ISO 27001 certification in Quebec
Quebec is the one province where the answer to "does location matter" is yes. Law 25 changes what has to sit inside the scope, and the Charter of the French Language changes what language your management system runs in.
ISO 27001 certification works the same way in Quebec as it does in Ontario or British Columbia. The certification body is accredited by the Standards Council of Canada or one of its international peers, the audit runs in two stages, and the fees are the same $15,000 to $40,000 CAD in year one. Three things are genuinely different, and all three are about what surrounds the certificate rather than the certificate itself: Law 25 imposes obligations no certificate discharges, the Charter of the French Language shapes what language your documented information and your training exist in, and you have to choose a certification body that can put a French-speaking audit team in front of your people.
That last point is the one to settle first, because it constrains which bodies you can even quote.
What actually changes with Quebec in scope
| What | Where it comes from | Effect on the management system |
|---|---|---|
| Privacy obligations | Law 25, amending the private-sector privacy act | A named person in charge of privacy, privacy impact assessments, breach reporting to the Commission d'acces a l'information, and transparency about automated decisions. None of it is covered by the standard. |
| Assessment before sending data outside Quebec | Law 25 | A documented assessment before personal information is communicated outside the province, which reaches straight into your cloud region and subprocessor decisions. |
| Language of documented information | Charter of the French Language | Policies, procedures and training that staff are required to read need to work in French where French is the working language. |
| Language of the audit | Practical, not legal | Interviews happen with the people who operate the controls. If they work in French, you need auditors who do too. |
| Contracts and supplier terms | Charter of the French Language | Supplier agreements are an Annex A control, and standard-form contracts in Quebec carry their own French-language requirements. |
Nothing in that table changes the standard. It changes the scope statement, the risk assessment inputs and the evidence you have to produce, which is where the extra work and the extra cost sit.
Law 25 and what the certificate does not do
Law 25 is the modernisation of Quebec's private-sector privacy regime, and it is stricter than PIPEDA on most points that matter to a software company. It requires a person responsible for the protection of personal information to be named and published, privacy impact assessments for projects involving personal information and for transfers outside Quebec, notification of confidentiality incidents presenting a risk of serious injury, and disclosure when a decision is based exclusively on automated processing. Penalties under the regime run to a percentage of worldwide turnover, which is a different order of consequence from what most Canadian privacy law carried before.
An ISO 27001 certificate answers none of that directly. The standard covers safeguards, and Law 25 is largely about consent, purpose, retention, rights of access and correction, and governance of decisions. The single Annex A control on privacy and protection of personally identifiable information is the hinge, and what an auditor expects to see behind it is that your management system knows which personal information is in scope and which regime governs it.
Law 25 follows the data, not your office
A company in Toronto or Vancouver with customers or employees in Quebec is handling personal information governed by Law 25. Provincial privacy law attaches to the individuals whose information you hold rather than to where your servers or your head office sit. If you are scoping an ISMS anywhere in Canada and you have a Quebec customer list or a Quebec payroll, this page applies to you as much as it applies to a company on Rue Saint-Jacques. The Montreal and Quebec City pages cover the local consulting market itself.
Running a management system in French
ISO 27001 says nothing about language. It says a great deal about competence and awareness, in clause 7.2 and 7.3, and about documented information in 7.5, and those requirements are what create the language obligation in practice. If your engineers work in French, a policy set written only in English does not demonstrate that staff are aware of the policy relevant to their work, and an auditor is entitled to test that by asking somebody.
The Charter of the French Language, as amended in 2022, tightens this further for employment documentation, standard-form contracts and software made available to staff and to consumers, with a registration obligation for employers above a size threshold. Get current advice on the thresholds and deadlines rather than relying on a summary, because that part of the regime has moved repeatedly. What is stable enough to plan around is the direction: if the work happens in French, the management system has to work in French too.
Practically, that means deciding early which documents are bilingual and which are French only. Translating a full policy set after it is approved costs more than writing it in the right language, and a bilingual set doubles the change control burden for the life of the system. The usual sensible answer is French for anything staff must read and act on, English for anything an international customer or auditor reads, and one controlled source of truth per document rather than two drifting copies.
Choosing a certification body that audits in French
There is no French-language accreditation. What there is, is a small number of auditors accredited for ISO 27001 who work in French, and they are booked further out than the English-speaking pool. Ask three questions of every body you shortlist.
