// REFERENCE HUB · CANADIAN PROGRAM FOR CYBER SECURITY CERTIFICATION

CPCSC, explained

  • Owner: PSPC
  • Standard: ITSP.10.171, 2nd release
  • Level 1: live
  • Level 2: spring 2027
  • Last verified: 2026-10-05

CPCSC is Canada's mandatory cyber security certification for defense suppliers. If your systems hold Specified Information under a Department of National Defence contract, a certification level is becoming a condition of contract award, and it follows the data down to every subcontractor that touches it. Level 1 went live in April 2026. Level 2 third-party assessments are planned for select contracts from spring 2027.

This hub tracks the program as it moves. Every page carries a last-verified date, and the updates log records what changed and when, including PSPC's revision of the program overview on September 29, 2026.

The companion book, The Study Guide to CPCSC Readiness, is free to read, and the controls, audit scripts, and data behind it are open in the CPCSC repository on GitHub.

// STATUS · VERIFIED 2026-10-05
  • LIVE

    Level 1 self-assessment through CanadaBuys since April 1, 2026, and in select defense contracts since summer 2026.

  • SPRING 2027

    Level 2 third-party assessments planned for select contracts. Standards Council of Canada accreditation of certification bodies is under way, and a completed Level 1 self-assessment is a prerequisite.

  • IN DEVELOPMENT

    Level 3, assessed by National Defence, restated on September 29, 2026 as 130-plus controls.

  • NO AUTOMATIC RECOGNITION

    CMMC certification may be accepted case by case at Level 1; nothing announced for Levels 2 and 3.

  • US · SUSPENDED

    CMMC Phase 2, suspended July 13, 2026 and made binding on contracting officers September 3; the review report is unpublished.

Start here

// 01 · THE PROGRAM

What is CPCSC?

The Canadian Program for Cyber Security Certification is run by Public Services and Procurement Canada. It sets cyber security requirements for suppliers on Government of Canada defense contracts and verifies them through 3 certification levels. The level a supplier needs is named in the solicitation and the contract, one contract at a time.

Enforcement runs through procurement. There's no CPCSC inspector and no compliance deadline in the abstract; a supplier who can't show the named level isn't eligible for that award. The technical bar at Level 1 is modest. The weight sits in the signature, since the attestation is a representation made in a federal contract context.

// SPECIFIED INFORMATION

The program protects Specified Information, sensitive but unclassified government information that a contract identifies as needing safeguarding on supplier systems: drawings, statements of work, schedules, pricing, Controlled Goods data. It's Canada's counterpart to the American term Controlled Unclassified Information. The contract decides what counts, so the same drawing can be Specified Information on one job and ordinary correspondence on another.

// 02 · THE 8 FEDERAL BODIES

Who runs it

PSPC's program overview, revised September 29, 2026, names 8 federal bodies. Knowing which one owns a question saves time.

BodyRole in CPCSC
Public Services and Procurement CanadaLeads the program and runs the certification processes
Department of National DefenceShapes the requirements and performs Level 3 assessments
Standards Council of CanadaAccredits the certification bodies that perform Level 2 assessments
Canadian Centre for Cyber Security (part of CSE)Wrote ITSP.10.171, the technical standard
Treasury Board SecretariatOwns the policy framework
Innovation, Science and Economic Development CanadaIndustry readiness
Global Affairs CanadaThe allied-market access objective
Public Safety CanadaTies the program to the National Cyber Security Strategy

// 03 · THE 5 OUTCOMES

Why Ottawa built it

PSPC lists 5 outcomes for the program:

  1. Protect federal contract information held below the classified level on contractor systems.
  2. Keep Canadian industry eligible for international procurement that carries similar certification requirements.
  3. Raise the baseline of cyber security across the defense industry.
  4. Keep the supplier base reliable enough to support Canadian Armed Forces capability and readiness.
  5. Grow Canadian industry's participation in the certification program itself.

The second is the strategic one. Allied supply chains, the American one above all, are converging on certified suppliers, and building CPCSC on the same NIST SP 800-171 control lineage keeps Canadian shops interoperable while Ottawa keeps its own assessors, portal, and data governance. The fifth is a quiet admission that assessor capacity is a national problem as much as a supplier one. PSPC describes its approach as risk-based and adaptive, with standards and processes revised as the rollout teaches it things, which is why this hub carries an updates log.

// 04 · NEXT

Where to go next

If you've never read a contract clause for Specified Information, start with does it apply. If you know it applies, go to Level 1 and the Level 1 checklist. If Level 2 is ahead of you, scoping comes before anything you buy.

References

  1. Cyber security certification for defence suppliers in Canada: Program overviewModified 2026-09-29
    Public Services and Procurement Canadacanada.ca
  2. Canadian Program for Cyber Security Certification: Level 12026-04-14
    Public Services and Procurement Canadacanada.ca
  3. How to meet Level 1 requirementsModified 2026-09-29
    Public Services and Procurement Canadacanada.ca
  4. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.