Government and Public Sector IT
Federal and provincial buyers can't procure from a supplier who doesn't understand classification levels, and on most files the paperwork is the work. What gets judged is whether your Protected B handling, your control profile and your TRA survive a reviewer who has read a hundred of them. Worth knowing before you start: the control catalogue changed in March 2026. We name the regime that binds you, then point you at the service that answers it.
Which rules apply to you?
Protected A, B and C
Applies now
Each level changes where the data can physically live, who can reach it, and what you have to prove about both. Most files turn on Protected B, and most disagreements turn on what counts as reaching it.
ITSG-33, and ITSP.10.033
Applies now
Security control profiles, plus the Threat and Risk Assessment that has to accompany them in the format a reviewer expects. The control catalogue in Annex 3A was superseded in March 2026 by ITSP.10.033, which moves to NIST SP 800-53 Rev. 5, adds privacy controls, and renumbers Canadian controls from the 100s to the 400s.ITSP.10.033, March 2026
CPCSC
Applies conditionally
The Canadian Programme for Cyber Security Certification, which federal supply-chain contracts increasingly name.
PIPEDA and the Privacy Act
Applies now
The federal privacy baseline, and a Privacy Impact Assessment before a new programme touches personal information.
Bill C-8
Not yet in force
Part 2 is law but not yet in force, and no operators are designated, so today this is a readiness question rather than a duty.Royal assent 2026-06-15
Which services answer them?
- CPCSC Certification SupportThe certification federal supply-chain contracts increasingly require.
- Privacy Impact Assessment (PIA)Mandatory before a new programme touches personal information.
- Threat Risk Assessment (TRA)The TRA that ITSG-33 expects, against the catalogue that's current.
- Bill C-26 ReadinessWhere you'd stand if Part 2 is brought into force.
- On-Premise and Sovereign AIFor data that cannot leave Canadian soil, whatever the vendor promises.
- Centre de donnéesCanadian-resident infrastructure, documented for an auditor.
- Managed Security Services (MSSP)Monitoring with a Canadian SOC and Canadian log retention.
- PIPEDA ComplianceThe baseline that applies regardless of classification.
Whose kit does this run on?
The platforms we design, build and support. Named because a buyer with an estate already standardised on one of them needs to know before the first call, not after it.
Cisco, Palo Alto, F5, Azure, AWS, VMware, Fortinet