Frank Balonis on why Canadian partners need to start CPCSC prep now, and what CMMC taught us episode artwork

EPISODE · Sep 1, 2026 · 25 MIN

Frank Balonis on why Canadian partners need to start CPCSC prep now, and what CMMC taught us

from ChannelBuzz.ca

Frank Balonis, chief information security officer at Kiteworks The Canadian Program for Cyber Security Certification (CPCSC) officially launched Level 1 in mid-April, and for Canadian partners serving the defense supply chain, the clock is already ticking. In this episode of In The Channel, Kiteworks chief information security officer Frank Balonis joins us  to break down what the framework covers, where it differs from its U.S. counterpart, and what lessons from the CMMC rollout mean for Canadian MSPs and MSSPs. Balonis explains that while CPCSC is closely modeled on CMMC and shares the same NIST 800-171 foundation, the two frameworks diverge on one critical point: data sovereignty. Canadian defense data must remain in Canada, and partners who understand that requirement – along with the encryption and key-control implications that come with it – have a real advantage. The bigger opportunity, Balonis argues, lies in the cross-border play. Canadian partners who have already advised clients through CMMC preparation have built the muscle memory to tackle CPCSC. Those same partners can help Canadian defense suppliers meet Level 1 self-assessment requirements now, identify the “skeletons in the closet” before third-party audits arrive, and position themselves for the Level 2 requirements expected in 2027. Unlike CMMC, which paused and relaunched as 2.0, CPCSC is already live with a shorter runway. Balonis notes that CMMC has driven roughly half of Kiteworks’ deal flow over the last 18 months, and Canadian partners who start now can avoid the scramble that caught many U.S. contractors flat-footed. His core advice for partners: start with governance, not dashboards. Understanding where client data lives, how it is protected, and being able to demonstrate that control is the real work that will differentiate advisory relationships from product pitches. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca, and your host for the show. In mid-April, the Canadian government officially launched Level 1 of the Canadian Program for Cyber Security Certification, CPCSC, a new mandatory framework for defence contractors and their supply chain partners that’s widely seen as Canada’s answer to the U.S. CMMC program. For Canadian MSPs and MSSPs, it represents a significant and time-sensitive services opportunity, but one that comes with a shorter runway and a critical data sovereignty twist that its U.S. counterpart never had to address. To understand what the framework actually covers, how it differs from CMMC, and what lessons Canadian partners can borrow from the U.S. rollout, I sat down with Frank Balonis. He’s the chief information security officer at Kiteworks, where he’s spent years working with partners and defence contractors through CMMC preparations, and now he’s turning that experience toward the Canadian market. Let’s get right into it. My chat with Frank Balonis. Frank, thanks for taking the time. I appreciate it. Frank Balonis: Glad I could be here. Robert Dutt: Before we get into the policy stuff, let’s orient the audience a little bit. Kiteworks has been around for a long time and started under a different name, Accellion, which folks may remember. But can you kind of give me the nickel tour of where you’re at and what you do as a company today? Frank Balonis: Today, Kiteworks is positioned to protect and govern data in all channels in and out of an environment, provide governance to understand who, what, and where at all times for any data leaving your environment or coming in, to ensure sensitivity requirements and things of that nature across the board. Robert Dutt: Interesting place to be in right now because with AI and regulations around it and so many other things, governance is becoming a really big word. Frank Balonis: Yes, it is. And there’s so many aspects when you take into account AI and agents and chatbots, also possibly interacting with all that data coming in and out. It’s a bigger and bigger field out there. Robert Dutt: And tell me a little about your role. It’s kind of unusual to have a CISO as a guest voice on the show. A lot of folks tend to send channel chiefs, marketing folks, product type folks. Just given the nature of this conversation, why does it make sense to have the CISO be the person driving the conversation with partners? Frank Balonis: Well, mainly because of all the frameworks and requirements around that. And my unique position here at the company has grown throughout the years as I’ve been here for over 20 years, working through the company from the very beginning. So most of my experience is working with customers and the channel, all of our partners, and ensuring a successful deployment of the product and making sure it’s doing what it needs for them and their own end users. Robert Dutt: Okay. Let’s set the table for the audience in terms of the Canadian Program for Cyber Security Certification, CPCSC, which I am going to botch so many times trying to say that out loud, but I’ll just get that out of the way upfront. Officially launched Level 1 in mid-April. It’s an ongoing process. For a partner who hasn’t been following this space closely, can you give us kind of the rough definition on what exactly it’s covering and why does it matter right now? Frank Balonis: Well, what it’s covering is – actually the bigger thing to know is it’s very much a partner framework that’s based on the U.S. CMMC platform, which revolves around government defence contractors in protecting the sensitive data and working with the defence and the government, both in Canada and the U.S. It’s actually based on the same framework as CMMC. So it’s really important to know because they’ve been seeing from up north what the U.S. has been going through for the last 18 months, and hopefully they’ll be able to take some lessons learned from that entire process. Robert Dutt: I understand there are some technical differences between the two, including the fact that Canada is using a slightly newer version of the underlying NIST standards. How close is the Canadian standard that’s rolling out to the U.S.