Jurisdictional Control
Can the organization prove where data is stored, processed, backed up, accessed, and exposed to legal regimes?
DSCC Certification
DSCC certification helps organizations demonstrate auditable capability across data control, jurisdictional exposure, AI governance, vendor dependency, portability, security, accountability, and Indigenous Data Sovereignty alignment where applicable. Certification is based on documented evidence, structured review, independent assessment, and public verification. Organizations can now begin the certification process through the DSCC certification portal.
Evidence-based review · Auditor assessment · Committee decision · Public verification
DSCC certification applications are now accepted through the online certification portal. Applicants complete eligibility screening, select a certification pathway, submit organizational scope, pay applicable fees, upload required evidence, respond to auditor questions, and receive a decision through DSCC’s certification review process.
Purpose
DSCC certification is being designed to assess whether an organization can demonstrate sovereign capability through governance, evidence, controls, contracts, technical architecture, audit records, and accountable decision-making.
The purpose is not to reward slogans. The purpose is to verify whether an organization can show meaningful control over the data, AI systems, vendors, infrastructure, and governance obligations it depends on.
Can the organization prove where data is stored, processed, backed up, accessed, and exposed to legal regimes?
Can the organization show who owns decisions, controls access, approves use, and remains accountable?
Can the organization manage vendor lock-in, cloud dependency, subcontractors, cross-border exposure, and exit risk?
Can the organization govern AI models, training data, prompts, outputs, infrastructure, and third-party dependencies?
Can the organization move, return, delete, or recover data and digital workloads without institutional hostage-taking?
Where Indigenous data is involved, can the organization demonstrate respect for community authority, consent, stewardship, use restrictions, and data return obligations?
Process
DSCC certification follows a structured pathway from readiness screening to evidence submission, auditor review, certification decision, badge issuance, public verification, and renewal. Each step is designed to protect credibility and ensure certification is based on documented evidence.
The organization reviews DSCC standards and determines which certification pathway applies.
The organization completes eligibility screening and readiness questions to identify scope, risk, data types, AI use, and Indigenous data involvement where applicable.
The organization submits a formal certification application, including scope, responsible officers, declarations, and certification tier selection.
Applicable certification and audit fees are paid before formal review begins.
The organization uploads policies, contracts, architecture documents, governance records, AI documentation, and other required evidence.
A DSCC-assigned auditor reviews evidence, requests clarification, and scores the organization against applicable criteria.
A certification decision is made through an authorized review process separate from sales, membership, and training activities.
Approved organizations receive a certificate, badge, and public registry/verification listing for the certified scope.
Certification is time-limited and requires renewal, with annual attestation and full reassessment on a defined cycle.
Core Tiers
DSCC core certification tiers reflect increasing levels of organizational maturity, evidence, and sovereign capability. Each tier has defined eligibility criteria, evidence requirements, review depth, and renewal obligations.
Entry-level verification for organizations beginning their sovereignty journey.
Designed for organizations that can provide baseline evidence of data governance awareness, basic control mapping, policy foundations, and initial sovereignty readiness.
For small and mid-sized organizations, early-stage readiness, organizations beginning documentation, and organizations preparing for deeper certification.
Primary organizational certification tier.
Designed for organizations that can demonstrate defined policies, governance accountability, jurisdictional control, vendor management, security safeguards, portability planning, and audit-ready evidence.
For established organizations, public institutions, corporate members, technology providers, and organizations seeking public credibility.
Higher-maturity certification for organizations with strong sovereignty architecture.
Designed for organizations that can demonstrate advanced sovereign control, mature governance, vendor independence, AI/data portability, continuous monitoring, executive accountability, and evidence-based resilience.
For public-sector institutions, critical infrastructure organizations, mature enterprises, organizations with complex data/AI systems, and organizations seeking leading-market credibility.
Specialty Streams
Specialty streams assess specific sovereignty risks and operating environments beyond the core organizational certification pathway. Applicants may apply for a specialty stream alone where eligible, or combine a specialty stream with a core organizational certification.
For organizations seeking to demonstrate governance over AI systems, models, training data, prompts, outputs, vendors, infrastructure, and AI-related dependency risk.
Covers: AI system inventory, model governance, training data controls, prompt/output governance, vendor AI dependency, human oversight, AI portability, explainability and auditability.
