The Cyber Centre’s Cloud Service Provider (CSP) Information Technology Security (ITS) Assessment Program assists Government of Canada (GC) departments and agencies in their evaluation of cloud services being procured for use by the GC. It aims to equip them with the expertise, frameworks and tools they need to safeguard systems, reduce risk and build resilience against evolving cyber threats. The goal is to ensure secure, consistent and standardized cloud adoption across the GC — whether at the enterprise or departmental level.
On this page
- What the program offers
- How the program operates
- Assessment process
- Canadian third-party organization accreditation program
- Related training
- Additional resources
- Contact us
What the program offers
The CSP ITS Program delivers standardized IT risk assessments of public cloud services for use across the GC. The assessments focus exclusively on the security controls that fall within the direct responsibility of the vendor to identify inherent risks within the CSP’s technical, operational and procedural environment.
Three cloud control baselines have been developed based on the GC’s security control catalogue and tailored specifically for traditional cloud computing. The appropriate assessment baseline is selected based on the service’s criticality and the sensitivity of the data it processes, ensuring the assessment aligns with the potential risk:
- Cloud Low (SaaS only): for cloud services processing up to Protected A level information, and where there is a low level of injury in situations of compromise to the availability and integrity of the system
- Cloud Medium: for cloud services processing up to Protected B level information, and where there is a medium level of injury in situations of compromise to the availability and integrity of the system
- Cloud High: for cloud services processing up to Protected B level information, and where there is a high level of injury in situations of compromise to the availability and integrity of the system
By centralizing these assessments, the Cyber Centre provides a standardized report that departments across the GC can reuse. This allows individual departments to focus their efforts on their own internal Security Assessment and Authorization (SA&A). Although each department must still conduct an internal SA&A to ensure their specific implementation and controls are effective, they can leverage the Cyber Centre’s assessment as verified evidence for the vendor's security posture. This streamlined process informs overall risk-based procurement and authorization decisions without duplicating efforts. The program is intended for government services hosted on commercial cloud providers with a maximum confidentiality of Protected B. It is not intended to assess any classified or national security systems.
How the program operates
The program is designed as a collaborative, iterative process rather than a rigid compliance exercise. It applies to accepted deployment models of infrastructure as a service (IaaS), platform as a service (PaaS) and software as a service (SaaS), helping guide departments and agencies in their procurement and implementation decisions.
To thoroughly assess a CSP’s security capabilities and deficiencies, the program aims to examine various security domains, including:
- a CSP’s information technology security (ITS)
- the physical security of the CSP’s data centres
- personnel security of privileged users
- compliance with Canadian privacy regulations
The assessment process also includes discussion and liaison with required authorities to ensure that cloud procurement purposes are understood and effectively reviewed.
Third-party assessments
The Cyber Centre is evolving its approach to cloud security assessments by engaging third-party assessment organizations (3PAOs) to perform evidence validation on its behalf. The list of 3PAOs is currently limited to companies with Federal Risk and Authorization Management Program (FedRAMP) accreditation. However, the Cyber Centre is working with the Standards Council of Canada (SCC) to develop a Canadian 3PAO accreditation program.
Assessment process
The CSP ITS assessment process provides a structured and trusted approach for evaluating cloud service providers within the GC.
This standardized process ensures consistency, transparency, and accountability, while reducing risks associated with adopting cloud services. It also supports two types of cloud security assessments (enterprise-level and local), helping organizations make informed decisions with confidence.
Enterprise-level assessment process
Enterprise-level assessments are conducted for enterprise services procured by Shared Services Canada (SSC) and Public Services Procurement Canada (PSPC) on behalf of the GC, such as Microsoft 365. They apply to services that will be deployed across most partner departments. This assessment is led by the Cyber Centre and follows a rigorous process:
- Intake and documentation: The department or agency submits non-disclosure agreements (NDAs), intake forms and initial input documents
- 3PAO engagement: Independent accredited assessors (3PAOs) conduct security testing and evidence validation and 3PAOs are funded by the vendors
- Cyber Centre review: The Cyber Centre reviews, validates and analyzes findings from 3PAOs, against GC security requirements
- Risk ratings: The Cyber Centre identifies risks and categorizes them to help departments understand security posture
- Final report: The Cyber Centre issues a comprehensive assessment report, providing departments with clear, actionable results to guide procurement and implementation decisions
Local assessment process
Local (departmental) assessments cover single-use SaaS CSPs procured by individual departments under their own authorities to meet specific needs, such as supply arrangements. This process is led by a department and follows a structured approach:
- Intake and guidance: The department engages the Cyber Centre for advice on cloud services procurement and assessment requirements
- Assessment package: The department provides standardized local assessment materials and methodology to either the departmental IT security team or 3PAO
- Departmental review: Departmental assessors conduct assessments using the provided framework and controls, or based on the 3PAO’s findings
- Cyber Centre oversight and verification: The Cyber Centre ensures assessments follow GC standards through checkpoints and validation
- Final report: The department issues a comprehensive assessment report to guide procurement and implementation decisions
Canadian third-party organization accreditation program
The Cyber Centre is working with the Standards Council of Canada (SCC) on a Canadian 3PAO accreditation program to further support the CSP ITS Assessment Program. This would allow SCC to provide accreditation to Canadian entities using realistic and achievable requirements based on the American Association for Laboratory Accreditation’s (A2LA) R311 requirements.
Once the accreditation program is established, the Cyber centre will require SCC to validate that each 3PAO is maintaining their adherence to the requirements and re-certify the 3PAOs based on a predetermined interval.
Related training
The Cyber Centre’s Learning Hub provides courses and ongoing guidance to build departmental expertise in cloud security and assessment, including the following:
- Conducting cloud service provider IT security assessment (CLD202C)
- Foundations of cloud security in the Government of Canada (CLD101C)
- Cloud computing in the GC - The security assessment and authorization process (CLD201C)
Additional resources
- Cloud service provider information technology security assessment process (ITSM.50.100)
- Cloud security risk management (ITSM.50.062)
- Guidance on cloud security assessment and authorization (ITSP.50.105)
- Security and privacy controls and assurance activities catalogue (ITSP.10.033)
- Guidance on the security categorization of cloud-based services (ITSP.50.103)
Contact us
To obtain information about the control profiles, cloud assessment reports for specific vendors or more, contact the Cyber Centre by email at contact@cyber.gc.ca.