Get Demo

CCCS ITSG-33 Services Canada — Government IT Security

ITSG-33 compliance in Canada is the mandatory framework for managing IT security risk in Canadian federal government departments and their contractors, providing a comprehensive set of security control profiles, a risk management process, and guidance for achieving Protected B readiness as directed by the Canadian Centre for Cyber Security (CCCS). For any organization handling government information or seeking to contract with the Government of Canada, implementing CCCS ITSG-33 is not merely a best practice—it is a contractual and operational necessity that defines how you classify, protect, and manage sensitive information assets.

What is CCCS ITSG-33 and Why Does It Matter?

ITSG-33, formally titled "IT Security Risk Management: A Lifecycle Approach," is the foundational IT security guidance document produced by the Communications Security Establishment's Canadian Centre for Cyber Security. It provides a structured methodology for managing security risks across the entire lifecycle of IT systems, from initial concept through decommissioning. The framework is built around three core components: a security control catalogue based on international standards (primarily ISO 27001 compliance and NIST SP 800-53), a risk management framework (RMF) tailored to the Government of Canada (GC) context, and a set of security control profiles that map specific security requirements to different system sensitivity levels, including Protected B.

For contractors, compliance with ITSG-33 is typically required under the Government of Canada's security policy framework, the Policy on Government Security (PGS), and the Treasury Board Secretariat (TBS) directives. Without a properly implemented ITSG-33 security posture, organizations cannot achieve or maintain the necessary security clearance level to bid on or deliver federal contracts that involve protected information.

Key Takeaways

Who Must Comply with ITSG-33 in Canada?

ITSG-33 applies to a broad range of entities, directly and indirectly, across Canadian federal, provincial, and contractor environments.

Federal Government Departments and Agencies

All institutions listed under Schedules I, I.1, and II of the Financial Administration Act are required to adopt ITSG-33 as their operational IT security risk management methodology. This includes every major department, from the Canada Revenue Agency to National Defence, as well as agencies like the Canadian Food Inspection Agency and the Canadian Space Agency.

Federal Contractors and Suppliers

Any private organization that processes, stores, or transmits government information, or operates an IT system on behalf of a federal department, must implement ITSG-33. This requirement is operationalized through the Government of Canada's Security Assessment and Authorization (SA&A) process under the TBS Directive on Security Assessment and Authorization. Failure to achieve and maintain SA&A means the organization cannot legally handle Protected information.

Regulated Critical Infrastructure (Indirectly)

While ITSG-33 is a federal government framework, its principles are increasingly referenced by provincial regulators and federal bodies such as OSFI (Office of the Superintendent of Financial Institutions). For example, OSFI's Guideline B-13 (Technology and Cyber Risk Management) expects federally regulated financial institutions (FRFIs) to adopt a risk management framework that aligns with international best practices—and ITSG-33 provides that structure for Canadian entities. Organizations in the energy, telecommunications, and transportation sectors subject to Bill C-26 and the forthcoming Critical Cyber Systems Protection Act (CCSPA) will also find ITSG-33 control profiles directly applicable to their compliance obligations.

Core Components of CCCS ITSG-33: Controls, Profiles, and Risk Management

ITSG-33 is not a single document but a family of publications. Understanding the four main volumes and their interplay is essential for effective implementation.

The first volume (ITSG-33 Part 1) establishes the risk management framework (RMF). It defines a six-step lifecycle approach: (1) Define System Context, (2) Identify Security Requirements, (3) Select Security Controls, (4) Implement Controls, (5) Assess and Authorize, and (6) Monitor Continuously. This maps closely to the NIST RMF (NIST SP 800-37) but is adapted for the Canadian federal context, including specific GC roles such as the Departmental Security Officer (DSO) and IT Security Coordinator.

The second volume (ITSG-33 Part 2) contains the security control catalogue. This catalogue lists over 600 individual controls organized into 18 control families (e.g., Access Control, Audit and Accountability, Configuration Management, Contingency Planning). Each control includes a statement of the security requirement, a description of expected implementation evidence, and references to related controls. The catalogue is mapped to both NIST SP NIST SP 800-53 (rev 4 and rev 5) and ISO/IEC 27002:2013, making it a hybrid standard that facilitates cross-certification.

Security Control Profiles

The third volume (ITSG-33 Part 3) defines security control profiles. These are pre-defined sets of controls and their respective assurance levels tailored to the sensitivity of the information handled. There are three primary profiles:

The fourth volume (ITSG-33 Part 4) provides guidance on developing system security documentation, including the System Security Plan (SSP), Security Risk Assessment (SRA), and Plan of Action and Milestones (POAM).

ITSG-33 vs. NIST SP 800-53 vs. ISO 27001: Key Differences

For organizations operating cross-border or seeking multiple certifications, understanding the comparative posture of ITSG-33 is critical.

