The Canadian Program for Cyber Security Certification, or CPCSC, is the Government of Canada program that sets cyber security requirements for suppliers on defence contracts. Public Services and Procurement Canada leads it, and National Defence and the Standards Council of Canada have defined roles in the higher levels.
The government says the controls are adapted from NIST SP 800-171 and 800-172 and published as the Canadian standard ITSP.10.171. That shared basis is why organizations that have worked on NIST 800-171 or CMMC are not starting from zero. Requirements and dates change, so treat the official pages as the source of truth.
How to get ready
- Find out whether it appliesNot every defence contract requires certification, and the level depends on the contract.
- Read the security requirements in each solicitation and contract.
- The government states that requirements begin appearing in defence contracts from summer 2026, starting with Level 1.
- Ask your prime contractor how requirements will flow down to you. The official Level 1 page does not set out subcontractor flow-down, so rely on your contract.
- Understand the three levelsThe levels step up in rigor and in who does the assessing.
- Level 1 is an annual self-assessment against 13 foundational controls.
- Level 2 is described as an external assessment by an accredited body, with annual affirmations and 98 controls. The government lists it as under development.
- Level 3 is described as an assessment by National Defence, with annual affirmations and more than 130 controls. The government lists it as under development.
- The Standards Council of Canada accredits the bodies that will perform Level 2 assessments.
- Know the 13 Level 1 controlsAs summarized from the government’s Level 1 requirements page. Read the original for the exact wording.
- Manage user accounts, and update them when people join, leave, or change roles.
- Give people only the access they need.
- Use only approved systems and devices.
- Prevent sensitive information from being shared publicly.
- Use individual accounts and strong passwords.
- Approve devices before they connect to your network.
- Enable multi-factor authentication for privileged accounts and for systems holding specified information.
- Wipe or destroy old devices and media.
- Keep a list of who can access secure areas.
- Control physical entry with locks and visitor procedures.
- Use basic network protections such as firewalls.
- Apply security updates promptly and track completion.
- Use antivirus and anti-malware software.
- Scope your environmentCompliance cost follows scope, so be exact about where specified information lives.
- List the systems, people, and locations that store, process, or transmit information the contract protects.
- Keep that information in a small, well-defined boundary instead of spreading it across the whole company.
- Document the boundary, because assessors and primes ask for it.
- Run the gap assessmentDo it early. Collecting evidence takes longer than fixing most gaps.
- Start with the 13 Level 1 controls and score each one honestly.
- Compare your program to ITSP.10.171 if you expect to need Level 2 or if your contracts reference it.
- Fix the cheap, high-value gaps first, such as multi-factor authentication, patching, and device approval.
- Keep evidenceA control you cannot demonstrate does not count.
- Write short policies and procedures for each control, and keep screenshots, exports, and tickets that show the control working.
- Assign an owner to every control and record the review date.
- Store the evidence where it can be retrieved quickly when an assessor or prime asks.
- Complete the self-assessmentLevel 1 uses the official online tool.
- Complete the government self-assessment tool each year.
- The government states that results are provided to your CanadaBuys profile, and that the self-assessment is required at contract award.
- Use the program contact page if something in the process is unclear.
General information, not legal or professional advice. Official documents change, so confirm details with the linked sources before you act.
// firms
Canadian firms that work on this
Firms whose own websites name CPCSC, NIST 800-171, CMMC or list closely related services. A listing is not an endorsement.
C3SA
Cybersecurity organization offering consulting, systems integration, training and cyber ranges, incident response and threat intelligence, with compliance work for ITSG-33, CMMC, CPCSC and SOC 2.
- Architecture
- IR and forensics
- Threat intel
- Privacy
- ITSG-33
- CMMC
- CPCSC
- SOC 2
Castellan Information Security Services Inc.
Governance, risk and compliance services including gap analysis, policy development, audit preparation, CPCSC and CMMC readiness, penetration testing, business continuity, and security staff augmentation.
- GRC advisory
- Audit and certification
- Pen testing
- IAM
- CPCSC
- CMMC
- PCI DSS
IRM Consulting & Advisory
Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.
- GRC advisory
- Audit and certification
- Privacy
- Pen testing
- AppSec
- +3
- SOC 2
- ISO 27001
- CMMC
- CIS Controls
- GDPR
- +3
Kobalt.io
Compliance and security firm offering gap assessments, audit readiness, vCISO, penetration testing and incident response, with a fixed-fee CPCSC programme for defence supply-chain vendors.
- GRC advisory
- Audit and certification
- Pen testing
- IR and forensics
- MDR and SOC
- +1
- CPCSC
- CMMC
- NIST 800-171
- SOC 2
- ISO 27001
- +6
OKIOK
Offensive security (penetration testing, vulnerability assessment), incident response, digital forensics, cybersecurity consulting, compliance and governance, and identity compliance as a service.
- Pen testing
- Vulnerability mgmt
- IR and forensics
- GRC advisory
- IAM
- +1
- ISO 27001
- SOC 2
- PCI DSS
- CPCSC
Pilotcore
Cloud and compliance consultancy offering DevSecOps, readiness assessments for CPCSC and CMMC, SOC 2 readiness, zero trust architecture and fractional CTO support.
- Cloud security
- GRC advisory
- Audit and certification
- Architecture
- CPCSC
- CMMC
- SOC 2
// faq
Common questions
Does every defence supplier need CPCSC?
No. The government states that not all defence contracts require certification. Your contract names the level, if any.
Is CPCSC the same as the U.S. CMMC?
No. They are separate programs with a similar technical basis in NIST SP 800-171. Do not assume that one satisfies the other. Check what your contract requires.
Do I need a consultant for Level 1?
Level 1 is a self-assessment, and many organizations complete it themselves. Outside help is most useful for scoping, for the gap assessment, and for preparing for Level 2.
What is ITSP.10.171?
It is the Canadian Centre for Cyber Security publication that defines the security requirements behind the program. It is adapted from NIST SP 800-171, using Canadian terminology and references.
// more hubs
Keep going
Windows hardening
An ordered path to harden Windows clients and servers, with the official baselines and documentation to build from.
Small business security baseline
A 90-day plan built on the Canadian Centre for Cyber Security baseline controls for small and medium organizations.
Privacy breach response in Canada
A practical sequence for handling a breach involving personal information, covering PIPEDA and Quebec Law 25 duties.