What CPCSC is
The Canadian Program for Cyber Security Certification (CPCSC) is the Government of Canada's supplier cyber security certification program for defence procurement, run by Public Services and Procurement Canada. It exists to protect unclassified contractual information that suppliers hold while doing defence work, and it makes a supplier's security posture a condition of contract rather than a promise in a proposal.
If you sell into Canadian defence supply chains, directly or through a prime contractor, CPCSC is not optional reading. Level 1 requirements began appearing in select contracts in summer 2026, which means suppliers bidding this season are meeting the requirement for the first time.
The three levels
| Level | What it is | Who checks | Status |
|---|---|---|---|
| Level 1 | Self assessment against baseline requirements drawn from ITSP.10.171, recorded in your CanadaBuys supplier profile and affirmed annually. | You attest; the government relies on your affirmation. | Available since April 2026; mandatory in select contracts since summer 2026. |
| Level 2 | 98 controls based on ITSP.10.171, with a system security plan and evidence behind each control. Recertification every three years, annual affirmation between. | External assessment by a certification body accredited by the Standards Council of Canada. | Expected in select contracts from spring 2027. |
| Level 3 | Additional requirements for the most sensitive unclassified work. | External, with program details still to come. | Introduction planned from April 2027, with Levels 1 and 2 expanding through 2028. |
What Level 1 actually involves
Level 1 is deliberately achievable. It is a self assessment: nobody visits, nobody audits. You assess your organization against the published Level 1 self assessment criteria, record the result in your CanadaBuys supplier profile, and affirm it annually. The criteria are a compact set of baseline requirements drawn from ITSP.10.171, and they concentrate on a handful of themes:
- Accounts and access: individual user accounts, least privilege, and control over connections to and from external systems.
- Authentication: multifactor authentication and managed credentials, including changing vendor defaults.
- Boundaries: separation between the systems that hold contract information and the rest of your network.
- System integrity: patching known flaws and maintaining protection against malicious code.
- Media and physical: sanitizing or destroying media that held contract information, and controlling physical access, including alternate work sites.
The trap in a self assessment is answering hopefully. Every answer should have a record behind it: a policy, a configuration screenshot, a log, an access review. Two reasons. First, your affirmation is a contractual representation. Second, Level 2 is an external assessment of largely the same territory, and the evidence you assemble now is the evidence you will need then.
What Level 2 will ask
Level 2 moves the same discipline up a weight class: 98 controls based on ITSP.10.171, a system security plan describing how each is met, and an external assessor from an accredited certification body checking evidence rather than intentions. Certification is expected to run on a three year cycle with an annual affirmation between assessments.
The practical difference is not the control count. It is that every control needs to be demonstrably operating: not a policy that says patching happens, but patch records; not an access control statement, but access reviews with dates and names. Organizations that treat Level 1 as evidence practice arrive at Level 2 with most of the file already built.
If you already run ISO 27001
ITSP.10.171 is Canada's adaptation of the same family of requirements as NIST SP 800-171, and its territory overlaps heavily with an ISO 27001 information security management system. If you hold or are building 27001, much of the work transfers:
| ITSP.10.171 territory | Where your 27001 work already covers it |
|---|---|
| Access control, identification and authentication | Access control policy, joiner and leaver process, privileged access management, MFA rollout |
| Configuration management, flaw remediation | Change management, hardening baselines, vulnerability and patch management |
| Incident response | Incident management procedure, records, and lessons learned |
| Media protection, physical security | Asset handling, disposal procedure, physical entry controls |
| Audit and accountability | Logging and monitoring controls, internal audit discipline |
| Awareness and training | Security awareness program and training records |
What does not transfer automatically: the scoping concept (CPCSC cares specifically about where contract information lives), the CanadaBuys attestation mechanics, and the control by control evidence mapping an external assessor will want. The efficient path is a mapping exercise first, then closing the genuinely new gaps, rather than standing up a parallel program.
Getting started, in order
- Read your contracts. Find the security clauses in what you hold and what you are bidding. Identify which level applies and when.
- Scope small. Identify exactly which systems, people, and locations touch contract information. Everything you keep out of scope is work you do not do.
- Self assess honestly. Run the Level 1 criteria and record what is true today, not what is planned.
- Close gaps in deadline order. Sequence remediation by when your contracts need it.
- Build the file as you go. Each control fixed produces its own record. Keep them in one place, mapped to the criteria.
- Affirm, and calendar the renewal. Record the attestation in CanadaBuys and put the annual affirmation on a clock someone owns.