Our Valued Partners
BUILT TO THE STANDARDS THAT MATTER
CPCSC · CMMC LEVEL 1 & 2 · ISO 27001 · SOC 2 TYPE II · NIST 800-171 · PIPEDA
Code to Cloud Security Compliance to contract.
WHAT WE DO
Lunima combines automated security scanning with senior human expertise to deliver what large enterprise security firms charge $50,000+ for — at a price that works for a 20-person defence supplier or a regional credit union. We find vulnerabilities, fix critical ones first, map everything to your regulatory obligations, and provide documentation you can hand to a contracting officer, regulator, or insurance broker.
Which rules actually apply to you?
Pick your sector. We'll show you what your buyers, regulators and insurers actually check — and exactly what Lunima hands you.
Government of Canada & the defence supply chain
WHAT APPLIES TO YOU
WHAT LUNIMA HANDS YOU
CPCSC — now a gate on DND and PSPC contracts
NIST SP 800-171 / CAN-CIOSC 104 controls
ITSG-33 and ITSP.10.171 hardening guidance
Protected A / B handling and SRCL clauses
Flow-down obligations to your subcontractors
Gap assessment dual-mapped to CPCSC and 800-171
A System Security Plan and POA&M you can hand to a prime
24/7 managed EDR on every endpoint
A monthly evidence pack that supports your attestation
One named person on the phone, not a ticket queue
Cybersecurity for you
From kickoff to attest-ready.
Choose LUNIMA
Businesses choose Lunima because we deliver results in days, and never send a surprise invoice.

Scan & scope
We map what's in play — endpoints, cloud, data flows, and the contracts or regulations you're on the hook for. You get a written scope and a fixed price before any work starts.

Assess & fix
We independently assess all 13 CPCSC practices. Non-intrusive — no admin credentials, no downtime. We fix critical vulnerabilities and map every finding to Canadian law.

Report delivered
Complete attestation package: gap report, SSP framework, POA&M, CMMC crosswalk. 60-minute debrief with Siman. Board-ready. Contracting-officer-ready. Yours.
Proof, not promises.
Huntress-powered 24/7 SOC — real analysts making decisions, not alerts sent to nobody
Canadian-owned and operated, mapped to CPCSC, ITSG-33, PIPEDA, PHIPA and OSFI
Non-intrusive assessment — no admin credentials, no downtime, no agents on your servers
Evidence you can hand over — gap report, System Security Plan, POA&M, CMMC crosswalk
One named practitioner on the phone — not a ticket queue, not a rotating account manager
FIXED PRICE, IN WRITING
Quoted flat, in Canadian dollars, before any work starts. No hourly creep, no surprise invoice.
NO LOCK-IN, EVER
Monitoring is month to month. Cancel any time. We keep the work because it earns its place.
FREE SCOPING CALL
30 minutes, no obligation. If you're already in good shape, we'll say so.
If you don't need us, we'll tell you.
We'll take an honest look at where you stand, free. If there's a real gap, we'll show you exactly what it is. If you're already in good shape, we'll say so — and leave you alone.
A firm that only makes money when you sign has every reason to tell you you're at risk. We'd rather be the one you call when a prime finally asks the question — because we were straight with you the first time.