Encryption Is Not a Defence: Canada's Controlled Goods Test Asks Who Can Reach Your Data, Not Where It Sits
Canada's Controlled Goods Directorate publishes one sentence that should change how every cloud and SaaS vendor answers a defence prospect. A provider that permits the storage and processing of controlled goods data is considered to be in "actual and/or constructive possession" of that data — and is required to obtain and maintain a valid registration (Public Services and Procurement Canada, 2024a).
Read it again: possession, not access. The guidance is explicit that although the provider may never examine the stored bytes, control over them transferred, and provider and customer share the safeguarding obligation. Encryption narrows your exposure. It does not exempt you.
So when a prospect asks whether your platform is cleared for controlled goods, the data-residency map most vendors reach for is answering a question nobody asked. Residency tells you where the bytes sit. Canada's test is about who can reach them.
The Controlled Goods Program turns on control, not location and not comprehension. Storage or processing of controlled-goods technical data is treated as possession whether or not you can read it (Public Services and Procurement Canada, 2024a). And since November 2025, a second and separate test applies: if there is a "reasonable possibility" that someone outside Canada could examine that technology, you have made a transfer requiring an export permit — a threshold Global Affairs defines as "more than a mere possibility, but less than the standard of more likely than not" (Global Affairs Canada, 2025). Neither test asks where your data centre is. Both ask who holds the keys and who holds the access.
Possession Without Comprehension
The Controlled Goods Program (CGP) is a personnel-screening and safeguarding regime, not a cybersecurity program. Its legal basis is Part 2 of the Defence Production Act and the Controlled Goods Regulations, SOR/2001-32 (Controlled Goods Regulations, 2001; Defence Production Act, 1985). Anyone in Canada who examines, possesses, or transfers controlled goods must register unless excluded or exempt.
The word that trips cloud vendors is not goods. The Schedule to the Defence Production Act captures technical data — blueprints, drawings, specifications, manuals, and software, in paper or electronic form. A controlled drawing uploaded to object storage is controlled-goods technical data the moment it lands.
The obligations that follow are operational, not clerical. Registration itself carries no fee and is valid for a period not exceeding five years, but it commits you to appoint a Designated Official who is a Canadian citizen or permanent resident ordinarily resident in Canada, run a security assessment on every person with access, maintain a security plan for each place of business, and report any actual or potential security breach within three days (Controlled Goods Regulations, 2001).
And the sanction is not nominal. Contravention of the controlled-goods provisions carries, on indictment, a fine not exceeding CA$2 million or imprisonment up to 10 years, or both (Defence Production Act, 1985).
Notice what none of that measures. There is no clause about where the servers are. The regime screens people and governs access.
The Market Already Answered This Question
The largest cloud providers in this market did not litigate the possession question. They registered.
Microsoft's published position is that in the context of operating online services the company "isn't in constructive possession of controlled goods data" — and Microsoft Canada registered anyway, filed an approved controlled-goods security plan covering cloud services, and tells customers they bear ultimate responsibility for their own compliance (Microsoft, 2026). SAP Canada registered on November 18, 2025 (SAP Canada, 2025). Green House Data, a US-headquartered company based in Wyoming, registered in February 2020 specifically to serve customers handling controlled data in the Canadian market (Green House Data, 2020). Amazon Web Services publishes a shared-responsibility user guide for defence customers navigating the program (Amazon Web Services, 2024).
Two conclusions follow, and both are commercially useful.
First, foreign ownership is not a bar. The program registers a Canadian entity and screens the individuals who touch controlled goods — not the foreign parent. A US-headquartered vendor can hold registration through a Canadian entity. Green House Data is the cleanest proof of that.
Second, a vendor's legal position is not your safe harbour. Microsoft's non-possession argument is about Microsoft's exposure. Quoting it back to a Department of National Defence prospect as evidence that your platform is exempt is a category error, and one that a procurement officer with counsel on the call will catch.
The Second Test Nobody Screens For
Even if you resolve the possession question, a separate statute is waiting — and it is the one that actually bites a globally distributed platform.
On November 5, 2025, Global Affairs Canada issued Notice to Exporters No. 1159, addressing the movement and storage of controlled technology in the cloud. Under the notice, disclosing controlled technology from a place inside Canada to a place outside Canada in a way that creates a "reasonable possibility" of examination abroad is a transfer requiring an export permit (Global Affairs Canada, 2025).
