Ron Lloyd BETWEEN INTENT AND OUTCOMES

Home / Published Work / Aligning Canada's Policy Architecture

POLICY PERSPECTIVECANADIAN GLOBAL AFFAIRS INSTITUTEAPRIL 2026

Aligning Canada's Policy Architecture with the Defence Industrial Strategy

The consolidated blueprint: six reform pillars and a sequenced roadmap

Defence & National Security Governance & Decision-Making Digital Government & Procurement

SYNOPSIS

The Defence Industrial Strategy sets out an ambitious vision for expanding Canada's industrial base and strengthening sovereign capability. This paper argues that if the enabling instruments beneath it remain unchanged, it risks becoming another well-articulated strategy constrained by the very systems meant to enable it. Strategy can signal intent; only structural alignment delivers capability. Written as the consolidating piece of the Digitalizing for Defence series, it sets out why the constraint is structural rather than technological, and then does what the earlier papers did not: it gathers every recommendation from the series into a single annex organized under six reform pillars, with lead responsibility and sequencing attached to each, and a four-phase implementation roadmap running from ninety days to two years.

“Strategy does not fail because culture resists it. Strategy fails when the policy architecture that shapes culture remains untouched.”

From the paper, page 5

KEY FINDINGS

  1. 1

    The Defence Industrial Strategy is, at its core, a sovereignty project. For decades Canada operated within the strategic comfort of proximity to the United States. That environment has shifted, and sovereignty must now be sustained through institutional capability. In earlier eras railways and highways bound a vast federation into a functioning economic whole; today the decisive infrastructure is institutional rather than physical.

  2. 2

    The constraint is structural, not technological. Canada has capable public servants, sophisticated firms and advanced digital tools. When classification frameworks, accreditation regimes, export controls, contract security requirements and digital governance authorities remain calibrated for a prior era, they become binding constraints on delivery. The paper argues that Canada's fall in the United Nations E-Government Development Index, from third in 2010 to forty-seventh in 2024, reflects an institutional coherence problem rather than a shortage of talent or ambition.

  3. 3

    The levers that decide whether the strategy succeeds sit outside it. Many of them reside with functional authorities, Treasury Board Secretariat, CSE, Shared Services Canada and the RCMP, rather than with the delivery departments. Those authorities operate largely outside the formal scope of the strategy, yet they determine whether its objectives are achievable within acceptable timelines and cost. Without their alignment, delivery departments cannot overcome structural delay regardless of funding.

  4. 4

    Small p policy defines culture, not the other way round. The familiar adage that culture eats strategy for breakfast has become a convenient explanation for implementation failure. Classification frameworks, cyber controls, contract security instruments, export regimes and oversight authorities establish the incentives and constraints that govern daily institutional behaviour, and while they remain unchanged they will quietly neutralize any strategy misaligned with them.

  5. 5

    Proportional alignment strengthens the security posture rather than weakening it. The objective is not deregulation. Overclassification and disproportionate assurance regimes do not increase security; when low-risk activity is subjected to controls designed for high-risk environments, execution slows and oversight focus disperses. Concentrating safeguards where risk is real restores execution speed as a component of sovereignty.

  6. 6

    Federation alignment depends on federal coherence first. In a federation, digital sovereignty cannot be imposed; it must be interoperable. But without proportional calibration of federal classification, cyber and assurance frameworks, intergovernmental interoperability risks exporting existing structural friction across jurisdictions rather than resolving it. Australia and Germany recalibrated federal governance instruments before integrating.

A TESTABLE CLAIM

The paper is explicit that its analysis is not offered as a matter of opinion. If implementation does not improve procurement velocity, small and medium enterprise participation and digital adoption timelines within measurable periods, the diagnosis will have been incorrect. If it does, the constraint will have been structural rather than strategic. The annex and roadmap are published in that spirit, with assumptions, dependencies and sequencing made explicit so that progress, or the lack of it, can be assessed against a common reference point by parliamentarians, committees, journalists and academics as well as by those inside government.

THE SIX REFORM PILLARS

Annex A consolidates the recommendations of the series into twenty-five actionable decisions, each with a policy lever, a lead responsibility and a sequencing dependency.

