Decoding ITSP.10.171
BY ARNOLD VILLENEUVE

When the Government of Canada officially launched the Canadian Program for Cyber Security Certification (CPCSC) in March 2025, it did more than announce a new policy—it ignited a long-overdue transformation in how cyber security is operationalized across the Canadian Defence Industrial Base (DIB) contractors and suppliers. In our previous article, “CPCSC Overview” we introduced the structure, the goals, and the phased roadmap. But now, as the dust settles and implementation begins in earnest, one thing is abundantly clear: the ITSP.10.171 security framework is the cornerstone of the entire program.
Released by the Canadian Centre for Cyber Security (CCCS), ITSP.10.171 is the definitive set of security controls that must be met to achieve CPCSC Level 2 certification. While Level 1 remains a self-attestation process, Level 2—now actively piloted—requires formal third-party assessment. And every requirement, every control, every assessor checklist, maps directly back to ITSP.10.171.
If you’re a supplier, subcontractor, or service provider handling sensitive government information, this is the document that will determine your eligibility to win defence contracts in Canada moving forward.
WHY ITSP.10.171 MATTERS
Let’s be blunt: if your organization can’t show that it meets the requirements in ITSP.10.171, you will be excluded from upcoming Level 2 and Level 3 defence contracts. It doesn’t matter how good your product is. It doesn’t matter how long you’ve served the government. Without conformance to ITSP.10.171, your business is simply not cyber-resilient enough to be trusted with Controlled Information (CI).
This isn’t just bureaucracy—it’s national security. With our allies already implementing stringent frameworks like the US CMMC, the CPCSC ensures Canada stays interoperable and credible on the global stage. And ITSP.10.171 is the Canadian equivalent to the US NIST SP 800-171 standard. If you’re a Canadian supplier doing cross-border work, understanding both frameworks is now a core competency, not a bonus skill.
WHAT’S INSIDE?
ITSP.10.171 outlines a comprehensive suite of over 100 cyber security requirements, categorized into families such as Access Control, Incident Response, Media Protection, and Risk Assessment. These aren’t abstract ideals. Each control in ITSP.10.171 contains tangible requirements—what must be documented, implemented, and verifiable. There is no room for ambiguity.
Assessors won’t just be checking for policies on a shelf. They’ll be examining whether your technical configurations, SOPs, and staff behaviours align with what the standard demands. If you claim to implement multi-factor authentication, be ready to show logs, screenshots, and configuration settings. If you say you conduct regular security awareness training, have sign-in sheets and course content ready to review.
PREPARING FOR CERTIFICATION
Now that ITSP.10.171 has been released, every company in the Canadian DIB has their homework assignment. You need to: • Conduct a Gap Analysis using ITSP.10.171 as your checklist; • Build a System Security Plan (SSP) that maps how your organization meets each requirement; • Prepare a Plan of Action and Milestones (POA&M) for controls not yet fully implemented; • Engage with cyber security consultants, instructors, or internal champions who understand how to translate policy into evidence.
Organizations that wait for PSPC to mandate certification at the contract level will already be too late. The smart ones are preparing now—integrating ITSP.10.171 into procurement readiness, IT project planning, and employee training.
WHY TIMING MATTERS
Let’s not forget what Phase 2 of CPCSC implementation entails. By Fall 2025, Level 1 certification becomes a requirement for some defence contracts, and Level 2 pilot assessments begin. This means that third-party assessor organizations are already being trained and accredited to conduct assessments based on ITSP.10.171.
It also means that PSPC will be evaluating the readiness of Canadian industry as it gears up to mandate Level 2 certification in early 2026. In short, the clock is ticking—and ITSP.10.171 is the instruction manual for how to stay in the game.
FINAL THOUGHTS
The release of ITSP.10.171 represents a watershed moment for cyber security in Canada. It sets the bar for what it means to be a trusted partner in the defence supply chain. It also signals that future RFPs will not just favour—but require—organizations that can demonstrate robust cyber hygiene and resilience.
This isn’t theoretical. It’s happening now. And ITSP.10.171 isn’t just a document—it’s your roadmap to cyber security compliance, business continuity, and competitive advantage in a digitally hostile world.
If you’re not already studying this document and preparing your organization, you’re not just behind—you’re exposed.
Arnold Villeneuve is Director of Achieva Tech Incorporated. For more information, visit, www.achievatech.com. The views expressed here are his own and do not necessarily represent a CDR editorial position.

