- LIVE
Level 1 self-assessment through CanadaBuys since April 1, 2026, and in select defense contracts since summer 2026.
- SPRING 2027
Level 2 third-party assessments planned for select contracts. Standards Council of Canada accreditation of certification bodies is under way, and a completed Level 1 self-assessment is a prerequisite.
- IN DEVELOPMENT
Level 3, assessed by National Defence, restated on September 29, 2026 as 130-plus controls.
- NO AUTOMATIC RECOGNITION
CMMC certification may be accepted case by case at Level 1; nothing announced for Levels 2 and 3.
- US · SUSPENDED
CMMC Phase 2, suspended July 13, 2026 and made binding on contracting officers September 3; the review report is unpublished.
// REFERENCE HUB · CANADIAN PROGRAM FOR CYBER SECURITY CERTIFICATION
CPCSC, explained
- Owner: PSPC
- Standard: ITSP.10.171, 2nd release
- Level 1: live
- Level 2: spring 2027
- Last verified: 2026-10-05
CPCSC is Canada's mandatory cyber security certification for defense suppliers. If your systems hold Specified Information under a Department of National Defence contract, a certification level is becoming a condition of contract award, and it follows the data down to every subcontractor that touches it. Level 1 went live in April 2026. Level 2 third-party assessments are planned for select contracts from spring 2027.
This hub tracks the program as it moves. Every page carries a last-verified date, and the updates log records what changed and when, including PSPC's revision of the program overview on September 29, 2026.
The companion book, The Study Guide to CPCSC Readiness, is free to read, and the controls, audit scripts, and data behind it are open in the CPCSC repository on GitHub.
Start here
Does it apply to you?
The test is the data, not the size of your company or how much defense work you do.
Level 1
13 requirements, an annual self-assessment, and a signature with legal weight. Includes multifactor authentication, which the American Level 1 doesn't.
Level 2
98 requirements, a third-party assessor, and a calendar that starts now if spring 2027 matters to you.
Level 3
Mostly unpublished.
Scoping
Where Specified Information lives decides what you pay.
The 98 requirements
Family by family, each with a plain reading of what it asks at a small shop.
CPCSC vs CMMC
Same control lineage, separate machinery, no automatic recognition between them.
For MSPs and integrators
Templates and checklists
14 free resources, most of them buildable in the policy builder with your company's details.
Glossary · Updates log · FAQ
// 01 · THE PROGRAM
What is CPCSC?
The Canadian Program for Cyber Security Certification is run by Public Services and Procurement Canada. It sets cyber security requirements for suppliers on Government of Canada defense contracts and verifies them through 3 certification levels. The level a supplier needs is named in the solicitation and the contract, one contract at a time.
Enforcement runs through procurement. There's no CPCSC inspector and no compliance deadline in the abstract; a supplier who can't show the named level isn't eligible for that award. The technical bar at Level 1 is modest. The weight sits in the signature, since the attestation is a representation made in a federal contract context.
The program protects Specified Information, sensitive but unclassified government information that a contract identifies as needing safeguarding on supplier systems: drawings, statements of work, schedules, pricing, Controlled Goods data. It's Canada's counterpart to the American term Controlled Unclassified Information. The contract decides what counts, so the same drawing can be Specified Information on one job and ordinary correspondence on another.
// 02 · THE 8 FEDERAL BODIES
Who runs it
PSPC's program overview, revised September 29, 2026, names 8 federal bodies. Knowing which one owns a question saves time.
| Body | Role in CPCSC |
|---|---|
| Public Services and Procurement Canada | Leads the program and runs the certification processes |
| Department of National Defence | Shapes the requirements and performs Level 3 assessments |
| Standards Council of Canada | Accredits the certification bodies that perform Level 2 assessments |
| Canadian Centre for Cyber Security (part of CSE) | Wrote ITSP.10.171, the technical standard |
| Treasury Board Secretariat | Owns the policy framework |
| Innovation, Science and Economic Development Canada | Industry readiness |
| Global Affairs Canada | The allied-market access objective |
| Public Safety Canada | Ties the program to the National Cyber Security Strategy |
// 03 · THE 5 OUTCOMES
Why Ottawa built it
PSPC lists 5 outcomes for the program:
- Protect federal contract information held below the classified level on contractor systems.
- Keep Canadian industry eligible for international procurement that carries similar certification requirements.
- Raise the baseline of cyber security across the defense industry.
- Keep the supplier base reliable enough to support Canadian Armed Forces capability and readiness.
- Grow Canadian industry's participation in the certification program itself.
The second is the strategic one. Allied supply chains, the American one above all, are converging on certified suppliers, and building CPCSC on the same NIST SP 800-171 control lineage keeps Canadian shops interoperable while Ottawa keeps its own assessors, portal, and data governance. The fifth is a quiet admission that assessor capacity is a national problem as much as a supplier one. PSPC describes its approach as risk-based and adaptive, with standards and processes revised as the rollout teaches it things, which is why this hub carries an updates log.
// 04 · NEXT
Where to go next
If you've never read a contract clause for Specified Information, start with does it apply. If you know it applies, go to Level 1 and the Level 1 checklist. If Level 2 is ahead of you, scoping comes before anything you buy.
References
- Cyber security certification for defence suppliers in Canada: Program overviewPublic Services and Procurement Canadacanada.ca
- Canadian Program for Cyber Security Certification: Level 1Public Services and Procurement Canadacanada.ca
- How to meet Level 1 requirementsPublic Services and Procurement Canadacanada.ca
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.
CPCSC Level 1 readiness
A review against all 13 Level 1 requirements, a written gap list in plain language, and the self-assessment record a supplier needs to attest in CanadaBuys.