Canada’s recently-released Defence Industrial Strategy (DIS), the first of its kind in Canada, sets out several ambitious goals, not the least of which is to route 70% of Canada’s defence procurement spending toward Canadian firms. While the ecosystem has started a lively debate on what it means for a firm to be Canadian, the definition is far from the only challenge in the way of realizing this goal. As Canadian companies shift toward dual-use and defence application in response to the present funding environment, they face regulatory challenges in a system that is not ready to absorb the demand.
In this interview, I learn from Loki Jörgenson, CTO of Circle Innovation about the regulatory bottleneck that is fast approaching. We get into the weeds of Circle Innovation’s approach to supporting companies as they begin to scale, the imminent rush to meet regulatory requirements for defence procurement, and what it’s going to take to meet that demand.
Loki has lived everything Canada’s innovation ecosystem has to offer, and his insights are essential reading both for Canadian businesses considering a pivot toward defence, and policy makers gearing up to execute on the vision set out in the DIS.
Your email client will probably truncate this post. My key takeaways are presented at the end, so be sure to read the web version if you want to get the whole story. Many thanks to Loki for taking the time to share his insights.
Interviewer’s note: Loki Jörgenson approved the final version of the section entitled “Interview with Loki Jörgenson” and had editorial input on that section, with the option to rephrase and expand on the ideas discussed in the interview without changing or removing any intended meaning. The key takeaways presented at the end are my own commentary, and do not necessarily represent the views of Loki Jörgenson or Circle Innovation.
Interview with Loki Jorgenson
KB: Tell us about yourself. How did you get to where you are today?
LJ: I originally did my degree in physics, which is why you and I get along so well. Then I spent about seven years in mathematics and recognized that there were opportunities I could continue to drive into, but I got very curious about business. So I made a jump from the academic scene into business. To cut that short: FinTech, IT, MedTech, about nine companies over 22 years, primarily in the role of CTO, sometimes chief scientist doing algorithmic work, what we might call AI today. Back then, it was predictive systems of various sorts.
Through that, I was constantly coming into contact with NCEs, Wavefront, and funding programs like Mitacs. The challenge of innovation kept arising within the companies I was in, along with a sense that the larger ecosystem was also challenged to achieve what was intended with all of these initiatives. So when I thought I was more or less done with entrepreneurial life, I started thinking about the innovation problem as a problem to solve, learning how it actually works and what could be done differently. I subsequently encountered Circle Innovation, which has a specific methodology, so I was attracted to that. It sounded different, very direct, and very bottom-up. In finally approaching innovation as a problem needing a solution and reflecting back on my entrepreneurial experience, I ended up as the CTO for Circle Innovation and I run funded programs for SMEs, helping them overcome particular barriers to innovation.
KB: Tell us about the Circle Innovation model. How has it evolved?
LJ: Circle is a non-profit that spun out from Simon Fraser University. It was originally part of one of the NCEs, and its CEO, Sylvain Moreno, a professor at SFU and an entrepreneur (previously at U of T), has been heading up Circle Innovation for the last ten years. I joined about three years ago.
What caught my eye in conversation with him and the COO at the time, Tom Philpott, was that they were taking a very involved, bottoms-up approach instead of what I had been seeing in an ecosystem making a series of assumptions about what needed and how to address it. That was leading to companies, as I’d experienced it, saying, “Okay, you have this program with these requirements; I’ll try to take that shape or look like the candidate you’re looking for to get to the money.” I think we’ve trained a whole generation of entrepreneurs to get to non-dilutive funding that way.
At Circle, we inverted all of that and instead, sit down with the company and ask: “What do you need? What barrier are you facing?”. Note that we focus on companies at a certain stage. Ideally for us, they are facing just one barrier to growth, somewhere around Series A, ready to get into growth mode, but facing that barrier. We aim to help them rapidly overcome it, and off they go, creating an economic impact almost immediately.
Between incubators/accelerators and superclusters, there’s a gap, and we operate in that gap. From an investment standpoint, investors are often no longer supporting companies solely on promises and prospects; they want to see traction, sales, and revenue. That’s where a lot of companies can get stuck, and it can be a very dry period and a big challenge. The longer they sit there, the more likely they are to fail. So from that pool of companies at that stage, you can rapidly translate a lot of effective potential into something concrete.
