ITSG-33 and Protected B: What Government IT Contractors Need to Know

Win a Government of Canada IT contract and the paperwork often arrives before the project does. Departments now expect vendors and contract staff to show working knowledge of ITSG-33 and Protected B requirements before they touch a departmental system. If your team is new to public sector work, this framework decides what controls you build, what evidence you keep, and who signs off before you go live.
Not sure which certification maps to this kind of work? Book a training consultation and get a plan built around the roles your contract needs.
What ITSG-33 Covers
ITSG-33 is the Government of Canada’s core guidance for managing IT security risk across a system’s full life. The Canadian Centre for Cyber Security publishes it, and it has applied since 2012, replacing older standards from the 1990s. According to the Canadian Centre for Cyber Security’s own guidance, the goal is straightforward: build security into a project from the start instead of bolting it on before launch.
The framework runs at two levels. At the departmental level, officials define security needs, deploy controls, monitor results, and update the approach on a repeating cycle. At the system level, security work follows the project itself, from initiation through development, integration, operation, and disposal. Controls fall into three families: management, technical, and operational. A contractor who understands where their deliverable sits in this cycle avoids the late-stage surprise of a security review stalling a launch date.
Protected B in Plain Terms
Protected B is the security categorization for information likely to cause serious harm if it leaked. Think client financial details, medical records, or internal case files, not classified national security material. It sits below Secret and above Protected A on the scale departments use to sort data by sensitivity.
ITSG-33’s Annex 4A security control profile for Protected B spells out a medium integrity and medium availability baseline. In practice, this means specific requirements around encryption, access control, logging, and where the data physically sits. Most contracts touching citizen data land here, which makes it the categorization contractors run into most.
- Encrypt Protected B data at rest and in transit using approved algorithms.
- Log access and keep audit trails a department reviews on request.
- Confirm hosting location meets data residency terms in the contract.
Where Screening and IT Requirements Overlap
ITSG-33 governs the systems. A separate process, the Contract Security Program, governs the people and the company. The Public Services and Procurement Canada page on contracting security requirements lays out the personnel screening levels a contract calls for: Reliability Status for baseline roles, Secret for more sensitive information, and Top Secret for the most sensitive work. Contractors bidding on defence-related work face an added layer through the Defence Supplier Cyber Security Certification program.
These two tracks run side by side. A developer with Reliability Status clearance still needs to build to the ITSG-33 Protected B control profile if the system stores Protected B data. Teams treating clearance as the finish line often miss the technical controls a security assessor checks before authorizing a system to operate.
Where Contractors Lose Time
The most common delay is not a missing clearance. It is a team building a system first and mapping it to ITSG-33 controls after the fact. Retrofitting logging, encryption, or access management into a finished build costs far more than designing to the control profile from day one. The second most common delay is documentation. Departments expect evidence, not a verbal assurance the controls are in place, so a security assessment or authority to operate stalls for weeks while a vendor produces records it should have kept from the start.
Building This Into Your Team’s Skills
A working grasp of ITSG-33 and the Contract Security Program is not something most IT staff pick up on the job. Structured cybersecurity training gives your team a shared baseline before a contract starts, not during a review already behind schedule. Ultimate IT Courses runs vendor-neutral cybersecurity training through Mile2, built around hands-on labs rather than theory alone, alongside the standard vendor certification paths departments recognize. Browse the full cybersecurity training programs or check the broader certification course catalogue to see what maps to your contract’s screening level.
Your Next Step
ITSG-33 and Protected B are not optional reading for a government IT contract. They decide the design decisions your team makes on day one and the evidence you hand over on delivery day. View government-ready certification tracks and get your team prepared before the next contract lands on your desk.
