CPCSC

What CPCSC actually requires

The Canadian Program for Cyber Security Certification is the federal government's cyber certification for defence suppliers. Here is what it covers, who runs it, and what each level asks for, sourced from canada.ca.

The program

What CPCSC is, and who runs it

CPCSC protects Specified Information: sensitive, unclassified contractual information that Government of Canada authorities identify in a contract, when it lives on a defence supplier's own networks, systems, or applications. It is not a general small-business security law. It applies where a contract says it applies.

Four organizations run it, and each has a distinct job. Canada.ca's program overview puts it this way:

Public Services and Procurement Canada (PSPC)

"PSPC is the federal lead for the CPCSC, responsible for program coordination across government, development of certification processes, and overall implementation."

Department of National Defence (DND)

"DND performs the highest level of cyber security assessments (Level 3) and collaborates with PSPC to ensure that cyber security requirements reflect the needs of the defence community."

Standards Council of Canada (SCC)

"SCC accredits the certification bodies that conduct external assessments (Level 2) and supports the establishment of a robust and credible certification ecosystem."

Canadian Centre for Cyber Security

Part of CSE, it "developed the Canadian cyber security standard (ITSP.10.171) that forms the foundation of CPCSC controls."

Scope

Which suppliers it applies to

CPCSC applies to defence suppliers handling Specified Information under a federal contract. It shows up as a requirement inside select National Defence solicitations and contracts, not as a blanket rule for every company that sells to the government. Level 1 self-assessment is required at contract award, not during bidding: you complete it, then post the attestation and its expiry date to your CanadaBuys profile and reference it when you submit a bid.

Read the government's own guidance before you assume you are in scope: How to meet Level 1 cyber security certification requirements and the Level 1 scoping guide.

The three levels

Level 1, 2, and 3

Level 1

Live since April 2026

An annual cyber security self-assessment against 13 controls drawn from ITSP.10.171. You attest yourself, no third party is involved. Canada.ca describes it as "requiring an annual cyber security self-assessment (13 controls)."

Level 2

Under development, expected in 2027

An external assessment led by a certification body accredited by the Standards Council of Canada, plus an annual affirmation, against 98 controls. Canada.ca describes it as "requiring external cyber security assessments led by an accredited certification body, plus an annual affirmation (98 controls)."

Level 3

Under development, no date published

An assessment run directly by National Defence, plus an annual affirmation, against 200 controls. Canada.ca states Level 3 "is reserved for the highest risk scenarios."

Source: canada.ca program overview and the April 2026 Level 1 announcement. Level 1 became available to suppliers on April 1, 2026, and requirements began appearing in select defence contracts starting summer 2026. Canada.ca states Level 2 will be added to select defence contracts starting in 2027; Level 3 has no published date.

Control basis

ITSP.10.171 and NIST SP 800-171

Every level of CPCSC is built on ITSP.10.171, "Protecting specified information in non-Government of Canada systems and organizations", published by the Canadian Centre for Cyber Security. It is the Canadian version of NIST SP 800-171, organized into 17 security requirement families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment and monitoring, system and communications protection, system and information integrity, planning, system and services acquisition, and supply chain risk management. The publication took effect April 2, 2025.

Level 1 pulls a 13-control baseline from that standard for cyber hygiene. Level 2 and Level 3 pull far more of it: 98 controls and 200 controls respectively, per canada.ca's own count. Higher levels also draw on NIST SP 800-172's enhanced requirements for information under greater threat.

Timelines

Where things stand today, and what to do first

Level 1 is live now. It has applied as a condition of award in select DND contracts since summer 2026.
Level 2 is under development. Canada.ca says it is expected to start appearing in select defence contracts in 2027.
Level 3 is under development with no published date. It is reserved for the highest-risk work.
If you are a small supplier and none of this is scoped yet, start with the scoping step, not the assessment: identify what Specified Information you actually touch, where it flows, and every asset involved. Canada.ca calls scoping "a business decision" that needs IT, security, and business leadership in the room together, before anyone opens the self-assessment tool.
CPCSC vs CMMC

How it compares to the US program

CPCSC and the US Cybersecurity Maturity Model Certification (CMMC) share a lineage: both are three-level programs built around the NIST SP 800-171 family of controls, and both exist to protect sensitive contractual information sitting on a supplier's own systems. They are not the same certification, and one does not automatically stand in for the other.

Canada.ca does draw one explicit bridge: a supplier can meet CPCSC Level 1 either by completing the annual self-assessment or by "having an existing valid Cybersecurity Maturity Model (CMMC) certification." The catch is scope: "the Government of Canada may accept a contractor's valid CMMC certification on a case-by-case basis, after confirming that the assessment covers the required scope." If you already hold CMMC and expect it to cover CPCSC automatically, confirm that with the contracting authority before you rely on it.

CPCSC FAQ

What is the Canadian Program for Cyber Security Certification?

CPCSC is the federal government’s cyber security certification program for defence suppliers. It protects sensitive but unclassified contractual information, called Specified Information, that sits on supplier networks and systems. Public Services and Procurement Canada is the federal lead.

Who has to get certified?

Defence suppliers whose contracts require it. The contract, not your industry in general, determines whether CPCSC applies, which level, and which systems are in scope. It shows up as a requirement in select National Defence solicitations and contracts, tracked through your CanadaBuys profile.

What is ITSP.10.171?

ITSP.10.171 is the Canadian Centre for Cyber Security’s standard, "Protecting specified information in non-Government of Canada systems and organizations." It is the Canadian version of NIST SP 800-171, organized into 17 security requirement families, and it is the control basis for all three CPCSC levels.

Is CPCSC the same as CMMC?

No, but they are closely related. Both are three-level programs built on the NIST SP 800-171 lineage. Canada.ca states that suppliers may meet Level 1 by completing the self-assessment or "having an existing valid Cybersecurity Maturity Model (CMMC) certification," and that "the Government of Canada may accept a contractor’s valid CMMC certification on a case-by-case basis, after confirming that the assessment covers the required scope." The two programs are not automatically interchangeable beyond that.

How long does Level 1 certification last?

The self-assessment is annual. Canada.ca says the result comes with an expiry date, which you post to your CanadaBuys profile and reference when you submit a bid.

What should a small supplier do first?

Scope it before you assess it. Canada.ca’s Level 1 scoping guide has you identify the Specified Information in your contracts, map where it flows (received, created, stored, emailed, transferred, backed up, destroyed), list every asset that touches it, and then validate that scope against the 13 requirements.

Readiness, not certification

Need help scoping and preparing for CPCSC?

We run the Level 1 self-assessment and Level 2 readiness work: scoping, the gap assessment against ITSP.10.171, policies, and evidence. See what your CPA handles and what we handle.