Front cover of The Study Guide to CPCSC Readiness: A Field Reference for Canadian Defense Suppliers, by Hans Study, CISSP. First edition 2026, revision 1.3, October 2026. A worn Canadian flag over a map of Canada on a dark circuit background.

// THE STUDY GUIDE · BOOK 3 · REVISION 1.3 · OCTOBER 2026

The Study Guide to CPCSC Readiness

A field reference for Canadian defense suppliers

Canada's defense supply chain now has a cyber security gate on it. CPCSC Level 1 went live in April 2026, the first contract clauses landed that summer, and Level 2 third-party assessments arrive in 2027. This book is the working manual for getting through the gate: what the program is, whether it reaches you, and the order to do things in.

Free to read and share under CC BY-ND 4.0. DOI 10.5281/zenodo.23145960.

Loading the book

Arrow keys turn pages. Trouble with the reader? Open the PDF directly.

// WHO IT’S FOR

It’s written for the person who found out on a Tuesday. The network admin keeping the business running who just got forwarded a solicitation with a certification clause in it. The office manager handed “compliance” because nobody else put their hand up. The IT lead at a 30-person shop expected to become a certification program on top of everything else. Plain language, sized for evenings and stolen Friday afternoons, built on scenarios inspired by ISO 27001, PCI-DSS, and CMMC readiness engagements with real suppliers.

// WHAT’S INSIDE

Twelve chapters in the order you’d actually work: what CPCSC is and why Ottawa built it, the 3 levels, whether the program applies to you, how it compares with CMMC and where the overlap saves you effort, the Level 1 controls and the attestation you’re signing, scoping an enclave that keeps assessment costs sane, running a gap assessment worth trusting, the technical work family by family, documentation that survives an assessor, Level 2 preparation, small shop realities including the MSP conversation, and staying certified after the first attestation. Study Notes from the field throughout, plus a Level 1 readiness checklist and a Canada-US terminology translation table in the appendices.

// FORMATS

Free digital PDF, ISBN 978-1-0680175-2-0, tagged and searchable, 61 pages: Download the PDF.
EPUB, ISBN 978-1-0680175-3-7, free on Apple Books, Kobo, and Google Play, and on Kindle.
Paperback, 8.5 × 11, 72 pages, ISBN 978-1-0680175-1-3, from Amazon.
First edition, revision 1.3, October 1, 2026, including the September 29, 2026 program changes. DOI 10.5281/zenodo.23145960.
Licensed CC BY-ND 4.0: share it freely with credit, unmodified.

Paperback on Amazon

// THE LIVING COMPANION

A printed book can’t chase a moving program, so this one doesn’t pretend to. The companion pages carry the current program state with a last-verified date: the CPCSC hub and CPCSC vs CMMC. The policy templates and checklists from the appendices are at CPCSC templates as editable downloads. The controls, Windows audit scripts, and data are open in the CPCSC repository on GitHub.

// CONTENTS

  1. 1 What CPCSC is and why Ottawa built it
  2. 2 The 3 levels, plainly
  3. 3 Does this apply to you
  4. 4 CPCSC, CMMC, and ITSP.10.171
  5. 5 Level 1: the 13 requirements and the attestation you’re signing
  6. 6 Scoping: where Specified Information lives
  7. 7 Running your own gap assessment
  8. 8 The technical work, control family by control family
  9. 9 Documentation that survives an assessor
  10. 10 Level 2 prep: what third-party assessment looks like
  11. 11 Small shop realities: MSPs, cloud, cost, and sequencing
  12. 12 Staying certified: life after the first attestation
  13. A to E Appendices: Level 1 checklist, Canada and US terminology table, sources, templates, and the full ITSP.10.171 requirement index

Hans Study, CISSP · Ontario, Canada · independent network and security consultant. Readiness engagements: CPCSC and CMMC services.

Questions

Is the CPCSC book free?

Yes. The 61-page PDF is free to read online or download, and the paperback is sold on Amazon.

Who is the book for?

The person who found out on a Tuesday: the network admin forwarded a solicitation with a certification clause in it, the office manager handed compliance, or the IT lead at a small shop. It's written in plain language for Canadian defense suppliers.

Does the book cover Level 2?

Yes. Chapter 10 covers what third-party assessment looks like, and the appendices include the full ITSP.10.171 requirement index. All 98 requirements are read in plain language.

Does the book cover CMMC?

Chapter 4 compares CPCSC, CMMC, and ITSP.10.171 and shows where the overlap saves you effort. A CMMC certificate doesn't satisfy CPCSC automatically, though PSPC may accept a valid one case by case at Level 1.

Is the book kept up to date?

It's first edition, revision 1.3, October 2026, including the September 29, 2026 program changes. A printed book can't chase a moving program, so the CPCSC hub and CPCSC vs CMMC pages carry the current state with a last-verified date.

Can I share the book with my team?

Yes. It's licensed CC BY-ND 4.0, so you can share it freely with credit, unmodified.