{"url_path":"/sec/cxxif/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K ** **Cybersecurity**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-06-12","source_url":"https://www.sec.gov/Archives/edgar/data/831609/0001062993-26-003168-index.html","accession_number":"0001062993-26-003168","cik":"0000831609","ticker":"CXXIF","issuer_name":"C21 Investments Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/831609/0001062993-26-003168-index.html","primary_entity_key":"0000831609","primary_entity_name":"C21 Investments Inc."},"word_count":350,"has_tables":true,"body_markdown":"**Item 16K.** **Cybersecurity**\n\n**Risk Management and Strategy**\n\nAs of the date of the filing of this Annual Report, the Company has information systems in place and has not suffered a \"cybersecurity threat\" (as defined in Item 106(a) of Regulation S-K) or \"cybersecurity incident\" (as defined in Item 106(a) of Regulation S-K). Moreover, the Company is aware of the evolution of cybersecurity risks and is taking proactive steps by keeping up to date our information systems and educating our personnel about these risks.\n\nRefer to the \"Cybersecurity risk\" section in \"*Item 3-D - Risk Factors\"*for the complete information regarding cybersecurity risks and, the potential likelihood of impacting the Company's technology systems.\n\nIn order to mitigate these risks to a degree, the Company has a full-time IT manager (\"**Manager\"**) and also engages third-party service providers to monitor and update the Company's information systems. The Manager has 25 years' experience in company-wide email security, centrally managed security suites, and requisite experience drafting, updating and enforcing corporate IT policy including cyber and network security.\n\nThe Company has implemented multiple measures to combat and reduce the risk of cybersecurity threats and cybersecurity incidents such as:\n\nHiring the Manager, who is available to respond immediately in the event of any cybersecurity threat or cybersecurity incident;\n\nDeveloping an internal IT Control Guide (\"**IT Guide**\") reviewed by the COO;\n\nEnhancing the scrutiny of the emails received via third-party security service provider to identify potential threats; \n\nImplementing informal educational outreach programs including email reminders to educate staff about certain cybersecurity risks.\n\n**Governance**\n\nThe Manager monitors cybersecurity risks and potential incidents while following and periodically reviewing the IT Guide, recommending updates to the COO where needed. The COO advise the Board of any potential cybersecurity threat and the corresponding mitigation steps needed. In addition, the Board includes a member with expertise and experience in cybersecurity matters.\n\n \n\n \n\n \n\n73\n\nAt the time of filing this Annual Report the Company does not have a subcommittee dedicated to cybersecurity but will consider increased oversight from the Board as the Company's situation evolves responsible for the oversight of risks from cybersecurity threats.\n\n______________________________\n\nPART III."}