- Can you provide a lead auditor who conducts the audit in French, and can you commit to that in the proposal rather than in conversation.
- Which accreditation body accredited you for ISO/IEC 27001, and what is your entry on their public register. Verify it yourself on the register rather than taking the answer, using the method on certification bodies in Canada.
- What is the lead time for a stage 2 with a French-speaking team, and what happens to the surveillance schedule if that auditor is unavailable.
The third question is the one that bites in year two. A body that can staff your initial audit in French and cannot staff the surveillance audit has left you with a visit conducted through translation, which is slower and produces worse findings in both directions.
What it adds in Canadian dollars
Less than people expect on the audit side and more than people expect on the readiness side. The certification body fee is driven by audit days, and language does not change the day count, so expect the same $15,000 to $40,000 CAD in year one that any Canadian company of your size would pay. Where the money goes is the work around it.
| Line | Typical addition | Why |
|---|---|---|
| Law 25 program work | $10,000 to $30,000 | Privacy officer appointment, impact assessments, transfer assessments, incident register and public disclosures. Separate from the ISMS and often forgotten in the budget. |
| French-language documentation | $3,000 to $12,000 | Writing or translating the policy set, procedures and awareness training that staff must act on. |
| French-speaking readiness consultant | No premium to modest | The Montreal and Quebec City consulting market is deep enough that this is a scheduling question rather than a price one. |
| Certification body | No premium | Priced on audit days. Book earlier, because the French-speaking auditor pool is smaller. |
| Quebec addition, first year | $13,000 to $42,000 | On top of the national ranges on the cost page |
The national figures those sit on top of are on the ISO 27001 cost page, and the calculator gives the three-year total. If the Law 25 work is the larger problem, do it first: it is a legal obligation that applies whether or not anybody asks for a certificate, while the certificate is a commercial one that only exists because a customer asked.
A sensible order for a Quebec project
- Confirm what the customer asked for in writing, and whether they will accept a certificate covering a scope that excludes some of your operations.
- Map where Quebec personal information sits, because that answer sets both the ISMS boundary and the Law 25 assessment obligations.
- Appoint the person responsible for the protection of personal information. It is required regardless and it gives the ISMS a named privacy owner for free.
- Decide the language of the document set before writing any of it.
- Shortlist certification bodies on French-language capability and accreditation, and get the three-year day counts in writing.
- Run the implementation normally from there, with the Law 25 assessments treated as a parallel workstream rather than a control.
Get quotes from firms that work in French
Tell us your scope, your timeline and whether the audit has to be conducted in French, and we will match you with firms that do this work in Quebec.
Get matchedCommon questions
Does ISO 27001 certification make us compliant with Law 25?
No. Law 25 governs consent, purpose, retention, access and correction rights, privacy impact assessments, breach notification and automated decisions. ISO 27001 governs safeguards through a management system. A certificate is useful evidence that your safeguards are managed, and it answers none of the obligations above. Run the two as related workstreams with one owner.
Does the audit have to be in French?
Not as a matter of law. It has to be conducted with the people who operate the controls, so if those people work in French then in practice the audit does too. Interviews conducted through translation take longer, cost more days, and produce findings that both sides then have to re-litigate. Ask for a French-speaking lead auditor in the proposal.
Do our policies have to be in French?
The standard does not say so. Clause 7.3 requires staff to be aware of the policy and of their contribution to the management system, and Quebec language legislation reaches employment documentation and standard-form contracts. If your people work in French, both point the same way. Decide the language question before the policy set is written rather than after.
We are outside Quebec but have Quebec customers. Does this apply?
The Law 25 half does. Provincial privacy obligations follow the individuals whose personal information you hold, so a company anywhere in Canada with Quebec customers or Quebec employees is inside that regime. The language obligations are tied to operating in Quebec, so they usually are not your problem if you have no Quebec staff or Quebec-facing consumer contracts.
Are there certification bodies based in Quebec?
Certification bodies are national or global businesses with auditors distributed across the country, so the useful question is not where the body is registered but whether it is accredited for ISO/IEC 27001 and can field a French-speaking team for your audits over three years. Check the accreditation on the accreditation body's public register rather than on the certification body's website.