity Keep current · Sunset Keep current | |||
| Supplier organization and personnel security screening Only if Authorization source also | Every procurement whose Security Requirements Check List identifies a security requirement, and the same applies to subcontractors at every tier. Organization screening covers Protected A, B and C; a facility clearance is for Classified. | Finds out early what clearance level the work needs. Screening often runs longer than the procurement. | The Contract Security Program screens. The supplier appoints a company security officer. Individual staff apply through their employer. |
| What it isThe clearances a company and its individual staff must hold before touching sensitive government work. A department cannot issue them itself, and the work cannot be awarded until the clearance is confirmed in writing.When it comes upAlpha Check · Beta Gather, Sign or accept · Growth Keep current · Maturity Keep current | |||
| Contracts awarded to Indigenous businesses (the 5% target) Only if Standing duty source | Only when buying. The target belongs to the department and not to any one contract, so no single procurement has to be set aside. Every procurement is where the target is met or missed, which is why departments plan for it up front. Whether a supplier counts is verified through Indigenous Services Canada. | Says early whether the requirement could be met by an Indigenous business, and says so before the solicitation is written, when the route is still open. | The contracting authority chooses the route and runs it. The department's procurement function plans against the target and reports the results. |
| What it isA government-wide commitment that at least 5% of the total value of contracts goes to Indigenous businesses each year. Departments plan for it, report against it, and meet it or miss it one procurement at a time.When it comes upDiscovery Check · Alpha Gather | |||
5.8Hosting and cloud
Where the service runs is worth deciding deliberately, because otherwise it is decided by whoever sets up the first environment. There is a government-wide order of preference to work through, and choosing something else is allowed with a case for it. One thing to watch: a service categorized at Protected B or below that runs on anything other than public cloud goes to the government-wide architecture board however small the spend, since that trigger has no dollar floor. The cloud security work in the second row applies only to a cloud-hosted service.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| Application hosting decision, and the public cloud default Review source | Every service has to make the decision. The trigger is specific: an initiative categorized at Protected B or below that uses a deployment model other than public cloud for hosting, deployment or development must go to the Government of Canada Enterprise Architecture Review Board. There is no dollar floor on that trigger. | States what the service needs from its hosting, and makes the case where the answer is anything other than public cloud. | The departmental architecture and hosting functions decide. A departmental architecture review board approval is mandatory on application hosting initiatives. |
| What it isThe decision about where the service runs, made against a government-wide preference order: software as a service before platform before infrastructure, and public cloud before hybrid before private before non-cloud. Departing from that order needs a case.When it comes upAlpha Check, Submit · Beta Sign or accept · Maturity Keep current | |||
| Cloud security profile, guardrails, and the cloud authorization Only if Authorization source | Only for cloud-hosted services. The Protected B control profile is the usual starting point. The Cyber Centre separately assesses cloud service providers, so a department inherits that assessment rather than repeating it, and assesses only its own configuration and use. | Says what the service holds, so the right control profile is picked. | The departmental security team, with the cloud team, works out the split of responsibility with the provider; the provider's own assessment is inherited. |
| What it isThe extra security work a cloud-hosted service carries: a ready-made control profile to build against, guardrails that have to be implemented, validated and reported within the first 30 business days of getting a cloud account, and a security assessment that accounts for the split between what the provider does and what the department does.When it comes upAlpha Check, Gather · Beta Fill, Sign or accept · Growth Keep current · Maturity Keep current | |||
5.9Identity and sign-in
This applies where people or businesses have accounts, sign in, or are identified. Both rows follow from what would happen if the service got someone's identity wrong, and both shape the design early. The shared government sign-in services are the expected route, and building your own is the choice that needs explaining. Joining a shared service takes time, so it is worth asking about early.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| Identity and credential assurance levels Only if Assessment source also | Any service where people or businesses have accounts, sign in, or are identified. There are four levels, one to four, running from little confidence needed to very high confidence needed. A worksheet in the Guideline on Defining Authentication Requirements produces the level for a given service. | Makes the judgement about what harm results from getting someone's identity wrong. | The departmental identity management function sets the level, with the security team. |
