Guide · Defence Supplier Security

The Canadian defence supplier's guide to CPCSC

What the Canadian Program for Cyber Security Certification is, when each level actually bites, what the Level 1 self assessment involves, and how to get ready without doing the work twice.

Published August 21, 2026 · facts verified against the sources listed at the end · educational, not legal advice

What CPCSC is

The Canadian Program for Cyber Security Certification (CPCSC) is the Government of Canada's supplier cyber security certification program for defence procurement, run by Public Services and Procurement Canada. It exists to protect unclassified contractual information that suppliers hold while doing defence work, and it makes a supplier's security posture a condition of contract rather than a promise in a proposal.

If you sell into Canadian defence supply chains, directly or through a prime contractor, CPCSC is not optional reading. Level 1 requirements began appearing in select contracts in summer 2026, which means suppliers bidding this season are meeting the requirement for the first time.

The three levels

LevelWhat it isWho checksStatus
Level 1Self assessment against baseline requirements drawn from ITSP.10.171, recorded in your CanadaBuys supplier profile and affirmed annually.You attest; the government relies on your affirmation.Available since April 2026; mandatory in select contracts since summer 2026.
Level 298 controls based on ITSP.10.171, with a system security plan and evidence behind each control. Recertification every three years, annual affirmation between.External assessment by a certification body accredited by the Standards Council of Canada.Expected in select contracts from spring 2027.
Level 3Additional requirements for the most sensitive unclassified work.External, with program details still to come.Introduction planned from April 2027, with Levels 1 and 2 expanding through 2028.
A date worth watching: the mandatory third party assessment model behind Level 2 is under public policy debate, including an August 2026 commentary arguing Canada should keep the standards but pause the assessment mandate, noting the United States paused its equivalent. Nothing has changed officially. Treat spring 2027 as a date that can move, and build readiness that pays off regardless: the controls are the same either way, and primes already ask suppliers for proof.

What Level 1 actually involves

Level 1 is deliberately achievable. It is a self assessment: nobody visits, nobody audits. You assess your organization against the published Level 1 self assessment criteria, record the result in your CanadaBuys supplier profile, and affirm it annually. The criteria are a compact set of baseline requirements drawn from ITSP.10.171, and they concentrate on a handful of themes:

  • Accounts and access: individual user accounts, least privilege, and control over connections to and from external systems.
  • Authentication: multifactor authentication and managed credentials, including changing vendor defaults.
  • Boundaries: separation between the systems that hold contract information and the rest of your network.
  • System integrity: patching known flaws and maintaining protection against malicious code.
  • Media and physical: sanitizing or destroying media that held contract information, and controlling physical access, including alternate work sites.

The trap in a self assessment is answering hopefully. Every answer should have a record behind it: a policy, a configuration screenshot, a log, an access review. Two reasons. First, your affirmation is a contractual representation. Second, Level 2 is an external assessment of largely the same territory, and the evidence you assemble now is the evidence you will need then.

What Level 2 will ask

Level 2 moves the same discipline up a weight class: 98 controls based on ITSP.10.171, a system security plan describing how each is met, and an external assessor from an accredited certification body checking evidence rather than intentions. Certification is expected to run on a three year cycle with an annual affirmation between assessments.

The practical difference is not the control count. It is that every control needs to be demonstrably operating: not a policy that says patching happens, but patch records; not an access control statement, but access reviews with dates and names. Organizations that treat Level 1 as evidence practice arrive at Level 2 with most of the file already built.

If you already run ISO 27001

ITSP.10.171 is Canada's adaptation of the same family of requirements as NIST SP 800-171, and its territory overlaps heavily with an ISO 27001 information security management system. If you hold or are building 27001, much of the work transfers:

ITSP.10.171 territoryWhere your 27001 work already covers it
Access control, identification and authenticationAccess control policy, joiner and leaver process, privileged access management, MFA rollout
Configuration management, flaw remediationChange management, hardening baselines, vulnerability and patch management
Incident responseIncident management procedure, records, and lessons learned
Media protection, physical securityAsset handling, disposal procedure, physical entry controls
Audit and accountabilityLogging and monitoring controls, internal audit discipline
Awareness and trainingSecurity awareness program and training records

What does not transfer automatically: the scoping concept (CPCSC cares specifically about where contract information lives), the CanadaBuys attestation mechanics, and the control by control evidence mapping an external assessor will want. The efficient path is a mapping exercise first, then closing the genuinely new gaps, rather than standing up a parallel program.

Getting started, in order

  1. Read your contracts. Find the security clauses in what you hold and what you are bidding. Identify which level applies and when.
  2. Scope small. Identify exactly which systems, people, and locations touch contract information. Everything you keep out of scope is work you do not do.
  3. Self assess honestly. Run the Level 1 criteria and record what is true today, not what is planned.
  4. Close gaps in deadline order. Sequence remediation by when your contracts need it.
  5. Build the file as you go. Each control fixed produces its own record. Keep them in one place, mapped to the criteria.
  6. Affirm, and calendar the renewal. Record the attestation in CanadaBuys and put the annual affirmation on a clock someone owns.

Five minutes tells you where you stand.

The free readiness check maps to the Level 1 self assessment criteria and shows you what an assessor would ask next.