AuditGround

Canada's CPCSC certification: what defence suppliers need to know

Guide · Regulation · Last reviewed: August 2026

If your company sells to Canada's Department of National Defence, or hopes to, a new requirement now sits between you and some of those contracts. The Canadian Program for Cyber Security Certification, or CPCSC, is Canada's first mandatory cyber security certification for defence suppliers. Level 1 became available to suppliers in April 2026 and starts appearing in select defence contracts from summer 2026. This guide explains what it is, what Level 1 actually asks of you, how it connects to the American CMMC and to ISO 27001, and what a supplier should do before it turns up in a solicitation.

The short version
  • CPCSC is a contract gate. When a defence contract requires it, a supplier that cannot certify at the stated level is not eligible for that work.
  • Level 1 is an annual self-assessment against 13 controls. No external assessor, no fee to a certification body.
  • It is required at contract award, not during bidding, and only on contracts that call for it.
  • A valid US CMMC certification may be accepted case by case, after Canada confirms it covers the right scope.
  • Levels 2 (98 controls) and 3 (200 controls), which involve external assessment against far larger control sets, follow in later years.

What CPCSC is, and why it exists

Canada funded the program through its Defence Industrial Strategy, with the stated aim of protecting sensitive government information held on suppliers' systems and keeping Canadian defence supply chains interoperable with allies. The controls themselves are built on the Canadian Centre for Cyber Security's industrial standard, ITSP.10.171, which in turn draws on the same American NIST foundation that underpins the US CMMC program. That shared ancestry is the single most useful thing for a supplier to understand, and we come back to it below.

The information CPCSC protects is called Specified Information: sensitive but unclassified government data that a contract identifies as needing protection when a supplier handles, processes or stores it. Contract details not meant for public release, controlled goods information, and protected information all fall inside that boundary. If a contract never puts Specified Information on your systems, the requirement may not attach to you at all, which is why scoping matters before you assume you need to act.

The three levels

Level 1: annual self-assessment

Thirteen controls covering basic cyber hygiene. You assess your own implementation, attest to it, and keep the evidence. No third party is involved. This is where most small and mid-sized suppliers start, and it is the level active now.

Level 2: external assessment

A far larger control set — 98 controls — assessed by an accredited certification body on a recurring cycle, plus an annual affirmation. Aimed at suppliers handling more sensitive information. Under development; expected to enter select contracts in later phases, not yet in force.

Level 3: assessed by National Defence

The most demanding tier — 200 controls — with assessment conducted by National Defence itself, plus an annual affirmation. Reserved for the highest-sensitivity work and scheduled for a later phase of the rollout.

The rollout is deliberately phased so suppliers and assessors have time to adapt. For most companies reading this, Level 1 is the immediate question and the rest is planning.

What Level 1 actually asks: the 13 controls

The 13 controls sit under six ordinary categories of cyber hygiene. None of them require a formal security program or expensive tooling. Most are documentation and discipline: know what you have, control who can reach it, keep it patched, and be able to show you do these things. Here is the shape of it.

Access control

  • Keep a current list of user accounts and disable them promptly when people leave
  • Give each person only the access their job needs
  • Restrict work to approved systems and devices
  • Stop sensitive information reaching public channels

Identification and authentication

  • Individual logins and strong passwords, with screens that lock when idle
  • Approve devices before they connect to your network
  • Multifactor authentication on privileged accounts and systems holding Specified Information

Media protection

  • Wipe or physically destroy storage before disposal, and log what you disposed of

Physical protection

  • Track who can enter areas holding sensitive information
  • Control physical entry, escort visitors, and store printed material securely

Systems and communications

  • Basic network protection: a firewall, blocked unnecessary inbound traffic, public systems separated from internal ones

System and information integrity

  • Apply security updates and patch quickly
  • Run reputable antivirus with automatic updates and real-time scanning

A supplier that already runs a tidy IT operation will recognise most of this. The work is usually less about buying anything and more about writing down what you do, filling the gaps the self-assessment exposes, and keeping the evidence where you can produce it. Canada provides an online self-assessment tool, and for an organisation that already knows its own environment the assessment is designed to be quick to complete.

The evidence you keep

Level 1 is an attestation, but attestation without evidence is thin. Keep account and device lists, access-review notes, your written policies, training records, update and patching logs, visitor logs, firewall settings and MFA configuration screens, for at least your attestation cycle. The standard Canada sets is proportionate: the evidence does not need to be elaborate, it needs to exist and match how you actually operate. A supplier that manufactures paperwork the week before award, with nothing behind it, is not meeting the intent and would struggle if a technical authority looked closely.

How CPCSC relates to CMMC and ISO 27001

This is where suppliers selling into more than one market should pay attention, because the overlap can save real work, and misreading it can waste it.

CPCSC and the US CMMC share the same NIST-based ancestry. That means the evidence you assemble for one often repackages for the other, and Canada may accept a valid CMMC certification in place of a CPCSC self-assessment, on a case-by-case basis, after confirming the CMMC assessment covered the right scope. Recognition currently runs one way and is not automatic: a CMMC certificate can help with a Canadian contract, but Canada confirms scope case by case and may verify specific controls, and your Canadian attestation and expiry are still recorded to your CanadaBuys profile. Do not assume automatic reciprocity in either direction, and do not assume the two scopes are identical.

ISO 27001 helps but does not substitute. An existing ISO 27001 management system means many of the underlying practices are already in place, which makes the Level 1 self-assessment faster to complete. It does not replace the CPCSC filing, and holding it is not the same as being certified under CPCSC. Treat it as a head start, not a shortcut around the requirement.

What to do now

The most common mistake in the early phase is to over-react or under-react. Two things are worth stating plainly. First, not every defence solicitation requires CPCSC yet, and the requirement attaches at contract award rather than during bidding, so a supplier does not need Level 1 in hand to bid on work that lists it. Second, when a contract does require it, you cannot manufacture cyber hygiene overnight, so waiting until award to start is the wrong bet.

A sensible path for a supplier that expects to pursue Government of Canada defence work: find out where Specified Information would live in your systems, run the Level 1 self-assessment against the 13 controls to see where you stand, close the gaps the assessment exposes, write the short policies the controls expect, and keep the evidence current. If you already hold ISO 27001 or a CMMC certification, map what you have against the 13 controls first, since much of the work may be done. Make sure you have an active CanadaBuys account if you intend to bid on or hold contracts that require Level 1, because that is where the attestation and expiry date are recorded.

None of this requires a large budget. It requires knowing your own environment, doing the basics properly, and being able to prove it. For most suppliers, that is the whole of Level 1.

CPCSC is now part of Canadian defence procurement rather than a future plan. For a supplier that keeps a reasonable IT operation, Level 1 is achievable without new spending. The suppliers who will struggle are the ones who wait until a contract requires it and discover, at award, that the evidence does not exist. The work is small; the timing is the risk.

Sources: Public Services and Procurement Canada and the Canadian Centre for Cyber Security (CPCSC programme pages, the April 2026 announcement, and ITSP.10.171). This guide summarises publicly available government information for buyers and is not legal or procurement advice. Confirm current requirements against the official Canada.ca pages before acting.