ITSP.10.033 vs NIST SP 800-53 Rev. 5
What actually differs between the Canadian catalogue and its American parent — and what it costs you to cross the border
If you design, build or assess secure systems in North America, NIST SP 800-53 is probably your default reference. For work touching the Government of Canada, the broader public sector or regulated Canadian enterprise, the Canadian Centre for Cyber Security maintains its own: ITSP.10.033, Security and privacy controls and assurance activities catalogue.1
ITSP.10.033 is not a competing standard. It is Canada's tailored adaptation of NIST SP 800-53 Rev. 5, and it says so.16 But the differences that remain sit at exactly the level that changes an architecture review — how controls are structured, how assurance is expressed, and what evidence an assessor expects to see.
Executive Comparison#
| Dimension | NIST SP 800-53 Rev. 5 | CCCS ITSP.10.033 |
|---|---|---|
| Issuing authority | NIST (United States) | Canadian Centre for Cyber Security |
| Governance scope | US federal (FISMA), FedRAMP, global enterprise | Government of Canada, Crown corporations, Canadian critical sectors |
| Control families | 20 | 20 — identical mapping |
| Catalogue items | 1,000+ base controls and enhancements | 1,000+ — NIST baseline plus Canadian extensions |
| Assurance model | Split: SP 800-53 for controls, SP 800-53A for assessment procedures | Unified: controls and assurance activities in one catalogue |
| National extensions | None | 400-series — SA-400, IA-04(400) |
| Guidance layers | US law, OMB memoranda, executive orders | Dual-layered: general discussion plus GC discussion |
| Effective | Rev. 5 (2020), updated | 31 March 2026, superseding ITSG-33 Annex 3A |
Shared DNA: The 20 Control Families#
Both catalogues use the same taxonomy, and both fully absorb the modernized disciplines Rev. 5 introduced — Supply Chain Risk Management (SR) and privacy engineering under Personal Information and Transparency (PT).
Scroll the diagram sideways to see every profile →
For anyone migrating from ITSG-33, this is the quiet headline. The old Annex 3A catalogue predated Rev. 5, so PM, PT and SR are new arrivals in the Canadian catalogue — and a control library built against the legacy annex has three families it has never scoped.1
The Four Structural Differences#
1. Assurance activities live in the same catalogue#
In the NIST ecosystem, control requirements live in SP 800-53 and the procedures for assessing them — examine, interview, test — live in a separate publication, SP 800-53A.7
ITSP.10.033 organizes controls and assurance activities into the same twenty families, in the same catalogue, with the same entry structure. An assurance activity is defined as:
[A] description of tasks, such as engineering tasks, documentation content requirements, and assessment tasks, to be completed as part of a project that increases the confidence that controls are appropriately implemented.
ITSP.10.033That is the successor to what ITSG-33 called security assurance requirements, and it is the reason the catalogue's full title names both halves.3
Scroll the diagram sideways to see every profile →
2. The semantic shift: controls versus activities#
NIST puts every operational obligation under the single word control. ITSP.10.033 draws a deliberate line, and states it plainly: "We refer to assurance-related 'controls' as activities, rather than controls."1
| Controls | Assurance activities | |
|---|---|---|
| What it is | A safeguard that prevents, detects or mitigates risk | Engineering, documentation and assessment tasks |
| Answers | Is the risk addressed? | Do we have confidence it is, and that it stays that way? |
| Example shape | Automated account lockout after failed attempts | The review cadence, the design documentation, the test that proves the lockout fires |
Adopt the vocabulary in your findings. An assessor writing "control not met" against an assurance activity is describing the wrong kind of thing, and it shows.
3. Canadian extensions: the 400-series#
Legacy ITSG-33 numbered Canadian enhancements from 100 — AC-2(101) and the like. As NIST expanded its own catalogue, collisions became inevitable.
ITSP.10.033 moves every Canadian-specific enhancement into the 400+ range, SA-400 and IA-04(400) among them, explicitly to avoid colliding with NIST numbering.1
4. Dual-layered guidance#
NIST discussion sections are framed around US federal regulation. ITSP.10.033 splits its discussion in two:
- General discussion — technology-agnostic implementation advice, useful to any enterprise or municipality.
- GC discussion — "specifically directed to a GC audience as it addresses requirements derived from laws, policies, directives, and standards that GC departments and agencies need to comply with."2
In practice the GC discussion is where a control stops being advisory and starts pointing at the Policy on Government Security, the Directive on Service and Digital and the Privacy Act.
