Jun 23, 2026 · Field notes

The cost Canada cannot measure

Canada is spending $81.8B to rebuild its defence industry and named Secure Cloud a sovereign capability. The platforms its primes run classified workloads on are still under US legal authority. The cost of that exposure is invisible by design, and the absence is itself the cost.

Canada is spending $81.8 billion to rebuild its defence industry by 2030, has named Secure Cloud one of ten sovereign capabilities it commits to building, and was selected to host the headquarters of a new multilateral defence bank.12 The platforms its primes run classified workloads on are still operated under US legal authority, a posture an earlier piece in this series walked in full. The dollar cost of that exposure should be a number you can put in a business case. It isn’t, and this piece works out why.

Canada does not measure what it spends

The first reason the cost is invisible is that Canada does not measure it. The Auditor General said as much in 2022: four years after the government directed departments to adopt cloud services, the Treasury Board Secretariat had still not provided a cost model or a funding approach, and security controls were being applied inconsistently across departments.3 A government that lacks a cost model for cloud cannot tell you what cloud costs it, let alone what the foreign-jurisdiction premium inside that spend amounts to. The exposure premium is a line item inside a total that’s itself not computed.

This inverts the usual shape of a cost argument. The problem here isn’t a large, alarming number. It’s that the number doesn’t exist anywhere, including inside the government that’s paying it. When the buyer cannot price what it’s buying, the price of the part that matters most disappears into the part that was never measured.

Gag orders make the events unobservable

The second reason is that the events that would generate a cost are designed to be unobservable. A US legal order served on a US-incorporated provider can carry a non-disclosure obligation, so the provider cannot tell the affected customer, and the customer cannot tell anyone. There’s no publicly documented case of a US CLOUD Act order served on a Canadian customer, and the analysts who have looked hardest, at Citizen Lab, the Canadian Bar Association, and the Office of the Privacy Commissioner, all note the same thing: the absence of public cases is a property of the regime, not evidence that nothing has happened.45

The Privacy Commissioner has held the load-bearing position for over a decade: “no contract, no matter how well crafted, can override the laws of the foreign jurisdiction.”6 The most direct confirmation came not from a critic but from the operator. Asked under oath at the French Senate in June 2025 whether Microsoft could guarantee that French customer data would never be transmitted to US authorities, Microsoft France’s director of public and legal affairs answered, “Non, je ne peux pas le garantir.”7 The exposure is real enough that the vendor will admit it under oath. The cost stays invisible because the regime that produces it is built to leave no record.

A risk you cannot observe and cannot price is worse than one you can, because it cannot be managed actuarially. It can only be removed structurally.

The numbers that do exist are damning

What can be measured is the scale of the dependency, and there the numbers aren’t flattering. Shared Services Canada signed a software and services agreement with Microsoft worth $940 million over seven years.8 Microsoft’s December 2025 commitment of $19 billion in Canadian investment, including $7.5 billion for expanded Azure regions in Toronto and Quebec City, was announced under an explicit “digital sovereignty” banner, six months after the same company’s French subsidiary testified that data residency doesn’t defeat US compulsion.9 An independent dataset assembled by a Vancouver lawyer estimates that roughly two-thirds of the SaaS platforms in use in Canada sit under CLOUD Act jurisdiction, and that of the tools offering Canadian data residency, about a third remain under US parent control.10 Inside government, the Parliamentary Budget Officer found that the Department of National Defence carries the highest task-based IT contractor premium of any department, 25.7 percent over an equivalent in-house position, against departmental informatics spending of $346 million in a single year.11

None of these is the cost of CLOUD Act exposure. Each is a measure of how deep the dependency runs, which is the surface the exposure attaches to. The dependency is growing, and it’s concentrated in exactly the vendors whose jurisdiction is the problem. The exposure premium rides on top of a base that is already this size.