-based CMMC that is in fact in play right now, and where does that comparison kind of break down? Frank Balonis: The biggest and first breakdown of that is it compares quite a bit, actually. It’s very – like you said, it’s just a newer version of the original that it’s based on. So it’s extremely similar. The one divergent part is the data sovereignty for Canada that is put in place. The CMMC in the U.S. is more about protecting the data. It doesn’t matter where it’s at rest, as long as it’s properly protected and governed by the controls put in place. Whereas the Canadian – and I have an issue as well with the CPCSC framework – there’s data sovereignty, which means it must remain in Canadian land and maintain that sovereignty. Robert Dutt: Who are we talking about when we say folks who are involved as Canadian defence suppliers here? The first thing that pops to mind are the big defence companies, the Lockheed Martins of the world, but there’s also a pretty big SMB world here. I guess I want to get into what does the actual supply chain look like and how that’s relevant to the MSP and MSSP community that’s listening to us. Frank Balonis: Yeah, so it applies to everyone who is doing business and processing sensitive data between their own organization and the government defence agency. So it can be the big, large – the Boeings of the world, the General Dynamics – but it is also the small SMB, even a five-person company that is doing some special design work for software, hardware, whatever it might be. They’re all tied into the same framework. Now, there’s going to be various levels. As you mentioned, Level 1 is in play right now. Level 2 will be later and so on until Level 3, very much similar to CMMC. So it varies depending on what type of data and what industry they’re in, but it affects all of them. Robert Dutt: How do those levels ramp over time? What’s the dividing line between Level 1, Level 2, Level 3? Frank Balonis: Well, Level 1 starts out with a self-assessment where an organization will have to look at the framework, the controls, and self-assess and attest to meeting those requirements. As you move into Level 2, you will have to have a third party – a C3PAO – to perform these audits. And when Level 3 comes out as it’s finalized, it is only the defence organization that can do those audits. And that’s still, as you mentioned, in progress. Robert Dutt: Okay. So it’s sort of a measure of who keeps track of it and how rigorous that attestation is. Got it. You rightly point out the really big wrinkle on the Canadian side of things: data sovereignty. It means you can’t just take Protected B data in Canada and put it on a U.S.-hosted cloud environment, make sure everything’s as locked down as it needs to be, and call it done. How big a deal is that in practice compared to what you saw with CMMC in the States? And what does it mean for partners to have to include that in their calculus and their thinking? Frank Balonis: Well, the good news is that from what I’ve seen in all the customers and partners we’ve been working with, although it’s not a hard requirement with CMMC, most of them are trying to – it makes it easier to answer that question if you know that it’s where it’s at in the U.S. and safe. So the bigger issue in Canada would be more reliant on: there are cloud services, colocation facilities, things of that nature. You can also do a hybrid as long as the data remains in Canada within your own area or within a hosted facility. Of course, there are also concerns of the CLOUD Act and issues in that manner. And that’s why you would need to ensure that you are specifically – these can be addressed with other technologies such as encryption at rest and things of that nature that would protect you from having to worry about that. Robert Dutt: That’s kind of a generally overhanging concern though. It’s not necessarily specific to this particular regulation. It’s an industry-wide thing if I’m not mistaken. Frank Balonis: 100%. I deal with this globally all the time and we work together to provide the right tooling and controls to ensure that you can meet the data sovereignty and you do not have to be concerned about the CLOUD Act. Robert Dutt: That must be a super fun challenge given the array of countries that have various regulations that are going in various directions at various times and the propensity of those to change. Frank Balonis: Yes. That’s why the important part that we always work with our customers and partners on is understanding that – making sure that the customer, the end user itself, that organization has full control of their data by controlling the keys, maintaining awareness and control of where the data is, how it’s stored. It allows them to address any framework or global requirements. Robert Dutt: So let’s take away some of the lessons if we can from CMMC and that experience. You guys have been living with CMMC since the early days of the rollout, working with defence contractors, partners through the whole experience. Looking back, what actually happened in the U.S. market when it landed and became law of the land? Did the partner community step up and help solve the problem? Was it chaos? What did we experience? Frank Balonis: Actually, a little bit of all of the above really. There was a lot of chaos. There’s still a lot of chaos, honestly. As you understand the scope and the breadth of all of the companies that are going to be in focus for both of these frameworks, there’s still a lot to be learned. But there are a number of partners and MSPs that have understood really where to lock in on what these