INDUSTRIES

Government and Public Sector IT

Federal and provincial buyers can't procure from a supplier who doesn't understand classification levels, and on most files the paperwork is the work. What gets judged is whether your Protected B handling, your control profile and your TRA survive a reviewer who has read a hundred of them. Worth knowing before you start: the control catalogue changed in March 2026. We name the regime that binds you, then point you at the service that answers it.

WHAT APPLIES

Which rules apply to you?

  • Protected A, B and C

    Applies now

    Each level changes where the data can physically live, who can reach it, and what you have to prove about both. Most files turn on Protected B, and most disagreements turn on what counts as reaching it.

  • ITSG-33, and ITSP.10.033

    Applies now

    Security control profiles, plus the Threat and Risk Assessment that has to accompany them in the format a reviewer expects. The control catalogue in Annex 3A was superseded in March 2026 by ITSP.10.033, which moves to NIST SP 800-53 Rev. 5, adds privacy controls, and renumbers Canadian controls from the 100s to the 400s.ITSP.10.033, March 2026

  • CPCSC

    Applies conditionally

    The Canadian Programme for Cyber Security Certification, which federal supply-chain contracts increasingly name.

  • PIPEDA and the Privacy Act

    Applies now

    The federal privacy baseline, and a Privacy Impact Assessment before a new programme touches personal information.

  • Bill C-8

    Not yet in force

    Part 2 is law but not yet in force, and no operators are designated, so today this is a readiness question rather than a duty.Royal assent 2026-06-15

TECHNOLOGY

Whose kit does this run on?

The platforms we design, build and support. Named because a buyer with an estate already standardised on one of them needs to know before the first call, not after it.

Cisco, Palo Alto, F5, Azure, AWS, VMware, Fortinet

QUESTIONS

What buyers in this sector ask.

Ask any supplier this first, and ask what changes at each level rather than which box they tick. Protected B is where most federal files sit, and it constrains where data can live, who can reach it, and what you can show afterwards about both.

Both, and the distinction matters as of March 2026. ITSP.10.033 supersedes ITSG-33 Annex 3A, the security control catalogue. It aligns to NIST SP 800-53 Rev. 5 rather than Rev. 4, adds privacy controls, and renumbers Canadian-specific controls from the 100 series into the 400s.

In Canada, in infrastructure we can name and document for an auditor. On a federal file this is the first architecture decision, not the last one, and "our provider says it's in Canada" isn't the same as being able to prove it when a reviewer asks.

Ask this as a yes or no and expect a yes or no. CPCSC is increasingly named in federal supply-chain contracts, and a supplier's certification status is a fact, not a positioning statement. Public sector cybersecurity buying runs on that distinction more than any other market.

If your department needs an independent assessor to sign off on the controls, that can't be the firm that built them. We build, document and hand over. Someone independent attests. Knowing which of the two you are buying belongs in the statement of work.

PARLONS-EN

Un spécialiste chevronné répond en moins d'une heure, 24/7.