Anatomy of a Catalogue Entry#
Knowing the entry structure tells you where to look when a control is ambiguous. Every ITSP.10.033 entry carries:2
| Section | What it gives you |
|---|---|
| Identifier and name | e.g. CP-09 System backup |
| Control or activity statement | The requirement, split into lettered parts — A., B., C. |
| Discussion (optional) | Implementation guidance, split into general and GC layers |
| Related controls and activities | What else in the catalogue supports or depends on this |
| Enhancements (optional) | Additional capability, numbered (01), (02)… and 400+ for Canadian additions |
| References | The laws, policies, directives and standards behind it |
The lettered parts matter for assessment: a control with statements A through D has four things to evidence, and "partially met" without saying which letter is not a finding anybody can act on.
Crossing the Border#
If your platform already meets NIST SP 800-53 Rev. 5 Moderate or FedRAMP Moderate, the technical foundation largely transfers. What remains is not re-engineering — it is evidence and sovereignty.
- Start from a NIST Rev. 5 or FedRAMP Moderate baselineThe control engineering is substantially the same
- Re-map evidence to assurance activitiesSame safeguard, different proof obligations
- Filter for 400-series enhancementsThe Canadian delta, isolated in one pass
- Re-read the GC discussion on every in-scope controlWhere advisory becomes mandatory
- Verify cryptography against CCCS-approved algorithmsITSP.40.111 governs, not FIPS alone
- Write the assessment procedures yourselfThere is no Canadian SP 800-53A
Conclusion#
ITSP.10.033 is best read as NIST SP 800-53 Rev. 5 with three deliberate Canadian edits: assurance folded in beside the controls, sovereign requirements isolated at 400, and every control given a second layer of guidance that ties it to Canadian law.
Building to NIST Rev. 5 delivers the foundation. Achieving ITSP.10.033 compliance is largely an exercise in aligning operational evidence with CCCS assurance criteria and sovereign policy extensions — plus, for now, writing the assessment procedures that the catalogue has not yet published.
Frequently Asked Questions#
Is ITSP.10.033 a different standard from NIST SP 800-53?#
No. It is an adapted version of NIST SP 800-53 Rev. 5, reflecting Canadian business and legislative requirements. The twenty control families and their identifiers are identical, so AC-2 means the same thing in both. The differences are in packaging, national extensions and guidance layers.
Does ITSP.10.033 replace NIST SP 800-53A?#
No. ITSP.10.033 contains assurance activities — tasks you perform to increase confidence a control is correctly implemented. It does not contain assessment procedures in the SP 800-53A sense. The catalogue states it "creates a foundation for developing assessment methods and procedures", which means departments still define their own.
What is the 400-series?#
Canadian-specific controls and enhancements, numbered from 400 upward — SA-400, IA-04(400) — to avoid collision with NIST numbering as the US catalogue expanded. Legacy ITSG-33 used a 100-series for the same purpose. Any 400-series identifier signals a requirement with no NIST equivalent.
What is the difference between a control and an assurance activity?#
A control is a safeguard that prevents, detects or mitigates risk. An assurance activity is the engineering, documentation or assessment work that gives confidence the control is properly implemented and stays that way. ITSP.10.033 makes the distinction explicit, stating that it refers to assurance-related items as activities rather than controls.
If we already hold FedRAMP Moderate, what is left to do for Canada?#
The control engineering largely transfers. What remains is re-mapping evidence onto assurance activities, assessing against the 400-series enhancements, re-reading the GC discussion on in-scope controls, verifying cryptography against CCCS-approved algorithms rather than FIPS alone, and writing your own assessment procedures.
What changed for teams coming from ITSG-33?#
ITSP.10.033 superseded ITSG-33 Annex 3A on 31 March 2026. Beyond the renumbering to 400, the catalogue adds the PM, PT and SR families that Rev. 5 introduced — so a control library built against the legacy annex has three families it has never scoped. ITSG-33's other annexes were not withdrawn.
References#
- ITSP.10.033 — Security and privacy controls and assurance activities catalogue ↩Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/itsp10033
- ITSP.10.033 — Concepts and structure ↩Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/itsp10033/concepts-structure
- ITSP.10.033 — The controls and assurance activities families ↩Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/itsp10033/controls-assurance-activities-families
- ITSG-33 Annex 3A — Security control catalogue (superseded) ↩Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/annex-3a-security-control-catalogue-itsg-33
- ITSP.40.111 — Cryptographic algorithms for unclassified, Protected A and Protected B information ↩Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cryptographic-algorithms-unclassified-protected-and-protected-b-information-itsp40111
- NIST SP 800-53 Rev. 5 — Security and Privacy Controls for Information Systems and Organizations ↩National Institute of Standards and Technology · https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
- NIST SP 800-53A Rev. 5 — Assessing Security and Privacy Controls in Information Systems and Organizations ↩National Institute of Standards and Technology · https://csrc.nist.gov/pubs/sp/800/53/a/r5/final
- Policy on Government Security ↩Treasury Board of Canada Secretariat · https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=16578