CPCSC Level 1 Self-Assessment: A Step-by-Step Walkthrough
CPCSC Level 1 is a self-assessment: you attest to your own environment, no external assessor reviews it before you submit. That makes the biggest risk not failing an audit, but scoping it wrong or skipping the documentation canada.ca expects you to have on hand if a contracting authority ever asks. This walkthrough follows the government's own scoping guide and "how to meet Level 1" guidance, in order.
Quick answer. The CPCSC Level 1 self-assessment has five stages: scope what Specified Information you hold and where it flows, close any gaps against the 13 required controls, document your internal rules, complete the online self-assessment tool, and post your attestation and expiry date to your CanadaBuys profile. Keep supporting evidence for at least one year.
Step 1: Scope Before You Assess
Canada.ca's Level 1 scoping guide calls scoping "a business decision," not a purely technical exercise, and expects IT, security, and business leadership in the room together before anyone opens the self-assessment tool.
Identify the Specified Information named or implied in your contract: the sensitive but unclassified contractual information a Government of Canada authority has flagged as requiring protection.
Map every point that information touches: where it is received, created, stored, emailed, transferred, backed up, and eventually destroyed. Canada.ca's scoping guide walks through exactly this lifecycle.
List every system, device, and account that touches Specified Information anywhere in that flow, not just your primary production environment. A laptop that occasionally receives an email attachment is in scope.
Once you have the asset list, validate it against the 13 Level 1 requirements below. If an asset in your list has no bearing on any of the 13, it may fall outside scope; if it does, it needs to meet every applicable control.
Step 2: Close Gaps Against the 13 Controls
Canada.ca's own Level 1 guidance groups the 13 controls under six practice areas. Close any gaps here before you touch the self-assessment tool.
Access control
- Manage user accounts
- Give people only the access they need
- Use only approved systems and devices
- Prevent sensitive information from being shared publicly
Identification and authentication
- Use individual accounts and strong passwords
- Approve devices before they connect
- Enable multifactor authentication
Media protection
- Wipe or destroy old devices before disposal
Physical protection
- Keep a list of who can access secure areas
- Control physical entry
Systems and communications protection
- Use basic network protections
System and information integrity
- Apply security updates
- Use antivirus and anti-malware software
Common gap
Common gap: device wiping. Teams that recycle old laptops or hand them down internally often skip a documented wipe or destruction step entirely, which is a direct gap against the media protection control.
For the full picture of how these 13 controls sit inside the larger 17-family ITSP.10.171 structure, and where Level 2 and 3 expand beyond them, see our ITSP.10.171 control families breakdown.
Step 3: Write Your Internal Documentation
Canada.ca's guidance asks you to "make a few internal rules for your organization" before you assess. In practice, this means short, plain documents covering:
- Password requirements (length, complexity, rotation if you require it)
- A list of approved systems and devices
- Your user access request and approval procedure
- Device management rules, including what happens when a device is retired
These do not need to be long. What matters is that they exist, are followed, and can be produced if a contracting authority asks.
Step 4: Complete the Online Self-Assessment
Once scoping and gap closure are done, complete the self-assessment at the government's tool, cyberpostureassessments.ops.cyber.gc.ca/cpcsc-pccc. Answer against the scope you defined in Step 1, not a broader or narrower environment.
Step 5: Save Your Results and Attest
Print or save the results page. It shows an expiry date for your attestation. Provide proof of your self-attestation and that expiry date to your CanadaBuys profile, so it is on record when you submit a bid that requires Level 1.
Step 6: Retain Your Evidence
Canada.ca expects supporting evidence retained for the duration of your attestation cycle, or at least one year. Keep the internal rules from Step 3, your asset and scoping documentation from Step 1, and the results page from Step 5 together, so you are not reconstructing them under deadline next year.
What Happens When the Attestation Expires
Level 1 is annual. When your expiry date approaches, repeat the process: re-validate your scope (has your environment changed since last year?), re-check the 13 controls, and re-run the self-assessment. A supplier already holding a valid CMMC certification may be able to rely on that instead, on a case-by-case basis, once the Government of Canada confirms it covers the required scope.
Scoping correctly the first time, and keeping the documentation current instead of rebuilding it every renewal, is exactly the readiness work a fractional CISO runs for Canadian defence suppliers. See what your CPA handles and what we handle or book a call.