CPCSC: cyber security requirements for Canadian defence suppliers
CPCSC is the Government of Canada’s cyber security program for defence suppliers, led by Public Services and Procurement Canada and National Defence and being phased into selected defence contracts. It has three levels, built on the Cyber Centre’s ITSP.10.171 standard, which is closely adapted from NIST SP 800-171. Level 1 became available in April 2026; if you sell to National Defence, the time to prepare is now.
What are the three CPCSC levels?
| Level | Controls | Assessed by | Planned in contracts (as of September 2026) |
|---|---|---|---|
| 1 | 13 | You: annual self-assessment, declared to the government | Some contracts, starting summer 2026 |
| 2 | 98 | One of the accredited certification bodies, every three years, plus annual affirmation | Some contracts, starting spring 2027 |
| 3 | 200 | National Defence every three years, plus annual affirmation | Reserved for the highest-risk work |
The figures are from PSPC’s program overview and its April 2026 backgrounder, as of September 2026. Treat the dates as the government’s stated plan and confirm them against each solicitation.
What is the ITSP.10.171 standard based on?
ITSP.10.171 protects “specified information” held on non-government systems: any information, other than classified, that a Government of Canada authority identifies in a contract as requiring safeguarding. PSPC describes it as closely adapted from NIST SP 800-171 and 800-172, and the Level 1 criteria as having no substantial technical changes from NIST SP 800-171A Rev. 3.
The 13 Level 1 controls are basic hygiene: account management and access enforcement, use of external systems, publicly accessible content, user and device authentication, multi-factor authentication, media sanitization, physical access, boundary protection, flaw remediation and malicious code protection. The full list is in the Level 1 criteria.
When does a contract require CPCSC?
Do you have to meet Level 1 before you bid? Not in the initial phase. Public Services and Procurement Canada has said meeting Level 1 will be required on contract award rather than throughout the bidding process, which buys time to prepare but not time to start from zero.
The level is set contract by contract through a cyber security risk assessment and stated in the solicitation and contract clauses. PSPC gives administrative support and basic IT with no sensitive data as self-assessment territory, and names controlled defence information, weapon systems, critical infrastructure access and information shared with Five Eyes partners as work for Level 2 or 3.
How does CPCSC relate to CMMC?
CPCSC uses the same underlying technical controls as the US CMMC, but Canada runs it separately, with its own assessors. Does a CMMC status count? Possibly, but not automatically. Canada may accept a valid CMMC status case by case, after confirming the assessment covers the required scope, and may still verify specific controls. If you sell to both governments, build once against NIST SP 800-171 and keep one evidence set mapped to both.
What should a defence supplier do first?
- Find where specified information actually lives, and keep that environment small. Scope drives every later cost.
- Run the Level 1 self-assessment honestly against the 13 controls.
- Close gaps before you declare. A Level 1 declaration is a statement to the Government of Canada; make it only when it is true.
- If your work touches controlled defence information, plan for a Level 2 assessment now rather than when a contract asks for it.
The myth to drop: that Level 1 is paperwork. Multi-factor authentication, patching and boundary protection are operational controls, and an assessor at Level 2 will test them. For a broader baseline, see NIST CSF 2.0 in plain terms and security for BC public sector vendors.
Where we fit
Level 1 is your own self-assessment, which you declare to the government; Level 2 is assessed by one of the accredited certification bodies recognized through the Standards Council of Canada; and Level 3 by National Defence. We help you get ready for each; we do not issue any of them. Scoping, gap analysis and evidence are our regulated-sector readiness work.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
When does CPCSC apply to our contracts?
As of September 2026, Level 1 has been available to suppliers since 1 April 2026, and the government’s stated plan was to include it in selected defence contracts starting summer 2026, with Level 2 planned from spring 2027. The solicitation itself says which level, if any, a contract requires.
Do we have to meet Level 1 before we bid?
Not in the initial phase. Public Services and Procurement Canada has said meeting Level 1 will be required on contract award rather than throughout the bidding process, which buys time to prepare but not time to start from zero.
Does CMMC status count?
Possibly, but not automatically. Canada may accept a valid CMMC status case by case, after confirming the assessment covers the required scope, and may still verify specific controls.
Who assesses each level?
Level 1 is your own self-assessment, which you declare to the government; Level 2 is assessed by one of the accredited certification bodies recognized through the Standards Council of Canada; and Level 3 by National Defence. We help you get ready for each; we do not issue any of them.
Getting ready for Level 1 and Level 2
Send us the security clauses from the solicitation and a rough picture of your environment. The reply says what is in scope and what is missing. More of our writing is indexed at writing.