That’s where Circle’s methodology, which is called SWaT (SME Workforce and Technologies), comes into play. We work with the company, figure out their barrier, collaborate with them to define a project that will overcome those barriers, get that co-funded, and then work with them throughout the project. We try to stay out of their way, since they know their business best, and when they need outside support, subject matter experts, or connections to academia or clinicians, we bring those to the table as quickly as possible, often during the project definition phase so we have perspective on what they need to overcome that particular barrier. We figure out who needs to be part of that, get that project going, and get it done. Six to nine-month quick-spin projects with products going into market is one of our constraints.
Over the 10 years, this approach has led to multiple multi-million dollar, multi-year programs funded both provincially and nationally. We’re in BC, so a lot of our work tends to be regionally focused if it’s through an RDA, but we also operate nationally.
KB: Can you give me a concrete example of a company and the barrier you were able to work through with them?
LJ: A lot of our projects are simply curating companies’ access and getting them to that barrier resolution. But when we do our best work, it’s unexpected. That’s why you can’t do a top-down program: every company has its own story, and you can’t predict what will be important to them in the moment.
For example, Human in Motion Robotics is an exoskeleton company based in Vancouver. It solution was originally intended for people with spinal injury conditions whose legs were no longer working properly, helping them walk earlier during rehabilitation as a recovery mechanism. Along the way, they’ve developed some amazing actuators and robotics technology. What they had as an opportunity was to take this into home use, which changed the game dramatically for them. They hadn’t really focused on the FDA and they were suddenly faced with validating as a Class II medical device. What did they need? They needed a mechanical engineer with Quality Systems experience, which is an interesting blend of skills. We were able to field three candidates for them, they selected one, and they were able to pivot their operations and get their QS in place rapidly.
That kind of pivot or change in direction can catch a company and slow it down at a critical moment. We felt like we were able to grease those rails, get them where they needed to go as quickly as possible, bring on that new person with those skills, and keep them moving forward. That’s the kind of project we like to cite as one of our better stories.
KB: In that example there’s obvious potential military applications. With an increase in the number of companies operating in the defence space, regulatory requirements become a serious consideration. What are the regulatory implications for Canadian SMEs seeking to move into the defence space?
LJ: Stepping back for a moment, the other thing Circle does when declaring a program is look around the ecosystem for major sources of friction affecting a whole ecosystem or necessary changes needed by that ecosystem. Working with our friends at Export Navigator, we recognized that this cybersecurity certification, Canadian Program for Cybersecurity Certification (CPCSC), though a relatively mundane requirement that companies in the defence market face, poses a critical challenge to ensure they are at an appropriate level in a timely fashion. The level varies according to how they handle and protect confidential or sensitive information, and that they have the IT infrastructure and procedures in place to protect it and demonstrate that protection.
You see these requirements in various regulatory spaces; healthtech and FinTech are similar. Companies that have been operating in a civilian market now considering themselves dual-use and looking at the defence market are faced with a set of regulations they may have never anticipated. Fair enough, that’s just part of making a change, and you can make that change. But we are faced with a unique moment right now. CPCSC is being implemented at a rapid pace with a hard set of requirements. Companies moving towards dual-use need to be properly certified so they are at least able to look at RFPs to determine whether they can deliver. Canada is not able to support that many companies moving all at once to get their Level 1s and Level 2s sorted out.
Looking to the US, Cybersecurity Maturity Model Certification (CMMC) has similar levels also based on the NIST 800-171 standard, so there are lots of similarities between CMMC and CPCSC. The Americans moved earlier in enforcing the need to have CMMC in place, whether you’re a Canadian or US provider. What they have seen are the prime contractors pulling on Tier 1, 2, or 3 suppliers to meet the standards and comply. Primes are ultimately responsible for their entire supply chain, and they get penalized if anybody in that supply chain doesn’t meet compliance standards. They were about a year ahead of us and we are seeing the first multi-million dollar penalties being applied.
The real challenge, oddly enough, is in the assessment step. Level 1 is self-assessed, which isn’t too bad and takes a month or two to sort out and make a self-attestation. Level 2, however, is third-party assessed. In the US, there are about 100 C3PAOs (third-party assessment organizations) and about 800 assessors for 80,000 companies.
What they are experiencing is a sudden rush. Level one takes a couple of months with about 13 controls to implement in the Canadian version. However, Level 2 requires about an order of magnitude more controls, around a hundred, and it can take 12 to 18 months to sort out and complete the 3rd party assessment. There are simply not enough assessors in the US market, and we are even farther behind in Canada.
