Industry Standards

ULC, UL, CSA, TIA, BICSI, IEEE, NIST, CIS, and ISO, explained and put in context for Canadian physical and integrated security practice.

Plain-language guides

What each standard requires, who it binds, and where it trips people up. Written for the trades, linked to the official texts.

Standards bodies

ULC
Underwriters Laboratories of Canada
Canadian certification body for fire protection, security systems, and electrical products
Intrusion AlarmsFire SystemsAccess ControlCCTV

ULC is Canada's primary product safety certification body. Key standards include ULC S301 (Central Station Burglar Alarm Systems), ULC S303 (Local Burglar Alarm Units), ULC S304 (Signal Receiving Centre and Premise Burglar Alarm Control), ULC S319 (Electronic Access Control Systems), and ULC S326 (Audible Signal Devices). These standards define minimum requirements for security equipment used in Canadian installations and are referenced in provincial building codes and insurance requirements.

Full reference: ULC
ElectricalTelecommunicationsStructured Cabling

CSA Group develops standards adopted into Canadian law and codes. Relevant standards for security practitioners include CSA T528 (Design Guidelines for Administration of Telecommunications Infrastructure), CSA T529 (Telecommunications Cabling Systems for Commercial Buildings), and CSA T530 (Building Facilities Design Guidelines for Telecommunications). The Canadian Electrical Code (CSA C22.1) governs all electrical wiring, including low-voltage security and communications cabling.

Full reference: CSA
Structured CablingData CentresCategory Cable

TIA standards are widely adopted in Canadian projects alongside CSA equivalents. TIA-568 (Commercial Building Telecommunications Cabling Standard) defines cabling architecture, component requirements, and installation practices for Cat5e, Cat6, Cat6A, and fibre. TIA-569 covers pathways and spaces. TIA-606 addresses administration. TIA-942 defines data centre infrastructure requirements. These standards are referenced in BICSI training and widely specified in Canadian commercial and institutional projects.

Full reference: TIA
RCDD CredentialTDMMITS Design

BICSI is the professional body for ICT infrastructure design, recognized globally and throughout Canada. The Telecommunications Distribution Methods Manual (TDMM) is the definitive reference for structured cabling and ITS design. The Registered Communications Distribution Designer (RCDD) credential is the gold standard for cabling and infrastructure consultants. BICSI also publishes standards for data centres, healthcare facilities, and intelligent buildings that are commonly specified in Canadian projects.

Full reference: BICSI
PoEEthernetNetworkingWi-Fi

IEEE standards are foundational to IP-based security systems. IEEE 802.3af, 802.3at, and 802.3bt define Power over Ethernet (PoE) specifications critical for IP cameras, access control readers, and intercoms. IEEE 802.1X defines port-based network access control used for securing security device connections. IEEE 802.11 (Wi-Fi) standards apply to wireless access points and devices. 802.1Q defines VLAN segmentation used to isolate security networks.

Full reference: IEEE
Cybersecurity FrameworkRisk ManagementOT Security

The NIST Cybersecurity Framework (CSF) is widely adopted by Canadian organizations for managing cybersecurity risk. It provides a common language around five core functions: Identify, Protect, Detect, Respond, and Recover. NIST SP 800-82 covers industrial control system (ICS) security relevant to physical security operational technology. NIST SP 800-115 covers technical security testing. Canadian federal government and critical infrastructure operators frequently reference NIST frameworks alongside Canadian Centre for Cyber Security guidance.

Full reference: NIST
CIS ControlsBenchmarksHardening

The CIS Controls are 18 prioritized security actions that provide a practical framework for defending against cyber threats. For security integrators, CIS Benchmarks provide hardening guidelines for operating systems, network devices, and applications including common VMS and access control server platforms. CIS Controls v8 is increasingly referenced in Canadian federal and provincial procurement requirements for connected security systems.

Full reference: CIS
Product ListingFire AlarmAccess ControlCCTV

UL standards are produced by Underwriters Laboratories in the United States and are accepted in Canada, particularly in areas where ULC has not produced a Canadian equivalent. UL 294 covers access control system units. UL 681 covers installation and classification of burglar and holdup alarm systems. UL 1981 covers central station automation systems. Many products sold in Canada carry UL listing as evidence of third-party safety testing, and insurance underwriters may specify UL-listed equipment.

Full reference: UL
ISO 27001ISO 9001ISO 31000

ISO standards relevant to Canadian security practitioners include ISO/IEC 27001 (Information Security Management Systems) and ISO/IEC 27002 (Code of Practice for Information Security Controls), which define requirements for managing information security in organizations with connected security systems. ISO 31000 provides principles and guidelines for risk management. ISO 9001 (Quality Management) is relevant for security firms seeking to demonstrate structured quality practices. Many Canadian government and institutional clients require ISO 27001 alignment for systems handling sensitive data.

Full reference: ISO
Critical InfrastructureIncident ReportingSupply Chain

Bill C-26 introduced the Critical Cyber Systems Protection Act (CCSPA), Canada's framework for protecting critical infrastructure from cyber threats. It applies to federally regulated sectors including telecommunications, finance, energy, and transportation, and it requires designated operators to establish a cyber security program, report cyber incidents to the Canadian Centre for Cyber Security, manage supply chain and third-party risk, and follow cyber security directions. For security integrators and consultants serving critical infrastructure clients, C-26 raises the bar on how connected physical security systems are governed, monitored, and reported when an incident occurs.

Full reference: C-26
OT SecurityICSZones and Conduits

The ISA/IEC 62443 series is the leading international standard for the security of industrial automation and control systems and operational technology. It defines a risk-based approach built around zones and conduits, security levels, and requirements for asset owners, integrators, and product suppliers. For physical security work that touches building automation, OT networks, and converged IT and OT environments, 62443 provides the vocabulary and controls for segmenting and hardening control systems. It is increasingly referenced alongside NIST guidance in Canadian critical infrastructure and industrial projects.

Full reference: IEC 62443
CloudVSaaSTrust Services

SOC 2 is a reporting framework from the AICPA that evaluates a service organization's controls against five trust services criteria: security, availability, processing integrity, confidentiality, and privacy. For cloud video (VSaaS), cloud access control, and managed monitoring providers, a SOC 2 Type II report is common evidence that the provider operates sound controls over time. Canadian buyers evaluating hosted security platforms frequently request SOC 2 reports as part of due diligence, alongside data residency and privacy questions.

Full reference: SOC 2
ProcurementRestricted EquipmentGovernment

Section 889 of the US National Defense Authorization Act restricts federal agencies and their contractors from procuring or using certain Chinese-made telecommunications and video surveillance equipment, including named manufacturers. It is implemented through the Federal Acquisition Regulation (FAR 52.204-25). While it is US law, Section 889 shapes global manufacturer roadmaps and procurement policy, and Canadian government, defence, and critical infrastructure buyers often mirror its restrictions or ask whether equipment is compliant when specifying video surveillance and access control.

Full reference: NDAA 889