requirements are. At the end of the day, in the U.S., for instance, the CMMC was actually just another enforcement of something that was already required of the contractors with the NIST SP 800-171. They were already required to meet those. CMMC was just a more rigid framework that has to be completed, whether it’s your own self-attestation or third party. So there’s the aspect of that. Once you understand these requirements have already existed and that the main point of this is governance and evidence to prove that you are following these controls – where the organizations focused on that, as opposed to just trying to cover everything, they succeeded in making this a successful program for a number of our customers. And I’ve seen it in how they work with other companies and vendors to do the same thing. So focusing on the governance part is where it needs to happen. Robert Dutt: Any other common threads that you saw among partners who built successful practices around CMMC, or around customers who are subject to CMMC? What did those partners do differently – technical services, different service models, a go-to-market thing, a combination of any of that? Frank Balonis: There was a lot of go-to-market. We see not only with just us as a vendor, but other partner vendors that we have working with our partners to build an entire framework to help meet the needs of CMMC. Technologies like Kiteworks and other security platforms, they can meet a majority of the controls, but there are some areas that it doesn’t make sense or it just doesn’t fit, that they can meet all the controls. So bringing all of those together and understanding the controls and staying focused on those was what drove the success that we’ve seen in putting together an entire ecosystem to properly provide the evidence and the governance over the platform and your environment. Robert Dutt: Okay. Your own data for the CMMC experience shows some pretty sobering numbers – less than half of contractors feel prepared for Level 2 and more than half still haven‘t done a gap analysis. I’m curious if you think Canada is tracking along a similar way. Are there any signs that we’re better prepared because folks have been able to sit back and watch the experience in the U.S. and kind of seeing where the mines are in the minefield? Frank Balonis: Yes, I think they’re going to be in a better place as long as you learn from history and are able to move forward. As we see in the close proximity of the two countries, the fact that those two frameworks were actually purposely built off the same framework for that commonality – I’m already working with partners and customers from Canada that need to meet the CMMC requirements. So those organizations already have a leg up because they already have all of these things in place. Now they may have to make adjustments because of the sovereignty rule that we talked about earlier, but it allows them to quickly address these needs. So as long as they’ve been paying attention to the neighbours down south and enacting these things, they’ll have a leg up on where the U.S. was a few years ago with CMMC. The downside is they have a shorter runway to do it because CMMC launched and then they paused and then they launched again with CMMC 2.0 and they built through all of that. Whereas CPCSC is already live and continuing to move forward, and you have to meet requirements as soon as this summer and sooner than later you’re going to have Level 2 requirement and a Level 3 requirement, depending of course where you are and what data you’re working with. So it’s something one has to be on top of fairly quickly if one is affected or working with organizations that are. Robert Dutt: Absolutely. And a lot of the partners – one of us actually earlier working with a partner that is out of Canada to provide services for CMMC – we have these partners that understand exactly how you need to move forward in addressing these things. So as long as the partners have a very good future of being able to help their customers, as long as they’ve been paying attention, they’ll be able to help these organizations that don’t have a compliance person, they’re too small of an organization, they don’t have all of these things in place, and they are going to have to rely on these partners to help them out. I wanted to expand a little bit on what you were talking about with the kind of cross-border opportunity. You flagged it with partners who are in Canada, who today have some experience working with CMMC, they’ve built up some of the muscle memory to deal with CPCSC as it comes online. I imagine somewhere down the road in the not too distant future, by the sounds of it, we’re going to have Canadian partners who are CPCSC certified, who are therefore partially down the road to understanding and being able to solve for CMMC. How much of that – how real is that cross-border bidding opportunity and how should a partner be thinking about positioning that? Frank Balonis: I think there’s a real opportunity there because the partners up north might not have been able to be the third-party auditors for CMMC, but they could be the advisors. As long as they’re working through all of that, they could take their experience from being advisors to their customers to prepare for CMMC and convert that into the ability to actually work with auditors for the CPCSC and help implement that. Where, again, a number of our customers utilize this – since there isn’t that sovereignty requirement with CMMC and there is that natural instinct of an organization that wants to stay completely in control, they already have their data up in Canada, which means they’ve already got a framework in place to meet the CMMC requirements for the U.S. and they can easily convert that to CPCSC very, very easily. So the best advice I could give to an organization is to properly vet and find a partner that has that experience and can quickly work with you to get you up to speed because, as