Agenda
Pre-Conference Workshops
January 26, 2027
Day 1 – Main Conference
January 27, 2027
Registration and Continental Breakfast
Keynote: Navigating Canada’s Defence Expansion: New Markets, New Players and a New Export Compliance Reality
Navigating AI Export Controls, Advanced Computing and Remote Access: Preparing for the Next Regulatory Frontier
AI, remote access, cloud technology and export controls are increasingly converging. Canadian organizations using U.S. technology and AI systems need to prepare for an environment in which the technology itself and potentially access to it may become subject to evolving controls.
Points of Discussion Include:
- Anticipating how future U.S. export controls may address AI models, model weights, advanced computing technologies and remote access
- Assessing how Canadian companies using U.S. advanced computing items and AI models could create export or reexport implications when technologies are accessed or transferred across jurisdictions
- Understanding how organizations should conduct due diligence around who is using AI systems, where users are located and which destinations may become involved in transactions
Morning Networking Break
LIVE AUDIENCE POLLING
Aligning Canadian Export Controls and U.S. ITAR/EAR Requirements: Managing Compliance Across Both Sides of the Border
Canadian organizations increasingly need to understand how Canada’s export control framework, Controlled Goods requirements, EAR and ITAR operate together rather than managing each regime in isolation. This session will address where the systems complement one another, where they diverge and how companies can build processes that work across both jurisdictions.
Points of Discussion Include:
- Comparing Canadian export control laws with U.S. EAR and ITAR requirements and identifying where the regulatory systems complement one another and where significant differences remain
- Understanding the requirements that need to be satisfied from the Canadian side to support ITAR compliance, and vice versa
- Navigating transactions where Canadian and U.S. requirements overlap or create multiple licensing, classification and compliance obligations
- Building compliance programs capable of satisfying both Canadian and U.S. regulatory requirements without treating the two regimes as entirely separate systems
Navigating Canada’s New Cloud Computing Policy: Technology Transfers, Potential Access and Cross-Border Compliance
Canada’s evolving approach to cloud computing expands the compliance conversation beyond actual transfers to the potential for controlled technology to be accessed. Canadian companies need practical guidance on what this means for cloud providers, users and cross-border technology environments.
Points of Discussion Include:
- Examining how Canada’s cloud computing policy expands the concept of a technology transfer and how the Canadian approach differs from other jurisdictions
- Understanding when the potential for access to controlled technology may trigger permit considerations even where an actual transfer has not occurred
- Assessing cloud service providers, storage environments, user access and internal controls when determining whether controlled technology may become accessible across borders
- Comparing Canadian and U.S. approaches to cloud-based technology transfers and identifying practical governance and documentation practices for organizations operating under both systems
Networking Luncheon
GOVERNMENT INTERVIEW
Understanding U.S. Export Controls in Canada: Extraterritorial Reach, Reexports and Continuing Jurisdiction
U.S. export controls continue to have an outsized impact on Canadian organizations because U.S. jurisdiction can follow controlled goods and technology long after the original export. Hear directly from U.S. government on the regulatory and enforcement priorities Canadian companies need to understand as they manage U.S.-origin goods, software and technology across borders
Repeated examinations of reexport shipments can create significant operational delays and unnecessary costs for Canadian organizations. This practical discussion will focus on why shipments are selected and what companies can do to make recurring reexport activity more efficient.
Points of Discussion Include:
- Examining why U.S. reexport shipments are selected for examination and identifying factors that may contribute to elevated examination rates
- Strengthening documentation and compliance practices to reduce unnecessary examinations and improve the efficiency of recurring reexport activity
- Managing customs examinations more effectively when they occur while minimizing operational disruption, demurrage and detention costs
- Applying practical lessons from organizations managing recurring cross-border reexport programs and identifying opportunities to improve internal processes
Afternoon Networking Break
Strengthening Entity List Screening, Foreign Direct Product Rule Compliance and China-Related Due Diligence
Recent enforcement activity demonstrates the importance of understanding not only who a company is transacting with, but also whether products become subject to U.S. jurisdiction through increasingly complex rules. This session will examine the controls and due diligence necessary to manage Entity List and Foreign Direct Product Rule exposure.
