Home / Published Work / Canada's “as is” Contract Security Program
Canada's “as is” Contract Security Program
and the Aggregate Risk Profile of the Nation
SYNOPSIS
One of the challenges for large bureaucracies is identifying the second and third order effects of risk mitigation postures across the enterprise. This paper takes the aggregate risk profile introduced in the previous paper and applies it to the Contract Security Program, which handles roughly 90 per cent of procurements carrying a security requirement. It argues that the “as is” program provides a false sense of security to government and to Canadians, and traces the effects: higher procurement costs, unintended consequences for new Canadians seeking to supply the nation, corresponding impacts on diversity and inclusion outcomes, reinforcement of staff augmentation procurement practices, and an impediment to the Digital Ambition. It compares Canada's approach with those of allies and partners and makes eight recommendations to shift resources toward the procurements that actually carry national security risk.
“Absent diagnosing and resolving the strategic problems associated with higher level policies, Canada's aggregate risk will continue to increase.”
From the paper, page 1
KEY FINDINGS
- 1
The two clearances sit at opposite ends of the risk matrix, yet look almost the same. A Designated Organization Screening covers Protected A and B; a Facility Security Clearance covers Confidential, Secret and Top Secret. Other than the level of personnel screening, the only difference is that key senior officials complete a personnel security screening form for the FSC. A DOS takes up to four months, an FSC six months or more.
- 2
The program is under extraordinary pressure and is being risk managed. Over ten years the number of companies requiring a DOS or FSC rose from roughly 12,000 to roughly 27,000, and the program must review about 18,000 companies a year. It is currently unable to deliver within its program objectives, and reviews for national security procurement are themselves being risk managed.
- 3
The burden falls hardest on new Canadians. A five-year background check is straightforward for someone who has lived in Canada their whole life, and problematic for most new Canadians. Of the top ten source countries for permanent residents, only the United States and France have information exchange agreements with Canada, and together they account for 9 per cent of that top ten. Average wait times run to months and years.
- 4
It discourages the information sharing it exists to protect. Where an industry partner provides an unclassified document and someone in government applies a protected marking, the DOS applies. Rather than reinforcing security, applying it in circumstances that are clearly unclassified undermines the overall posture and disincentivizes industry from sharing information with government.
- 5
Canada is an international outlier. Of roughly 44 nations that reported to PSPC, only ten require vetting for information classified below Confidential, and all of those still recognize the classification “restricted”, which Canada does not. Canada is unique in requiring contractors to hold a government-issued clearance to access non-national security classified information.
- 6
Risk has to be managed at the enterprise level, not one program at a time. A control can reduce the risk a single program is accountable for while adding to the risk carried by the nation, through procurement cost, delay, constrained labour supply, reduced competition and opportunity cost. The paper's stated aim is to identify those second and third order effects, and it argues that assessing the Contract Security Program only against the risk it was designed to mitigate conceals what that control creates elsewhere in the enterprise.
RECOMMENDATIONS
The paper makes eight recommendations.
WHERE THIS FITS
Added September 2026
This was the third paper in the series. The second introduced the aggregate risk profile as an idea. This paper applied it to a single program and showed what it looks like in practice: a control that is defensible on its own terms, accumulating through procurement cost, hiring, information sharing and industrial participation into risk carried by the nation. It is also the first paper to follow the consequences outward to people, to new Canadians waiting on a background check and to the small firms that cannot compete while they wait.