// CPCSC · ITSP.10.171 · 98 REQUIREMENTS
The 98 requirements
Last verified: 2026-10-05
ITSP.10.171 is the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171 Revision 3; the second release, dated October 28, 2025, is current. It holds 98 requirements in 17 families: the 97 from Revision 3 plus 03.14.09, dedicated administration workstation, which Canada added from its own control catalogue. Gaps in the numbering are the identifiers NIST withdrew in Revision 3, which Canada keeps as "not allocated" so the numbers line up across the border. The 13 Level 1 requirements are marked.
Many requirements contain organization-defined parameters: how long before an inactive account is disabled, how many failed logins before lockout, how long logs are kept. Unless a contract names a value, you choose it, record it in your system security plan, and defend it at assessment. The bracketed values in the templates are exactly those choices.
// 17 FAMILIES
Access control
The right people reach the right data and nothing more.
Awareness and training
People who touch the data know what it is, how to handle it, and what an attack on them looks like this year.
Audit and accountability
When something happens, you can reconstruct it.
Configuration management
Systems run in a known state and change on purpose.
Identification and authentication
Know who is on the system before it does anything.
Incident response
When it goes wrong, you act instead of improvising.
Maintenance
Control who services the systems, with what tools, from where.
Media protection
Protected data on removable and portable media is controlled from creation to destruction.
Personnel security
Screen people before they get access to protected data, and pull access cleanly when they leave or move roles.
Physical protection
The hardware holding protected data sits behind physical access control with a short key list.
Risk assessment
Assess risk to the protected data periodically, scan for vulnerabilities on a cycle, and fix what the scans find inside a defined window.
Security assessment and monitoring
Check that the controls work, plan and track the fixes, and keep watching.
System and communications protection
The network architecture itself defends the data.
System and information integrity
Patch on a cadence with proof, run current malware protection everywhere in scope, act on the alerts your own tools raise, and do administrative work only from a dedicated, isolated workstation.
Planning
The system security plan exists, describes the real environment and boundary, and gets updated when the environment changes; rules of behaviour for users are written down.
System and services acquisition
Security is considered when systems and services are bought or built, including what external providers are responsible for.
Supply chain risk management
Know who is in your supply chain for the in-scope systems, assess the risk they bring, and flow requirements down where protected data flows down.
// ALL 98 REQUIREMENTS · 13 AT LEVEL 1
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
- How to meet Level 1 requirementsPublic Services and Procurement Canadacanada.ca
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.