CPCSC

What Is ITSP.10.171? A Plain-Language Guide for Canadian Defence Suppliers

What Is ITSP.10.171? A Plain-Language Guide for Canadian Defence Suppliers

If you supply products or services to Canada’s Department of National Defence (DND), or you are a subcontractor to a company that does, you have likely started seeing a document number appear in contract language and supplier questionnaires: ITSP.10.171. This post explains what it is, who it applies to, what it requires, and how it connects to the certification you will need to keep winning defence work.

ITSP.10.171 is now in effect, and its requirements are being written into defence contracts through 2026 and 2027. If you are new to it, the useful question is not whether it applies to you. It is how far your current security posture is from what it asks for, and how long closing that distance will take.

What is ITSP.10.171?

ITSP.10.171 is the publication number for guidance titled “Protecting specified information in non-Government of Canada systems and organizations,” published by the Canadian Centre for Cyber Security, the part of the Communications Security Establishment (CSE) responsible for Canada’s cyber security guidance.

In plain terms, it is the set of security requirements a company must meet to handle sensitive but unclassified government information on its own systems. The Cyber Centre released the first version on April 2, 2025 and a second release on October 28, 2025.

ITSP.10.171 is the Canadian adaptation of the U.S. National Institute of Standards and Technology publication SP 800-171, Revision 3. The Cyber Centre kept the technical requirements substantially the same as the NIST source and adjusted the language to match Canadian laws and policy. If your organization has worked toward NIST SP 800-171 for U.S. defence work, most of what you built carries over.

What is “specified information”?

“Specified information” is the Canadian term at the centre of ITSP.10.171. It means any information, other than classified material, that a Government of Canada authority identifies in a contract as requiring safeguarding.

This is Canada’s equivalent of the U.S. term “controlled unclassified information (CUI).” If you have handled CUI on a U.S. defence contract, specified information is the same idea under a Canadian name. The obligation is triggered by the contract: when a DND or other Government of Canada contract designates information as specified, ITSP.10.171 defines how you protect it on your systems.

Who does ITSP.10.171 apply to?

ITSP.10.171 applies to organizations outside the Government of Canada that store, process, transmit, or otherwise handle specified information under a government contract. In the defence supply chain, that reaches well beyond the large primes:

  • Manufacturers and machine shops producing parts for defence programs
  • Engineering, software, and professional services firms supporting defence contracts
  • Distributors and logistics providers handling contract data
  • Subcontractors at any tier who receive specified information from a prime or another supplier

The requirement follows the information. If a prime contractor passes specified information down to you, the obligation to protect it under ITSP.10.171 passes down with it. Many smaller suppliers first learn this when a prime sends a security requirement as a condition of staying on an approved supplier list.

If you are a Canadian supplier trying to understand where you sit in this chain, our guide to CPCSC Level 1 compliance for DND contractors walks through the practical starting point.

How ITSP.10.171 relates to CPCSC

ITSP.10.171 is the control set. The Canadian Program for Cyber Security Certification (CPCSC) is the program that verifies you have implemented it.

The Government of Canada runs CPCSC to confirm that defence suppliers meet a required level of cyber security before they can be awarded certain contracts. CPCSC draws its control requirements directly from ITSP.10.171, and it sorts them into levels:

  • CPCSC Level 1 covers 13 controls drawn from ITSP.10.171, verified through an annual self-assessment and a signed affirmation using the Government of Canada’s online tool. No third-party auditor is involved at this level.
  • CPCSC Level 2 covers the full ITSP.10.171 control set and is verified by an independent, certified assessor rather than by self-assessment.

Higher levels exist for the most sensitive information. For most suppliers entering the program, Level 1 is the immediate requirement and Level 2 is what to plan for next.

For the official program details, see the Government of Canada’s CPCSC program overview.

How ITSP.10.171 relates to NIST SP 800-171 and CMMC

If you also serve the U.S. defence market, this is the part worth reading twice.

ITSP.10.171 follows NIST SP 800-171 Revision 3, which organizes requirements into 17 control families. The U.S. Cybersecurity Maturity Model Certification (CMMC) program currently runs on NIST SP 800-171 Revision 2, which uses 14 families and 110 requirements. The two revisions cover the same ground, but they are structured differently and the requirement text does not line up one to one.

For a supplier pursuing both Canadian and U.S. defence work, that means CPCSC and CMMC share most of their substance while sitting on different revisions of the same source. The overlap is large enough to reuse most evidence, and the differences are specific enough that you cannot assume one certificate satisfies the other. We cover this in more detail in CMMC 2.0 compliance: what Canadian organizations need to know and on our NIST SP 800-171 framework page.

What ITSP.10.171 actually requires

ITSP.10.171 organizes its requirements into 17 control families. Each family groups related practices for protecting specified information:

  • Access control
  • Awareness and training
  • Audit and accountability
  • Configuration management
  • Identification and authentication
  • Incident response
  • Maintenance
  • Media protection
  • Personnel security
  • Physical protection
  • Risk assessment
  • Security assessment and monitoring
  • System and communications protection
  • System and information integrity
  • Planning
  • System and services acquisition
  • Supply chain risk management

Across those 17 families sit roughly 97 individual security requirements. Some are technical, such as encrypting specified information and enforcing multi-factor authentication. Others are procedural, such as maintaining an inventory of the systems that handle specified information and documenting who has access to it.

CPCSC Level 1 asks for 13 of these controls, assessed against 71 determination statements. CPCSC Level 2 asks for the complete set. The Cyber Centre’s companion guidance, ITSP.10.171-01, sets out how each requirement is assessed, which is what an assessor will use to judge your evidence.

What this means for your timeline

CPCSC is arriving through a phased rollout, and the dates are close.

CPCSC Level 1 became available to suppliers on April 1, 2026, and the Government of Canada has begun writing mandatory Level 1 requirements into select defence contracts through the summer of 2026. Level 2, the third-party assessed tier built on the full ITSP.10.171 control set, is scheduled to become mandatory in select contracts beginning in spring 2027.

Two details change how you should read those dates:

  • Requirements apply contract by contract, not against a single national deadline. A clause requiring CPCSC certification can appear in your next solicitation regardless of the broader schedule.
  • The attestation is required at contract award, not during bidding, and there is no grace period. A company that cannot demonstrate the required certification level when a contract clause calls for it is not eligible for the award.

That structure rewards suppliers who start early and penalizes those who wait for a specific deadline that never arrives in the form of a single fixed date.

Where to start

If you are new to ITSP.10.171 and CPCSC, begin by finding out where your current posture stands against the Level 1 controls. That takes an afternoon, not a project.

Take the free CPCSC Level 1 self-assessment to see which of the 13 Level 1 controls you already meet and which need work. Then download the CPCSC Readiness Checklist for 2026 to map your position across the full requirement set before your next contract clause lands.

When you have a picture of your gaps and want to understand what closing them involves, read the next post in this series, ITSP.10.171 requirements: what Canadian defence suppliers actually need to do, which walks through each control family in practice and the choice between handling the work in-house, with software, or with a managed model.

Carbide pairs an automation platform with a credentialed advisory team that handles CPCSC and ITSP.10.171 compliance work end to end. The platform is hosted on Canadian infrastructure, which satisfies the data residency the program expects. You can see how the pieces fit on our defence supplier compliance page.

Share