Your Data-Residency Map Is Half the Controlled Goods Answer — and It's the Easy Half
Canada's Controlled Goods Directorate publishes cloud guidance with two sections that decide whether a vendor can serve a defence customer. One is headed Data residency. The other is headed Restricted access. Read them together and the compliance conversation changes shape.
On residency: "Program registrants should take note of any data residency options to ensure that their controlled goods data is stored on servers located in Canada" — and for data stored on servers outside Canada, "Global Affairs Canada must be consulted" about export licensing (Public Services and Procurement Canada, 2025).
On access: "Program registrants must employ a principle of least privilege by monitoring and restricting access to their cloud stored controlled goods data. Access may only be granted to employees who have been security assessed" under section 15 of the Regulations (Public Services and Procurement Canada, 2025).
Notice the verbs. Residency is should. Access is must and may only.
Canada asks cloud vendors two questions about controlled goods data, and the one every vendor prepares for is the weaker one. Residency is an expectation — data should sit on Canadian servers, and if it doesn't, that is an export-licensing conversation with Global Affairs Canada rather than an automatic disqualification. Access is a requirement — a registrant may only grant access to security-assessed employees (Public Services and Procurement Canada, 2025). Almost every vendor can produce a data-centre map. Almost none can produce an access-control record. That asymmetry is where defence deals are lost.
What the Program Actually Governs
The Controlled Goods Program (CGP) is a personnel-screening and safeguarding regime, not a cybersecurity certification. Its legal basis is Part 2 of the Defence Production Act and the Controlled Goods Regulations, SOR/2001-32 (Controlled Goods Regulations, 2001; Defence Production Act, 1985). Anyone in Canada who examines, possesses, or transfers controlled goods must register unless excluded or exempt.
The word that catches cloud vendors is not goods. Controlled goods include technical data — and a controlled drawing uploaded to object storage is controlled-goods technical data from the moment it lands.
The obligations are operational rather than clerical. There is no cost to register (Public Services and Procurement Canada, n.d.), and a registration is "valid for a period not exceeding five years from the date of approval by the Minister" (Controlled Goods Regulations, 2001). In exchange you appoint a Designated Official, security-assess every person with access, maintain a security plan for each place of business, and advise the Minister of any actual or potential security breach "within three days after the day on which they discover the breach" (Controlled Goods Regulations, 2001).
The sanction is not nominal. Contravention carries, on indictment, "a fine not exceeding $2,000,000 or to imprisonment for a term not exceeding 10 years, or to both" (Defence Production Act, 1985).
The Rule Softened in 2025 — and Almost Nobody Noticed
Here is the part that has not been written up anywhere I can find, and it changes how you answer a prospect.
The version of the CGD cloud guidance that circulated through 2024 stated a bright-line rule: "If a cloud service provider permits the storage and/or processing of controlled goods technical data using its solutions… this provider is considered to be in actual and/or constructive possession of controlled goods technical data. As such, these cloud service providers are required to obtain and maintain a valid registration" (Public Services and Procurement Canada, 2024). Storage alone triggered registration.
That language is gone. The guidance now published says the opposite of a bright line: "Cloud service providers typically do not examine, possess, or control their users' content stored in the cloud, but they may provide services to registrants that require them to examine or possess the controlled data… which then requires the cloud service provider to be registered." Unregistered providers "may be at risk of contravening the Act" where support or maintenance "involves examining the controlled data of its user" — the example given is reviewing a user's controlled data in decrypted form. Registration is described as something providers "choose to" do (Public Services and Procurement Canada, 2025).
The trigger moved from storage to examination. If you built a compliance position on the older rule, it is now stricter than what Canada publishes. If you built one on we never look at customer data, you have more room than you think — but only if you can prove it, which brings you straight back to access control.
Why the Market Registered Anyway
The largest providers did not wait for the rule to soften, and their behaviour is the more useful signal.
Microsoft's published position is that "in the context of operating Online Services, Microsoft isn't in constructive possession of controlled goods data" — and Microsoft Canada is registered with the CGP "for both traditional purposes, including consulting services, and online cloud services," holding an approved controlled goods security plan. It also tells customers plainly: "you bear ultimate responsibility for complying with controlled goods regulatory obligations" (Microsoft, 2026). SAP Canada registered on 18 November 2025 (SAP Canada, 2025). Green House Data, a US company headquartered in Wyoming, registered in February 2020 to serve the Canadian market (Green House Data, 2020). And Amazon states it directly in its own defence-customer guide: "Amazon Web Services Canada, Inc. is a registrant with the CGP, and our registration is listed in the CGP registration directory" (Amazon Web Services, 2024).
Two conclusions, both commercially useful. Foreign ownership is not a bar — the program registers a Canadian entity and screens the individuals who touch controlled goods, not the foreign parent. And a vendor's legal position is not your safe harbour — Microsoft's non-possession argument concerns Microsoft's exposure, not yours, and a procurement officer with counsel on the call will say so.
