Karsten Wenzlaff, Advisor
August 26th, 2025
July 20, 2026 | NCFA Resource | Cybersecurity And Fraud, Risk Compliance And Regtech, Capital Markets And Market Infrastructure

On July 15, 2026, the Canadian Securities Administrators published new cybersecurity guidance for registered dealers, advisers, and investment fund managers (Download the 12 page PDF report). CSA Staff Notice 33-322 combines findings from a focused review of 73 firms with practical expectations for policies, employee training, risk assessments, third party oversight, and incident response.
The notice is most useful as a compliance review tool. Firms can compare their written controls, operating practices, and supporting records against the deficiencies and effective practices identified by securities regulators. The guidance is particularly relevant for smaller and medium sized firms that may not have dedicated cybersecurity teams.
The notice organizes cybersecurity readiness around five areas that regulators examined under section 11.1 of National Instrument 31-103:
The review found useful benchmarks. 8% of firms had no written cybersecurity policies, while 55% had policies that needed improvement. Twenty one per cent provided no employee cybersecurity training. Forty five per cent completed risk assessments that could have been stronger, and 12% had no documented assessment during the review period.
Third party oversight was one of the clearest weaknesses. All examined firms used service providers with access to systems or data, but 62% had no documentation or limited documentation supporting their cybersecurity oversight. The CSA expects firms to complete and document due diligence before onboarding a provider and repeat that review throughout the relationship.
The guidance identifies information firms should assess, including data storage, encryption, access controls, patch management, incident notification, subcontractors, operating jurisdictions, and shared responsibility in cloud environments. It also recommends maintaining a complete vendor register and reviewing current SOC 2 or similar reports where available.
Incident preparedness also receives detailed attention. Fifteen per cent of firms had no written incident response plan. Among firms with a plan, 53% needed stronger procedures and 63% should have tested their plans more regularly. The notice describes tabletop exercises and simulated attacks as practical ways to test whether people, processes, and technical controls work together during an incident.
The primary audience is firms registered as dealers, advisers, portfolio managers, investment fund managers, exempt market dealers, and restricted portfolio managers. Chief compliance officers, directors, technology leaders, privacy professionals, and internal audit teams can use the notice to organize a control review and identify missing documentation.
Boards and senior executives can also use it to test whether cybersecurity oversight is tied to clear responsibilities, regular reporting, and evidence that controls operate as intended. Written policies alone aren’t enough when actual practices, testing schedules, or access controls differ from the documented process.
Cybersecurity consultants, legal advisers, insurance providers, managed service providers, and software vendors can use the findings to better understand the records and evidence registered firms may need during a regulatory review.
The notice is strong because it combines regulatory expectations with observed deficiencies, percentages, effective practices, and practical takeaways. It covers both governance and technical controls, including multifactor authentication, encryption, backups, access rights, patching, email filtering, endpoint protection, and activity logging.
It also makes documentation a central requirement. Firms should be able to show when policies were reviewed, who completed training, how risks were assessed, what vendor due diligence occurred, and when incident plans or backup recovery procedures were tested.
The guidance does not create a complete technical cybersecurity standard, and it doesn’t replace obligations under privacy, securities, corporate, or other applicable laws. Expectations also vary with the firm’s size, operating complexity, client information, service provider reliance, and exposure to cyber risk.
Firms should therefore use the notice as a regulatory gap assessment and evidence checklist, then supplement it with appropriate legal advice, technical standards, testing, and controls suited to their operations.
CSA Staff Notice 33-322 (cybersecurity examination findings and guidance for registered firms)
CSA Staff Notice 33-321 (foundational 2017 cybersecurity and social media guidance)
NIST Cybersecurity Framework (risk management structure for identifying, protecting, detecting, responding, and recovering)
CIS Critical Security Controls (prioritized technical and operational safeguards)
Wealthsimple Confirms Breach Impacting Clients (third party exposure and incident response)
Proposed Class Action Targets Equifax Access Controls (access governance and third party permissions)
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Leave a Reply