CPCSC readiness: what your CPA handles, and what we handle
Your CPA keeps the financial side of a defence contract in order. The security readiness work is a separate job, and that is where we come in: scoping, the ITSP.10.171 gap assessment, controls, and your Level 1 self-assessment.
Your accountant, your assessor, and your readiness work are three different jobs
What your CPA or an accredited body handles
- Keep the books, tax, and contract finances in order, including the billing and cost records a defence contract depends on.
- Spot the CPCSC clause when a new contract lands, and point you to readiness help early, before the deadline gets tight.
- If the firm is accredited by the Standards Council of Canada for it, carry out the Level 2 external assessment once that level is live.
The readiness work, which is ours
- Scope which systems and information count as Specified Information under your contract.
- Run the gap assessment against ITSP.10.171 or tell you which of the 13, 98, or 200 controls you are missing.
- Write your policies, implement access controls, or configure your systems.
- Build the System Security Plan and remediation tracker (the CPCSC equivalent of an SSP and POA&M) that an assessor will expect to see.
- Collect and organize the evidence an assessment needs.
- Run your Level 1 self-assessment for you. You attest to your own environment.
Level 2 certification is issued by a certification body accredited by the Standards Council of Canada, per canada.ca's program overview. That is a separate accreditation from the one a CPA firm uses to sign a financial audit or a SOC 2 report. We have not found a public list of SCC-accredited CPCSC bodies yet, and Level 2 is expected in 2027.
The readiness work, end to end
We are not an accredited certification body and we do not issue CPCSC certification. Level 2 external assessment, once it exists, comes from a body accredited by the Standards Council of Canada. Read what CPCSC requires for the full program breakdown.
Two engagements, our published rates
CPCSC Level 1 self-assessment
Scoping your Specified Information, a gap check against the 13 Level 1 controls, the fixes to close what is missing, and the self-assessment itself, run to the scope of our Audit-Readiness Gap Assessment.
CPCSC Level 2 readiness
Full readiness ahead of an external assessment: scoping, the ITSP.10.171 gap assessment, policies and controls, your System Security Plan and remediation tracker, and evidence, run to the scope of our SOC 2 Readiness Sprint. Level 2 is not live yet; this gets you ahead of it.
Every number is published on our pricing page. No quote wall.
For CPA and audit firms
If a client of yours has a CPCSC clause in a defence contract, send them our way. We run the readiness work and stay out of the accounting and assurance work. We don't pay or accept referral fees, so nothing touches your independence. How our partner program works.
CPCSC readiness FAQ
Can my CPA firm certify me for CPCSC?
Only if that firm is separately accredited by the Standards Council of Canada as a CPCSC Level 2 certification body, once Level 2 is live. That is a different accreditation from the one that licenses CPA firms to do financial audits or SOC 2 attestations. We have not found a published list of SCC-accredited CPCSC Level 2 bodies yet. If your firm plans to offer it, they can tell you.
What does a CPA or accountant actually do for CPCSC?
They keep the financial side of the business and the contract in order, and they are often the first to spot a CPCSC clause and flag it. A CPA firm could also carry out Level 2 assessments if it becomes accredited by the Standards Council of Canada for that. Scoping, controls, and the Level 1 self-assessment are security work, which is where a readiness partner like us comes in.
What is the readiness work an auditor or assessor cannot do for me?
Scoping, the gap assessment against ITSP.10.171, writing and implementing policies and controls, building the System Security Plan and remediation tracker, collecting evidence, and running the Level 1 self-assessment itself. An assessor checks your work. They do not build it, and for Level 1, nobody but you signs the attestation.
What does Xorabyte charge for CPCSC readiness?
The same published pricing that covers our SOC 2 and general audit-readiness work. A CPCSC Level 1 self-assessment engagement fits the scope of our Audit-Readiness Gap Assessment, $6,000 to $9,000. A full Level 2 readiness engagement, scoping through evidence, fits the scope of our Readiness Sprint, $12,000 to $20,000. Every number is on the pricing page, no quote wall.
Does Xorabyte issue the certification?
No. We are not an accredited certification body and we do not certify anyone. We do the readiness work: scoping, the gap assessment, policies, controls, your System Security Plan, evidence, and the Level 1 self-assessment. Level 2 certification, once it exists, is issued by a body accredited by the Standards Council of Canada.
We are a small supplier and have not started. Where do we begin?
Scoping, before anything else. Identify what Specified Information your contract actually involves, map where it flows, and list every system and person that touches it. That is exactly what canada.ca’s own Level 1 scoping guide walks through, and it is the first thing we do together on a readiness engagement.
Start with a scoping call.
Tell us which contract is driving this. You leave the call knowing what Specified Information you hold and what it will take to get ready.