home / guides / cpcsc-defence-suppliers

Sector and contracting · Public Services and Procurement Canada

CPCSC for defence suppliers

The Canadian Program for Cyber Security Certification sets cyber requirements for suppliers on defence contracts.

Who this applies to

Suppliers and subcontractors that handle information on federal defence contracts.

What to know

  • The program has three levels. As published by the government, Level 1 is an annual self-assessment, Level 2 is an external assessment by an accredited body, and Level 3 is an assessment by National Defence.
  • Public Services and Procurement Canada leads the program, and the Standards Council of Canada accredits the bodies that perform Level 2 assessments.
  • The Canadian Centre for Cyber Security developed the underlying standard.
  • Rollout is phased, so which level a contract needs depends on the contract.

What to do

  • Read the security requirements in each contract to see which level applies.
  • Do a gap assessment early. Evidence takes longer to collect than the fixes take to make.
  • Check the government program page for the current status, because dates and requirements move.