The Second Test, Which Is Where Location Actually Bites
Residency is soft inside the CGP. It is not soft under export control.
On 5 November 2025, Global Affairs Canada issued Notice to Exporters No. 1159 on the movement and storage of controlled technology in the cloud. Disclosing controlled technology from inside Canada to outside Canada in a way that creates a "reasonable possibility" of examination abroad is a transfer requiring an export permit. The threshold is "more than a mere possibility, but less than the standard of more likely than not" (Global Affairs Canada, 2025).
That is far below what most engineering teams assume. The question is not whether a foreign national read the file; it is whether one could have. An offshore site-reliability engineer with standing production access, or a key-management service operated outside Canada, satisfies it without anyone opening anything.
The notice also sets out the way through, and it reads as an architecture specification: industry-standard strong encryption; encryption keys managed so there is no more than a remote possibility of examination outside Canada; and, where decryption is unavoidable, decryption "through non-human intervention" on a closed system where all unencrypted copies are destroyed. Compliance with the Canadian Centre for Cyber Security's cloud guidance generally removes the permit requirement (Global Affairs Canada, 2025). Canadian counsel reading the notice reached the same conclusion (Blake, Cassels & Graydon LLP, 2025; McCarthy Tétrault LLP, 2026).
So location does matter — through the export-permit regime rather than through a CGP residency rule. The practical posture is the same either way: keep controlled data and its keys in Canada, or be ready to explain to Global Affairs Canada why you didn't.
Both Questions Are Really One Question
There is a useful framing for this in the research literature. A 2025 peer-reviewed review defines digital sovereignty as the capability of a nation or institution to control and supervise its digital infrastructure, data, and technology free from excessive reliance on foreign forces, with sovereign control extending past storage to the algorithms and models built on that data (Misra et al., 2025).
Canada has written that idea into two instruments that check the same thing from different angles. The CGP asks who may examine and possess. Notice 1159 asks who could reach it from abroad. Residency is how you make both answers easy — not because a rule demands Canadian servers, but because keeping the data and the keys in Canada is what shrinks the set of people who can reach them.
Which means the artifact that wins a defence conversation is not the residency page on your website. It is the pairing of that map with an access-control record: who can decrypt, from where, under what screening, and what happens to cleartext when the process ends. Most vendors have the first and not the second.
Where the Exposure Concentrates
Sorted by what actually happens to customer content, a platform falls into three tiers.
Where the registration trigger actually sits
What vendors answer
What the Directorate asks
Our data is stored in CanadaResidency is the softer of the two questionsWe are a cloud provider, so we are out of scopeExamination is the trigger, not storageWe hold the encryption keysAccess in the clear is what counts
Tier 1 — persistent storage. Object stores, key-value stores, managed databases, durable state, media pipelines, retained logs, hosted assets. Controlled technical data landing here puts you in the possession conversation.
Tier 2 — decrypt, inspect, discard. Products that terminate TLS, inspect in memory, re-encrypt and forward, persisting nothing. Under the current guidance this tier turns on whether anyone examines the data — automated machine inspection with no human access is a defensible position, and it is the position you must be able to evidence.
Tier 3 — packet-level transit. No decryption, no retention, headers only. Clean.
Then the configuration trap, which is the single most dangerous line in this analysis: enabling verbose or debug logging on a Tier-2 product moves cleartext into retention and puts a human-readable copy where staff can reach it. A logging change is a scope change. Treat it like one.
What This Opens
Canada's defence industry generated CA$17.3 billion in revenues, contributed over CA$11.1 billion to GDP, and supported 81,800 jobs in 2024, with small and medium-sized businesses making up over 90% of firms (Innovation, Science and Economic Development Canada, 2026). Registration is free to file; the investment is a Designated Official, per-person security assessments, a security plan per site, records, breach reporting, and inspection readiness.
What Sagentix Does — and Does Not Do
Scope: Sagentix prepares organizations for independent assessment; it is not a 3PAO and does not perform the independent assessment, issue certification, run penetration tests, or operate a security operations centre. Sagentix also does not perform Controlled Goods Program registrations or act as export-controls counsel. What it does do is prepare organizations for assessment, and advise vendors on go-to-market strategy — positioning, pricing, sales process, buyer journey — so they can sell into markets where compliance is the buying trigger. The CISSP underwrites both. The registration decision and the Notice 1159 position belong to your governance team and Canadian counsel.
