Suppliers keep asking me which CPCSC level they should certify to, and the honest answer is that it’s the wrong question. You don’t pick your level. Each procurement gets a cyber security risk assessment, which the program’s industry briefings call the Contract Cyber Security Risk Assessment, the CCSRA, and that assessment decides which level the contract carries. PSPC’s public pages put it plainly: the required level is set on a contract-by-contract basis and communicated in the RFP and the contract clauses. Your only real choice is whether you find out what your contracts look like before the assessment does.

What the CCSRA weighs

The assessment turns on the information the contract exposes, not on the size of your company or the dollar value of the work. Commercial off-the-shelf supply with no specified information attached sits outside the program entirely. Once a contract involves non-COTS activity or specified information, the assessment determines both applicability and level.

Specified information itself gets graded. The briefing material sorts it into low, medium, and high sensitivity bands, and the low band, the one mapping to Level 1, covers material most suppliers wouldn’t think of as sensitive at all: Protected A information, low-sensitivity technical data on dual-use goods, routine procurement documentation like RFQs, purchase orders, and delivery schedules, and non-critical supplier financial information.

Read that list again. Purchase orders and schedules. If DND work touches your business at all, the floor of the program probably touches you too.

The self-assessment you should run first

Before any formal assessment lands on your contracts, walk them yourself with the same lens:

  • List every active and pipeline contract with a defence connection, direct or through a prime
  • For each one, write down what information actually moves: drawings, specs, schedules, pricing, technical data, anything marked Protected
  • Grade honestly against the sensitivity bands rather than against your instinct that “it’s just a PO”
  • Flag contracts where you receive information you never asked for; primes routinely over-share, and what lands in your inbox scopes you whether you wanted it or not
  • Note where each information type is stored, because the assessment outcome becomes your certification boundary later

That last habit, tracking the unrequested over-share, is the one that changes behaviour. Once you see that a prime’s habit of attaching the full drawing package to every email is what’s dragging your certification level up, you start having a different conversation with that prime.

Why this matters before 2027

Level 1 is self-attested today: an annual self-assessment against 13 controls, required at contract award rather than at bid. As Level 2 assessments phase in from spring 2027, the assessment outcome on a contract stops being paperwork and starts being a gate with a third-party assessor and a multi-month lead time behind it. A supplier who knows their contract portfolio maps to Level 1 can bid with confidence. A supplier who discovers mid-bid that one legacy contract’s data pushes them into Level 2 territory has a scheduling problem no proposal team can write around.

Read your contracts the way the assessment will. It costs an afternoon, and it’s the cheapest risk assessment your company will run this year.

The long form of this is The Study Guide to CPCSC Readiness, and I run contract-portfolio scoping reviews for suppliers who want a second set of eyes before the assessment provides one. Details on the CPCSC and CMMC readiness page.

References

  1. Canadian Program for Cyber Security Certification: Program overview
    Public Services and Procurement Canadacanada.ca
  2. Additional information and support for suppliers about cyber security
    Public Services and Procurement Canadacanada.ca
  3. Canadian Program for Cyber Security Certification: Level 1 criteria
    Public Services and Procurement Canadacanada.ca
  4. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.