CanFlow Global
← All insights
cbsacarmedicertificatescompliance

CBSA Certificate Migration August 4: Test Your CAD Transmission Now or Face Filing Failures

CBSA is switching from Entrust to SECTIGO for SSL certificates on August 4, 2026. If your EDI software or broker's transmission stack hasn't updated its certificate trust store by then, your CAD filings will fail and releases will stop. This is a test-it-now issue, not an IT-will-handle-it issue.

CBSA’s August 4 maintenance window is a certificate authority switchover, not a routine patch. The agency is moving from Entrust to SECTIGO Limited because Entrust lost trust status across major browsers and platforms. If your Electronic Data Interchange (EDI) setup or your broker’s transmission software still has Entrust in its certificate keystore and hasn’t added SECTIGO, your Commercial Accounting Declarations (CADs) won’t reach CBSA after the cutover.

That means no release. No PARS pull. No RMD clearance. Just transmission errors and a stuck shipment.

Why Entrust Lost Trust

Entrust’s root certificates were flagged by browser vendors and platform maintainers over compliance and issuance practice issues. Google, Mozilla, and Apple all signaled they’d stop trusting Entrust-issued certificates. CBSA can’t run critical import processing infrastructure on a certificate authority that browsers won’t validate, so the migration to SECTIGO is a forced move, not an upgrade preference.

The practical upshot: any system connecting to CBSA’s CARM environment that hasn’t updated its trusted certificate list will see the new SECTIGO certificate as untrusted and refuse the TLS handshake. CAD transmission fails. Release doesn’t happen.

Who Needs to Act

Three groups need to confirm readiness before August 4:

Customs brokers. If you run your own EDI stack or use third-party software (CDS, Descartes, BorderConnect, similar platforms), check that your certificate trust store includes SECTIGO Limited’s root and intermediate certificates. Most enterprise EDI platforms push updates automatically, but if you’re on a legacy or self-managed system, this is a manual update. Test in CBSA’s development environment if you have access. Don’t wait until the production cutover at 3 AM August 4 to find out your CADs bounce.

Importers with direct EDI. If you’re filing CADs in-house as a non-resident importer (NRI) or through a self-accounting setup, the same rule applies. Update your keystore, test the connection, confirm SECTIGO validates. If you’re unsure whether your IT team has handled this, ask now. The CBSA’s technical notices typically include keystore update instructions, but you need to action them.

Software vendors. If you sell or support EDI software used by Canadian brokers or importers, push the SECTIGO certificate update to all clients and confirm compatibility. A client’s CAD filing failure on August 4 because your software didn’t trust the new certificate is a support disaster.

What Breaks If You Miss It

If your system isn’t ready and you try to file a CAD after the cutover, the transmission fails at the TLS layer. CBSA doesn’t receive the declaration. You don’t get a release number. The shipment doesn’t clear.

For PARS shipments crossing the Ambassador Bridge or doing pre-arrival filings, that means the cargo sits at the carrier’s yard or the port until you resolve the transmission issue. For release-prior-to-payment (RPP) arrangements where timing matters, a filing failure on a Friday night means the cargo doesn’t release until Monday at earliest, and your importer’s Monday dock schedule is now in question. If that dock is at a Montreal sufferance warehouse with a tight inbound window, the drayage delay compounds.

For NRI filers, the penalty exposure is immediate. CBSA expects timely CAD filing. A technical failure is still a failure. The Administrative Monetary Penalty System (AMPS) doesn’t care that your certificate trust store was out of date.

How to Confirm You’re Ready

Test your CAD transmission connection now. If you’re using commercial software, contact your vendor and confirm the SECTIGO update is deployed. If you run your own stack:

  • Update your Java keystore (if applicable) with SECTIGO root and intermediate certificates.
  • Update your OS-level certificate store (Windows Cert Manager, Linux ca-certificates, macOS Keychain).
  • Test a dummy CAD filing in CBSA’s test environment if available, or at minimum verify your TLS handshake to CBSA endpoints succeeds with SECTIGO validation.
  • Check that Entrust certificates are either removed or deprioritized, so the system doesn’t try to validate against the old chain.

If you don’t have a test environment, the minimum step is confirming with your EDI provider or IT team that the update is done. “IT will handle it” is fine as a process answer, but you need to hear back that they did handle it.

Timing and Downtime

The switchover runs August 4, 2026, from 3:00 AM to 6:00 AM Eastern Time. CBSA systems will be unavailable during that window. Normal practice is to hold filings until the window closes and systems come back online. But if your certificate store isn’t updated when systems return at 6 AM, your filings still fail.

Plan to test a CAD transmission right after 6 AM if you have shipments clearing that morning. Don’t assume silence means success. Confirm that your first CAD post-cutover actually reaches CBSA and generates a release.

The Broader CARM Infrastructure Question

This isn’t the first time CBSA’s CARM migration has required infrastructure updates from the trade community. The original CARM rollout in 2024 forced brokers and importers to overhaul account structures, bond management, and EDI templates. Certificate authority changes are smaller in scope but no less disruptive if you miss them.

The larger pattern is that customs brokerage in the CARM era has higher technical dependencies and less tolerance for legacy system inertia. If your EDI stack is old, manually managed, or siloed from vendor updates, this kind of last-minute certificate scramble will keep happening. Entrust today, another deprecated CA next year, TLS version upgrades the year after.

If this notice caught you by surprise or you’re unsure whether your systems are ready, that’s a signal your compliance and technical infrastructure need tighter integration. CBSA won’t slow down technical changes to accommodate outdated setups.

Most brokers and large importers will handle this update without issue. The risk is small shops running old software, NRI setups that haven’t had IT review in years, or anyone who assumes “the system just works” without actively monitoring CBSA technical bulletins.

If your CAD transmission fails on August 4 and you’re not sure why, the certificate store is the first place to check. If you’re reading this on August 3 and haven’t tested yet, test today.

We file CADs all day and track these notices as part of the job. Second opinions on EDI readiness land on our desk regularly. Get in touch.

Source: CSCB

Talk to a broker