# CIRA Cyber Stack: Canadian control, dependencies and evidence

> An independent assessment of CIRA Cyber Stack's Canadian control, service dependencies, evidence, and questions buyers should ask before purchase.

[Canonical HTML page](https://trustcyber.ca/insights/cira-cyber-stack-assessment-2026/)

- Author: Junior Williams
- Type: Field guide
- Published: 2026-09-03
- Modified: 2026-09-03
- Topics: Cybersecurity risk, Canada, Digital sovereignty, Technology procurement

## What this examines

CIRA Cyber Stack brings together XDR, MDR, DNS security, Anycast DNS, awareness training, and a customer portal. This assessment maps where Canadian control is documented, where global or third-party dependencies remain, and what buyers should verify.

## Why it matters

Canadian control is not one property of a product name. Data location, operators, suppliers, legal entities, support access, recovery, and exit terms vary by service. Buyers need a service-by-service evidence map before treating a sovereignty claim as a decision-ready control.

## Key ideas

- CIRA's Canadian governance and Canadian-hosted XDR and MDR provide the clearest parts of the sovereignty proposition.
- Awareness training processes data in Canada and Europe, while Anycast DNS uses a globally distributed network.
- XDR and MDR have a shorter operating record than CIRA's established DNS services, and CIRA Hub is still under development.
- ISO/IEC 27001:2022 coverage is useful evidence, but buyers should confirm the purchased components, partners, and subprocessors inside the certified scope.
- A limited deployment and written answers on data flows, response authority, performance, export, deletion, and continuity should precede purchase.

## What the record shows

CIRA launched Cyber Stack as a shared name for XDR, awareness training, Anycast DNS, and DNS Firewall; each service remains available separately. XDR collects and analyzes telemetry, while MDR adds 24/7 Canadian monitoring, investigation, threat hunting, and coordinated response.
The DNS services have the longest operating record. CIRA reports millions of DNS Firewall users and more than 145 billion average Anycast queries per day, but those figures use different measures and are not Cyber Stack subscription counts. CIRA Hub remains under development, so buyers should confirm what the portal covers today.
- CIRA is a Canadian member-based not-for-profit that operates .CA; it is not a federal security or intelligence agency.
- CIRA's FY26 report says XDR missed its original market forecast and that the company revised its approach.
- The published product pages describe intended functions; buyers still need to confirm architecture, contract terms, partners, and performance in their own environment.

## Services and dependencies

The sovereignty proposition changes by service. CIRA documents Canadian hosting and operations most clearly for XDR and MDR. Awareness training uses a third-party platform with processing and storage in Canada and Europe. Anycast DNS is intentionally globally distributed, and XDR integrations can introduce additional providers under their terms.
- XDR: telemetry collection, log analysis, incident management, and automated playbooks; confirm connectors, ingestion limits, retention, tuning, and integration data flows.
- MDR: 24/7 monitoring, investigation, threat hunting, and coordinated response by Canadian personnel; confirm the partner, analyst authority, evidence handling, and response targets.
- DNS Firewall: recursive DNS filtering, reporting, APIs, and content controls; confirm resolver locations, logging, retention, sharing, false-positive handling, and SIEM integrations.
- Awareness training: bilingual courses, phishing simulations, reports, and optional email analysis; confirm the supplier, data regions, deletion, export, and optional AI-feature boundaries.
- Anycast DNS and CIRA TLD Anycast: authoritative DNS through Canadian and international nodes or global infrastructure; confirm management-plane and log locations, DNSSEC, failover, and SLA exclusions.
- CIRA Hub: portal views, alerts, trends, and action items are described publicly, but current product coverage and development status should be confirmed.

## How Canadian control differs by service

The Government of Canada's digital-sovereignty framework treats control as a combination of governance, data location, operations, technology, suppliers, assurance, continuity, and exit. Canada will continue to depend on an interconnected global internet, so the useful question is where control is documented and where dependencies remain.
- Canadian governance: CIRA's ownership and Canadian internet mission reduce foreign-parent exposure, but buyers should identify every licensor, partner, and supplier.
- Data location: XDR and MDR carry clear Canada-residency statements; awareness training uses Canada and Europe; Anycast DNS is globally distributed.
- Operational control: CIRA documents Canadian operations for core services, while MDR initially partners with Calian's Canadian SOC; contracts should name all parties that can access data or authorize response.
- Technology and supply chain: XDR is presented as open and modular, while awareness training and integrations introduce third-party dependencies.
- Assurance: ISO/IEC 27001:2022 recertification covers the published managed-services scope; buyers should confirm the purchased component, partner, and subprocessor coverage.
- Continuity and exit: modular products and an open XDR are useful starting points, but contracts should define exports, transition support, deletion evidence, renewal dates, and notice requirements.