To get companies to Level 1, they need to be aware that they need it. A lot of them don’t know, or they think it’s out on the horizon somewhere and aren’t too worried about it. Level 1 for CPCSC was laid out in March of this year and is now starting to appear in DND contracts this summer; it will likely be fully enforced by next year. By next March, Level 2 will be in place, and everyone is waiting for those detailed requirements.
The companies already in the defence market are aware and have put processes in place to achieve their levels. However, any emerging dual-use companies will face a full pipeline with limited assessment capabilities. If they thought they were going to get their Level 1 or Level 2 on demand, they are going to be shocked and surprised.
You could say that’s simply bad timing and bad planning on the part of those dual-use companies. But federally, Canada wants to move from about 43% Canadian procurement to over 70% Canadian procurement by 2035. To do that, we have to significantly increase the number of Canadian companies participating in the defence market from its current level at around 600. So, if we want to achieve that goal, yet lack the capacity in the ecosystem to get all the companies aligned, just at the cybersecurity level, not to mention controlled goods, security clearances, and many other considerations, we are talking about one piece of a larger puzzle that will end up being a critical blocker. It will create a backlog, and everything will slow down, yet it is foreseeable.
We can do something about it now before it becomes a problem, and arguably we are already at that stage. We have to move quickly, but that’s the challenge. It sounds like regulatory complexity, but it is precisely that complexity which will introduce friction at the exact moment when we really need to be agile and get our Canadian sovereign defence strategy together.
KB: The Defence Industrial Strategy indicates intention to to buy 70% Canadian, and we have regulatory requirements that create a bottleneck. Where is the disconnect?
LJ: A lot of attention and money are going toward making this happen, so it’s not as if the federal government or the ecosystem is unaware of what needs to be done. Quite a lot of money is flowing specifically through BDC to SMEs who are trying to make this pivot. What is clear, however, is that there is a gap between what prospective emerging dual-use companies understand about how this works and the ecosystem’s response to the demand. That demand has not fully arisen yet. There is going to be a lag in the ecosystem’s response to build up sufficient capacity. We really have to look forward into the future and see this as an upcoming wall or blockage.
Most attention is being placed on SMEs already in the defence market or those with existing relationships with primes. What is being missed is that capacity has to work end-to-end. We must have sufficient assessment and certification capacity to get enough SMEs into and through that pipeline. That larger, end-to-end picture has been overlooked. Various pieces are getting attention, but the overall end-to-end effect hasn’t been sufficiently addressed.
KB: Early in the conversation, you noted that companies shape themselves to facilitate access funding. How do you distinguish between these and companies that legitimately have dual-use potential?
LJ: That is a great question because there is a lot of ambiguity. Part of the overall problem we face is an insufficient definition generated early enough for individual companies and ecosystem members to respond effectively. So that is an obvious problem we need to tackle: what does dual use look like, and how do you meet those requirements? Can any given company decide to modify its business model to make itself dual use, and how does it figure that out? That is a critical decision.
Anytime a company pivots like that, an awful lot is committed. The defence market is not like a civilian market in many ways; you don’t do standard sales and marketing, rather, it is all business development and relationships, and the timeframes are much longer. Does the company understand what it is going to take? Fortunately, various organizations are tackling that education problem and helping companies evaluate themselves.
In the meantime, while waiting for definitions from those organizations, the federal government, and supporting programs, we are taking a practical, functional approach. We look at the requirements to operate in that space and the readiness of companies to take them on; for example, ensuring that they understand the implications, costs, time, and business changes involved in CPCSC certification. We assess their readiness to take those additional steps and ensure they are appropriately educated by supporting organizations. This includes factors like Canadian IP, sovereignty, data residency, security clearances, and cybersecurity requirements. We can also sit down with a company and evaluate various aspects of that.
While many good programs do that, we want to make sure each company understands every aspect. If they claim they are ready for dual use and want to pursue CPCSC certifications, we ensure they have everything in view. An expert panel sits down in a rapid engagement with the company to go through all the requirements and confirm they have a clear view. If we see a gap there, we deselect that company as not ready to take that step and favour a company that has thoroughly examined it.
KB: Care to take a stab at what you think should be the litmus test for what constitutes a Canadian company?
LJ: That is a very active discussion as well. Everyone recognizes that when we talk about sovereignty, you instantly introduce tension. We cannot operate in a silo as a purely sovereign nation with no contact, interaction, or relationships with outside companies; we have those relationships and will continue to have them. So who do we favour? What do we call a sovereign Canadian company or infrastructure with appropriate data residency? That is really above my pay grade.
