Framework · Last verified

Cloud Service Provider (CSP) Information Technology Security (ITS) Assessment Program

The Cyber Centre's CSP ITS Assessment Program assesses cloud services for GC procurement up to Protected B — the output is a report, not a certificate. Departments "can leverage" the results under Treasury Board's SPIN 2017-01, but the assessment is one accepted input, not a mandatory gate.

Class
Framework
Owner
Canadian Centre for Cyber Security (Cyber Centre / CCCS)
Last verified

What it is

The program's full name, in the Cyber Centre's own words, is the "Cloud Service Provider (CSP) Information Technology Security (ITS) Assessment Program"; the program page's title is "Cloud Security Assessment Program". The Cyber Centre states its scope directly: "The program is intended for government services hosted on commercial cloud providers with a maximum confidentiality of Protected B. It is not intended to assess any classified or national security systems."

The assessment runs against three baselines, each defined verbatim by the Cyber Centre: "Cloud Low (SaaS only): for cloud services processing up to Protected A level information"; "Cloud Medium: for cloud services processing up to Protected B level information, and where there is a medium level of injury"; "Cloud High: for cloud services processing up to Protected B level information, and where there is a high level of injury." A term used in industry compliance pages, "CCCS Medium", and the earlier profile term "PBMM" (Protected B, Medium Integrity, Medium Availability, from ITSM.50.100, 2018) do not appear as the current program's own naming — the program page uses the Cloud Low/Medium/High baseline names.

The program's process document, ITSM.50.100, states its objective: "The objective of the CSP ITS Assessment Program is to assist Government of Canada (GC) departments and agencies in their evaluation of CSP services being procured for use by the GC." The control basis for the assessment is the GC's own selected controls in "ITSG-33 IT Security Risk Management: A Lifecycle Approach, Annex 3 – Security Control Catalogue."

The output is explicitly a report, not a certificate or authorization: "The Cyber Centre issues a comprehensive assessment report, providing departments with clear, actionable results to guide procurement and implementation decisions."

Who owns it

The program is run by the Canadian Centre for Cyber Security (the Cyber Centre / CCCS), which assesses CSPs itself and issues centralized, reusable reports — it does not delegate assessment to third-party assessment organizations as FedRAMP does with its 3PAOs. The Cyber Centre does, however, use existing third-party evidence where available: ITSM.50.100 states, "The CCCS CSP ITS assessment process uses evidence from these and other third party assessed attestations wherever possible."

Who assesses it

The Cyber Centre performs the assessment centrally. Two intake streams exist, in the program's own words: "Enterprise-level assessments are conducted for enterprise services procured by Shared Services Canada (SSC) and Public Services Procurement Canada (PSPC) on behalf of the GC, such as Microsoft 365"; and "Local (departmental) assessments cover single-use SaaS CSPs procured by individual departments under their own authorities to meet specific needs, such as supply arrangements." A fixed re-assessment cycle (e.g., annual) is not defined in the sources reviewed as of 31 August 2026 — ITSM.50.100 states only that some services "will need to be re-evaluated periodically" and that "CCCS will provide recommendations to the GC client as to how often their public cloud services should be reassessed."

Levels

  • Cloud Low — "Cloud Low (SaaS only): for cloud services processing up to Protected A level information." (cyber.gc.ca, 31 August 2026)
  • Cloud Medium — "Cloud Medium: for cloud services processing up to Protected B level information, and where there is a medium level of injury." (cyber.gc.ca, 31 August 2026)
  • Cloud High — "Cloud High: for cloud services processing up to Protected B level information, and where there is a high level of injury." (cyber.gc.ca, 31 August 2026)

Who asks for it

The program "assists Government of Canada (GC) departments and agencies" evaluating cloud services procured for GC use — it is not a general-market requirement. Whether it functions as a hard precondition for GC cloud procurement was directly tested against the binding policy instrument: Treasury Board's Direction on the Secure Use of Commercial Cloud Services (SPIN 2017-01, effective 1 November 2017) states, in §6.1.4, "Departments that are seeking to consume cloud services can leverage the results of GC-assessed CSPs … to support risk-based decisions" — permissive language, not a requirement to use this program specifically. The one mandatory element in the same section is a department's own obligation: "Departments must perform security assessment and authorization of their information systems or services before approving them for operation." SPIN §6.1.3 lists CCCS assessments as one of several accepted forms of third-party assurance a department may leverage for that obligation, alongside ISO/IEC 27001, 27017, 27018, FedRAMP, PCI-DSS, CSA STAR and AICPA SOC reports. SPIN applies to "all departments within the meaning of Schedules I, I.1, II, IV and V of the Financial Administration Act unless excluded by specific acts, regulations or orders-in-council." No publicly accessible registry of GC-assessed CSPs was found in the sources reviewed as of 31 August 2026.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Cloud Service Provider (CSP) Information Technology Security (ITS) Assessment Program." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/cccs-cloud

All frameworks & audits →