ITSP.10.171 is the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171 Revision 3, and it is the technical control set underneath the Canadian Program for Cyber Security Certification (CPCSC). If your business sells into the Canadian defence supply chain, or supports a prime contractor that does, ITSP.10.171 is the standard your systems will eventually be assessed against, whether you self-attest at Level 1 or go through a third-party assessment at Level 2.
What Is ITSP.10.171?
ITSP.10.171 is a guidance document published by the Canadian Centre for Cyber Security (part of the Communications Security Establishment). It defines the security controls required to protect Controlled Unclassified Information, referred to in the Canadian context as Protected B-equivalent information, when it lives on non-federal systems. In plain terms: if you are a supplier, subcontractor, or vendor handling defence-related data that is not classified but is still sensitive, ITSP.10.171 tells you what security controls you need in place.
The document is not written from scratch. It is Canada's tailored version of an American framework, which matters a lot for how you approach compliance.
How ITSP.10.171 Relates to NIST SP 800-171
ITSP.10.171 is built directly on NIST SP 800-171 Revision 3, the U.S. standard that underpins the Cybersecurity Maturity Model Certification (CMMC) program used by the U.S. Department of Defense. The Canadian government did not invent a parallel set of controls. It adapted the American framework, adjusting terminology, references, and a handful of implementation details to fit Canadian legal and regulatory context, then published it as domestic guidance.
For a Canadian SMB, this has a practical upside. If you have already looked at CMMC or NIST SP 800-171 because of a U.S. defence contract, you are not starting from zero. The control families are the same: access control, incident response, configuration management, media protection, system and communications protection, and so on. What changes is the certification pathway, the assessing body, and how the requirement gets enforced through Canadian federal procurement rather than U.S. Department of Defense contracts.
How ITSP.10.171 Maps to CPCSC
The Canadian Program for Cyber Security Certification is the compliance program that operationalizes ITSP.10.171. CPCSC has two levels, and the level your business needs depends on the sensitivity of the information you handle under a given Department of National Defence contract or subcontract.
- CPCSC Level 1 covers 13 controls and is self-assessed. It became available to self-assess in April 2026, and DND has signalled it will become mandatory for select contract streams starting summer 2026.
- CPCSC Level 2 covers the full 97 controls drawn from ITSP.10.171 and requires a third-party assessment. It is scheduled to become mandatory in April 2027.
In short: ITSP.10.171 is the control catalogue, and CPCSC is the certification scheme that tells you which subset of that catalogue applies to your business and how you prove it. Most SMBs entering the defence supply chain for the first time will start at Level 1. We break down exactly what those 13 controls require and how to prepare for self-assessment in our CPCSC Level 1 guide.
Why This Matters Now for Canadian SMBs
The timeline is tighter than most subcontractors realize. If your business currently supplies parts, engineering services, IT support, or logistics to a defence prime, or you expect to bid on DND work in the next two years, the self-assessment window is already open. Contracts referencing CPCSC Level 1 are expected to start appearing in solicitations through the second half of 2026, and primes are already asking their supply chains to demonstrate readiness ahead of that.
Waiting until a contract explicitly requires certification is a common mistake. Getting 13 controls in place, documented, and self-assessed takes real time, especially for SMBs without a dedicated security function. Level 2's 97 controls take considerably longer and involve an external assessor, so businesses expecting to handle higher-sensitivity information should start gap analysis well before the April 2027 deadline, not after.
What the 13 Level 1 Controls Generally Require
While the full detail lives in the standard itself, Level 1 controls under ITSP.10.171 focus on foundational cyber hygiene rather than advanced controls. Expect requirements touching on:
- Limiting system access to authorized users and devices
- Identifying and authenticating users before granting access
- Sanitizing or destroying media containing sensitive information before disposal or reuse
- Controlling and monitoring remote access sessions
- Applying basic physical protections to systems and facilities
These are the same fundamentals most SMBs already touch on in a SOC 2 or ISO 27001 program, which is good news if you have prior compliance work to build on. It is not a reason to assume you are automatically covered. CPCSC self-assessment requires you to map your actual environment against each control and document the evidence, not just assert general good practice.
Where ITSP.10.171 Fits Alongside Other Canadian Compliance Requirements
ITSP.10.171 and CPCSC sit in the defence-specific lane, distinct from broader Canadian privacy and security obligations like PIPEDA or Quebec's Law 25. A company can be fully PIPEDA-compliant and still fail a CPCSC Level 1 self-assessment, because the two frameworks protect different things: PIPEDA governs personal information, while ITSP.10.171 governs controlled information tied to defence contracts. If your business operates across both worlds, for example a Waterloo-based manufacturer with both consumer data obligations and a DND subcontract, you need a compliance program that addresses each on its own terms rather than assuming overlap will cover the gaps.
How to Prepare for ITSP.10.171 and CPCSC
The practical starting point is a gap assessment: map your current environment, policies, and technical controls against the 13 Level 1 requirements, identify what is missing, and prioritize fixes by how long they take to implement. Access control and media sanitization policies can often be closed quickly. Logging, remote access monitoring, and physical security controls sometimes require more lead time, particularly for businesses running mixed on-premises and cloud environments. traztech works with Canadian SMBs across Toronto, Ottawa, Waterloo, Vancouver, Calgary, and Montreal to run this gap assessment, build the missing controls, and prepare for CPCSC self-assessment or third-party audit. Our broader compliance readiness work covers ITSP.10.171 alongside SOC 2 and other frameworks Canadian businesses are asked to demonstrate, so you are not running separate programs for every contract requirement.
If you supply, or plan to supply, the Canadian defence sector and need to understand where you stand against ITSP.10.171 and CPCSC, contact traztech to book a readiness conversation.