📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Governance, risk & compliance

CCCS Cloud Control Profiles (ITSP.50.103) ITSP.50.103 Annexes A and B

Canadian Centre for Cyber Security cloud security control profiles, from ITSP.

50. 103 Guidance on the security categorization of cloud-based services (effective 20 May 2020).

An organization categorizes each cloud service by the injury a compromise would cause, selects the matching profile, tailors it, allocates each control between the cloud provider and itself by service model, assesses the provider through third-party reports (ITSP. 50.

105), assesses its own controls, and authorizes the service (ITSM. 50.

062). Two profiles are published: Cloud Low (Annex A, 252 controls and enhancements, up to Protected A) and Cloud Medium (Annex B, 353 controls and enhancements, up to Protected B with medium integrity and availability, formerly called PBMM).

The Cloud High profile is not public and is obtained from the Cyber Centre. Both profiles are drawn from ITSG-33 across 17 control families.

ITSP. 10.

033, effective 31 March 2026, replaces the ITSG-33 control catalogue with one aligned to NIST SP 800-53 Rev 5; the cloud profiles have not been reissued against it yet. Each profile control is mapped to the shared library through the matching NIST SP 800-53 control, so work credited there counts here.

Assessment tiers & levels Lavawall supports

Lavawall assesses CCCS Cloud Control Profiles (ITSP.50.103) at every level below, so you can start where you are and step up as your program matures.

Tier / levelWhat it coversBuilds on lower
Cloud Low profileITSP.50.103 Annex A, the CCCS Low cloud profile: 252 controls and enhancements for services handling information up to Protected A with low integrity and availability injury. SaaS only in the Cyber Centre assessment program.—
Cloud Medium profileITSP.50.103 Annex B, the CCCS Medium cloud profile (formerly PBMM): 353 controls and enhancements for services handling information up to Protected B with medium integrity and availability injury. Includes everything in the Low profile.Yes

How Lavawall® helps you get to CCCS Cloud Control Profiles (ITSP.50.103) compliance

Most of CCCS Cloud Control Profiles (ITSP.50.103) comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to CCCS Cloud Control Profiles (ITSP.50.103), and tracks your posture continuously instead of once a year at audit time.

  • Assess your current state against CCCS Cloud Control Profiles (ITSP.50.103) in the Lavawall GRC module, with the questionnaire and control set built in.
  • Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
  • Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.

Related

Lavawall® supports CCCS Cloud Control Profiles (ITSP.50.103) as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.

At a glance

Framework
CCCS Cloud Control Profiles (ITSP.50.103) ITSP.50.103 Annexes A and B
Category
Security
Region
Canada
Levels
2 assessment tiers

Official source →


Map this framework freeTalk to our team