| What it isTwo ratings, from one to four, of how sure the service has to be about who someone is and how strong the sign-in has to be. They constrain the design from the beginning, because they decide what the sign-in has to do before anyone builds it.When it comes upDiscovery Check · Alpha Gather, Fill · Growth Keep currentThe stand-alone Standard on Identity and Credential Assurance was archived on 28 June 2019. The live version is Appendix A of the Directive on Identity Management. | |||
| Government of Canada credential and sign-in services Only if Standing duty | Any external-facing service where clients sign in. Joining a shared platform involves compliance checks and testing before go-live, and the platform's own team sets what those are. | Picks the credential route before the prototype hard-codes a sign-in of its own, and allows for the onboarding time in the schedule. | The departmental identity and integration teams, with the platform's onboarding team. |
| What it isThe shared sign-in services a department can use in place of building its own: the government-branded credential service, the commercial bank-based option, and the newer federated sign-in platform. Using one of them is the default, and a sign-in built from scratch is what needs justifying.When it comes upAlpha Check · Beta Fill, Submit · Maturity Keep current | |||
5.10Publishing on canada.ca
If the service is public-facing, a good deal of how it looks is decided for you: the page templates, the information architecture and the content style are all set centrally. Those are easier to work with than to work around, so it helps to bring the departmental web team and communications in while the design can still change, and not at Beta when it has already been built.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| Publishing under the canada.ca brand Only if Standing duty source | Every external-facing website and web application. Inside the department the head of communications is accountable for external-facing websites and for mobile applications, and the directive holds both to its Appendix D, the Standard on External-facing Websites and Mobile Applications. The same directive requires the official web analytics tool administered by Service Canada. | Brings the departmental web team and the head of communications in before the first prototype, and settles the web address with them before any launch date is promised. | The departmental web team and content designers, under the communications organization. The departmental web account manager files the domain request. |
| What it isThe rules for anything the public sees: the domain, the global header and footer, the Government of Canada signature and wordmark, the mandatory page templates, the information architecture, and the content style guide. They are mandatory, and they constrain how a service can look and where it can live.When it comes upAlpha Check, Gather · Beta Submit, Sign or accept · Growth Keep current · Maturity Keep current · Sunset Close outThe governing instrument changed on 27 March 2025: the Directive on the Management of Communications and Federal Identity replaced the 2016 communications directive, and its Appendix D replaced the former mandatory procedures for social media and web communications. Anything citing the older instrument is citing an archived one. | |||
| Responsive web, or a native mobile app Only if Standing duty | Every public-facing website and web application. | Decides between responsive web and a downloadable app, with evidence from user research. | The service team and the departmental web team. |
| What it isThe rule that a public-facing service works properly on a phone, and that choosing a downloadable app over a responsive web page has to be justified. A downloadable app also adds a central publishing step the department does not control.When it comes upAlpha Check · Beta Fill · Maturity Keep current · Sunset Submit | |||
5.11Registries and records
Registers are how the service becomes visible to the rest of government, and records are the information it keeps. Neither is difficult, and both are easy to overlook because they arrive after launch, when the project team has usually moved on. Two things worth knowing. Only one of the two registers has anywhere to say the service is critical. And nothing may be destroyed without written consent from Library and Archives Canada: everything else in these tables can be fixed late at some cost, and a destroyed record cannot, because it is gone. The last row is the one to read before buying anything, since it says what the system itself has to be able to do with records. How data is modelled, described and kept usable is the subject of the Data stewardship thread.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| GC Service Inventory Register source also | Every external service and every internal enterprise service, meaning one department serving other departments government-wide. Purely internal departmental services are out of scope. A department with no services files a deputy minister declaration. | Names the service in words its clients would recognise, and supplies the details for the register entry. | The designated official for service registers it. |
| What it isThe government-wide register of what services exist, who they serve, how digital they are, and how much volume they handle. Its 70 published fields include nothing about criticality, recovery or continuity.When it comes upStabilization Submit · Maturity Keep current · Sunset Close out | |||
| Application Portfolio Management (APM) Register | Every business application behind a service. No dollar threshold, though the system is in practice used by a subset of departments. | Rates the application's criticality, business value and condition. Left blank, no government-wide record shows the service as critical. | A departmental portfolio delegate holds the inventory and coordinates entry. |
