Framework · Last verified
Cloud Service Provider (CSP) Information Technology Security (ITS) Assessment Program
The Cyber Centre's CSP ITS Assessment Program assesses cloud services for GC procurement up to Protected B — the output is a report, not a certificate. Departments "can leverage" the results under Treasury Board's SPIN 2017-01, but the assessment is one accepted input, not a mandatory gate.
- Class
- Framework
- Owner
- Canadian Centre for Cyber Security (Cyber Centre / CCCS)
- Last verified
What it is
The program's full name, in the Cyber Centre's own words, is the "Cloud Service Provider (CSP) Information Technology Security (ITS) Assessment Program"; the program page's title is "Cloud Security Assessment Program". The Cyber Centre states its scope directly: "The program is intended for government services hosted on commercial cloud providers with a maximum confidentiality of Protected B. It is not intended to assess any classified or national security systems."
The assessment runs against three baselines, each defined verbatim by the Cyber Centre: "Cloud Low (SaaS only): for cloud services processing up to Protected A level information"; "Cloud Medium: for cloud services processing up to Protected B level information, and where there is a medium level of injury"; "Cloud High: for cloud services processing up to Protected B level information, and where there is a high level of injury." A term used in industry compliance pages, "CCCS Medium", and the earlier profile term "PBMM" (Protected B, Medium Integrity, Medium Availability, from ITSM.50.100, 2018) do not appear as the current program's own naming — the program page uses the Cloud Low/Medium/High baseline names.
The program's process document, ITSM.50.100, states its objective: "The objective of the CSP ITS Assessment Program is to assist Government of Canada (GC) departments and agencies in their evaluation of CSP services being procured for use by the GC." The control basis for the assessment is the GC's own selected controls in "ITSG-33 IT Security Risk Management: A Lifecycle Approach, Annex 3 – Security Control Catalogue."
The output is explicitly a report, not a certificate or authorization: "The Cyber Centre issues a comprehensive assessment report, providing departments with clear, actionable results to guide procurement and implementation decisions."
Who owns it
The program is run by the Canadian Centre for Cyber Security (the Cyber Centre / CCCS), which assesses CSPs itself and issues centralized, reusable reports — it does not delegate assessment to third-party assessment organizations as FedRAMP does with its 3PAOs. The Cyber Centre does, however, use existing third-party evidence where available: ITSM.50.100 states, "The CCCS CSP ITS assessment process uses evidence from these and other third party assessed attestations wherever possible."
Who assesses it
The Cyber Centre performs the assessment centrally. Two intake streams exist, in the program's own words: "Enterprise-level assessments are conducted for enterprise services procured by Shared Services Canada (SSC) and Public Services Procurement Canada (PSPC) on behalf of the GC, such as Microsoft 365"; and "Local (departmental) assessments cover single-use SaaS CSPs procured by individual departments under their own authorities to meet specific needs, such as supply arrangements." A fixed re-assessment cycle (e.g., annual) is not defined in the sources reviewed as of 31 August 2026 — ITSM.50.100 states only that some services "will need to be re-evaluated periodically" and that "CCCS will provide recommendations to the GC client as to how often their public cloud services should be reassessed."
Levels
- Cloud Low —
"Cloud Low (SaaS only): for cloud services processing up to Protected A level information." (cyber.gc.ca, 31 August 2026)
- Cloud Medium —
"Cloud Medium: for cloud services processing up to Protected B level information, and where there is a medium level of injury." (cyber.gc.ca, 31 August 2026)
- Cloud High —
"Cloud High: for cloud services processing up to Protected B level information, and where there is a high level of injury." (cyber.gc.ca, 31 August 2026)
Who asks for it
The program "assists Government of Canada (GC) departments and agencies" evaluating cloud services procured for GC use — it is not a general-market requirement. Whether it functions as a hard precondition for GC cloud procurement was directly tested against the binding policy instrument: Treasury Board's Direction on the Secure Use of Commercial Cloud Services (SPIN 2017-01, effective 1 November 2017) states, in §6.1.4, "Departments that are seeking to consume cloud services can leverage the results of GC-assessed CSPs … to support risk-based decisions" — permissive language, not a requirement to use this program specifically. The one mandatory element in the same section is a department's own obligation: "Departments must perform security assessment and authorization of their information systems or services before approving them for operation." SPIN §6.1.3 lists CCCS assessments as one of several accepted forms of third-party assurance a department may leverage for that obligation, alongside ISO/IEC 27001, 27017, 27018, FedRAMP, PCI-DSS, CSA STAR and AICPA SOC reports. SPIN applies to "all departments within the meaning of Schedules I, I.1, II, IV and V of the Financial Administration Act unless excluded by specific acts, regulations or orders-in-council." No publicly accessible registry of GC-assessed CSPs was found in the sources reviewed as of 31 August 2026.
Sources
- Canadian Centre for Cyber Security — Cloud Security Assessment Program (scheme owner) ↗ — accessed
- Canadian Centre for Cyber Security — ITSM.50.100, Cloud service provider information technology security assessment process (1 October 2018) ↗ — accessed
- Canadian Centre for Cyber Security — ITSP.50.105, Guidance on cloud security assessment and authorization (May 2020) ↗ — accessed
- Treasury Board of Canada Secretariat — Direction on the Secure Use of Commercial Cloud Services: Security Policy Implementation Notice (SPIN 2017-01), effective 1 November 2017, modified 23 June 2022 (opened in a real browser) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.