2026-09-30 · 5 min read

CPCSC Level 1 Self-Assessment: A Step-by-Step Walkthrough

CPCSC Level 1 is a self-assessment: you attest to your own environment, no external assessor reviews it before you submit. That makes the biggest risk not failing an audit, but scoping it wrong or skipping the documentation canada.ca expects you to have on hand if a contracting authority ever asks. This walkthrough follows the government's own scoping guide and "how to meet Level 1" guidance, in order.

Quick answer. The CPCSC Level 1 self-assessment has five stages: scope what Specified Information you hold and where it flows, close any gaps against the 13 required controls, document your internal rules, complete the online self-assessment tool, and post your attestation and expiry date to your CanadaBuys profile. Keep supporting evidence for at least one year.

Step 1: Scope Before You Assess

Canada.ca's Level 1 scoping guide calls scoping "a business decision," not a purely technical exercise, and expects IT, security, and business leadership in the room together before anyone opens the self-assessment tool.

01Identify Your Specified Information

Identify the Specified Information named or implied in your contract: the sensitive but unclassified contractual information a Government of Canada authority has flagged as requiring protection.

02Map Where It Flows

Map every point that information touches: where it is received, created, stored, emailed, transferred, backed up, and eventually destroyed. Canada.ca's scoping guide walks through exactly this lifecycle.

03List Every Asset That Touches It

List every system, device, and account that touches Specified Information anywhere in that flow, not just your primary production environment. A laptop that occasionally receives an email attachment is in scope.

04Validate Scope Against the 13 Requirements

Once you have the asset list, validate it against the 13 Level 1 requirements below. If an asset in your list has no bearing on any of the 13, it may fall outside scope; if it does, it needs to meet every applicable control.

Step 2: Close Gaps Against the 13 Controls

Canada.ca's own Level 1 guidance groups the 13 controls under six practice areas. Close any gaps here before you touch the self-assessment tool.

Access control

  • Manage user accounts
  • Give people only the access they need
  • Use only approved systems and devices
  • Prevent sensitive information from being shared publicly

Identification and authentication

  • Use individual accounts and strong passwords
  • Approve devices before they connect
  • Enable multifactor authentication

Media protection

  • Wipe or destroy old devices before disposal

Physical protection

  • Keep a list of who can access secure areas
  • Control physical entry

Systems and communications protection

  • Use basic network protections

System and information integrity

  • Apply security updates
  • Use antivirus and anti-malware software

Common gap

Common gap: device wiping. Teams that recycle old laptops or hand them down internally often skip a documented wipe or destruction step entirely, which is a direct gap against the media protection control.

For the full picture of how these 13 controls sit inside the larger 17-family ITSP.10.171 structure, and where Level 2 and 3 expand beyond them, see our ITSP.10.171 control families breakdown.

Step 3: Write Your Internal Documentation

Canada.ca's guidance asks you to "make a few internal rules for your organization" before you assess. In practice, this means short, plain documents covering:

  • Password requirements (length, complexity, rotation if you require it)
  • A list of approved systems and devices
  • Your user access request and approval procedure
  • Device management rules, including what happens when a device is retired

These do not need to be long. What matters is that they exist, are followed, and can be produced if a contracting authority asks.

Step 4: Complete the Online Self-Assessment

Once scoping and gap closure are done, complete the self-assessment at the government's tool, cyberpostureassessments.ops.cyber.gc.ca/cpcsc-pccc. Answer against the scope you defined in Step 1, not a broader or narrower environment.

Step 5: Save Your Results and Attest

Print or save the results page. It shows an expiry date for your attestation. Provide proof of your self-attestation and that expiry date to your CanadaBuys profile, so it is on record when you submit a bid that requires Level 1.

Step 6: Retain Your Evidence

Canada.ca expects supporting evidence retained for the duration of your attestation cycle, or at least one year. Keep the internal rules from Step 3, your asset and scoping documentation from Step 1, and the results page from Step 5 together, so you are not reconstructing them under deadline next year.

What Happens When the Attestation Expires

Level 1 is annual. When your expiry date approaches, repeat the process: re-validate your scope (has your environment changed since last year?), re-check the 13 controls, and re-run the self-assessment. A supplier already holding a valid CMMC certification may be able to rely on that instead, on a case-by-case basis, once the Government of Canada confirms it covers the required scope.

Scoping correctly the first time, and keeping the documentation current instead of rebuilding it every renewal, is exactly the readiness work a fractional CISO runs for Canadian defence suppliers. See what your CPA handles and what we handle or book a call.

Related reading

Frequently asked questions

Who completes the CPCSC Level 1 self-assessment?
You do. Level 1 is a self-assessment, not a third-party audit. Canada.ca describes it as an annual cyber security self-assessment against 13 controls, and no external assessor is involved at this level.
Where do I complete the CPCSC Level 1 self-assessment?
At the government's online self-assessment tool, cyberpostureassessments.ops.cyber.gc.ca/cpcsc-pccc. You complete it after scoping your Specified Information and closing any gaps against the 13 controls, not before.
What happens after I complete the self-assessment?
You save or print the results page, which shows an expiry date, and post proof of your self-attestation and that expiry date to your CanadaBuys profile so it can be referenced when you submit a bid.
How long is the Level 1 self-assessment valid for, and what evidence do I need to keep?
The self-assessment is annual. Canada.ca says to retain your supporting evidence for the duration of your attestation cycle, or at least one year, whichever your contract requires.
Can an existing CMMC certification replace the CPCSC Level 1 self-assessment?
Sometimes. Canada.ca states a supplier may meet Level 1 either by completing the self-assessment or by having an existing valid CMMC certification, accepted on a case-by-case basis after the Government of Canada confirms the assessment covers the required scope.

Xorabyte

Get a security leader in your corner.

Xorabyte is a fractional CISO for startups facing SOC 2, security questionnaires, and enterprise security reviews. Tell us what triggered the need and we will map the path.