Your next defence contract has security clauses in it.
Canada's defence expansion is pulling thousands of companies into a supply chain with certification requirements attached. CPCSC Level 1 is already in select contracts. The work takes you through Levels 1, 2 and 3, self guided or guided, ending in evidence an assessor will accept.
The buyers are being built right now
The Defence Industrial Strategy, launched February 17, 2026, deliberately pulls new firms into the defence supply chain through its Build, Partner, Buy framework. Most of the companies about to win this work have never been defence contractors, and the security requirements arrive with the contract.
The CPCSC timeline
The Canadian Program for Cyber Security Certification phases in through 2028. Where your contracts sit on this line decides how much work you need, and when.
Level 1 available
Suppliers self assess against baseline requirements drawn from ITSP.10.171 and record their attestation in their CanadaBuys supplier profile, affirmed annually.
Level 1 mandatory in select contracts
Suppliers bidding this season are hitting the requirement for the first time. This is the live obligation today.
Level 2 enters select contracts
98 controls based on ITSP.10.171, external assessment by a certification body accredited by the Standards Council of Canada, recertification every three years with annual affirmation between.
Level 3 introduced; expansion through 2028
Levels 1 and 2 progressively expand across applicable defence contracts.
Choose your level
The same arc at every level: understand what applies, put proportionate safeguards in place, prove it with evidence, and keep it current as requirements evolve.
Level 1 · available now
Most suppliers get stuck at the same points: knowing whether the requirement applies to them, knowing where to start, and turning the published criteria into things their own team can actually do. That is the work.
We start by reading your contracts and telling you plainly what applies and what does not. Then we take you through it end to end: scoping the systems that actually hold contract information, a gap assessment against the 13 requirements with a prioritized action list, the documentation and evidence behind each answer, guided support through the self assessment, and the CanadaBuys affirmation with renewal tracking so it holds year over year.
Level 2 · prepare now
Level 2 brings external assessment, and the preparation is a build, not a document exercise: a defined boundary, working technical controls, and evidence that operates. For most suppliers the honest question is not whether to prepare, but how much of it they already have.
So the work begins there: boundary scoping and a gap assessment that maps what you already run, including anything built for ISO 27001 or CMMC aligned work, so you do not start from zero. It produces a sequenced remediation register, and the readiness programme that follows, remediation support, evidence architecture, and preparation for external assessment, is quoted from that register.
Level 3 · highest sensitivity
For the small set of suppliers on the highest sensitivity defence work. Preparation is shaped by the specific contract, system boundary, and information sensitivity, so each engagement is scoped individually.
Nine steps, contract to sustainment
The same sequence in both delivery modes. Self guided, your team runs it with ascio reviewing at fixed points; guided, ascio runs it with you. Every stage produces an artifact you keep.
- Contract triage
Read the live or target contracts. Identify the security clauses, the CPCSC level required, and what contractual information you will actually hold.
- Scope definition
Which systems, people, and locations touch that information. Small and defensible is the goal; scope is the main cost lever.
- Level 1 readiness check
Assessment against the actual attestation criteria, producing a gap register.
- Remediation plan
Gaps mapped to ITSP.10.171 controls and sequenced by contract deadline.
- Implementation
Your team executes. We design, support, and verify as controls land.
- Evidence assembly
Policies, configurations, and records an assessor would ask for, each mapped to a control.
- Attestation
Level 1 affirmation recorded in your CanadaBuys supplier profile, with the file behind it.
- Level 2 preparation
If your contracts will require it: system security plan, evidence program, mock assessment.
- Ongoing cycle
Annual affirmation, flow down to your own suppliers, recertification readiness.
Artifacts, not advice
- A defined, defensible scope for contract information
- A gap register against the Level 1 criteria, and against ITSP.10.171 where Level 2 applies
- A remediation plan sequenced by your contract dates
- An evidence pack mapped control by control
- A recorded attestation with records that survive scrutiny
- An annual affirmation calendar so readiness holds
Ongoing support
Most clients keep us on after the initial work. The Assurance Desk maintains your evidence, manages your renewal dates, and handles new questionnaires as they arrive. Starting from $495 CAD per month.
Asked often
Is CPCSC Level 1 a certification?
No. Level 1 is a self assessment: you assess against the published criteria and record your affirmation in your CanadaBuys supplier profile, then affirm annually. External certification arrives at Level 2, expected in select contracts from spring 2027.
We already hold ISO 27001. Does that cover CPCSC?
It helps materially. ITSP.10.171 and ISO 27001 overlap heavily, and existing ISMS evidence usually shortens the work. But the CPCSC criteria are their own set, and the attestation is separate. We map what you have before building anything new.
When does Level 2 apply to us?
Level 2 enters select contracts in spring 2027, with 98 controls based on ITSP.10.171 and assessment by an externally accredited certification body. Whether it lands in your contracts depends on what you bid on. Reading those clauses is the first step of the engagement.
How long does Level 1 readiness take?
It depends almost entirely on scope. A supplier with contract information confined to a small set of systems moves quickly; a flat network takes longer. The gap register lands early either way, so you see the size of the work before the build starts.
What decides the price?
Your environment: the number of systems in scope, existing controls, and how much evidence already exists. Starting prices cover typical single environment suppliers.