## Where Cyber Stack fits

Cyber Stack supplies several controls within a broader defence-in-depth program. XDR and MDR can support detection, investigation, and monitoring, while DNS Firewall and Anycast DNS address DNS-layer prevention and public DNS resilience. Awareness training addresses part of human risk.
- Organizations still need incident-response plans, legal and privacy workflows, forensics, crisis communications, insurance coordination, and tested recovery decisions.
- Endpoint, identity, network, cloud, application, data-protection, and supply-chain controls remain separate responsibilities unless the proposed scope explicitly covers them.
- Customers remain accountable for compliance, configuration, lawful data handling, and the evidence needed to demonstrate their own control environment.

## Evidence available today

Public records support CIRA's Canadian governance, the scale of its DNS services, ISO recertification in the published scope, and the existence of a Yukon University XDR case study. The public record is thinner for newer XDR and MDR operating results, independent comparisons, and the current state of CIRA Hub.
- Ask how CIRA defines and measures threat-feed, detection-speed, phishing-click, and MDR-containment metrics in a comparable environment.
- Separate paid-customer counts, monitored assets, and service outcomes from free Canadian Shield users and from different DNS usage measures.
- Request current references from organizations with a similar environment, security-team model, and data-residency requirement.

## Questions to ask before purchase

Ask CIRA or its reseller to answer the following in writing before committing to a purchase. The answers should be specific to the products, versions, data classes, integrations, partners, and contract proposed for the organization.
- Which products and current versions are included, and which endpoint, identity, network, email, cloud, and SaaS sources are supported?
- Where is each data class stored, processed, backed up, administered, and viewed, and which legal entities or subprocessors can access it?
- What is monitored 24/7, what actions can analysts take, and what are the contractual targets for acknowledgement, investigation, escalation, and containment?
- What is inside the ISO 27001 scope, and may the customer review penetration-test summaries, continuity results, and material incident history?
- How are data, rules, cases, dashboards, and evidence exported, what transition assistance is included, and what proof of deletion is available at termination?

## Test the service before purchase

Run a limited deployment with predefined success criteria. Test connectors, alerts, analyst workflow, containment approvals, bilingual support, performance, data export, and failover. Use one tabletop incident to test handoffs among CIRA, its MDR partner, the customer's security team, legal counsel, and executives.

## Conclusion

Cyber Stack gives Canadian public-interest and mid-market organizations a domestic XDR and MDR option, established DNS services, and bilingual support. CIRA's Canadian governance, DNS operations, and Canadian-hosted XDR and MDR are the clearest parts of its sovereignty claim, while awareness training, Anycast DNS, and integrations require a more detailed dependency map.
Buyers seeking Canadian control should include CIRA's ownership in their review and require service-level data flows, supplier lists, customer counts, independent results, and explicit exit terms before treating the proposition as decision-ready.

## Selected primary sources

- [CIRA Cyber Stack overview](https://www.cira.ca/en/cybersecurity/)
- [CIRA XDR](https://www.cira.ca/en/cybersecurity/cira-xdr/)
- [CIRA MDR](https://www.cira.ca/en/cybersecurity/cira-mdr/)
- [CIRA DNS Firewall](https://www.cira.ca/en/cybersecurity/dns-firewall/)
- [CIRA Anycast DNS](https://www.cira.ca/en/cybersecurity/anycast-dns/)
- [CIRA Cybersecurity Awareness Training](https://www.cira.ca/en/cybersecurity/cybersecurity-awareness-training/)
- [CIRA ISO 27001 recertification](https://www.cira.ca/en/resources/news/about/cira-achieves-iso-27001-recertification/)
- [CIRA Fiscal Year 26 Annual Report to Members](https://www.cira.ca/en/resources/documents/about/fiscal-year-26-annual-report-to-members/)

## Caveat

This is an independent public assessment, not a competitor ranking, legal opinion, compliance certification, or purchase recommendation. Verify current products, partners, terms, data locations, and performance in the proposed environment.

## Evidence note

The assessment reviews CIRA product pages, policies, contracts, plans, and reports published through 3 September 2026, along with the Government of Canada's digital-sovereignty framework. It had no access to private architecture, customer contracts, demonstrations, penetration-test results, paid analyst research, or independent laboratory testing.

## Resources

- [Downloadable PDF](https://trustcyber.ca/guides/cira-cyber-stack-constructive-assessment-2026.pdf)
