DSCC Certification

Certification turns sovereignty from a claim into evidence.

DSCC certification helps organizations demonstrate auditable capability across data control, jurisdictional exposure, AI governance, vendor dependency, portability, security, accountability, and Indigenous Data Sovereignty alignment where applicable. Certification is based on documented evidence, structured review, independent assessment, and public verification. Organizations can now begin the certification process through the DSCC certification portal.

Evidence-based review · Auditor assessment · Committee decision · Public verification

Certification applications are open.

DSCC certification applications are now accepted through the online certification portal. Applicants complete eligibility screening, select a certification pathway, submit organizational scope, pay applicable fees, upload required evidence, respond to auditor questions, and receive a decision through DSCC’s certification review process.

Purpose

What DSCC certification is designed to prove

DSCC certification is being designed to assess whether an organization can demonstrate sovereign capability through governance, evidence, controls, contracts, technical architecture, audit records, and accountable decision-making.

The purpose is not to reward slogans. The purpose is to verify whether an organization can show meaningful control over the data, AI systems, vendors, infrastructure, and governance obligations it depends on.

Jurisdictional Control

Can the organization prove where data is stored, processed, backed up, accessed, and exposed to legal regimes?

Governance and Accountability

Can the organization show who owns decisions, controls access, approves use, and remains accountable?

Vendor and Cloud Dependency

Can the organization manage vendor lock-in, cloud dependency, subcontractors, cross-border exposure, and exit risk?

AI Sovereignty

Can the organization govern AI models, training data, prompts, outputs, infrastructure, and third-party dependencies?

Portability and Exit Capability

Can the organization move, return, delete, or recover data and digital workloads without institutional hostage-taking?

Indigenous Data Sovereignty Alignment

Where Indigenous data is involved, can the organization demonstrate respect for community authority, consent, stewardship, use restrictions, and data return obligations?

Process

How DSCC certification works

DSCC certification follows a structured pathway from readiness screening to evidence submission, auditor review, certification decision, badge issuance, public verification, and renewal. Each step is designed to protect credibility and ensure certification is based on documented evidence.

Core Tiers

Core certification tiers

DSCC core certification tiers reflect increasing levels of organizational maturity, evidence, and sovereign capability. Each tier has defined eligibility criteria, evidence requirements, review depth, and renewal obligations.

Core Certification Tier

DSCC Verified

Entry-level verification for organizations beginning their sovereignty journey.

Designed for organizations that can provide baseline evidence of data governance awareness, basic control mapping, policy foundations, and initial sovereignty readiness.

For small and mid-sized organizations, early-stage readiness, organizations beginning documentation, and organizations preparing for deeper certification.

Primary Pathway Core Certification Tier

DSCC Certified Data Sovereign Organization

Primary organizational certification tier.

Designed for organizations that can demonstrate defined policies, governance accountability, jurisdictional control, vendor management, security safeguards, portability planning, and audit-ready evidence.

For established organizations, public institutions, corporate members, technology providers, and organizations seeking public credibility.

Advanced Certification Tier

DSCC Advanced Sovereign Organization

Higher-maturity certification for organizations with strong sovereignty architecture.

Designed for organizations that can demonstrate advanced sovereign control, mature governance, vendor independence, AI/data portability, continuous monitoring, executive accountability, and evidence-based resilience.

For public-sector institutions, critical infrastructure organizations, mature enterprises, organizations with complex data/AI systems, and organizations seeking leading-market credibility.

Specialty Streams

Specialty certification streams

Specialty streams assess specific sovereignty risks and operating environments beyond the core organizational certification pathway. Applicants may apply for a specialty stream alone where eligible, or combine a specialty stream with a core organizational certification.

Specialty Certification Stream

DSCC Sovereign AI Ready

For organizations seeking to demonstrate governance over AI systems, models, training data, prompts, outputs, vendors, infrastructure, and AI-related dependency risk.

Covers: AI system inventory, model governance, training data controls, prompt/output governance, vendor AI dependency, human oversight, AI portability, explainability and auditability.

Specialty Certification Stream

DSCC Indigenous Data Sovereignty Aligned

For organizations that handle Indigenous, First Nation, Métis, Inuit, Nation, community, treaty, cultural, or community-controlled data and need to demonstrate alignment with authority, consent, stewardship, restrictions, and community governance obligations.

Covers: community authority, consent and permission, data-sharing agreements, cultural protection, AI/secondary-use restrictions, data return/deletion, vendor restrictions, community oversight.

Specialty Certification Stream

DSCC Sovereign Government Ready

For organizations seeking to demonstrate readiness to support government or public-sector data sovereignty requirements.

Covers: jurisdictional control, procurement readiness, public-sector data handling, security and privacy baseline, vendor dependency, audit evidence.

Specialty Certification Stream

DSCC Sovereign Public Sector Ready

For public institutions, agencies, nonprofits, and public-service organizations seeking to strengthen data and AI sovereignty readiness.

Covers: public accountability, data governance, privacy/security controls, vendor oversight, accessibility and transparency, records and retention obligations.

Specialty Certification Stream

DSCC Sovereign Critical Infrastructure Ready

For organizations operating in sectors where data, AI, infrastructure, continuity, and jurisdictional resilience are mission-critical.

Covers: resilience, continuity, vendor dependency, incident response, data recovery, access control, sovereign infrastructure risk.