Points of Discussion Include:
- Analyzing lessons from recent BIS enforcement actions involving Chinese Entity List entities and identifying the compliance failures companies should be watching
- Understanding how the Foreign Direct Product Rule continues to expand U.S. jurisdiction and how products can become subject to U.S. controls even when manufactured outside the United States
- Strengthening screening, supplier verification, customer due diligence and internal controls to reduce the risk of transactions involving restricted parties
- Assessing whether semiconductor chips, advanced technologies and other components are subject to the Foreign Direct Product Rule before incorporating them into products destined for higher-risk end users
FIRESIDE EXECUTIVE & C-SUITE PANEL
What Is Keeping You Up at Night? Navigating Business Risk Amid Geopolitical, Regulatory and Technological Change
An interactive, audience-led discussion where senior executives address the most pressing questions around geopolitical, regulatory and technological change—and what these shifts mean for business, investment and risk.
Key Themes Include:
- Emerging geopolitical and business risks
- The long-term impact and cost of policy change
- High-risk sectors and jurisdictions
- Shifting investor priorities and concerns
- Open audience Q&A
Closing Remarks from Conference Co-Chairs
Day 2 – Main Conference
January 28, 2027
Registration and Continental Breakfast
Opening Comments from the Conference Co-Chairs
GOVERNMENT INTERVIEW
Navigating Canada’s Controlled Goods Program: Registration, Defence Growth and Compliance Under the Defence Production Act
Case Study
Learning from U.S. Enforcement: Avoiding Consent Agreements and Identifying Compliance Weaknesses Before Regulators Do
In this case study, recent Department of State consent agreements and enforcement actions will be examined to identify recurring compliance failures and regulator expectations. The discussion will highlight practical lessons small and mid-sized companies can apply to strengthen their compliance programs and address vulnerabilities before they escalate.
Morning Networking Break
HYPOTHETICAL SCENARIOS AND LIVE AUDIENCE POLLING
Expanding Beyond the U.S.: Managing Export Controls, Real World Experiences from the Growing Defence Markets, Sanctions and Geopolitical Risk in New Defence Markets
Canadian companies are increasingly pursuing opportunities in Europe, Asia, the Middle East and other international defence markets. Expansion beyond familiar U.S. relationships requires a more sophisticated approach to geopolitical and regulatory risk.
Points of Discussion Include:
- Assessing prospective defence markets for elevated sanctions, export control and geopolitical risks before entering new jurisdictions
- Navigating unfamiliar licensing and compliance environments as Canadian companies diversify beyond traditional U.S. defence relationships
- Understanding how changing U.S. policies toward jurisdictions such as the UAE and Saudi Arabia may affect Canadian companies participating in international defence transactions
- Building scalable export compliance functions capable of supporting international growth without compromising regulatory obligations
Expanding Beyond the U.S.: Managing Export Controls, Sanctions and Geopolitical Risk in New Defence Markets
Canadian companies are increasingly pursuing opportunities in Europe, Asia, the Middle East and other international defence markets. Expansion beyond familiar U.S. relationships requires a more sophisticated approach to geopolitical and regulatory risk.
Points of Discussion Include:
- Assessing prospective defence markets for elevated sanctions, export control and geopolitical risks before entering new jurisdictions
- Navigating unfamiliar licensing and compliance environments as Canadian companies diversify beyond traditional U.S. defence relationships
- Understanding how changing U.S. policies toward jurisdictions such as the UAE and Saudi Arabia may affect Canadian companies participating in international defence transactions
- Building scalable export compliance functions capable of supporting international growth without compromising regulatory obligations
Networking Luncheon
FIRESIDE CHAT
Navigating AUKUS (Australia–United Kingdom–United States) and the Canadian Exemption: Positioning Canadian Industry for the Next Phase of Allied Defence Trade
As AUKUS continues to evolve, Canadian defence companies are watching closely for changes affecting technology sharing, licensing and participation in allied defence initiatives. This discussion will examine where Canada fits within the broader framework and what organizations should monitor next.
