ITSP.10.171 Control Families Explained
Every level of the Canadian Program for Cyber Security Certification (CPCSC) is built on one document: ITSP.10.171, "Protecting specified information in non-Government of Canada systems and organizations," published by the Canadian Centre for Cyber Security. Before you can make sense of Level 1, 2, or 3, it helps to see the 17 families the whole standard is organized around, and which of them Level 1 actually touches.
Quick answer. ITSP.10.171 organizes its controls into 17 security requirement families. CPCSC Level 1's 13-control self-assessment draws on 6 of those 17 families: access control, identification and authentication, media protection, physical protection, systems and communications protection, and system and information integrity. Level 2 (98 controls) and Level 3 (200 controls) draw more broadly across the full set of 17, per canada.ca, though a published per-family breakdown for those two levels was not found.
The 17 Security Requirement Families
Per the Canadian Centre for Cyber Security's ITSP.10.171 guidance, the standard is organized into these 17 families:
- Access control: who can reach a system, and what they can do once they are in.
- Awareness and training: making sure staff understand their information security responsibilities.
- Audit and accountability: generating and reviewing records of system activity.
- Configuration management: controlling how systems are set up and changed.
- Identification and authentication: verifying the identity of users and devices before granting access.
- Incident response: detecting, reporting, and handling security incidents.
- Maintenance: performing system maintenance in a controlled, secure way.
- Media protection: protecting and properly disposing of physical and digital storage media.
- Personnel security: screening people before they get access, and handling access changes when they leave or change roles.
- Physical protection: limiting physical access to systems and facilities.
- Risk assessment: identifying and evaluating risk to information and systems.
- Security assessment and monitoring: periodically checking whether controls are working.
- System and communications protection: securing networks and the boundaries between them.
- System and information integrity: finding and fixing flaws, and defending against malicious code.
- Planning: documenting how the organization approaches information security.
- System and services acquisition: building security into how systems and services are acquired or developed.
- Supply chain risk management: managing information security risk introduced through suppliers.
This is the same underlying structure the site's CPCSC overview points to: canada.ca describes ITSP.10.171 as the Canadian counterpart to the NIST SP 800-171 family of controls, and it took effect April 2, 2025.
How Level 1's 13 Controls Map to the Families
Level 1 does not test all 17 families. Canada.ca's own "how to meet Level 1" guidance groups the 13 Level 1 controls under six families, framed as six cyber hygiene practice areas:
Manage user accounts, give people only the access they need, use only approved systems and devices, and prevent sensitive information from being shared publicly. Four of the 13 controls sit here, more than any other family at Level 1.
Use individual accounts with strong passwords, approve devices before they connect, and enable multifactor authentication.
Wipe or destroy old devices before disposal, so decommissioned storage does not leak Specified Information.
Keep a list of who can access secure areas, and control physical entry to where in-scope systems and information live.
Use basic network protections. Level 1 keeps this to a single foundational control; the deeper network segmentation and monitoring expectations show up at higher levels.
Apply security updates, and run antivirus and anti-malware software on systems that touch Specified Information.
The other eleven families, including audit and accountability, incident response, personnel security, risk assessment, planning, and supply chain risk management, are not part of the Level 1 self-assessment. They come into scope at Level 2.
Where Level 2 and Level 3 Widen the Scope
Canada.ca states Level 2 draws on 98 controls and requires an external assessment by a certification body accredited by the Standards Council of Canada, and that Level 3 draws on 200 controls assessed directly by National Defence, reserved for the highest-risk scenarios. Both are described as drawing on the same 17-family ITSP.10.171 structure Level 1 uses, now spread across families Level 1 does not touch at all, such as audit and accountability, personnel security, risk assessment, planning, and supply chain risk management. Level 3 also draws on NIST SP 800-172's enhanced requirements for information under greater threat, per canada.ca.
We could not find a published breakdown of the 98 or 200 controls by family. If your contract requires Level 2 or Level 3, treat the family list above as the shape of what is coming, not a substitute for the government's own published control catalog once it is available for your target level.
What This Means If You Are Starting From Level 1
If your current contract only requires Level 1, you are being tested against 6 of 17 families and 13 of what will eventually be a much larger control set. That is useful to know two ways: it tells you exactly where to focus right now, and it tells you not to assume Level 1 readiness carries you very far into Level 2, since 11 additional families become live.
Scoping which families and controls actually apply to your contract, and building toward the level your next contract will require, is exactly the kind of judgment call a fractional CISO makes for Canadian defence suppliers. See what your CPA handles and what we handle or book a call.