Much of the conversation right now focuses on governance qualifications: who owns how much of the company and how it is controlled. Establishing thresholds like 51% ownership, Canadian headquarters, and Canadian infrastructure not subject to foreign data access laws is a good start. However, we also need to know when to make exceptions or relax particular constraints for a company providing a specific role. We can consider that on a spectrum. Almost every company likely has some degree of non-sovereign character, and we look at companies individually based on the solutions they are aiming to serve.
Again, at Circle, we tend to work bottom-up, evaluating each company individually as opposed to applying bulk rules and filters across the ecosystem. It might sound a bit evasive regarding what we consider sovereign, but there is a lot of work for others to do to provide clear direction on that.
KB: Circle Innovation is proposing the Defence Readiness and Advanced Capabilities Cluster (DRACC) program aimed at addressing the CPCSC bottleneck. Give us an overview of DRACC and how you see this unfolding.
LJ: We always try to create handy acronyms. DRACC stands for Defence Readiness and Cybersecurity Certification, and it is primarily aimed at what I described as the CPCSC bottleneck. It is intended to identify companies in near-term need of certification so they don’t face obstacles entering the market simply because they don’t meet regulatory requirements. It builds awareness where necessary, selecting companies best prepared to take advantage of the defence market.
We have what we call Stage 1, where we rapidly take a company through a due diligence process to establish that they are positioned, have potential, and understand what they need. Some companies need Level 1, while about 40% overall will need Level 2 or possibly Level 3, and they must understand those heavier implications.
Once that awareness is in place, we aim to get them certified as quickly as possible through co-funding and guidance, working with compliance certification companies across Canada capable of delivering that certification. Additionally, I want to stress that we are developing means to accelerate beyond current capacity, increasing capacity by doing it faster and better. We are working or aiming to work with compliance companies capable of accelerating the process so that instead of taking 12 to 18 months to achieve Level 2, companies can reach it in under 12 months. We have done similar things with SOC 2 Type 2, typically a 12-month process brought down to six months, and we can repeat that here. We would develop a sovereign Canadian solution to enable that acceleration, which advances Canadian service providers while speeding up and expanding capacity overall for all Canadian companies pursuing these certifications. So it operates on two levels: getting individual companies through required certifications via co-funded, rapidly delivered projects, and improving existing processes to build overall capacity in the ecosystem. We also want to signal to others in the ecosystem that we need more assessors and certification capacity overall, but DRACC’s focus is to establish those processes and capabilities.
KB: Are you aiming at both CPCSC and CMMC, or is there enough overlap between their requirements that you can do them in parallel?
LJ: They can generally be done in parallel. There is a lot of similarity between the two of them, though they are not identical. Getting your CMMC is distinct from CPCSC, but if you have one, you are very close to having the other.
An awful lot of Canadian companies are looking at the American market as part or all of where they need to focus, as its size and capacity are attractive and often a necessary part of doing business. The programs we focus on would primarily be about CPCSC, but we should be able to support CMMC as well so Canadian companies can operate south of the border. More broadly, when we think about Europe and NATO, that is another set of processes. But again, the original NIST standard, 800-171, is the common base for all these different processes. So, you can get a company a long way down the path toward operating in any of those spaces with a primary focus on CPCSC.
KB: I understand that you are anticipating $50,000 per company as a rough cost of going through that level and certification. How do those costs break down?
LJ: Our current estimate is $50,000 for a Level 2. Level 3 is going to be more expensive, and Level 1 is much less expensive. For a typical project Circle operates in the $50,000 to $100,000 overall cost range and we partially co-fund that effort. So the company has a lot of skin in the game as it is not 100% covered.
What is typical for them is engaging consultants and processes to do the scoping for that particular company, identifying, for example, who within the company handles particular types of information, how that information is stored, where that equipment is, and who has access to it. That is really a company-by-company scoping process. Once that is in view, it is back to the company to start making those changes and implementing them properly, often with additional guidance but a lot of internal work.
Level 2 is externally assessed by third parties, so certification requires engaging third parties to do that audit and assessment. Those kinds of costs extend over a period that of 12 months or so, though we would like to see that period much shorter. It could be as much as $100,000 depending on the company and their scope. We are aiming to compress that in both cost and time, so maybe targeting $50,000 or less would be great.