Specialty Pathway

Indigenous Data Sovereignty Alignment pathway

Where an organization handles Indigenous, First Nation, Métis, Inuit, Nation, community, treaty, cultural, or community-controlled data, ordinary privacy and cybersecurity controls may not be enough. The organization may need to demonstrate how it respects community authority, consent, stewardship, use restrictions, cultural protection, AI limitations, vendor boundaries, and data return or deletion obligations.

Community Authority

Who has authority to approve collection, access, sharing, analysis, retention, return, or deletion?

Consent and Permission

What was approved, by whom, for what purpose, and under what restrictions?

Stewardship and Possession

Who holds the data, who controls it, and what obligations apply to the holder?

Cultural Protection

Does the data include sensitive cultural, historical, land-related, language, governance, or community information requiring special protection?

AI and Secondary Use

Can the data be used for analytics, AI training, automated decision-making, commercialization, or secondary research?

Vendor and Jurisdictional Exposure

Can third-party vendors, cloud providers, subcontractors, or foreign jurisdictions access the data?

Data Return and Deletion

Can the data be returned, deleted, restricted, or excluded from downstream systems where required?

Community Oversight

Is there an ongoing process for review, correction, dispute, withdrawal, or governance escalation?

DSCC’s Indigenous Data Sovereignty work should be informed by an Indigenous Advisory Circle to help review relevant standards, training content, resources, terminology, and alignment criteria. Advisory review does not replace the authority of any Indigenous Nation, government, community, or organization over its own data.

Apply for Indigenous Alignment Review Request Alignment Guidance

Evidence

Evidence domains

DSCC certification requires applicants to provide documentation and evidence across applicable domains. Evidence requirements depend on certification tier, scope, sector, AI use, vendor dependency, jurisdictional exposure, and Indigenous data involvement.

Data Inventory

What data exists, where it sits, who uses it, and what systems depend on it.

Data Residency

Where data is stored, processed, backed up, and replicated.

Vendor and Cloud Contracts

How vendors, cloud providers, subcontractors, and processors handle data and access.

Governance Policies

Who has authority, accountability, and decision rights.

Security and Privacy Controls

How data is protected, monitored, accessed, retained, and disclosed.

AI Governance

How AI systems, models, prompts, outputs, training data, vendors, and dependencies are governed.

Incident Response

How the organization responds to breaches, loss, unauthorized access, and operational disruption.

Backup and Recovery

How data and systems can be restored, recovered, or maintained during disruption.

Exit and Portability

How data, workloads, records, and systems can be moved, returned, deleted, or replaced.

Indigenous Data Governance

Where applicable, how the organization demonstrates authority, consent, stewardship, cultural protection, restrictions, and return/deletion obligations.

Clarity

What certification is — and what it is not

Membership Is Not Certification

DSCC membership indicates participation in the DSCC community and access to member benefits. It does not mean the member or organization has been certified.

Training Is Not Organizational Certification

Completing DSCC training may demonstrate learning or professional development. It does not certify an organization’s data sovereignty posture.

DSCC Certification Is Not Government Approval

DSCC certification is a DSCC-issued certification based on DSCC standards and certification processes. It should not be presented as government authorization, regulatory approval, legal immunity, or a substitute for legal advice.

Lifecycle

Renewal and public verification

DSCC certifications are time-limited, renewable, and subject to status controls. Approved organizations receive a certificate, badge, verification link, and registry listing for the certified scope. Expired, suspended, revoked, or scope-limited certifications are clearly distinguishable from active certifications.

Renewal model

  • Annual attestation
  • Material change disclosure
  • Three-year renewal cycle
  • Reassessment where required
  • Public status updates
  • Revocation/suspension rules

Verification pages and registry listings help the public confirm whether a DSCC certification is active, expired, suspended, revoked, or limited to a specific scope.

Verify

Verify a certification

Anyone can confirm a DSCC certification. Public verification shows the organization, certification tier or specialty stream, status, issue and expiry dates, verification ID, and certified scope — so a DSCC credential can be checked against the public record.

Verify a Certification View Public Registry

FAQ

Certification questions, answered

Is DSCC certification available now?
Yes. DSCC certification applications are accepted through the online certification portal. Applicants complete readiness screening, select a pathway, submit an application, pay applicable fees, upload evidence, complete review, and receive a certification decision.
Is membership the same as certification?
No. DSCC membership indicates participation in the DSCC community and access to member benefits. It does not certify an organization’s data sovereignty posture.
Does training completion certify an organization?
No. Training may support readiness and professional development, but organizational certification requires a separate application, evidence review, and certification decision.
What will organizations need to provide?
Evidence may include data inventories, policies, vendor contracts, cloud architecture, security controls, AI governance documentation, backup and recovery plans, exit strategies, and Indigenous data governance evidence where applicable.
How long does certification last?
Certification is time-limited. Certified organizations must complete annual attestation and full reassessment on the renewal cycle. Expired certifications are marked as expired in the public verification system.
Will certification be publicly verifiable?
Yes. Approved organizations receive a verification ID, certificate, badge, and public verification page showing certification status, scope, issue date, expiry date, and applicable specialty streams.
What is Indigenous Data Sovereignty Alignment?
It is a specialty pathway intended to support organizations in demonstrating respectful alignment where Indigenous data governance obligations arise. DSCC does not replace Indigenous authority over Indigenous data.
Is DSCC certification government approval?
No. DSCC certification is issued by DSCC based on DSCC standards and processes. It is not government authorization, regulatory approval, legal immunity, or legal advice.

Start your DSCC certification application.

Organizations can now apply for DSCC certification through the certification portal. Begin with readiness screening, select the appropriate certification pathway, submit your scope, upload evidence, and proceed through DSCC’s evidence-based review process.