01 · CPCSC Readiness

Your next defence contract has security clauses in it.

Canada's defence expansion is pulling thousands of companies into a supply chain with certification requirements attached. CPCSC Level 1 is already in select contracts. The work takes you through Levels 1, 2 and 3, self guided or guided, ending in evidence an assessor will accept.

CPCSC Level 1 entered select defence contracts summer 2026
Level 2: 98 controls, external assessment, expected in select contracts spring 2027
Why now

The buyers are being built right now

The Defence Industrial Strategy, launched February 17, 2026, deliberately pulls new firms into the defence supply chain through its Build, Partner, Buy framework. Most of the companies about to win this work have never been defence contractors, and the security requirements arrive with the contract.

$180B
defence procurement opportunities over 10 years
92%
of Canada's defence industrial base is small and medium enterprises
240%
targeted growth in Canadian defence industry revenues
The obligation

The CPCSC timeline

The Canadian Program for Cyber Security Certification phases in through 2028. Where your contracts sit on this line decides how much work you need, and when.

April 2026

Level 1 available

Suppliers self assess against baseline requirements drawn from ITSP.10.171 and record their attestation in their CanadaBuys supplier profile, affirmed annually.

Summer 2026 · in force

Level 1 mandatory in select contracts

Suppliers bidding this season are hitting the requirement for the first time. This is the live obligation today.

Spring 2027

Level 2 enters select contracts

98 controls based on ITSP.10.171, external assessment by a certification body accredited by the Standards Council of Canada, recertification every three years with annual affirmation between.

April 2027 onward

Level 3 introduced; expansion through 2028

Levels 1 and 2 progressively expand across applicable defence contracts.

Note: Level 2 dates can move. The preparation keeps its value either way; primes already ask for proof.
The work

Choose your level

The same arc at every level: understand what applies, put proportionate safeguards in place, prove it with evidence, and keep it current as requirements evolve.

Level 1 · available now

Most suppliers get stuck at the same points: knowing whether the requirement applies to them, knowing where to start, and turning the published criteria into things their own team can actually do. That is the work.

We start by reading your contracts and telling you plainly what applies and what does not. Then we take you through it end to end: scoping the systems that actually hold contract information, a gap assessment against the 13 requirements with a prioritized action list, the documentation and evidence behind each answer, guided support through the self assessment, and the CanadaBuys affirmation with renewal tracking so it holds year over year.

Starting from $750 CAD

Level 2 · prepare now

Level 2 brings external assessment, and the preparation is a build, not a document exercise: a defined boundary, working technical controls, and evidence that operates. For most suppliers the honest question is not whether to prepare, but how much of it they already have.

So the work begins there: boundary scoping and a gap assessment that maps what you already run, including anything built for ISO 27001 or CMMC aligned work, so you do not start from zero. It produces a sequenced remediation register, and the readiness programme that follows, remediation support, evidence architecture, and preparation for external assessment, is quoted from that register.

Quoted after scoping

Level 3 · highest sensitivity

For the small set of suppliers on the highest sensitivity defence work. Preparation is shaped by the specific contract, system boundary, and information sensitivity, so each engagement is scoped individually.

Quoted after scoping
Independence: ascio prepares; we do not certify. Levels 2 and 3 will require independent external certification, and the program is still finalizing the assessment details. We get you ready for whatever form they take.
How the engagement runs

Nine steps, contract to sustainment

The same sequence in both delivery modes. Self guided, your team runs it with ascio reviewing at fixed points; guided, ascio runs it with you. Every stage produces an artifact you keep.

  1. Contract triage

    Read the live or target contracts. Identify the security clauses, the CPCSC level required, and what contractual information you will actually hold.

  2. Scope definition

    Which systems, people, and locations touch that information. Small and defensible is the goal; scope is the main cost lever.

  3. Level 1 readiness check

    Assessment against the actual attestation criteria, producing a gap register.

  4. Remediation plan

    Gaps mapped to ITSP.10.171 controls and sequenced by contract deadline.

  5. Implementation

    Your team executes. We design, support, and verify as controls land.

  6. Evidence assembly

    Policies, configurations, and records an assessor would ask for, each mapped to a control.

  7. Attestation

    Level 1 affirmation recorded in your CanadaBuys supplier profile, with the file behind it.

  8. Level 2 preparation

    If your contracts will require it: system security plan, evidence program, mock assessment.

  9. Ongoing cycle

    Annual affirmation, flow down to your own suppliers, recertification readiness.

What you walk away with

Artifacts, not advice

  • A defined, defensible scope for contract information
  • A gap register against the Level 1 criteria, and against ITSP.10.171 where Level 2 applies
  • A remediation plan sequenced by your contract dates
  • An evidence pack mapped control by control
  • A recorded attestation with records that survive scrutiny
  • An annual affirmation calendar so readiness holds
Afterwards

Ongoing support

Most clients keep us on after the initial work. The Assurance Desk maintains your evidence, manages your renewal dates, and handles new questionnaires as they arrive. Starting from $495 CAD per month.

Questions

Asked often

Is CPCSC Level 1 a certification?

No. Level 1 is a self assessment: you assess against the published criteria and record your affirmation in your CanadaBuys supplier profile, then affirm annually. External certification arrives at Level 2, expected in select contracts from spring 2027.

We already hold ISO 27001. Does that cover CPCSC?

It helps materially. ITSP.10.171 and ISO 27001 overlap heavily, and existing ISMS evidence usually shortens the work. But the CPCSC criteria are their own set, and the attestation is separate. We map what you have before building anything new.

When does Level 2 apply to us?

Level 2 enters select contracts in spring 2027, with 98 controls based on ITSP.10.171 and assessment by an externally accredited certification body. Whether it lands in your contracts depends on what you bid on. Reading those clauses is the first step of the engagement.

How long does Level 1 readiness take?

It depends almost entirely on scope. A supplier with contract information confined to a small set of systems moves quickly; a flat network takes longer. The gap register lands early either way, so you see the size of the work before the build starts.

What decides the price?

Your environment: the number of systems in scope, existing controls, and how much evidence already exists. Starting prices cover typical single environment suppliers.

Bidding on a contract with security clauses?

Start with the free Level 1 readiness check. Five minutes, mapped to the self assessment criteria, and the report shows you what an assessor would ask next.