KB: What is the status of the DRACC program now?
LJ: This has been a rapidly emerging problem that we have responded to. We are now putting this proposal in front of provincial, regional, and federal funding sources (regional in the sense of RDAs). There has been a change at the federal level where responsibilities related to defence have moved from ISED over to DIA, the Defence Investment Agency. Things are shifting, and it is a bit of a shell game at the moment, but we will get a clear response in the coming weeks as to whether this can be funded in the short term - it is very time-sensitive. Often, cycles for this kind of funding are over a year: putting in a proposal, refining it, and waiting until the next round of funding is available. This cannot wait; it needs an early response if we are going to avoid that bottleneck.
KB: Shifting gears a bit, tell us about TICAN and how it interacts both with Circle Innovation’s work and with DRACC.
LJ: To respond to how TiCAN applies to DRACC: probably not much, because DRACC is quite focused on defence-related certification. Where TICAN comes in, we are constantly looking around the ecosystem to see where there is friction or gaps that to overcome. TICAN is a very specific response to a problem similar to CPCSC, though not related functionally. That problem can be articulated as: how do we incentivize academia and private industry to work together optimally?
Both when I worked in academia with companies and then working in companies with academia, there was always a level of challenge to overcome. I ended up summarizing it as an impedance mismatch (in an engineering sense): a lot of energy is lost trying to communicate, coordinate, or meet each other’s agendas, which are not similar. To use another metaphor, the currencies are quite different: papers, students, and research on the academic side; products, revenue, and markets on the company side. They are not talking the same language. It is often difficult to get them coordinated on a given project, especially when aimed at achieving economic outcomes. TICAN recognizes that and motivates both sides of the equation properly, which is why we are involved and excited about it.
This has been 10 years in the making, based on the MScAC program (the applied master’s program out of the University of Toronto) which has been very successful. TICAN brings together companies and researchers to execute a research program defined by a company that is seeking to get R&D done, generate IP, and generate HQP. What makes it different is that the research program is not adjacent to the master’s or PhD student’s primary work – it is their research program. An industry project is often an interruption in the academic process; the supervisor or researcher is looking to get the student through their research program, complete their thesis, and grant their degree. Working with a company often temporarily derails that process, creating friction.
TICAN addresses this by making the project the core of the student’s work rather than an adjacent or parallel aspect. The work in setting up a TICAN project is getting the researcher and company to identify common interest in a research program that has the necessary high-quality research potential leading to a degree while meeting the company’s needs for IP and R&D leading to economic impact. It is a real challenge, but the opportunity is that everybody gets their needs met. There is no longer an impedance mismatch or derailment; the student stays on the common program all the way through to their degree.
Scenarios can vary: a company may know a researcher and need to find a candidate, or someone in the company doing R&D may want to get a degree for their work and can move into the academic environment to do work for the company. Large companies may also want to build clusters of activity. There are many ways TICAN can support a project like that, but this is the main component, overcoming this key challenge in activating Canada’s academic potential and bringing its impact into private industry.
TICAN is funded and operational. We are in the process of building projects right now. Sometimes the researcher is looking for the company, sometimes the company for the researcher, and sometimes they have known each other for quite some time and now have an opportunity to fund work within the company or within the university system with proper support. We are seeing a lot of interest in the level of funding for the candidate. To attract high-level HQP, the stipend is on the order of $75,000 to $80,000 annually ,in one-year or two-year scholarships. This funding is significantly higher than a typical master’s, PhD, or postdoc stipend, enabling companies and researchers to attract top talent.
KB: Does TICAN take an active position in terms of the ownership or licensing of IP that arises in the course of that research?
LJ: IP has been another source of friction in the past. Many universities have straightforward IP policies when working with them, while others are very restrictive. TICAN takes the view that IP from the project flows to the company, structuring it appropriately and establishing agreements with universities on how TICAN operates within the academic environment. This removes natural friction around IP by making clear how projects are built and where IP goes.
At the same time, there is always room to improve the IP process. We have talked about your program, SAIL, which I am very fond of, and want to implement alongside TICAN.
KB: If you were advising federal leadership at ISED, DND, or wherever decision-making authority ends up once the dust settles, what funding commitments or policy moves would you advise in the short term (aside from “fund DRACC”)?
