There is no membership fee, which makes the real question a different one: can you evidence the security you already have?
Key takeaways
Partners in Protection is the CBSA’s trusted trader programme: a voluntary programme with no membership fee where businesses and the CBSA work together to enhance border and trade chain security. Membership buys expedited clearance through FAST lanes, lower examination rates, and recognition as a trusted trader abroad through the CBSA’s mutual recognition arrangements.
It is worth joining if you cross the border regularly, your lanes touch a FAST crossing or your examination rate is costing you delivery windows, and you can document the security you already practise. It is not worth starting if nobody in the business will own a written security profile, because the profile is the programme.
For businesses based in Canada, the CBSA opens membership to commercial carriers in the highway, rail, marine or air modes (including couriers, which enrol as carriers), importers, exporters, warehouse operators including marine terminal operators, freight forwarders and customs brokers. Customs brokers are noted as unable to access the Trusted Trader portal at present but may still apply by email.
US-based businesses can join too: carriers in all modes must hold a valid Canadian carrier code, and importers doing business in Canada must hold a valid Canadian business number and file Canadian customs declarations.
The 12-month history requirement is the one that catches new operations. A start-up carrier cannot join on day one, which matters when you are quoting a customer who wants a PIP member on the lane.
The CBSA groups the minimum security requirements into four areas: corporate security, cargo and conveyance security, physical security, and supply chain partner security. You must answer every question in the portal and attach evidence — documents or photographs — to support it.
Corporate security is where most applicants underestimate the work. The CBSA asks for a written risk assessment reviewed at least once a year, covering physical security and partners including third-party logistics and contracted IT providers; a description of what the business would do if trade is interrupted, including how it would keep people safe, continue operating and communicate with partners and the CBSA; and a statement of support signed by company leadership, displayed at company locations and discussed at meetings and training.
It also asks for personnel screening, a documented training programme with a written training plan, a stated frequency of at least annually, and a log of who was trained and when, and cybersecurity evidence: firewalls and antivirus, password policies, secure remote access, device inventory and secure disposal, a cyberattack response plan, and a policy to remove access when an employee leaves.
The CBSA requires that seals used by PIP members meet or exceed the current PAS/ISO 17712 standards for high security — bolt or cable seals made of strong metal, removable only with cable cutters, usually identified by an “H” stamped on the seal.
The obligation reaches past your own gate. The CBSA states that any company that participates in a PIP member’s international supply chain must use seals too, including domestic and foreign suppliers, manufacturers, cargo handling and storage facilities, and warehouses, and that members must define, document and implement seal procedures their partners follow.
Applications run through the Trusted Trader portal, signed in with a GCkey or Sign-in Partner. The CBSA describes four dashboard sections — company profile, add and manage users, application profile, and security profile — with a separate security profile completed for each division of the business. Required documentation must be uploaded or the application will be denied, and only the account owner can submit.
Two later steps matter for planning. The CBSA’s standard is to process applications within 180 business days, and after review an officer may schedule a site visit to verify what the security profile claims. There is also a certification and authorisation to disclose information form, which is how the CBSA shares your business name, address, membership status, membership dates and identifiers with the mutual recognition partners you select.
Worked example: a Mississauga freight forwarder deciding whether to apply
The company has run cross-border freight for six years, has a locked yard, screens staff, and already uses bolt seals. On paper it is a strong candidate. The founder assumed the application was a form.
The gap was evidence, not practice. There was no written risk assessment, no dated training log, no signed leadership statement, and no documented seal procedure that partners were required to follow. Every one of those is asked for directly in the security profile.
The realistic project is therefore a documentation project of several weeks, followed by a wait measured in months against the 180-business-day service standard, followed by a site validation. Businesses that scope it that way finish. Businesses that scope it as an afternoon abandon it at the evidence-upload step and conclude the programme is closed to small operators, which it is not.
The CBSA lists the benefits as access to the Trusted Trader portal, a dedicated email inbox, an assigned CBSA contact, access to designated lower-wait-time FAST lanes where the shipment is eligible, lower examination rates at the border, and status as a trusted trader in Canada and abroad under the CBSA’s mutual recognition arrangements. It also notes the programme aligns with the World Customs Organization’s SAFE Framework and Authorized Economic Operator guidelines.
The mutual recognition list is long and specific. The CBSA records arrangements with US CBP’s CTPAT programme (June 2008), Japan, Korea and Singapore (2010), Mexico (2016), Israel and Australia (2017), Hong Kong and New Zealand (2019), Peru and the European Union (2022), the United Kingdom (June 2024) and Taiwan (December 2024). Members choose which partners they wish to receive benefits from.
PIP is not a certificate you file. The annual risk assessment review, the training log, the seal procedure and the partner requirements all have to stay current, because a site validation tests the live state of the business rather than the application.
The repeatable parts are genuinely automatable: keeping a training register with dates and attendees, raising the annual review as a task, holding the evidence pack in one place with version history, and drafting the update when a supply chain partner changes. Judgement calls — whether a change in a trading country’s threat level warrants a fresh review, whether a partner’s seal practice is adequate — stay with the person who signs the profile.
No. The CBSA describes PIP as a voluntary program with no membership fee. The cost is internal effort.
Not by itself. PIP covers the Canadian side; for FAST into the US the CBSA states the truck must belong to a CTPAT FAST-approved carrier carrying qualifying goods for a FAST-approved importer.
The CBSA’s published service standard is 180 business days to process an application, before any site validation is scheduled.
The CBSA requires a security profile for each division of your business, so a multi-division operation should scope the work accordingly.
A 30-minute call is enough to tell you whether AI pays for itself in your back office.