home / frameworks / nist-csf / using-nist-csf-in-canada

// NIST CSF hub

Using the NIST CSF in Canada

How Canadian regulators, critical infrastructure programs, and organizations reference the NIST CSF, and how it maps to Canadian Centre for Cyber Security guidance.

Why a U.S. framework appears in Canada

The CSF is voluntary in the United States and has no legal status in Canada. It still turns up often in Canadian organizations. The most common route is commercial. U.S. customers, insurers, and partners ask suppliers to describe their security program in CSF terms, and many vendor risk questionnaires are organized by its functions.

The second route is through Canadian bodies that have adopted or mapped to it. Because the CSF describes outcomes rather than controls, it works as a common language between Canadian guidance, international standards, and U.S. requirements.

Canadian Centre for Cyber Security

The Canadian Centre for Cyber Security published its Cross-Sector Cyber Security Readiness Goals Toolkit in October 2024. It sets out 36 readiness goals for owners and operators of Canadian critical infrastructure in any sector. That's a short list. Each goal is mapped to relevant NIST CSF 2.0 subcategories, so an organization already using the CSF can see where the Canadian goals fit.

The Cyber Centre's Baseline cyber security controls for small and medium organizations take a different approach. They're practical controls for organizations with fewer than 500 employees. The list is short. Examples include incident response planning, patching, strong authentication, and backups. The baseline document describes ITSG-33 Profile 1 as the Canadian specification of controls equivalent to the NIST CSF or ISO/IEC 27001. Smaller organizations often start with the baseline controls and later use the CSF to organize a fuller program.

Regulators and sector programs

Ontario's electricity sector is the clearest example. The Ontario Energy Board requires licensed electricity transmitters and distributors to assess and report their cyber security maturity using the Ontario Cyber Security Framework. The framework document, released in December 2017, says it was developed based on the NIST Cybersecurity Framework, with influences from the U.S. Department of Energy's C2M2 model and Privacy by Design. The OEB's Ontario Cyber Security Standard, now at version 3.1 (November 2025), sets the assessment and reporting rules, including independent assessments.

Federally regulated financial institutions follow OSFI Guideline B-13 on technology and cyber risk, which sets its own expectations rather than adopting the CSF. It doesn't name one framework. Many institutions still use the CSF internally to organize their programs and map them to B-13. The same is true for organizations under provincial privacy laws, which require reasonable safeguards without naming a framework.

Mapping the CSF to Canadian guidance

A simple mapping exercise helps Canadian organizations avoid running parallel programs. The CSF functions sit at the top. Under each subcategory, the organization records the Canadian control that meets it, for example an ITSG-33 control, a Cyber Centre baseline control, or a clause of OSFI B-13. It then adds the ISO/IEC 27001 Annex A control or SP 800-53 control used for U.S. or international customers.

NIST's informative references and the CSF 2.0 Reference Tool make the international side of this easier. The Canadian side usually has to be built by hand, starting from the Cyber Centre's own mapping in the readiness goals toolkit.

  • Use readiness goals to set priorities for critical infrastructure
  • Use baseline controls for small and medium organizations
  • Use ITSG-33 for Government of Canada systems and suppliers
  • Use the CSF as the reporting layer for U.S. customers

Certification and accreditation

There is no CSF certification in Canada or the United States, and the Standards Council of Canada does not accredit certification bodies for it. Organizations that need a certificate usually pair the CSF with ISO/IEC 27001 certification, a SOC 2 report, or the CyberSecure Canada program for small and medium organizations.

Resources

All NIST CSF resources

References

  1. Cross-Sector Cyber Security Readiness Goals Toolkit, Canadian Centre for Cyber Security
  2. Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Security
  3. Ontario Cyber Security Framework (December 2017), Ontario Energy Board
  4. Ontario Cyber Security Standard, Ontario Energy Board