I. Reset the security foundationAdopt a modern classification framework of Official, Official-Sensitive, Secret and Top Secret; articulate injury and business impact models; retire TRA-1; define data aggregation in line with allied practice; and explicitly accept transition risk in order to reduce aggregate risk. Foundational, and most of what follows depends on it.
II. Modernize cyber and digital architectureReplace ITSG-33 with a consolidated modern control framework; state explicitly that approved commercial software is acceptable for Official and Official-Sensitive data; reform the CPCSC to a risk-based, allied-aligned model accepting CMMC equivalency, or failing that hold Level 3 to roughly one per cent of suppliers; and adopt Zero Trust and data centric security explicitly.
III. Reform contract security and personnel assuranceAlign Designated Organization Screening with allied practice while retaining Facility Security Clearance rigour for classified procurements; replace clearance reliance with information-handling training for low-risk work; reallocate Contract Security Program resources toward foreign ownership, control and influence and high-risk activity; shorten reliability look-back periods; and make departments accountable for contractor screening.
IV. Restore Defence institutional authorityPermit Defence to host and manage all of its data and to acquire software applications against its own requirements, doing away with the false dichotomy of administrative versus operational data, and amend Order in Council 2015-1071 to remove Defence's dependency on Shared Services Canada so that SSC can be used where it genuinely makes sense.
V. Align trade and industrial security with alliesPublish and track industry compliance costs; integrate export controls with the Controlled Goods Program; modernize the Controlled Goods Regulations to enable risk-tiering and digital clarity, with statutory amendment only if residual authority gaps remain; and establish United States and Five Eyes assurance gating for streamlined trust.
VI. A national project: aligning the federationContingent on Pillars I to III. A First Ministers' Digital Sovereignty Accord; a national interoperability and trust framework covering identity, credentialing and secure data exchange; and harmonized risk-tiering and assurance standards across jurisdictions. Federation-wide interoperability must build on proportionally aligned federal frameworks, or it replicates the friction at greater scale.

THE IMPLEMENTATION ROADMAP

Annex B phases delivery so that foundational risk frameworks are reset before downstream instruments are modified, contradictory guidance is avoided during transition, ownership is clear at each stage, and progress is observable within defined horizons.

Phase 1 · 0 to 90 daysReset the foundational policy drivers of risk aversion and launch federation alignment. Interim classification direction, suspension of TRA-1, and a decision log and governance structure established. Led by Treasury Board Secretariat and the Privy Council Office.
Phase 2 · 90 to 180 daysModernize the digital and cyber policy framework and enable proportional adoption. An interim ITSG-33 replacement, consolidated cyber guidance, the data aggregation clarification, a Zero Trust directive and a draft interoperability and trust framework. Led by CSE, TBS and PCO.
Phase 3 · 180 to 365 daysRemove procurement and industry participation barriers and align the assurance regimes. Revised contract security guidance, a decision on CPCSC scope and phasing, a published compliance cost baseline, updated supplier onboarding and agreed cross-jurisdiction risk-tier guidance. Led by PSPC, TBS, DND and provincial central agencies.
Phase 4 · 12 to 24 monthsRestore Defence digital autonomy, align trade controls and institutionalize federation governance. A Defence-managed data and cloud operating model, an integrated Controlled Goods and export controls model, any legislative package required, Five Eyes assurance statements and a standing federal-provincial digital architecture council. Led by PCO, GAC, DND and TBS.

WHERE THIS FITS

Added September 2026

This is the paper that turns a series into a blueprint. The five before it each examined a distinct domain and, read together, described a consistent pattern; this one names that pattern as policy architecture, consolidates every recommendation into one annex with ownership and sequencing attached, and commits to a test by which the whole argument can be judged. It also makes the method explicit: Defence was used as a stress test rather than treated as an exceptional case, because an institution sitting at the intersection of high assurance, digital integration, industrial participation and allied interoperability reveals dynamics that run across government.

ABOUT THE AUTHOR

Vice-Admiral (Ret'd) Ron Lloyd was the 35th Commander of the Royal Canadian Navy and is a Fellow of the Canadian Global Affairs Institute. Transparency →