Points of Discussion Include:
- Examining the U.S. Department of State’s current direction for AUKUS (Australia–United Kingdom–United States) and identifying developments Canadian organizations should monitor over the next 12–18 months
- Assessing how the Canadian exemption fits within the broader AUKUS framework and whether additional reforms could affect Canadian industry
- Exploring opportunities for increased Canadian participation in defence collaboration, procurement and technology sharing as AUKUS policies mature
- Understanding the practical implications for licensing, defence cooperation, supply chains and future procurement opportunities
INTERACTIVE ROUNDRABLES
Participate in a series of interactive, peer-led roundtable discussions shaped by the audience. Based on live polling conducted during Day One, attendees will choose the conversations most relevant to their current challenges and rotate between discussion tables throughout the hour.
Potential roundtable topics may include:
- AI & Emerging Technology
- Sanctions
- CMMC
- Defence Markets
- Export Controls & Compliance
- Supply Chain Risk
- Geopolitical Risk
- Regulatory & Policy Change
Afternoon Networking Break
Join us for a high-level overview of the evolving CMMC landscape, examining what Canadian organizations need to understand about emerging requirements, implementation timelines, compliance expectations, and the potential implications for companies participating in U.S. defence supply chains.
HYPOTHETICAL SCENARIOS
Preparing for How Forced Labor Restrictions are Now Being Enforced, are affecting Supply Chain, and the Next Wave of Canadian Economic Security Controls
Forced labour and economic security are emerging as increasingly important trade compliance issues for Canadian organizations. Companies importing goods into Canada will need greater visibility into where products originate, how they are produced and how future restrictions may affect their supply chains.
Points of Discussion Include:
- Preparing for evolving Canadian restrictions affecting imports of products produced through forced labour and understanding how future rules may affect companies importing from China and other jurisdictions
- Assessing supply chains to determine where goods originate, how they are produced and whether forced labour risks may exist further upstream
- Strengthening due diligence processes to identify prohibited sourcing risks before goods reach the Canadian border
- Monitoring emerging government guidance, enforcement expectations and potential penalties as Canada develops a more robust forced labour regime
Closing Remarks from Conference Co-Chairs
End of Conference
CMMC & CPCSC Compliance for Canadian Industry
January 29, 2027
Registration and Continental Breakfast
Opening Remarks from Conference Co-Chairs
KEYNOTE/INTERVIEW
Navigating CMMC & CPCSC in 2027: Where Implementation Stands and What the Canadian Industry Needs to Do Now to Meet Requirement
This keynote interview will examine where CMMC and CPCSC implementation stands in 2027 and what Canadian organizations need to be doing now to prepare. The discussion will explore the phased implementation of CPCSC, key similarities and differences between the Canadian and U.S. certification frameworks, and the practical steps industry should prioritize to meet emerging requirements.
Maintaining Data Sovereignty: How Contractors Will Now Need to Apply Data Controls on Both Sides of the Border
The intersection between Controlled Unclassified Information, export-controlled technology and CMMC continues to create significant questions for Canadian organizations. This session will clarify where the requirements overlap, where they differ and how companies should manage sensitive information across their operations.
Points of Discussion Include:
- Distinguishing between export-controlled technical data that qualifies as CUI and CUI that is subject to cybersecurity requirements but is not export-controlled
- Clarifying whether companies holding export control licenses covering foreign-national access remain subject to additional CMMC requirements and identifying where organizations commonly become confused
- Mapping where CUI is found, processed, stored and transmitted across an organization and determining the appropriate boundaries for systems handling sensitive government information
- Assessing when organizations serving both commercial and government customers may need to separate environments because different data and users create different compliance obligations
Morning Networking Break
Building a Practical CMMC/CPCSC Compliance Program: Balancing Readiness, Resources and Implementation for Canadian Companies
Understanding the frameworks is only the beginning—companies need to translate the requirements into programs they can realistically implement and maintain. This session will examine practical implementation while accounting for organizational size, resources and risk.