That standard is far lower than most engineering teams assume. It is not "did a foreign national read the file." It is "could they have." An offshore site-reliability engineer with standing production access, or a key-management service operated outside Canada, can satisfy it without anyone opening anything.
The notice also sets out the way through, and it reads as an architecture specification rather than a paperwork exercise: strong industry-standard encryption; encryption keys managed so that there is no more than a remote possibility of examination outside Canada; and, where decryption is unavoidable, decryption through non-human intervention on a closed system with all unencrypted copies destroyed. Compliance with the Canadian Centre for Cyber Security's cloud guidance generally removes the permit requirement (Global Affairs Canada, 2025). Canadian counsel reading the notice reached the same conclusion — the automated, closed-system carve-out is the operative safe harbour for in-transit inspection (Blake, Cassels & Graydon LLP, 2025; McCarthy Tétrault LLP, 2026).
Why Your Residency Map Is the Wrong Artifact
Both tests point at the same thing, and the research literature has a name for it.
A 2025 peer-reviewed review of digital sovereignty defines it as the capability of a nation or institution to control and supervise its digital infrastructure, data, and technology free from excessive reliance on external commodities or foreign forces — with sovereign control extending past storage to the algorithms, models, and artifacts built on that data (Misra et al., 2025). Sovereignty, in that framing, is a property of control, not of geography. The authors' own strategy set is about governance and infrastructure control, not about pin-dropping a data centre.
Canada's two tests are that principle written into enforceable law. The CGP asks who may examine and possess. Notice 1159 asks who could reach. Neither is satisfied by a map.
Which means the artifact that answers a defence prospect is not your residency page. It is your access-control graph and your key-custody model: who can decrypt, from where, under whose screening, and what happens to cleartext when the process ends. That is a product and engineering answer before it is a compliance answer — and it is one most vendors have never assembled in a form a buyer can read.
The Exposure Map
The good news is that exposure concentrates. Sorted by what actually happens to customer content, a platform falls into three tiers.
Tier 1 — persistent storage. Object stores, key-value stores, managed databases, durable state, media pipelines, retained logs, hosted assets. If controlled technical data lands here, you are in the possession conversation. This is the short list that matters.
Tier 2 — decrypt, inspect, discard. Products that terminate TLS and inspect content in memory, then re-encrypt and forward, persisting nothing. This tier is genuinely contested: automated, machine-only inspection is defensibly not a person "examining," but the regulator's "processing" language is broad. The low-regret posture is the one Microsoft, SAP Canada, and Green House Data actually took — register and file a security plan.
Tier 3 — packet-level transit. No decryption, no retention, headers only. Clean.
Then there is the configuration trap, and it is the single most dangerous line in this whole analysis: enabling verbose or debug logging on a Tier-2 product silently moves cleartext into retention and converts a contested product into a storing one. A logging change is a scope change. Treat it like one.
What This Actually Costs
Registration is free to file. The real investment is a Designated Official, per-person security assessments, a security plan per site, records, the three-day breach-reporting process, and inspection readiness (Controlled Goods Regulations, 2001). For a provider that already runs a mature control framework, this is governance work rather than a technical rebuild — but it is ongoing work, not a one-time filing.
The market it opens is not small. Canada's defence industry generated CA$17.3 billion in revenues, contributed over CA$11.1 billion to GDP, and supported 81,800 jobs in 2024, with small and medium-sized businesses making up over 90% of firms (Innovation, Science and Economic Development Canada, 2026). Most of those firms have no in-house export-controls capability. The vendor who can hand them a clean answer is selling something scarce.
What Sagentix Does — and Does Not Do
Sagentix Advisors does not deliver SOC 2 readiness assessments. We do not run penetration tests, we do not certify products, and we do not perform Controlled Goods Program registrations or act as export-controls counsel. We advise vendors on go-to-market strategy — positioning, pricing, sales process, buyer journey — so they can sell into markets where compliance is the buying trigger. My CISSP credential gives that work domain fluency; it is a qualification, not a service line. The registration decision and the Notice 1159 position belong to your governance team and Canadian counsel.