For organizations that handle Indigenous, First Nation, Métis, Inuit, Nation, community, treaty, cultural, or community-controlled data and need to demonstrate alignment with authority, consent, stewardship, restrictions, and community governance obligations.
Covers: community authority, consent and permission, data-sharing agreements, cultural protection, AI/secondary-use restrictions, data return/deletion, vendor restrictions, community oversight.
For organizations seeking to demonstrate readiness to support government or public-sector data sovereignty requirements.
Covers: jurisdictional control, procurement readiness, public-sector data handling, security and privacy baseline, vendor dependency, audit evidence.
For public institutions, agencies, nonprofits, and public-service organizations seeking to strengthen data and AI sovereignty readiness.
Covers: public accountability, data governance, privacy/security controls, vendor oversight, accessibility and transparency, records and retention obligations.
For organizations operating in sectors where data, AI, infrastructure, continuity, and jurisdictional resilience are mission-critical.
Covers: resilience, continuity, vendor dependency, incident response, data recovery, access control, sovereign infrastructure risk.
Specialty Pathway
Where an organization handles Indigenous, First Nation, Métis, Inuit, Nation, community, treaty, cultural, or community-controlled data, ordinary privacy and cybersecurity controls may not be enough. The organization may need to demonstrate how it respects community authority, consent, stewardship, use restrictions, cultural protection, AI limitations, vendor boundaries, and data return or deletion obligations.
Who has authority to approve collection, access, sharing, analysis, retention, return, or deletion?
What was approved, by whom, for what purpose, and under what restrictions?
Who holds the data, who controls it, and what obligations apply to the holder?
Does the data include sensitive cultural, historical, land-related, language, governance, or community information requiring special protection?
Can the data be used for analytics, AI training, automated decision-making, commercialization, or secondary research?
Can third-party vendors, cloud providers, subcontractors, or foreign jurisdictions access the data?
Can the data be returned, deleted, restricted, or excluded from downstream systems where required?
Is there an ongoing process for review, correction, dispute, withdrawal, or governance escalation?
DSCC’s Indigenous Data Sovereignty work should be informed by an Indigenous Advisory Circle to help review relevant standards, training content, resources, terminology, and alignment criteria. Advisory review does not replace the authority of any Indigenous Nation, government, community, or organization over its own data.
Evidence
DSCC certification requires applicants to provide documentation and evidence across applicable domains. Evidence requirements depend on certification tier, scope, sector, AI use, vendor dependency, jurisdictional exposure, and Indigenous data involvement.
What data exists, where it sits, who uses it, and what systems depend on it.
Where data is stored, processed, backed up, and replicated.
How vendors, cloud providers, subcontractors, and processors handle data and access.
Who has authority, accountability, and decision rights.
How data is protected, monitored, accessed, retained, and disclosed.
How AI systems, models, prompts, outputs, training data, vendors, and dependencies are governed.
How the organization responds to breaches, loss, unauthorized access, and operational disruption.
How data and systems can be restored, recovered, or maintained during disruption.
How data, workloads, records, and systems can be moved, returned, deleted, or replaced.
Where applicable, how the organization demonstrates authority, consent, stewardship, cultural protection, restrictions, and return/deletion obligations.
Clarity
DSCC membership indicates participation in the DSCC community and access to member benefits. It does not mean the member or organization has been certified.
Completing DSCC training may demonstrate learning or professional development. It does not certify an organization’s data sovereignty posture.
DSCC certification is a DSCC-issued certification based on DSCC standards and certification processes. It should not be presented as government authorization, regulatory approval, legal immunity, or a substitute for legal advice.
Lifecycle
DSCC certifications are time-limited, renewable, and subject to status controls. Approved organizations receive a certificate, badge, verification link, and registry listing for the certified scope. Expired, suspended, revoked, or scope-limited certifications are clearly distinguishable from active certifications.
Verification pages and registry listings help the public confirm whether a DSCC certification is active, expired, suspended, revoked, or limited to a specific scope.
Verify
Anyone can confirm a DSCC certification. Public verification shows the organization, certification tier or specialty stream, status, issue and expiry dates, verification ID, and certified scope — so a DSCC credential can be checked against the public record.
FAQ
Organizations can now apply for DSCC certification through the certification portal. Begin with readiness screening, select the appropriate certification pathway, submit your scope, upload evidence, and proceed through DSCC’s evidence-based review process.