📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Governance, risk & compliance

CSA Staff Notice 33-322 - Registered Firm Cybersecurity 15 July 2026

RegionalCanada

The Canadian Securities Administrators' current cybersecurity expectations for registered firms, published 15 July 2026 after a review of 73 firms.

It hangs off section 11. 1 of National Instrument 31-103, which requires a registered firm to have a compliance system reasonably designed to manage the risks of its business - the CSA now reads cybersecurity squarely into that obligation.

Five practice areas: policies and procedures, training, risk assessments and controls, third-party service providers, and the incident response plan. This applies to every registered firm in Canada, including portfolio managers, exempt market dealers, and investment fund managers that are not CIRO Dealer Members.

Official reference: https://www.securities-administrators.ca/news/csa-publishes-updated-cybersecurity-findings-and-guidance-for-registered-firms/

How Lavawall® helps you get to CSA Staff Notice 33-322 - Registered Firm Cybersecurity compliance

Most of CSA Staff Notice 33-322 - Registered Firm Cybersecurity comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to CSA Staff Notice 33-322 - Registered Firm Cybersecurity, and tracks your posture continuously instead of once a year at audit time.

  • Assess your current state against CSA Staff Notice 33-322 - Registered Firm Cybersecurity in the Lavawall GRC module, with the questionnaire and control set built in.
  • Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
  • Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.

Related

Ready to tackle CSA Staff Notice 33-322 - Registered Firm Cybersecurity?

Assess, remediate, and stay audit-ready for CSA Staff Notice 33-322 - Registered Firm Cybersecurity — and every other framework you carry — from one Lavawall® console.

Lavawall® supports CSA Staff Notice 33-322 - Registered Firm Cybersecurity as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.