Phoenix is the only unit cost, and it measures the wrong thing

Canada does have one public unit cost for federal IT, and it’s the wrong one. The Phoenix pay system reached roughly $5.1 billion against an original budget of $310 million.12 It’s the number every observer reaches for, because it’s the only federal-scale IT figure with a clean public total and a clear lesson. But Phoenix priced the failure of a migration into a botched system. It did not price exposure to a foreign jurisdiction, and the two aren’t the same kind of cost. Phoenix is what failure looks like after it has happened, in dollars, on the public record. The cost of jurisdictional exposure is what risk looks like before it has happened, in a record that doesn’t exist.

Phoenix is useful for one thing only. It establishes that federal IT failure in Canada carries a real public unit cost once it materializes, which proves the bill comes due. It tells you nothing about the size of the bill for the exposure that hasn’t yet been called, because that bill, by design, is never itemized.

The strategy makes the silence expensive

The reason this matters now, rather than as a standing academic point, is that Canada has just put a very large number on the other side of the ledger. The Defence Industrial Strategy named Secure Cloud a sovereign capability, set a 70 percent Canadian-procurement target, committed to requiring multinational suppliers to do more work with Canadian-controlled firms and to reduce reliance on foreign software updates and intellectual property, and stood up a certification gate, the Canadian Program for Cyber Security Certification, that suppliers must now pass.113 The strategy is, in effect, a public declaration that the exposure is worth retiring. It commits real money to retiring it. What it cannot do is say how much the exposure was costing in the first place, because nobody measured it, and nobody could.

So the silence becomes expensive in a specific way. A government that cannot price a risk cannot easily justify the spending required to remove it, except by appeal to the risk’s structure rather than its dollar value. The Defence Industrial Strategy makes that appeal at the level of policy. The country has decided that some exposures must be removed even when they cannot be costed, because the cost of leaving them in place is the one number that can never be put in front of a committee.

The number Canada cannot publish

The cost Canada cannot measure runs through everything above. The government has no cost model, so the exposure is unpriced. The regime that triggers it forbids disclosure, so the events stay unobservable. The only comparable public figure measures a different failure, so there’s nothing to benchmark against. Put those together and the exposure premium on Canada’s classified workloads is, structurally, the one cost in the entire defence-procurement ledger that cannot be written down.

The number Canada cannot publish is the one that matters most: how much sovereignty is worth to a country that just put $81.8 billion on the table to buy it. A vendor cannot answer that question either. What a vendor can do is remove the exposure, so the unmeasurable cost stops accruing.

Northfleet is a Canadian-incorporated vendor building the sovereign supply chain that wraps a customer-operated classified cluster: a deploy-time bundle protocol, attestation chain, and tamper-evident audit trail. The customer’s cleared engineering teams operate the cluster on Canadian-jurisdictional infrastructure, under their own keys. Northfleet holds no customer data and no customer signing keys. Every release Northfleet ships carries provenance binding it to the source it was built from, which the customer can check without Northfleet’s participation. The architecture assumes the vendor can be compromised or compelled. That assumption is what stops a compelled vendor from silently changing what runs in the cluster.

If you’re evaluating sovereign infrastructure for classified workloads, and you’ve stopped trying to price an exposure that no one will let you measure, the conversation is open.

Footnotes

  1. Office of the Prime Minister, “Prime Minister Carney launches Canada’s first Defence Industrial Strategy,” February 17, 2026; the strategy names ten sovereign-capability areas including Secure Cloud, sets a 70 percent Canadian-procurement target, and commits to requiring multinational suppliers to do more work with Canadian-controlled firms and reduce reliance on ongoing foreign software updates and intellectual property. https://www.pm.gc.ca/en/news/news-releases/2026/02/17/prime-minister-carney-launches-canadas-first-defence-industrial. Analysis: https://www.blg.com/en/insights/2026/02/how-canadas-defence-industrial-strategy-reshapes-defence-acquisition-and-procurement-law. 2

  2. Department of Finance Canada, “Canada welcomes progress towards the establishment of the Defence, Security and Resilience Bank and hosting its headquarters,” April 29, 2026. https://www.canada.ca/en/department-finance/news/2026/04/canada-welcomes-progress-towards-the-establishment-of-the-defence-security-and-resilience-bank-and-hosting-its-headquarters.html.