| What it isThe register of the applications behind the services, rated for business value, technical condition, support cost and criticality, and sorted into tolerate, innovate, mitigate or eliminate. This is where criticality actually gets recorded, since the service inventory has no field for it.When it comes upStabilization Submit · Maturity Keep current · Sunset Close out | |||
| Records retention and disposition authority Register source also | All information and data. Library and Archives Canada issues either an institution-specific or a multi-institution authority; the department confirms which one covers its records and sets the retention periods itself. | Tells the information management office what records and data the service will create and hold, and sets how long each kind is kept. | The information management function under the departmental chief information officer. |
| What it isThe written consent from Library and Archives Canada without which no government record may be destroyed. The authority is permission to dispose. It does not order anyone to dispose, and it does not set retention periods; the department's own schedule does that.When it comes upAlpha Gather · Beta Fill · Maturity Keep current · Sunset Close out | |||
| Systems that manage information and data Standing duty source also | All systems, in force since 4 May 2022. Anything built or bought before that had 24 months to transition, and anything treated as legacy had 24 months to produce a plan. The capabilities can be met by one system or by several used together. | Puts these into the requirements before anything is bought, above all bulk export in open formats and the ability to apply a retention rule. A product that cannot do those two cannot be made to later without replacing it. | The information management function says what is needed; the service team or the supplier builds it. |
| What it isA set of things any system holding government information has to be able to do: apply retention and disposition rules in a way that can be audited, carry metadata, support the department's classification structures, work with other systems, and export in bulk in open formats.When it comes upAlpha Gather · Beta Check · Sunset Close out | |||
5.12Access to information and openness
Anyone at all can ask a federal institution for its records, and the institution then has to find them and release whatever the law allows. So plan on the basis that what this service records may one day be read by someone outside it. A second duty runs on a clock: contracts over $10,000, and grants and contributions over $25,000, are published every quarter whether or not anyone has asked to see them, and it is the department that has to remember, because no request arrives to prompt it. Both duties change what the service should record while it is running, and how quickly one record can be pulled out of thousands, which is something the build has to allow for.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Instrument | What brings it into scope | What the business owner does | Who does the work |
|---|---|---|---|
| Access to information readiness, and the duty to document Standing duty | All records under the department's control. Systems that manage information and data carry their own standard, which sets what a system has to be able to do with records. | Says what decisions the service makes and what evidence should be kept. | The service team builds the records so they can be found and released; the access to information and privacy office handles requests. |
| What it isEverything the service records can be asked for under an access request, and decisions of business value have to be documented in the first place. That shapes what gets written down, what the system keeps, and whether records can be found and released when someone asks.When it comes upAlpha Gather · Beta Fill · Maturity Keep current | |||
| Proactive publication Only if Filing | Triggered by what the service does rather than by its size. Any contract over $10,000 triggers contract publication; a grants or contributions program triggers the other. | Tells the contracting authority which contracts and grants cross the thresholds. | The department's proactive publication function publishes; the contracting authority supplies the contract data. |
| What it isPublication that happens without anyone asking, as a statutory duty. For a procured digital service the live ones are contracts over $10,000, grants and contributions over $25,000, and the titles of briefing materials.When it comes upBeta Submit · Maturity Keep current | |||
| Open data and open information Filing | Applies by default. What is actually released depends on privacy, security and legal restrictions, so the work is deciding what can be opened rather than whether the duty exists. | Says what the service will hold that could be released, and what stops it. | The departmental open government and information management functions. |
| What it isThe expectation that data and information of business value are released openly by default, in reusable formats, unless something specific stops it. Info Source separately describes what information the institution holds.When it comes upAlpha Check · Maturity Keep current | |||
APPENDIX A
Reuse before you buy or build
Look for something to reuse before making your own. These are the pieces already built and maintained by another part of government, so a team can configure rather than make. The table of official instruments is what a service has to deal with. This is what it can avoid having to make.
Choosing to make your own instead breaks no rule. The enterprise architecture framework does ask teams to look at reuse first, so a departmental architecture review board is likely to ask which of these were considered and why none of them fitted.
