| Measure | Value |
|---|---|
| Work roles | 59 |
| Strict elements | 1,148 |
| Subpoints (parsed enumeration lists) | 197 |
| With-examples elements | 1,345 |
| Elements per work role, strict | 19.5 |
| Elements per work role, with-examples | 22.8 |
CCSSF 2022
Canadian Cyber Security Skills Framework
At a glance
| Steward | Canadian Centre for Cyber Security |
| Canonical page | Cyber Centre publications |
| Version | 2022 edition (ITSM.00.039) |
| Source format | PDF, supplied directly by the Cyber Centre with Annexes A through F |
| License | Copyright Government of Canada, no licence notice in the document itself. Used with the Canadian Centre for Cyber Security’s written permission for full-text publication with attribution |
framework_summary slug |
ccssf-2022 |
Structure in cybed: terms
Counts
22 core cyber security roles sit under 4 activity areas (Annexes A through D: Oversee & govern, Design & develop, Operate & maintain, Protect & defend). Annex E’s 37 cyber-adjacent roles add further work roles from a single wide table rather than a per-role block. Annex F, a talent-alliance membership list, is not a role structure and is not ingested.
Provenance
Source
The Canadian Cyber Security Skills Framework (ITSM.00.039), 2022 edition, supplied directly by the Cyber Centre’s Cyber Skills Development Team with its full annexes.
Ingestion
scripts/010-ingest-ccssf.R parses each role block’s field labels (Functional description, Tasks, Competencies, Tools & technology, and the rest) and the Annex E table into the cybed schema.
License
The document carries no copyright line, Creative Commons statement, Open Government Licence reference, or all-rights-reserved statement of its own; it carries only Government of Canada publication identifiers and TLP:CLEAR / UNCLASSIFIED disclosure markings, which are not licences. The Canadian Centre for Cyber Security gave cybedtools written permission on 2026-09-21 for full-text publication with attribution.
Caveats
- CCSSF is an explicit adaptation of the US NICE Workforce Framework for Cybersecurity, and cites NICE work-role IDs throughout. Those citations are captured as their own crosswalk table rather than folded into the element counts above.
- Each core role’s field labels (Development pathway, Consequence of error or risk, Future trends affecting key competencies, and the rest) are preserved as the document’s own vocabulary, not normalised into cybed’s generic element types beyond the Task/Competency/Tool-or-Technology split shown here.
- Annex F is a membership list, not a role structure, and carries no framework content of its own.