What This Looks Like in Practice
A Sagentix Phase 1 proof-of-concept for a vendor selling into Canadian defence-adjacent sectors produces Sagentix Phase 01 Market Intelligence, 2026:
- A competitive positioning matrix on compliance-outcome dimensions — key-custody options, processing locality, access-evidence completeness — instead of feature parity
- A buyer journey map anchored on the actual procurement gates, including where the controlled-goods question enters and who asks it
- A bottom-up TAM/SAM/SOM filtered by NAICS codes for defence primes, sub-tier suppliers, and adjacent regulated sectors
- A pricing benchmark against the buyer's internal compliance labour cost, so the platform reads as an ROI line item rather than a security expense
The deliverable is a 60–90+ page evidence-traced document carrying a median of 38 APA 7th edition citations, passed through an 18-check quality gate.
Three Paths From Here
You do not need Sagentix to act on any of this.
- Build the access record to sit beside the residency map. List every role, service account and support pathway that can reach cleartext or keys, and mark which sit outside Canada. That single artifact answers the must half of the guidance — at zero cost.
- Fix the architecture before the paperwork. Key custody, processing locality and logging defaults decide both answers. That work belongs to product and engineering, and it is worth doing whether or not you ever register, because it is also the answer to Notice 1159.
- Pressure-test the positioning with an outside read. Bring in someone who can map your product tiers to the buyer's compliance questions and stress-test whether your go-to-market narrative survives a compliance-led procurement evaluation. That is the Sagentix Phase 1 proof-of-concept — 1,412 curated artifacts and an 18-check quality gate, CA$4.5K–$45K end-to-end in 6–8 weeks, with Phase 1 under a money-back guarantee (subject to terms) Sagentix GTM Methodology, 2026.
If you want to test whether your current positioning survives a defence procurement review, book a free 30-minute Strategy Diagnostic or email stephane@sagentix.ca.
This is only half of what a defence prospect is asking. The other half — the Canadian Program for Cyber Security Certification, which turns on a contract clause rather than on your architecture — has its own trap, and I take it up tomorrow.
Here is what I keep asking vendors in this market: you can almost certainly show me where your customer's data sits. Can you show me, on paper, every person who can decrypt it — and where each of them is?
References
- Amazon Web Services. (2024, June). AWS user guide to Canada's Controlled Goods Program (CGP). Amazon Web Services.
- Blake, Cassels & Graydon LLP. (2025, December 2). Global Affairs Canada issues guidance on controlled technology and cloud storage. Blake, Cassels & Graydon LLP.
- Controlled Goods Regulations, SOR/2001-32. (2001). Justice Laws Website. Department of Justice Canada.
- Defence Production Act, R.S.C. 1985, c. D-1. (1985). Justice Laws Website. Department of Justice Canada.
- Global Affairs Canada. (2025, November 5). Notice to exporters No. 1159: Movement to and storage of controlled technology in the cloud. Government of Canada.
- Green House Data. (2020, February 25). Green House Data continues to expand capabilities in the Canadian market with Canadian Controlled Goods Program registration [Press release]. BusinessWire.
- Innovation, Science and Economic Development Canada. (2026). State of Canada's defence industry 2026. Government of Canada.
- McCarthy Tétrault LLP. (2026, January 30). Navigating export controls in the clouds: Canada clarifies rules on cloud storage and transfers. McCarthy Tétrault LLP.
- Microsoft. (2026, June 2). Canada controlled goods. Microsoft Learn.
- Misra, S., Barik, K., & Kvalvik, P. (2025). Digital sovereignty in the era of Industry 5.0: Challenges and opportunities. Procedia Computer Science, 254, 108–117.
- Public Services and Procurement Canada. (2024). Guidance on cloud services for Controlled Goods Program registrants and registered cloud service providers [Superseded version, archived 10 February 2024]. Internet Archive capture.
- Public Services and Procurement Canada. (2025, May 8). Guidance on using or providing cloud solutions for controlled goods data. Government of Canada.
- Public Services and Procurement Canada. (n.d.). Register in the Controlled Goods Program. Government of Canada.
- SAP Canada. (2025, November 18). SAP Canada fortifies commitment to national security with Canadian Controlled Goods Program registration. SAP News Center.
Subscribe + get the workbook
The Bottom-Up TAM / SAM / SOM Workbook — free with your subscription
An 11-page tactical workbook with fillable worksheets — NAICS lookup, three-filter SAM test, Bull/Base/Bear SOM, and the diligence cross-checks. Not published anywhere else. Then get evidence-backed analysis every other Tuesday. No spam. Unsubscribe anytime. See past issues.

Stéphane Raby, CISSP, CMC, P.Eng., MBA
Founder & Principal — Sagentix Advisors
CMC | CISSP | P.Eng. | uOttawa Telfer Executive MBA — ranked #1 globally by CEO Magazine, 2023. 25+ years in technology strategy, cybersecurity, and management consulting.
Want This Evidence Applied to Your Market?
Phase 1 Market Intelligence starts at CA$4,500 with a money-back guarantee.