This table is wide. Turn the phone sideways to read it, and scroll sideways inside the table to reach the later columns.
| Piece | What you would otherwise build | Who runs it, and how to get it | Worth a look in |
|---|---|---|---|
| Finding what exists | |||
| Open Resource Exchange site | Starting from nothing, or rebuilding what another department already wrote. | Treasury Board of Canada Secretariat. Public website. Search it before writing a requirement. | Discovery, as part of the reuse scan an architecture review board will ask about. |
| What it isA catalogue of software, code and reusable components that Government of Canada organizations have published for others to use. | |||
| Talking to people | |||
| GC Notify site | An email and text sending system, its templates, its retry logic, and its delivery reporting. | Canadian Digital Service. Request an account. Free to Government of Canada teams. | Alpha, because whether notifications are bought, built or reused changes the build estimate. |
| What it isA notification service that sends email and text messages to the people using a service, with templates, delivery tracking and bilingual support built in. | |||
| Collecting information | |||
| GC Forms site | A form, its validation, its accessibility work, and somewhere safe to put the answers. | Canadian Digital Service. Request access. Free to Government of Canada teams. | Alpha for prototyping a form quickly, and Beta where the real one is a form rather than a system. |
| What it isA form builder that produces accessible, bilingual online forms without writing code, and delivers the responses securely. | |||
| How it looks | |||
| GC Design System site | Interface components, and the accessibility testing of each one. | Canadian Digital Service. Public. Use the components in the build. | Alpha for the prototype, Beta for the real build. |
| What it isReady-made interface components, buttons, inputs, error messages and the rest, already tested for accessibility and available in both official languages. | |||
| Canada.ca design system site | Page layouts, navigation patterns, and the research behind them. | Treasury Board of Canada Secretariat, with the canada.ca publishing team. Public. The mandatory parts are covered by the publishing rules, not by choice. | Alpha, before the first prototype fixes a look the web team will not accept. |
| What it isThe user-tested page templates, patterns and content styles for anything published under the canada.ca brand.Part of this one is not optional. The mandatory templates and information architecture are a standing duty, listed in the instrument table. | |||
| Digital Accessibility Toolkit site | Working out the accessibility requirements and testing approach from scratch. | The interdepartmental Access Working Group. Public website. | Alpha, where the accessibility clauses are written for the solicitation. |
| What it isHow-to guidance for designing, building, testing and buying accessible services, including the wording to put in a contract. | |||
| Signing in | |||
| GCKey and Sign In Canada | Accounts, passwords, multi-factor authentication, and account recovery. | Shared Services Canada and the Canadian Digital Service. Onboard through the platform's own process, which includes testing and an attestation. | Alpha, before a prototype hard-codes a sign-in of its own. |
| What it isShared sign-in services that identify the people using a service, so a department does not run its own username and password system.Closer to expected than optional. Reusing a credential service rather than building sign-in is treated as the default, so this one also appears in the instrument table. | |||
| Publishing and sharing | |||
| Open Government Portal site | A publishing route for open data, and the licence terms that go with it. | Treasury Board of Canada Secretariat. Through the department's open government contact. | Live, once the service is producing data worth releasing. |
| What it isWhere Government of Canada data and information are published openly, and where several things a service owes are filed.Some filings here are obligations. The algorithmic impact assessment and proactive publication are both published on this portal. | |||
APPENDIX B
A worked example: one service's path, step by step
The tables above say what exists. This appendix puts them in an order, by following one invented service from the first sign of trouble to the day it is replaced. Read it for the sequence, and for who Nadia has to talk to at each point. It is not a second list of instruments.
Nadia took one path, and the steps below are in the order that path produced. A department that buys a finished product, or builds in-house, or runs an agile procurement, meets the same checkpoints in a different order. Even where the contract is signed moves by a whole sub-phase depending on the route chosen, so treat the sub-phase headings here as this service's sequence rather than as the sequence.
Why Create fills most of this appendix
The official checkpoints are front-loaded. Almost every formal approval, review and sign-off happens before launch, so Create carries most of the steps. Live and Sunset look shorter here only because this appendix follows the checkpoints, and not because there is less work in them.
People in this journey
Who the steps below keep referring to. One line each, because what any of them does about a particular instrument is in that instrument's own row.
- The users
- The people the service is for, inside or outside government, present at every step from research to support.
- Business owner of the application
- Accountable for the service from before it exists until after it is switched off, and reaches everyone else here through corporate services.
- Corporate services
- The department's enabling branches: the CIO or IT office, finance, procurement, security, privacy, records. The first stop for everything.
- Departmental project-management office
- Helps score and cost the project and find a project manager. How it is organized varies; the deputy head is accountable for the score.
- DARB
- Departmental Architecture Review Board. Inside the department, chaired by its CIO, and it reviews the design.