What This Looks Like in Practice
A Sagentix Phase 1 proof-of-concept for a vendor selling into Canadian defence-adjacent sectors produces Sagentix Phase 01 Market Intelligence, 2026:
- A competitive positioning matrix built on compliance-outcome dimensions — key-custody options, processing locality, evidence-package completeness — instead of feature parity
- A buyer journey map anchored on the actual procurement gates, including where the controlled-goods question enters and who asks it
- A bottom-up TAM/SAM/SOM filtered by NAICS codes for defence primes, sub-tier suppliers, and adjacent regulated sectors
- A pricing benchmark against the buyer's internal compliance labour cost, so the platform reads as an ROI line item rather than a security expense
The deliverable is a 60–90+ page evidence-traced document carrying 50+ APA 7th edition citations, passed through a 16-point quality gate.
Three Paths From Here
You do not need Sagentix to act on any of this.
- Draw the access graph instead of the residency map. List every role, service account, and support pathway that can reach cleartext or keys, and mark which sit outside Canada. That one artifact answers both tests better than any data-centre diagram — at zero cost.
- Fix the architecture before the paperwork. Key custody, processing locality, and logging defaults decide the compliance answer. That work belongs to product and engineering, and it is worth doing whether or not you ever register, because it is also the answer to Notice 1159.
- Pressure-test the positioning with an outside read. Bring in someone who can map your product tiers to the buyer's compliance questions and stress-test whether your go-to-market narrative survives a compliance-led procurement evaluation. That is the Sagentix Phase 1 proof-of-concept — 727+ curated artifacts and a 16-point quality gate, CA$4K–$50K end-to-end in 6–8 weeks, with Phase 1 under a money-back guarantee (subject to terms) Sagentix GTM Methodology, 2026.
If you want to test whether your current positioning survives a defence procurement review, book a free 30-minute Strategy Diagnostic or email stephane@sagentix.ca.
This piece covers only half the question a defence prospect is really asking. The other half — the Canadian Program for Cyber Security Certification, which turns on a contract clause rather than on your architecture — is a separate regime with a separate trap, and I will take it up on Thursday.
Here is what I keep asking vendors in this market: if a prospect asked today who inside your company can decrypt their data and from which country, could you answer it with a document — or only with a promise?
References
- Amazon Web Services. (2024, June). AWS user guide to Canada's Controlled Goods Program (CGP). Amazon Web Services.
- Blake, Cassels & Graydon LLP. (2025, December). Global Affairs Canada issues guidance on controlled technology and cloud storage. Blake, Cassels & Graydon LLP.
- Controlled Goods Regulations, SOR/2001-32. (2001). Justice Laws Website. Department of Justice Canada.
- Defence Production Act, R.S.C. 1985, c. D-1. (1985). Justice Laws Website. Department of Justice Canada.
- Global Affairs Canada. (2025, November 5). Notice to exporters No. 1159: Movement to and storage of controlled technology in the cloud. Government of Canada.
- Green House Data. (2020, February 25). Green House Data continues to expand capabilities in the Canadian market with Canadian Controlled Goods Program registration [Press release]. BusinessWire.
- Innovation, Science and Economic Development Canada. (2026). State of Canada's defence industry 2026. Government of Canada.
- McCarthy Tétrault LLP. (2026). Navigating export controls in the clouds: Canada clarifies rules on cloud storage and transfers. McCarthy Tétrault LLP.
- Microsoft. (2026, June 2). Canada controlled goods. Microsoft Learn.
- Misra, S., Barik, K., & Kvalvik, P. (2025). Digital sovereignty in the era of Industry 5.0: Challenges and opportunities. Procedia Computer Science, 254, 108–117.
- Public Services and Procurement Canada. (2024a, May 16). Guidance on using or providing cloud solutions for controlled goods data. Government of Canada.
- SAP Canada. (2025, November 18). SAP Canada fortifies commitment to national security with Canadian Controlled Goods Program registration. SAP News Center.
Subscribe + get the workbook
The Bottom-Up TAM / SAM / SOM Workbook — free with your subscription
An 11-page tactical workbook with fillable worksheets — NAICS lookup, three-filter SAM test, Bull/Base/Bear SOM, and the diligence cross-checks. Not published anywhere else. Then get evidence-backed analysis every other Tuesday. No spam. Unsubscribe anytime. See past issues.

Stéphane Raby, CISSP, CMC, P.Eng., MBA
Founder & Principal — Sagentix Advisors
CMC | CISSP | P.Eng. | uOttawa Telfer Executive MBA — ranked #1 globally by CEO Magazine, 2023. 25+ years in technology strategy, cybersecurity, and management consulting.
Want This Evidence Applied to Your Market?
Phase 1 Market Intelligence starts at CA$4,000–CA$5,000 with a money-back guarantee.