we mentioned, they have a much shorter runway to get there. They can’t start at the beginning. They have to find someone that’s already been doing this for a while. Robert Dutt: If I’m a Canadian MSSP or a security-focused VAR listening to this right now, I’ve got a general security practice. Maybe I’ve been doing some compliance work in regulated industries. Where do I actually start with this? What’s the first conversation I should be having with my clients and what does engagement around CPCSC or CMMC look like in practice? Frank Balonis: It really starts with understanding whether they know where their data is and how that data is being protected. That is the biggest part of all of that. Working with the partner to understand what these requirements look like, where their data is, is the first place that I would really focus on because, again, the most important part is not a dashboard but the governance and the evidence of it and making sure that you control this. Robert Dutt: What’s kind of the best practice guideline, shall we say, for timelines? I imagine because of the nature of this, it’s not the kind of thing you want to be looking at that deadline and planning to slide in right at the deadline to reach compliance. You want to have some runway to make sure that all of your assumptions along the way have been correct, shall we say? Frank Balonis: If I was an organization up in Canada right now, I’d already be looking for a partner to help. Maybe not specifically setting any kind of deadlines other than the fact that you understand certain requirements are going to be in effect this summer. So the sooner you get on this, the faster, the better. So yesterday is the time to start on this, but if you can’t start yesterday, start today. That’s the best advice I could give because there’s always going to be those skeletons in the closet of, “Oh, I forgot about this,” or “Where is that?” As you start walking through the framework with your partners and understanding the controls, you are going to uncover things that you need to address as quickly as possible. Very similar to CMMC, you will have very little room to have any kind of out-of-control controls, so to speak, any findings or nonconformities depending on what framework you’re looking at and what type of audit. The area for margin is very small. Robert Dutt: Along that note, the last one for me: Level 1 is self-assessment, which is relatively accessible, I would think. But Level 2, you’re getting third-party assessments and that clock is ticking toward April 2027. Sort of along the same lines as the last question, but what’s basically your message to the Canadian partner community about the window of opportunity that exists right now? Frank Balonis: I would, for the folks that are going to be required for Level 2, I would do the Level 1 as soon as possible for you to understand where your gaps are. And you can attest to have your controls in place, because when Level 2 comes, the more information you already have by running through your own internal audit, which is effectively what a Level 1 is, the quicker you’ll be able to close those gaps and understand what you need to do before 2027 comes up on you. I personally, we’re working on consolidating a huge number of audits into a single one, and I’m already nervous that we’re three months away and still looking at a few things to complete all of them. We’ve done all of these individually, but we’re bringing them together, and that’s where you start seeing your gaps in between different organizations, different architectures. So the sooner you understand where you are, the sooner you can close those gaps and meet the requirements for Level 2. Robert Dutt: Sound advice. I appreciate it. Thanks for taking the time to walk us through the situation as it is and the opportunity out there for partners. Frank Balonis: My pleasure. I’m glad I could do this today. Robert Dutt: There you have it. Frank Balonis from Kiteworks. I’d like to thank Frank for his time. A couple of things from that conversation that I think are worth sitting with. First, the urgency. Balonis was clear that unlike CMMC, which paused, restarted, and gave the market time to catch its breath, CPCSC is already live and moving toward Level 2 third-party assessments. If you are a Canadian partner waiting for the phone to ring, you are already behind the partners who started this work six months ago. Second, the governance point. The line that stuck with me was that the important part is not a dashboard, but the governance and the evidence of it. In a market that loves to sell tools, the real compliance opportunity is advisory: helping clients understand where their data lives, how it is protected, and being able to demonstrate that control. That is a services play, not a product play. And third, the cross-border angle. Canadian partners who built CMMC advisory muscle with U.S. clients have a head start that is actually hard to replicate. The frameworks share the same foundation, and the sovereignty requirement is a wrinkle, not a wall. The firms that can bridge both sides of the border are going to be the ones that win the long-term compliance relationships. I’d like to thank you as always for listening to the show. Follow or subscribe wherever you get your podcasts – Apple Podcasts, Spotify, YouTube, most directories. Ratings and reviews are always appreciated and always help. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

Episode metadata supplied by the publisher feed · Published Sep 1, 2026

Embed this episode

NOW PLAYING

Frank Balonis on why Canadian partners need to start CPCSC prep now, and what CMMC taught us

0:00 25:03

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of ChannelBuzz.ca?

This episode is 25 minutes long.

When was this ChannelBuzz.ca episode published?

This episode was published on September 1, 2026.

Can I download this ChannelBuzz.ca episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!