Characteristic
CCCS ITSG-33
NIST SP 800-53 (rev 5)
ISO/IEC 27001:2022
Governing Authority
CCCS / TBS – Government of Canada
NIST – U.S. Federal Government
ISO – Private International Standard
Control Count
600+ (mapped from NIST and ISO)
>1100 (including enhancements)
93 Annex A controls + Statement of Applicability
Risk Management Methodology
6-step RMF (aligned with NIST)
NIST RMF (7 steps in SP 800-37)
Plan-Do-Check-Act (PDCA) with ISO 31000 alignment
Primary Use Case
Canadian federal government and contractors
U.S. federal agencies and systems
Commercial organizations and ISMS worldwide
Certification
SA&A (Security Assessment and Authorization)
ATO (Authority to Operate)
ISO 27001 certifiable by accredited bodies
Assurance Levels
Profiles: PA, PB, PC with defined assurance
Impact levels: Low, Moderate, High
Control selection via risk assessment (no fixed profiles)
Cloud Guidance
TBS Cloud Service Provider (CSP) validation with ITSG-33 mapping
ISO 27017 / 27018 for cloud

The key differentiator is that ITSG-33 is explicitly designed for the Government of Canada's policy environment, while NIST SP 800-53 serves U.S. federal needs, and ISO 27001 is a generic auditable standard. Many Canadian contractors implement a hybrid approach—using ITSG-33 for their federal clients while maintaining ISO 27001 for their commercial operations.

Achieving Protected B Readiness with ITSG-33

Protected B is the most common baseline for federal contractors. It applies to information that could cause serious injury—for example, a security breach affecting infrastructure or financial systems, or a privacy breach involving medical history or employment files. To achieve Protected B readiness, an organization must implement the full Protected B control profile from ITSG-33 Part 3 and undergo a formal SA&A review conducted by the contracting department or a qualified third party accredited by the Government of Canada.

The core control families requiring particular attention for Protected B include:

Critical Insight for CISOs: The most common SA&A failure point is not control availability, but control evidence. ITSG-33 requires demonstrated, continuous operation of controls—not just policy documentation. Organizations that do not have automated tools for monitoring their control environment (such as a SIEM with compliance dashboards) consistently fail accreditation audits. A properly configured ThreatHawk SIEM can automate the collection and correlation of audit logs, configuration baselines, and user activity, providing the evidence trail needed for a successful SA&A.

How to Implement ITSG-33 in Your Organization: A Step-by-Step Guide

Implementing ITSG-33 is a multi-phase project. For federal contractors, it is often the single largest security initiative alongside achieving cyber insurance compliance. Below is a phased, enterprise-grade approach:

1

Define System Context and Classification Level

Engage your IT and security architecture teams to document the system boundaries, data flows, and user constituencies. Identify the highest sensitivity of information that will be processed or stored—this determines whether you target the Protected A, B, or C profile. Work with your contracting authority (the Government of Canada department) to formally classify the information assets using the TBS Standard on Security Classification. This initial step, defined in ITSG-33 Part 1, is the foundation for all subsequent control selection.

2

Select Tailored Security Controls

Using the appropriate profile from ITSG-33 Part 3 (e.g., Protected B), begin with the baseline catalogue of controls. Then perform a contextual risk assessment to identify any environment-specific threats (e.g., if your system is hosted in a multi-tenant cloud, additional controls from the System and Communications Protection family may be required). Document all control selections in your System Security Plan (SSP). The SSP must include a justification for any controls that are inherited from a service provider (e.g., cloud infrastructure) versus those that must be implemented by your organization.

3

Implement Controls and Integrate with Existing Technologies

This is the engineering phase. For each selected control, assign a clear owner (e.g., the network team for configuration management controls, the SOC team for incident response controls). Implement technical controls such as endpoint detection and response (EDR), multi-factor authentication (MFA), network segmentation, and encryption. For controls that are procedural (e.g., security awareness training), ensure they are codified in policy and have a compliance measurement mechanism. An automated compliance management platform, such as CyberSilo Compliance Standards Automation, can map controls from your existing toolset directly to the ITSG-33 catalogue, reducing manual overhead.

4

Assess Controls and Conduct Security Assessment and Authorization (SA&A)

Before you can operate a system handling government information, a formal SA&A must be completed. This involves an external or internal assessment team verifying that the implemented controls meet the specified assurance level. The assessment produces a Security Assessment Report (SAR) that identifies any weaknesses or non-conformities. The final Authorization Officer (often the DSO or a delegated senior manager) reviews the SAR, the residual risk, and the Plan of Action and Milestones (POAM) before issuing an Interim or Full Authorization to Operate (ATO). This must be renewed periodically based on the system risk level (typically annually for Protected B).

5

Continuous Monitoring and Improvement

ITSG-33 is not a one-time project. The framework mandates continuous monitoring of all security controls. This includes automated asset inventory, vulnerability scanning, log monitoring, and periodic compliance reviews. Organizations should establish a Security Operations Center (SOC) capability—whether in-house or managed—to detect and respond to incidents in real time. A SIEM platform like ThreatHawk SIEM can serve as the central nervous system for this continuous monitoring, ingesting logs from all systems, correlating events against ITSG-33 control baselines, and alerting the team to deviations.

