The letter arrives from your customer, not from Ottawa. That’s the part of certification programs that catches lower-tier suppliers off guard: the government never contacts you. Your prime does, because their contract makes them responsible for the cyber posture of everyone underneath them, and they discharge that responsibility by pushing requirements down the chain with a questionnaire and a deadline.
Canada hasn’t fully built this machinery yet. The allies we align with have, and their model tells you what’s coming.
How the allies run it
The UK Ministry of Defence attaches a cyber risk profile to each contract through DEFCON 658, and prime contractors must run a risk assessment on every subcontract they place, cascading the process down through tier 2 and tier 3 until the risk profile drops low enough to stop. The US runs the equivalent through DFARS clauses and CMMC: clause 252.204-7012 requires the contractor to include the clause, without alteration, in every subcontract that involves covered defence information, and CMMC makes the subcontractor’s certification a condition of the award.
Two different mechanisms, one identical outcome: the prime becomes the enforcement arm, and a subcontractor’s cyber posture becomes a bid-eligibility question decided in someone else’s procurement office.
CPCSC is built to interoperate with these programs. Expecting Canadian defence primes to behave differently than their UK and US counterparts is a bet against every incentive in the system, because a prime whose sub can’t attest is a prime who can’t close their own compliance obligations.
What the questionnaire will ask
Having sat on the receiving end of supplier assurance questionnaires in other frameworks, the content is predictable:
- Whether you hold a current CPCSC attestation or certification, and at what level
- What specified information you’d receive under the subcontract, and where it would live
- Your sub-subcontractors, because the cascade doesn’t stop at you
- Incident reporting commitments, usually with timelines tighter than your current IR plan contemplates
- Evidence of specific controls when the risk profile is high enough, MFA and encryption at rest being the perennial first two
The suppliers who answer in a week win work from the suppliers who answer in a quarter. That’s the entire competitive dynamic, and it’s brutally simple.
Getting ahead of the letter
If you’re a tier 2 or 3 supplier with defence-adjacent revenue, complete your Level 1 self-assessment now, before anyone asks. Not because the contract requires it yet, but because “yes, attested, here’s the date” is a one-line answer to the hardest question on the form. Build a one-page data-handling summary you can hand any prime: what you receive, where it’s stored, who touches it. Then ask your own subcontractors the questions before your prime asks whether you did.
The flow-down letter is coming either way. The only variable is whether it finds you ready.
Readiness engagements for suppliers at any tier are described on the CPCSC and CMMC readiness page.