Points of Discussion Include:
- Building governance structures capable of integrating cybersecurity requirements with existing export compliance, IT, information security and defense contracting functions
- Assessing existing systems, policies, resources and cybersecurity practices to identify implementation gaps and determine where organizations need to strengthen their compliance environments
- Balancing robust compliance expectations with the financial, staffing and operational constraints facing small and mid-sized Canadian companies
- Implementing a practical compliance roadmap tailored to an organization’s circumstances while preparing for certification and future defense contracting requirements
Preparing for Audit Readiness, Certification and CMMC Assessments: Navigating NIST SP 800-171, SPRS, POA&Ms, Audit Readiness and Certification
Canadian organizations need to understand not only what CMMC compliance requires, but how they will demonstrate it during an assessment. This session will examine practical certification readiness, remediation and the documentation and evidence assessors will expect.
Points of Discussion Include:
- Conducting NIST SP 800-171 self-assessments, identifying control deficiencies and developing roadmaps that account for timelines, budgets and available resources
- Developing and maintaining the System Security Plan and understanding how it supports an organization’s overall CMMC readiness and assessment strategy
- Navigating SPRS scoring and submission requirements while managing POA&Ms, remediation timelines and outstanding compliance deficiencies
- Preparing for C3PAO assessments by understanding evidence requirements, assessor interactions and the technical and procedural controls organizations will need to demonstrate
Networking Luncheon
GOVERNMENT FIRESIDE CHAT
Aligning CMMC and CPCSC: Navigating Mutual Recognition and the Canadian Compliance Path
Canadian industry needs greater clarity on how CMMC and CPCSC will operate alongside one another and whether organizations may benefit from mutual recognition between the two programs. This discussion will examine alignment, the Canadian compliance path and what continued Canada-U.S. coordination could mean for industry.
This session will examine contractual flow downs, subcontractor oversight and the cost and resource implications of meeting these requirements.
Points of Discussion Include:
- Understanding how CMMC, DFARS and cybersecurity requirements flow through contracts to Canadian subcontractors and suppliers even when organizations do not contract directly with the U.S. Department of Defense
- Assessing subcontractor certification requirements and determining whether third parties have appropriate cybersecurity controls, documentation and compliance capabilities before sensitive information is shared downstream
- Strengthening pre-audits and ongoing oversight of subcontractors while managing compliance across increasingly complex multi-tier defense supply chains
- Evaluating the cost and resource implications of CMMC and CPCSC while recognizing that cybersecurity certification is increasingly becoming a business necessity for Canadian companies seeking defense contracting opportunities
Afternoon Networking Break
CYBERSECURITY CASE STUDY
When Compliance Meets Reality — Putting CMMC/CPCSC Controls to the Test During a Cyber Incident
In this case study, attendees will work through a realistic cyber incident to examine how CMMC/CPCSC controls perform when compliance meets real-world operational pressure. The discussion will explore incident response and reporting, internal and external resource coordination, common compliance successes and missteps, and the practical realities of maintaining controls, monitoring environments and remaining assessment-ready beyond certification.
- Cyber Incident and Breach Integration
- Mission Minded Monitoring, Communication and Compliance Next Steps
- Leveraging Internal and External Resources
- Beyond Certification: Next Steps for Continued Compliance
Cyber Threats to the Defense Industrial Base: The Finer Points of Protecting Critical Infrastructure, , AI and the Changing Attack Surface
Meeting a cybersecurity framework does not necessarily mean an organization is prepared for rapidly evolving threats. This session will examine how AI, critical infrastructure vulnerabilities and increasingly sophisticated attacks are changing the risk environment for the defense industrial base.
Points of Discussion Include:
- Examining how attackers are using AI to increase their capabilities, from crafting more sophisticated phishing attempts to identify new vulnerabilities and potential zero days
- Understanding how attackers may target critical infrastructure by entering through traditional IT environments rather than attacking operational infrastructure directly
- Assessing why organizations can meet compliance expectations while still lacking the skills and understanding required to think creatively about emerging cybersecurity threats
- Preparing for risks created by generative AI, AI agents and increasingly sophisticated attacks as barriers to entry fall and previously theoretical threats become operational realities