Verification & Badges

What the Verified and cybersecurity best-practices badges on Security Standards Canada listings mean, and how they are assessed.

Last updated June 29, 2026.

Verified by Security Standards Canada

The Verified badge means we have confirmed the basics of a listing: that the organization is real and active, that it operates in or serves the Canadian market, that the website and contact details resolve, and that the description and categories on this site reflect what the company actually does. It is a check on accuracy and legitimacy.

It is not an endorsement of any product, a certification, a security audit, or a guarantee of quality. A company cannot pay to be verified, and verification does not change where a listing ranks. We re-check verified listings periodically and remove the badge if details fall out of date.

Cybersecurity best practices

This badge marks companies that are publicly known to follow recognized cybersecurity practices in how they build and support their products. Signals we look for include signed firmware and secure boot, a published vulnerability disclosure or coordinated disclosure program, timely security advisories and patching, secure-by-default configuration, and alignment with recognized frameworks such as the NIST Cybersecurity Framework, IEC 62443, or ISO/IEC 27001.

It reflects the vendor's own security posture, not the security of any particular installation. As with verification, it cannot be bought, and it is reviewed over time.

Corrections

If a badge is wrong, out of date, or missing where it should apply, write to contact@securitystandards.ca. If you represent a listed company, every listing also carries an "Is this you?" link for updates or removal.