CCSSF 2022

Canadian Cyber Security Skills Framework

workforce
ca
Published

September 21, 2026

At a glance

Steward Canadian Centre for Cyber Security
Canonical page Cyber Centre publications
Version 2022 edition (ITSM.00.039)
Source format PDF, supplied directly by the Cyber Centre with Annexes A through F
License Copyright Government of Canada, no licence notice in the document itself. Used with the Canadian Centre for Cyber Security’s written permission for full-text publication with attribution
framework_summary slug ccssf-2022

Structure in cybed: terms

CCSSF structural mapping Frameworkccssf:FrameworkWork role(22 core roles across 4 activity areas, plus adjacent roles)ccssf:WorkRole= cybed:Role = cybed:OrganizingUnitTask, Competency, Tool/Technology= cybed:RoleElementcontainscybed:hasOrganizingUnithas elementcybed:hasElement
Click any box or edge label to flip between plain English and the technical schema name.

Counts

Table 1
Measure Value
Work roles 59
Strict elements 1,148
Subpoints (parsed enumeration lists) 197
With-examples elements 1,345
Elements per work role, strict 19.5
Elements per work role, with-examples 22.8

22 core cyber security roles sit under 4 activity areas (Annexes A through D: Oversee & govern, Design & develop, Operate & maintain, Protect & defend). Annex E’s 37 cyber-adjacent roles add further work roles from a single wide table rather than a per-role block. Annex F, a talent-alliance membership list, is not a role structure and is not ingested.

Provenance

Source

The Canadian Cyber Security Skills Framework (ITSM.00.039), 2022 edition, supplied directly by the Cyber Centre’s Cyber Skills Development Team with its full annexes.

Ingestion

scripts/010-ingest-ccssf.R parses each role block’s field labels (Functional description, Tasks, Competencies, Tools & technology, and the rest) and the Annex E table into the cybed schema.

License

The document carries no copyright line, Creative Commons statement, Open Government Licence reference, or all-rights-reserved statement of its own; it carries only Government of Canada publication identifiers and TLP:CLEAR / UNCLASSIFIED disclosure markings, which are not licences. The Canadian Centre for Cyber Security gave cybedtools written permission on 2026-09-21 for full-text publication with attribution.

Caveats

  • CCSSF is an explicit adaptation of the US NICE Workforce Framework for Cybersecurity, and cites NICE work-role IDs throughout. Those citations are captured as their own crosswalk table rather than folded into the element counts above.
  • Each core role’s field labels (Development pathway, Consequence of error or risk, Future trends affecting key competencies, and the rest) are preserved as the document’s own vocabulary, not normalised into cybed’s generic element types beyond the Task/Competency/Tool-or-Technology split shown here.
  • Annex F is a membership list, not a role structure, and carries no framework content of its own.
Back to top

Reuse

Government of Canada, with permission