Governance, risk & compliance
CCCS Cloud Assessment: Medium and PBHVA Program page June 2026; ITSM.50.100
Cyber Centre Cloud Service Provider IT Security Assessment Program, at the Cloud Medium (formerly PBMM) and Protected B High Value Assets (PBHVA) levels.
The Cyber Centre assesses commercial cloud services the Government of Canada buys, up to Protected B, against a cloud control profile, using the provider's third-party attestations (SOC 2 Type II, ISO/IEC 27001, 27017 and 27018, FedRAMP) and a detailed evidence review. The output is an assessment report that departments reuse in their own security assessment and authorization; it is not a certification and is not published.
PBHVA is an overlay on the Cloud Medium baseline that adds integrity and availability controls for Protected B workloads designated as high value assets; the Cyber Centre's program page now calls the levels Cloud Low, Cloud Medium and Cloud High. The PBHVA control list is not published by the Government of Canada and is obtained from the Cyber Centre (contact@cyber.
gc. ca); public vendor sources give counts between 110 and 137 controls.
The High tier here therefore groups the overlay's integrity and availability themes against the shared library, and should be replaced by the official list when you receive it. Use this framework if you sell a cloud service to federal departments through Shared Services Canada, PSPC, or a department's own procurement.
Assessment tiers & levels Lavawall supports
Lavawall assesses CCCS Cloud Assessment: Medium and PBHVA at every level below, so you can start where you are and step up as your program matures.
| Tier / level | What it covers | Builds on lower |
|---|---|---|
| Cloud Medium (PBMM) | Cyber Centre assessment of the cloud service against the CCCS Medium profile (formerly Protected B, Medium Integrity, Medium Availability), plus the program's process requirements: intake, attestations, evidence review, findings and reassessment. | — |
| PBHVA overlay | Protected B High Value Assets: the Cloud Medium baseline plus an overlay of integrity and availability controls for high value assets. The official overlay list comes from the Cyber Centre; the requirements in this tier group its themes against the shared library until you load the official list. | Yes |
How Lavawall® helps you get to CCCS Cloud Assessment: Medium and PBHVA compliance
Most of CCCS Cloud Assessment: Medium and PBHVA comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to CCCS Cloud Assessment: Medium and PBHVA, and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against CCCS Cloud Assessment: Medium and PBHVA in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Lavawall® supports CCCS Cloud Assessment: Medium and PBHVA as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.
At a glance
- Framework
- CCCS Cloud Assessment: Medium and PBHVA Program page June 2026; ITSM.50.100
- Category
- Security
- Region
- Canada
- Levels
- 2 assessment tiers
Map this framework freeTalk to our team