Transparent cost
See an instant estimate and the assumptions behind it before applying. Complade confirms the final quotation after reviewing the certification scope and required audit time.
FRLog in to Complade Portal Get a Standards Council of Canada (SCC) accredited ISO 27001 or CyberSecure Canada certification.
Know the expected cost, what auditors will examine and where your audit stands—from application to certification—in the Complade Audit Portal.
Complade independently audits organizations against recognized information security standards.
Complade combines SCC-accredited certification, published pricing and a portal that makes the audit process visible. Clients can see how their information risks and controls were evaluated and what evidence supports each conclusion.
See an instant estimate and the assumptions behind it before applying. Complade confirms the final quotation after reviewing the certification scope and required audit time.
Know the stages, responsibilities, evidence requirements, audit activities and expected timelines before the audit begins. The process is predictable; the certification outcome is never predetermined.
Audit conclusions are connected to applicable requirements, defined assessment criteria and recorded evidence. Professional judgment is exercised within controlled methods—not personal auditor preferences.
Plan the audit, submit evidence, follow evaluated audit points, manage corrective actions and receive reports and certificates through the Complade Audit Portal.
The portal handles more than applications and contracts. It is where clients submit evidence, plan the audit, see evaluated audit points, manage corrective actions and receive reports and certification records.
Complete the application, review the estimate, sign the certification agreement and mutual NDA, and manage certification contacts online.
Upload required management-system documents. Receive Stage 1 notes and results within three business days of a complete submission, update artifacts where needed, and resubmit evidence for up to three review cycles.
Work with the lead auditor on dates and a detailed schedule down to each clause or control. Add the people from your organization who will attend the relevant interviews and book meetings through the portal.
See each audit point, evidence request and recorded note. Once the audit team evaluates an audit point, its result becomes visible—providing transparent, near-real-time audit progress.
Record corrections, root-cause analysis and corrective-action plans directly in the portal. Assign owners, upload supporting evidence and track review and closure.
Access the Stage 2 report in the portal within two days of audit completion. Following independent certification review, receive the decision, certificate and applicable IAF CertSearch link in the same system.
Complade's ISO/IEC 27001 certification activities follow applicable requirements for accredited management-system certification bodies, including ISO/IEC 17021-1 and ISO/IEC 27006-1. The audit methodology is informed by ISO 19011, ISO/IEC 27007 and ISO/IEC TS 27008.
Organizations are certified against ISO/IEC 27001 or CAN/DGSI 104. The other documents govern or inform how certification and auditing are performed.
Complade is a Canadian certification body accredited by the Standards Council of Canada (SCC). SCC participates in international recognition arrangements through the International Accreditation Forum (IAF).
Complade conducts independent, third-party cybersecurity audits to certify organizations against recognized standards such as ISO/IEC 27001, the global information security management system standard, and CyberSecure Canada, Canada's national cybersecurity standard for small and medium organizations. Complade's SCC accreditation and the applicable IAF multilateral recognition arrangements support international recognition beyond Canada.
Organizations use Complade's online platform (app.complade.com) to submit application details, sign agreements, and upload certification evidence.
To maintain impartiality, Complade acts solely as an independent evaluator and cannot offer implementation or ISO consulting services.
First, sign in to app.complade.com, complete the application, and review your estimate. If you choose to proceed, electronically sign the agreement and mutual NDA. Complade then introduces your lead auditor and starts the certification process:
You upload the required documents to the portal. Within three business days or less, the Complade audit team reviews the Information Security Management System policies, scope, and risk assessment to confirm that the required controls are documented. For ISO 27001, the exact list is here.
A Complade lead auditor meets with you online or in person to review and test how well the documented policies operate in daily work. In-person audits are available in Toronto and Montreal; travel costs may apply elsewhere. The audit includes team interviews, log samples, and live technical evidence. What auditors look for is published here. Stage 2 commonly requires three or more full audit days, depending on organization size and complexity.
A Complade certification manager, acting as technical reviewer, examines the audit findings and recommendation. If all requirements are met and any nonconformities are resolved, Complade issues the accredited certificate and publishes applicable records on IAF CertSearch. The organization is certified; the organization itself is not accredited.
Annual surveillance audits verify that the certified management system remains active and compliant. ISO/IEC 27001 certification proceeds to a recertification audit in Year 3. Surveillance scope, audit time, and pricing are confirmed in the certification programme and quotation.
If you have been reading this so far, thank you for your patience. We hope it makes things a bit clearer. We are here to help you in each step. If you still have questions book an online meeting or let's grab a coffee.
After each audit, the certification team sends a feedback form to auditees to evaluate the audit process. We publish the results publicly to ensure transparency and support continuous improvement. Each category is scored out of 10.
Client satisfaction has remained consistently high over time, with no downward trend in scoring across audit cycles. We continue to monitor performance so quality and clarity remain central to our certification services. Client feedback has informed improvements including French-language audits and the launch of our certification portal at app.complade.com.
Complade is developing additional services, including European cybersecurity certification support and future ISO/IEC 42001 artificial intelligence and ISO/IEC 27701 privacy certification. Availability will be announced after the applicable approvals and programme readiness are complete.
Audit points are mapped to defined criteria, evidence is recorded against those criteria, and findings connect the applicable requirement, evidence examined and conclusion. Auditor judgment is applied within controlled methods and competence requirements.
No. The workflow, responsibilities and evaluation method are predictable, but certification is granted only when the applicable requirements are met and any required nonconformities are resolved.
Clients can manage applications, agreements, evidence, Stage 1 review cycles, meetings, Stage 2 scheduling and participants, audit-point visibility, corrective actions, reports, certification decisions, certificates and applicable IAF CertSearch links.
Complade explains the requirement, evidence examined and finding. To preserve impartiality, it does not prescribe a client-specific implementation or provide ISO consulting services.
Clients can see audit points, notes and evidence activity in the portal. A result becomes visible after the audit team evaluates that audit point; preliminary activity is not presented as a final certification decision.
A qualified certification decision-maker, separate from the audit delivery, reviews the audit recommendation and supporting records before certification is granted.
Three Complade clients describe their CyberSecure Canada certification experience.
If you have questions about the process or which certification fits your organization, book a meeting with Complade.