Overview
The Canadian Centre for Cyber Security published Baseline cyber security controls for small and medium organizations to give smaller Canadian organizations a short, realistic security program. It applies the 80/20 rule. The idea is to get about 80% of the benefit from 20% of the effort by focusing on the controls that stop the most common attacks, such as phishing, ransomware, and account takeover. The current version is 1.2, dated February 18, 2020. It's aimed at organizations that fit the federal definition of small or medium, meaning fewer than 500 employees.
The document opens with organizational controls. An organization confirms it fits the size range, decides which IT systems are in scope, assesses the harm a compromise could cause, identifies its main threats, and names someone responsible for security. Then come 13 baseline controls, numbered BC.1 to BC.13. They cover incident response, patching, anti-malware, secure configuration, strong authentication, awareness training, backups, mobile devices, perimeter defences, cloud and outsourced IT, websites, access control, and portable media. Each control comes with practical guidance and links to more detailed Cyber Centre publications.
The baseline is guidance, not a certification. Its content was turned into a National Standard of Canada, first CAN/CIOSC 104:2021 and now CAN/DGSI 104:2021 / Rev 1:2024, which SCC-accredited bodies can certify under CyberSecure Canada. The Cyber Centre also publishes shorter companions, including Top measures to enhance cyber security for small and medium organizations (ITSAP.10.035, February 2024) and Foundational cyber security actions for small organizations (ITSAP.10.300, May 2023).
Who it applies to in Canada
Small and medium organizations in Canada, defined as those with fewer than 500 employees, that want a practical starting set of cyber security controls.
It's free federal guidance written for Canadian businesses and non-profits. The national standard behind CyberSecure Canada certification was built from it, and its controls overlap heavily with CPCSC Level 1.
Controls at a glance
The document sets 5 organizational controls (OC.1 to OC.5) and then 13 baseline controls (BC.1 to BC.13).
Organizational controls (OC.1 to OC.5)
- Confirm the organization has fewer than 500 employees
- Define in-scope IT systems and document exclusions
- Assess harm to confidentiality, integrity, and availability
- Identify the main cyber threats
- Assign security leadership and commit to improvement
Respond and recover (BC.1, BC.7)
- Have an incident response plan
- Include recovery procedures in the plan
- Back up critical data
- Encrypt backups and store copies offsite
Keep systems clean (BC.2, BC.3, BC.4)
- Turn on automatic patching or manage vulnerabilities
- Run auto-updating anti-malware
- Use software firewalls on hosts
- Change default passwords
- Disable unneeded features and services
People and accounts (BC.5, BC.6, BC.12)
- Use two-factor authentication for important accounts
- Set sensible password policies
- Train staff in cyber security awareness
- Give users only the access they need
Devices and network (BC.8, BC.9, BC.13)
- Secure mobile devices and separate work data
- Use perimeter firewalls and DNS filtering
- Use VPNs for remote access
- Secure Wi-Fi networks
- Allow only encrypted, organization-owned portable media
Cloud and web (BC.10, BC.11)
- Ask cloud providers for SOC 3 or similar reports
- Choose providers that meet your security needs
- Build and run websites to OWASP guidance
Certification and assessment
Organizations measure themselves against the 13 controls and close gaps over time. Those wanting third-party proof can seek CyberSecure Canada certification to the related national standard.
Dates to know
- 2020-02-18
- Version 1.2 of the baseline controls published
Resources
Official texts and free tools for CCCS baseline controls. Links open the publisher’s site.
- Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Security
- CAN/DGSI 104, Baseline cyber security controls for small and medium organizations, Digital Governance Council
- Top measures to enhance cyber security for small and medium organizations (ITSAP.10.035), Canadian Centre for Cyber Securityguidance
- Foundational cyber security actions for small organizations (ITSAP.10.300), Canadian Centre for Cyber Securityguidance
Need help? Browse the directory or read the guides.
References
- Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Security
- Top measures to enhance cyber security for small and medium organizations (ITSAP.10.035), Canadian Centre for Cyber Security
- Foundational cyber security actions for small organizations (ITSAP.10.300), Canadian Centre for Cyber Security
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.