  3. Office of the Auditor General of Canada, 2022 Reports, Report 7 (cloud adoption): four years after the direction to deploy cloud services, the Treasury Board Secretariat had not provided departments with a cost model or funding approach, and controls were applied inconsistently. https://www.oag-bvg.gc.ca/internet/English/parl_oag_202211_07_e_44153.html.

  4. Khoo and Robertson, “Canada-US Cross-Border Surveillance Negotiations Raise Constitutional and Human Rights Whirlwind under US CLOUD Act,” Citizen Lab, University of Toronto, February 24, 2025. https://citizenlab.ca/2025/02/canada-us-cross-border-surveillance-cloud-act/.

  5. Canadian Bar Association, submission on the proposed Canada-US CLOUD Act agreement, recommending mandatory Canadian-court review of US requests. https://cba.org/our-impact/submissions/cloud-act-agreement/.

  6. Office of the Privacy Commissioner of Canada, standing guidance on cloud computing: “no contract, no matter how well crafted, can override the laws of the foreign jurisdiction.” https://www.priv.gc.ca/en/privacy-topics/employers-and-employees/outsourcing/02_05_d_57_os_01/.

  7. Anton Carniaux, director of public and legal affairs at Microsoft France, testifying under oath before the French Senate, June 18, 2025. Primary record: https://www.senat.fr/actualite/commande-publique-audition-de-microsoft-5344.html. Coverage: https://www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee.

  8. Shared Services Canada / Microsoft Canada software and services agreement, valued at $940 million over seven years (Windows, Exchange, Office 365, server operating systems, development tooling, and hybrid cloud rights). https://www.canada.ca/en/shared-services/corporate/about-us/transparency/publications/enables-modern-accessible-service.html.

  9. Microsoft, “Microsoft deepens its commitment to Canada with landmark $19 billion AI investment,” December 9, 2025, including $7.5 billion over two years for expanded Azure regions in Toronto and Quebec City, framed under “digital sovereignty.” https://blogs.microsoft.com/on-the-issues/2025/12/09/microsoft-deepens-its-commitment-to-canada-with-landmark-19b-ai-investment/.

  10. Upper Harbour, “CLOUD Act and Canadian data,” an independent dataset of 753 SaaS platforms used in Canada assembled by a Vancouver lawyer, estimating roughly two-thirds under CLOUD Act jurisdiction and that about a third of tools offering Canadian data residency remain under US parent control. The methodology is public; treat the figures as a directional independent estimate, not an official statistic. https://www.upperharbour.ca/resources/cloud-act-canadian-data.

  11. Office of the Parliamentary Budget Officer, “The fiscal cost of task-based IT contracting,” January 2025: the Department of National Defence carries a 25.7 percent contractor premium over an equivalent in-house position, the highest of any department, against departmental informatics spending of $346 million (2022-23). https://www.pbo-dpb.ca/en/publications/RP-2425-024-S—fiscal-cost-task-based-it-contracting—cout-financier-passation-contrats-ti-centres-taches.

  12. The Phoenix pay system reached roughly $5.1 billion as of June 2025 against an original budget of $310 million. https://en.wikipedia.org/wiki/Phoenix_pay_system. Auditor General coverage: https://www.oag-bvg.gc.ca/internet/English/parl_oag_201711_01_e_42666.html.

  13. Public Services and Procurement Canada, Canadian Program for Cyber Security Certification (CPCSC), with Level 1 effective April 1, 2026 as a procurement requirement for defence suppliers. https://www.canada.ca/en/public-services-procurement/news/2026/04/government-of-canada-introduces-level-1-of-canadian-program-for-cyber-security-certification.html.

Talk to us

If this maps to your procurement context, we should talk.

Northfleet is opening a founding design-partner cohort across the Canadian defence industrial base. A briefing follows first contact.

Contact Northfleet