LJ: In the context of defence, where CPCSC is one piece of a larger puzzle, leadership should look at critical capacities, such as the assessor requirements for CPCSC and beyond, ensuring sufficient attention, funding, and support are placed on all stages of needed ecosystem capacity. It is easy to overlook one, we identified one and are addressing it, but there will be others. In a time of rapid change, it is easy to trip over those pinch points. They should proactively identify and address innovation friction broadly, and not necessarily just in the defence picture.
The thing that comes back for me, both having worked as an entrepreneur within SMEs and also in this current role, is that we really need to go where the companies are. We need to meet them in their circumstance, understand what they need, and operate at their speed. Time is often of the essence. We need to work at the speed of business if the intention is to enable them. A lot of programs take too long or create new and additional work for companies, and that really burdens them in ways that work against what we are intending: innovation, economic impact, and growth. Really trying to meet companies where they are is one of the key admonitions.
KB: Is there anything I should have asked you but didn’t?
LJ: There are an awful lot of parts of the overall ecosystem that I think we could be talking about. I think one of the larger challenges we face is coherence as an ecosystem - there I don’t know what the answers are. Sometimes I start to feel like it’s cultural, where a lot of people have been ruminating about what it’s like to be Canadian, and maybe we don’t have what it takes, always shooting for second, and things like that. But what seems to be key overall is the need for leadership at various levels to maintain a level of risk tolerance, which, both as Canadians and as government specifically, is sometimes hard to come by - there is so much sensitivity to optics, how it looks and whether there’s a misstep. That’s often the end of the road for anyone who has failed even once. Entrepreneurs know that failure is often part of the game, but that’s not broadly how the ecosystem works.
If anyone is looking to find out more about Circle Innovation or DRACC, they can find us at circleinnovation.ca or contact us at industry@circleinnovation.ca or find me on LinkedIn.
Key Takeaways
When the DIS was first released, I was genuinely excited to see the commitments it made. If Canada has to increase its defence spending to such a degree, it only makes sense to use that as a way to strengthen our economy, and the 70% Buy Canadian commitment is an excellent means by which to do it. However, there are significant structural barriers to realizing this ambition, barriers that arise from the unique composition of Canada’s defence market. Loki makes clear that a purely top-down approach will not work:
“That’s why you can’t do a top-down program: every company has its own story, and you can’t predict what will be important to them in the moment.”
From the perspective of the public service, procurement processes are designed to reduce risk and avoid blame for failures, a process that naturally favours large incumbents. Picking a safe, established prime carries zero personal risk for a procurement officer, even if it undermines sovereign capability.
“Leadership [needs] to maintain a level of risk tolerance, which, both as Canadians and as government specifically, is sometimes hard to come by... Entrepreneurs know that failure is often part of the game, but that’s not broadly how the ecosystem works.”
In defence procurement, however, there is more to it. To some degree, there is structural necessity underlying the preference for primes. Across NATO, relatively few defence contracts go to SMEs directly, for the simple reason that relatively few SMEs produce an entire platform themselves at the necessary scale, and failures can cost more than just dollars.
For Canada, this poses a unique challenge to the ambition of the DIS, because 92% of Canadian defence firms are SMEs. Regardless of what we ultimately decide it means for a company to be Canadian, it will likely be that by any reasonable definition, it will be possible to count on one hand the number of large incumbent defence firms that will fit. (This is, in a nutshell, the problem that ITB policies are designed to solve, by requiring that foreign primes favour Canadian subcontractors, among other mechanisms).
However, the fact remains that engaging with SMEs is a more direct path to unlocking the economic benefits of defence spending. While the recently created Defence Investment Agency (DIA) is intended to streamline the process, its initial mandate limited it to contracts above $100M, which most SMEs still cannot service directly. The recent news that the head of the DIA is stepping down further suggests some challenges on implementation, and there remain disconnects between early programs like Innovative Solutions Canada and actual procurement contracts.
As much as I like to focus on the policy challenges, it is clear from the interview that in this case the problems are not limited to the public service. It is not a simple thing for a company that was not previously integrated with the defence establishment to achieve that integration, and with so much money flowing into defence, many companies that previously were not built to serve defence customers are eyeing the space. The systems through which onboarding happens are about to be overwhelmed, creating a bottleneck on the private sector side that will further frustrate the DIS if not proactively managed:
“[C]ybersecurity certification […] poses a critical challenge[…] Companies that have been operating in a civilian market now considering themselves dual-use and looking at the defence market are faced with a set of regulations they may have never anticipated. […]
Level 2[...] can take 12 to 18 months to sort out... There are simply not enough assessors in the US market, and we are even farther behind in Canada.”