- GC EARB
- Government of Canada Enterprise Architecture Review Board. Government-wide, and only for large or complex projects.
- Contracting authority
- The procurement officer who runs the competition and signs the contract. Never the business owner.
- Authorizing official
- The senior executive who signs the Authority to Operate and accepts the security risk that is left.
- ATIP or privacy office
- Supports the privacy assessment and the registrations that follow it. The program area still owns the assessment.
- Service management function
- Whoever owns the service inventory in your department, under whatever name. Registers the service and updates it when it retires.
- Information management office
- Holds the disposition authorities. Records cannot be destroyed without Library and Archives Canada's written consent.
This is Nadia's timeline, not a general one. It is what this one invented service experienced, and Create in particular can run considerably shorter or longer. Do not plan against it.
Meet Nadia, a director general
Her grants program has outgrown its spreadsheets, so she is buying a grants management system. Her project scores below her department's threshold, so no Treasury Board submission is needed. GC EARB is a separate question: six triggers send a department there and money is only one of them, so her team checks all six in Alpha and none of them fires. Both together are the ordinary case, roughly 95% of projects. Where another project would branch upward is shown in the amber boxes.
Why G&Cs is the example
This journey is built around a grants and contributions system because it is a useful worked case: it touches almost every checkpoint at once - public money, procurement, a security authorization, personal information, records, and a decision made about people. The guide as a whole is not limited to G&Cs; any service can be mapped through the same path.
Left is what Nadia does.
Right is who answers, and how. The tag on each response says whether the responder is her department or a central.
Funded from the department's existing operating budget. This is where the path is decided. Nadia has spotted a problem. Discovery is where she works out how serious it is, who needs to be brought in, and which path the project should take.
Notices the program is breaking.
Applications have doubled, her team cannot keep up, applicants cannot track anything, and auditors cannot verify decisions. She decides something has to change.
This is her problem to raise. The guide's point: she already owns a digital service, whether she calls it that or not.
Calls her own department's corporate services.
Asks, plainly, "where do I start?"
The enabling branches walk her through it and point her on:
- the CIO or IT office
- finance
- procurement
- security
- the privacy (ATIP) office
- records
If anything later needs a central agency, her department is the one that takes it there.
Pulls together a small team to look into it.
She cannot do this alone, and she is not meant to.
Some from her own program who know the work, and, through the CIO or IT office, a business analyst and often a project manager from the departmental project-management office. The team is small in Discovery and grows through Beta as the build and the supplier's people come on. Nadia sponsors it; she does not do the hands-on work herself.
Writes up the need and gets it onto the plan.
A short write-up of the problem and roughly what it would take, in whatever form her department's project intake asks for.
They add the initiative to the departmental plan and the departmental investment plan (approved by the deputy head). She feeds the initiative in; she does not update those plans herself.
Gets the project sized, risk-rated, and costed.
How big is this really, and how risky?
It helps her team complete the Project Complexity and Risk Assessment (PCRA). How that is organized varies by department.
- the deputy head is accountable for an accurate score
- that score is compared against the department's approved project-management capacity class
Asks the IT office whether anything on the GC shelf already does what she needs.
Reuse comes first in GC policy. She is not the one who searches; she is the one who decides.
They check:
- the GC Reference Architectures and the enterprise solutions catalogue (on the GC network)
- the Enterprise Architecture Community of Practice
- Shared Services Canada
If a fit exists, Nadia adopts it instead of buying.
Gets the build budget committed.
A budget outline. This covers getting from here to launch.
The department's own governance commits the budget to proceed, from existing funds and under its delegated financial authority. No Treasury Board submission. This covers Discovery, Alpha, and the Beta build.
The money to run it year after year (the operational budget) is different: that is set through the Estimates process once the service is Live. She should flag the expected operating cost now, even though the formal approval comes later. If the department has not thought about ongoing funding by Discovery, it is much harder to secure it after launch.
Common gap: teams plan the build cost carefully and treat the operational budget as someone else's problem. It is not - if the funding to run the service is not committed in principle by the time Beta starts, the service risks launching with no plan for what comes next.The service goes live here. Everything above is Create (the build); everything below is Live and Sunset (running it, then retiring or replacing it).
Nadia is invented, and so is her program. Any resemblance to real persons or programs is coincidental.