// CPCSC TEMPLATES · 13 OF 14

Shared responsibility matrix

Last verified: 2026-10-05

Requirement by requirement, who operates the control, who holds the evidence, and what deliverable arrives on what cadence. Supports 03.16.03 and the MSP conversation in chapter 11.

Download as Markdown

Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.

TPL-13 Static template
Requirement              Operates    Evidence held by     Deliverable / cadence
Patch management         [MSP]       [MSP]                patch report, monthly
Firewall rule set        [MSP]       [MSP + client copy]  rule review, quarterly
Log collection/review    [MSP]       [client mailbox]     weekly log digest
Access reviews           [Client]    [Client]             review record, quarterly
MFA enrolment            [MSP]       [Client]             enrolment list, on change
Backup and restore test  [MSP]       [MSP + client copy]  restore test log, quarterly
Awareness training       [Client]    [Client]             sign-off sheet, annual
Vulnerability scanning   [Third party] [Client]           scan report, quarterly
Incident reporting       [Client]    [Client]             per contract
Endpoint protection      [MSP]       [MSP + client copy]  console export, monthly

Add a row for every requirement in the index the provider touches. Attach the matrix to the service contract.

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.