Common ITSG-33 Compliance Challenges and How to Avoid Them

Even experienced security teams encounter pitfalls when implementing ITSG-33. Understanding these in advance can save months of rework.

How CyberSilo Supports Your ITSG-33 Compliance Journey

Navigating CCCS ITSG-33 requires a combination of deep regulatory knowledge, technical automation, and sustained operational capability. CyberSilo provides an integrated set of solutions designed specifically for Canadian federal contractors and departments.

Our Compliance Standards Automation offering allows you to map your existing security tools and configurations to the ITSG-33 control catalogue in real time. Rather than building spreadsheets and manual evidence packets, your team can generate a System Security Plan (SSP) and Security Assessment Report (SAR) with a few clicks, directly from your live environment. This reduces the preparation time for an SA&A from months to days and ensures your evidence is always current.

For continuous monitoring, our ThreatHawk SIEM is pre-configured with correlation rules covering ITSG-33 control families—Audit and Accountability, Access Control, Incident Response, and more. It provides real-time dashboards for your Security Operations Center (SOC) and alerts when controls deviate from their baseline. Because ThreatHawk is built to Canadian data residency requirements (sovereign cloud options in Toronto and Montreal), it is compliant with the TBS Standard on Data Residency for cloud services.

Ready to Accelerate Your ITSG-33 Compliance and Achieve Protected B Readiness?

Whether you are preparing for your first SA&A or need to streamline your existing compliance program, CyberSilo's compliance and SIEM experts can help. We understand the nuances of the CCCS framework and the requirements for Protected B ATOs.

Frequently Asked Questions About CCCS ITSG-33

What is the difference between ITSG-33 and the CCCS Baseline Controls?

The CCCS Baseline Controls are a subset of controls derived from ITSG-33. While ITSG-33 is a comprehensive risk management framework, the Baseline Controls are a minimum-security control set for all Government of Canada systems. ITSG-33 gives you the method to select and implement controls; the Baseline Controls define the floor that every system must meet irrespective of its risk profile.

How long does an ITSG-33 SA&A take?

The timeline varies significantly based on system complexity and the preparedness of the organization. For a simple, single-system deployment already using modern security tools, an SA&A can take 3 to 6 months. For a complex enterprise environment that requires significant remediation (e.g., adding MFA, network segmentation, logging infrastructure), the timeline can extend to 12 to 18 months. The key accelerant is having an automation platform in place to produce evidence continuously.

Can a system be authorized under ITSG-33 for multiple departments?

Yes. The Government of Canada is moving toward a model of shared and reciprocal authorizations through the Treasury Board's direction. If one department issues you an ATO, other departments may accept it if the system scope and risk context are the same. However, in practice, many departments still require a separate review or a re-issuance of the ATO. CyberSilo can help you build a system security package that is "portable" across departments by adhering to the most stringent version of the control profiles.

The Future of Canadian Federal Cybersecurity: Bill C-26, OSFI B-13, and ITSG-33

Canadian cybersecurity regulation is evolving rapidly. The introduction of Bill C-26 (which will create the Critical Cyber Systems Protection Act, or CCSPA) and the strengthening of OSFI Guideline B-13 for banks and insurers are pushing ITSG-33 principles beyond federal departments into the broader critical infrastructure security ecosystem. FRFIs regulated by OSFI are now expected to demonstrate a risk management framework comparable to ITSG-33, even if they do not directly contract with the government. Similarly, organizations in the energy, telecom, and transportation sectors regulated under CCSPA will likely be required to adopt a similar control baseline.

This convergence means that investing in ITSG-33 compliance today provides a strategic advantage for tomorrow's broader regulatory landscape. Organizations that build their security program around the CCCS framework will find it easier to comply with OSFI B-13, CCSPA, and Quebec Law 25 (which also mandates risk-based security practices).

Our Conclusion & Recommendation

CCCS ITSG-33 is the definitive cybersecurity framework for any organization that works with the Government of Canada. It is not a voluntary standard but an operational requirement enforced through the SA&A process. Organizations that underestimate the effort required to achieve and maintain Protected B accreditation often face costly delays in contract awards or, worse, security incidents that compromise the trust placed in them by federal partners.

Our recommendation is clear: treat ITSG-33 compliance as a continuous engineering program, not a one-time audit. Invest in automation platforms that map controls, generate evidence in real time, and monitor your environment for deviations. CyberSilo's Compliance Standards Automation and ThreatHawk SIEM are engineered to reduce the burden of ITSG-33 by automating the most labour-intensive parts of the process—evidence collection, control mapping, and continuous monitoring. Whether you are beginning your first SA&A or seeking to modernize an existing one, our team can help you achieve and maintain the security posture required by the CCCS.

Get an ITSG-33 Control Review

Our experts can assess your current posture against the Protected B profile and provide a clear remediation roadmap. Contact us today to schedule your review.