Overview
Federal cloud security for Protected B data has 3 parts. The first is a control profile. The original Government of Canada Security Control Profile for Cloud-based GC Services, dated July 26, 2016, defined a Protected B, medium integrity, medium availability (PBMM) baseline. Its list of controls has been replaced by the Canadian Centre for Cyber Security's Medium cloud control profile, published as Annex B of ITSP.50.103, Guidance on the security categorization of cloud-based services (May 2020). ITSP.50.103 also has a Low profile and asks departments to contact the Cyber Centre about high-category needs.
The second part is the Cyber Centre's Cloud Service Provider Information Technology Security Assessment Program. It assesses public cloud services against 3 baselines, Cloud Low for SaaS up to Protected A, Cloud Medium for up to Protected B with medium injury, and Cloud High for up to Protected B with high injury. Enterprise assessments cover services procured by Shared Services Canada or PSPC for many departments, and departments run local assessments for single-use SaaS. The assessment process (ITSM.50.100) relies on existing evidence such as FedRAMP system security plans, SOC 2 Type II reports, and ISO/IEC 27001 and 27017 reports. The Cyber Centre now also uses third-party assessment organizations (3PAOs). Vendors pay for them. For now they must hold FedRAMP accreditation, and the Cyber Centre is working with the Standards Council of Canada on a Canadian 3PAO accreditation program based on A2LA R311.
The third part is the GC Cloud Guardrails, a minimum set of configurations that departments must put in place within the first 30 business days of getting access to a cloud account. Departments own this step. Treasury Board updated the guardrails in October 2024 under Appendix G of the Directive on Service and Digital and extended them to solutions procured through PSPC. For a Canadian SaaS vendor, this means a security assessment before or during procurement, evidence mapped to the Medium profile, and a customer who will check data location and guardrail settings.
Who it applies to in Canada
Federal departments and agencies that use cloud services for Protected B, medium integrity, medium availability information, and the cloud and SaaS providers that sell those services to them.
These are the Government of Canada's own rules for cloud adoption. Any Canadian or foreign SaaS, PaaS, or IaaS provider that wants federal Protected B business has to fit the Cyber Centre's cloud profiles and assessment process.
Controls at a glance
Requirements are organized as a categorization method, cloud control profiles, a provider assessment process, and guardrails that departments apply to each cloud tenancy.
Security categorization (ITSP.50.103)
- Build an injury assessment table
- Inventory business processes and information assets
- Assess injury to confidentiality, integrity, and availability
- Group activities into business domains
- Pick a cloud profile and deployment model to match
Cloud control profiles
- Cloud Low for SaaS up to Protected A
- Cloud Medium for up to Protected B, medium injury
- Cloud High for up to Protected B, high injury
- Medium profile replaces the 2016 PBMM control list
- Controls split between provider and department
Provider assessment phases (ITSM.50.100)
- Confirm attestation documents
- Review detailed evidence
- Issue an initial report
- Issue a final report to provider and departments
- Re-evaluate some services periodically
Accepted evidence and assessors
- FedRAMP system security plans
- AICPA SOC 2 Type II reports
- ISO/IEC 27001 and ISO/IEC 27017 reports
- Vendor-funded 3PAOs, currently FedRAMP-accredited
- Canadian 3PAO accreditation with SCC in development
GC Cloud Guardrails 1 to 7
- Protect user accounts and identities
- Manage access
- Secure endpoints
- Set up enterprise monitoring accounts
- Control data location
- Protect data at rest
- Protect data in transit
GC Cloud Guardrails 8 to 13
- Segment and separate
- Use network security services
- Use cyber defence services
- Enable logging and monitoring
- Configure cloud marketplaces
- Plan for continuity
Departments implement and report within 30 business days of cloud account access.
Certification and assessment
The provider supplies third-party evidence such as SOC 2 Type II, ISO/IEC 27001 and 27017 reports, or FedRAMP packages, and a 3PAO validates it against the relevant cloud baseline. The Cyber Centre issues assessment reports to the provider and the federal clients, and each department then makes its own authorization decision.
Dates to know
- 2016-07-26
- Original GC Security Control Profile for Cloud-based GC Services (PBMM) published
- 2018-10-01
- Cloud service provider IT security assessment process (ITSM.50.100) takes effect
- 2024-10-08
- Updated GC Cloud Guardrails published in Appendix G of the Directive on Service and Digital
Resources
Official texts and free tools for GC cloud Protected B. Links open the publisher’s site.
- Cloud Security Assessment Program, Canadian Centre for Cyber Security
- Guidance on the security categorization of cloud-based services (ITSP.50.103), Canadian Centre for Cyber Security
- Cloud service provider information technology security assessment process (ITSM.50.100), Canadian Centre for Cyber Security
- Changes to the Policy on Service and Digital policy instrument, GC Cloud Guardrails, Government of Canada
- GC Cloud Guardrails repository, Government of Canada (canada-ca on GitHub)tool
- Government of Canada Security Control Profile for Cloud-based GC Services, Government of Canadaguidance
Need help? Browse the directory or read the guides.
References
- Cloud Security Assessment Program, Canadian Centre for Cyber Security
- Government of Canada Security Control Profile for Cloud-based GC Services, Government of Canada
- Cloud service provider information technology security assessment process (ITSM.50.100), Canadian Centre for Cyber Security
- Changes to the Policy on Service and Digital policy instrument, GC Cloud Guardrails, Government of Canada
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.