In short: Canadian SMEs seeking defence contracts are caught between top-down procurement policies that exclude them due to size, and bottom-up regulatory requirements that stall them due to capacity. Together, they create a bottleneck to the vast majority of Canadian companies that could take advantage of the push toward defence. Loki highlights the urgency:
“Often, cycles for this kind of funding are over a year: putting in a proposal, refining it, and waiting until the next round of funding is available. This cannot wait; it needs an early response if we are going to avoid that bottleneck.”
I should be clear where I stand on the regulatory question before going further: while I recognize the challenge posed by the regulatory environment, I do not view regulation as an inherently problematic thing. Done well, regulation can actually be the basis for very effective predictive tools. Cybersecurity, sound security clearance processes, and compliance with export control regimes are not optional, especially in defence. Nothing in this post should be read as a suggestion that these requirements should be relaxed or waived.
Nevertheless, it is inevitable that regulatory burden favours large, incumbent firms over smaller upstarts, and in a market where most firms are small upstarts, we need to get creative. Per Loki:
“The companies already in the defence market are aware and have put processes in place to achieve their levels. However, any emerging dual-use companies will face a full pipeline with limited assessment capabilities. If they thought they were going to get their Level 1 or Level 2 on demand, they are going to be shocked and surprised.
[…]
What is being missed is that capacity has to work end-to-end. We must have sufficient assessment and certification capacity to get enough SMEs into and through that pipeline. That larger, end-to-end picture has been overlooked.”
There has long been a tension between public and private sectors in Canada: the public sector points at flagging private investment in innovation and calls on the private sector to step up, while the private sector reminds the public that their decisions are driven by profit. If the profit is not there, neither is the incentive to act.
The not-for-profit private sector holds enormous potential to assist Canada in mediating that divide, and Circle Innovation’s DRACC program is an excellent example of how.
“We really need to go where the companies are. We need to meet them in their circumstance, understand what they need, and operate at their speed. Time is often of the essence.”
While a for-profit entity may not be incentivized to take on the challenge of streamlined onboarding processes for SMEs (though ITB policy overhauls have potential to tip the scales here), a not-for-profit like Circle Innovation derives value from more than just direct returns.
Regulatory compliance through programs like DRACC could clear the path to market for existing technologies, but domestic capability creation starts much earlier. A major hidden friction in building sovereign defence tech is what Loki calls an “impedance mismatch” between academia and industry. Traditional R&D programs treat industry projects as interruptions to academic degrees, leading to IP disputes and conflicting incentives:
“To use another metaphor, the currencies are quite different: papers, students, and research on the academic side; products, revenue, and markets on the company side. They are not talking the same language. It is often difficult to get them coordinated on a given project, especially when aimed at achieving economic outcomes. TICAN recognizes that and motivates both sides of the equation properly”
Programs like TICAN are examples of exactly the kind of incentive-aware approach I advocate for generally: by aligning a researcher’s core degree directly with an SME’s commercial roadmap, guaranteeing that IP ends up somewhere it can be used beyond the lab, and offering competitive stipends to retain top talent in Canada, TICAN can be seen as part of the system that creates the companies that then need guidance through regulation by DRACC.
Looking Ahead
If Canada's Defence Industrial Strategy is to succeed, policy makers cannot treat defence research, procurement policy, and regulatory compliance as separate domains. Buying 70% Canadian requires not just opening procurement doors at the top, but actively pulling valuable technologies through the research pipeline and building the institutional regulatory capacity to get domestic technologies past regulatory hurdles. As with every part of the innovation pipeline, no part of this can operate in a silo and expect the whole to function.
This in turn involves recognizing the constraints and incentives at play and using those incentives to direct strategy. Programs like DRACC demonstrate how the not-for-profit private sector can bridge the divide, but without public investment in compliance capacity and assessor throughput, the 70% ambition will remain a policy aspiration stalled by regulation.
Many thanks to Loki for taking the time to share his insights. Anyone looking to find out more about Circle Innovation or DRACC, can find him at circleinnovation.ca, email industry@circleinnovation.ca or find him on LinkedIn.




For non-defense folk, it would be interesting to see a schematic of how many regulatory regimes need to be satisfied in Canada. In this interview, several were mentioned. Are there more? Is there a way, or should there be a way, to simplify them as part of Canada's defense initiative?