System Brief // NA-ONE-NETWORK-TWO-CLOCKS-2026-09-27

One Network. Two Clocks.

Desmond Otieno Odhiambo · ClearGlass Intelligence · Burlington, Ontario · 27 September 2026

North America is already one attack surface. Most companies still run two security programs taped together. Identity, SaaS, and AI agents ignore the border. Regulation does not.

Most Canada–US operators do not have a North American security program. They have a Canadian policy binder, a US contract appendix, a shared Microsoft tenant, and an incident channel that starts with “who do we call first?”

ClearGlassInc’s position is simple: treat Canada and the United States as one technical estate with two legal clocks. Design the estate so you can answer four questions under pressure, in either jurisdiction.

  1. What changed?
  2. Who changed it?
  3. Where did the data sit when it changed?
  4. Which reporting clock started, and at what time?

If those answers live in screenshots and memory, you do not have a program. You have a hope.

The real problem is not more compliance

Mapping NIST to CIS to CMMC to CPCSC is necessary. It is not the work. The work is that the production system is already transnational, while the evidence system is still national.

Canada now has a real federal cyber statute. Bill C-8 received Royal Assent in mid-June 2026. Part 1 amended the Telecommunications Act immediately. Part 2 enacted the Critical Cyber Systems Protection Act. Designated-operator duties wait on in-force orders. Build evidence before a designation order compresses the clock.

US reporting clocks are already written. CIRCIA requires covered entities to report substantial incidents to CISA within 72 hours and ransomware payments within 24 hours. CISA targeted a September 2026 final rule after earlier misses. As of 27 September 2026, treat CISA.gov/CIRCIA and the Federal Register as the live source.

Add PIPEDA accountability for cross-border processing, Quebec Law 25, Ontario PHIPA, CPCSC Canadian storage for safeguarded defence contract data, and a CMMC program that suspended Phase II third-party certification on 13 July 2026 while leaving NIST SP 800-171 / DFARS 252.204-7012 obligations in force.

Canada still has no comprehensive federal AI statute. Bill C-27, including AIDA, died at prorogation in January 2025. Waiting for a Canadian AI Act is not a control.

Status box — verify live. CIRCIA final-rule publication is treated here as unconfirmed as of 27 September 2026. CMMC Phase II third-party certification is suspended; self-assessment and 800-171 duties remain. CCSPA designated-operator classes are not yet populated. Not legal advice. Not a certification claim.

What North American means in production

ShapeWhat it looks likeWhere programs break
Canadian operator, US customersOntario company on Microsoft 365 and US-east cloudPIPEDA comparable-protection and foreign-access notice; vendor AI training clauses
US operator, Canadian usersUS SaaS with a Toronto office or Canadian user basePIPEDA applies to Canadian personal information even if the company thinks it is US-only
Dual-entity groupTwo legal entities, one identity planeContracts say segregation; Entra groups and admin roles say otherwise
Defence or critical-systems supplierCanadian shop in a US prime supply chain, or the reverseCPCSC residency versus CMMC portability; CLOUD Act residual risk

Four planes, one evidence chain

1. Identity plane

Most board-level incidents in this region still start with identity. For a Canada–US estate, identity work is not “turn on MFA.” It is one source of truth for workforce, vendors, and agents; privileged roles treated as production systems; Conditional Access that encodes where and why; joiner-mover-leaver automation; and written rules for non-human identities.

If you cannot list every account that can move Canadian personal information into a US model or ticket queue, you do not have cross-border control. See Services & Engagements.

2. Residency and transfer plane

PIPEDA does not ban US processing. It keeps the Canadian organization accountable for comparable protection. CPCSC, unlike CMMC, has been described as requiring safeguarded contract data to stay in Canada. The operating requirement is a living data-flow map: systems, regions, subprocessors, AI tools, training clauses, and support-access paths.

3. Autonomy plane

In a dual-jurisdiction company, an ungoverned agent is a cross-border disclosure device with a friendly UI. Inventory models and agents. Bound data classes and tools. Require human approval for external send, privilege change, production deploy, and legal filing. Retain prompts, outputs, and tool calls as business records. See Artemis 2040.

4. Incident and evidence plane

ClockTriggerDestination
PIPEDAReal risk of significant harmOPC + individuals, as soon as feasible
CCSPAWhen designated and in forceCSE + sector regulator
CIRCIAWhen final and applicableCISA 72 hours / 24 hours for payment

Companion pieces: You Do Not Have a North American Security Program · Dual-clock runbook · CPCSC vs CMMC.

What good looks like in 90 days

Days 1–15 — Estate truth. Inventory identity, data classes, AI tools, regions, and decision-makers.

Days 16–45 — Reduce obvious exposure. Harden Entra ID and Windows. Kill standing privilege. Close orphaned guests. Brake AI tools that see client data. Write the dual-clock ledger.

Days 46–90 — Make it replayable. Logging that survives the incident. A residency register legal and engineering both accept. One cross-border identity tabletop. A board paper in plain language.

What to do this week

  1. Start with a read-only Security Quick-Audit (CAD $249).
  2. If the estate is a Microsoft problem, use the M365 + Windows Hardening Sprint (from CAD $2,500).
  3. For the operating-model conversation, see pricing and engagements.

The border is a legal fact. It is not a network boundary. Design accordingly.

Cluster: NA program brief · CPCSC vs CMMC · Dual-clock runbook · Canada–US control assessment
Claim boundary. Public statutes and regulator guidance only. No unverified performance claims. Not legal advice. Not a FedRAMP, CMMC, CPCSC, or SOC 2 certification claim. Last verified 27 September 2026.