Baseline Controls News Resources Glossary About

Understanding Canada's Baseline Cyber Security Controls for SMBs

Understanding Canada's Baseline Cyber Security Controls for SMBs

The Canadian Centre for Cyber Security (CCCS) has established a set of Baseline Cyber Security Controls specifically designed for small and medium organizations. Published as ITSM.10.089, this document represents the Government of Canada's recommended minimum security standard for Canadian businesses.

What Are the Baseline Controls?

The Baseline Controls are organized into 13 control areas that cover the fundamental aspects of cybersecurity that every organization should address:

  1. Incident Response Planning (BC.1) — Having a plan for when things go wrong
  2. Patch Management (BC.2) — Keeping software and systems up to date
  3. Anti-Malware (BC.3) — Protecting against viruses and malicious software
  4. Secure Configuration (BC.4) — Setting up systems securely from the start
  5. Authentication (BC.5) — Verifying who has access to your systems
  6. Security Awareness (BC.6) — Training employees to recognize threats
  7. Data Backup (BC.7) — Ensuring you can recover from data loss
  8. Mobile Devices (BC.8) — Securing phones and tablets
  9. Network Security (BC.9) — Protecting your network perimeter
  10. Cloud Services (BC.10) — Securing cloud-based tools and data
  11. Web Security (BC.11) — Protecting your public-facing websites
  12. Access Control (BC.12) — Managing who can access what
  13. Portable Media (BC.13) — Controlling USB drives and external storage

Why It Matters for Canadian SMBs

Small and medium businesses are increasingly targeted by cyber threats. According to Canadian government reports, many SMBs lack the resources for comprehensive security programs. The Baseline Controls provide a practical, achievable starting point.

These controls aren't about achieving perfect security — they're about establishing a minimum viable security posture that significantly reduces your risk of a successful cyber attack.

Explore Each Control Area

We've created detailed guides for each of the 13 Baseline Control areas:

Getting Started

The best way to begin is by assessing where your organization currently stands. Our free assessment tool evaluates your practices against all 13 control areas and provides specific, actionable recommendations for improvement. Learn how to use your assessment results once you've completed it.

You can also review the official ITSM.10.089 document directly on the Canadian Centre for Cyber Security's website.

Frequently Asked Questions

What are Canada's 13 Baseline Cyber Security Controls?

The 13 Baseline Cyber Security Controls are: incident response planning (BC.1), patch management (BC.2), anti-malware (BC.3), secure configuration (BC.4), authentication (BC.5), security awareness training (BC.6), data backup (BC.7), mobile device security (BC.8), network security (BC.9), cloud services security (BC.10), web application security (BC.11), access control (BC.12), and portable media (BC.13). Together they cover the fundamental areas of cybersecurity that the Government of Canada recommends every small and medium organization address.

Who publishes the Baseline Cyber Security Controls?

The Canadian Centre for Cyber Security (CCCS), part of the Communications Security Establishment, publishes them as document ITSM.10.089 — Baseline Cyber Security Controls for Small and Medium Organizations. The document represents the Government of Canada's recommended minimum security standard for Canadian businesses and is available free of charge on the CCCS website.

What is ITSM.10.089?

ITSM.10.089 is the CCCS publication number for Baseline Cyber Security Controls for Small and Medium Organizations. It is the source document that defines the 13 control areas, written specifically for organizations that lack the resources for a comprehensive enterprise security programme. The same controls underpin the federal CyberSecure Canada certification programme.

Are the Baseline Controls mandatory for Canadian businesses?

The Baseline Controls are guidance rather than legislation, so implementing them is voluntary for most Canadian businesses. They matter anyway: Canadian privacy law requires organizations to protect personal information with safeguards appropriate to its sensitivity, and the Baseline Controls are the most widely referenced Canadian benchmark for what reasonable safeguards look like. Insurers, enterprise customers, and government contracting processes increasingly ask about them as well. This is general information, not legal advice.

Where should a small business start with the Baseline Controls?

Start by establishing where you currently stand rather than trying to implement all 13 areas at once. The Baseline Controls are deliberately ordered with incident response planning first, because when an incident occurs everything else depends on having a plan to follow. A structured self-assessment against all 13 control areas will show which gaps to close first; our free assessment does this in under 30 minutes without collecting your data.

Do the Baseline Controls guarantee my business will not be breached?

No. The Baseline Controls are not about achieving perfect security — they establish a minimum viable security posture that meaningfully reduces the likelihood of a successful attack. No set of controls eliminates risk entirely. Their value is that they concentrate limited resources on the areas where Canadian small and medium organizations are most commonly compromised.

Cite This Page

Suggested citation:

Cybersecurity Canada (2026). Understanding Canada's Baseline Cyber Security Controls for SMBs. Retrieved from https://cybersecuritycanada.ca/news/posts/understanding-canadas-baseline-cyber-security-controls/

Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.

Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.

How does your organization measure up?

Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential — your answers never leave your browser.

Take the Free Assessment