// CPCSC LEVEL 1 · HANS STUDY · ONTARIO, CANADA
CPCSC Level 1: the 13 controls
CPCSC Level 1 is an annual self-assessment against 13 control families, available to suppliers since April 1, 2026, and required in select defence contracts from summer 2026, at contract award. Last verified against PSPC, 2026-10-01.
The 13 control families
These are the families PSPC lists for Level 1. The note beside each one is a general observation from readiness work with small suppliers, not a description of any one client; every engagement is scoped to the shop in front of it.
01. Access control
Shared logins on CNC and shop-floor PCs are the most common gap. One login per person, even on machines that never touch the internet.
02. Identification and authentication
A login prompt is not the same as identifying the person behind it. Shared service accounts and generic "operator" logins both fail this one.
03. Media protection
USB drives moving CAD files and NC programs between an air-gapped machine and the office network are the usual finding here.
04. Physical protection
A server or network closet behind an unlocked door in a shop is common, and it fails the control regardless of how good the network side looks.
05. System and communications protection
A consumer router at the edge, still on its default admin password, shows up more often than it should on a 30-person shop floor.
06. System and information integrity
Antivirus or endpoint protection that was installed once and never checked again is the typical state here, not malicious neglect, just no one owning it.
07. Awareness and training
One documented session a year, with a sign-in sheet, is usually enough to meet this at Level 1. Most shops have never done even that.
08. Audit and accountability
Few shop networks log anything beyond what the firewall keeps by default, and fewer still check those logs on a schedule.
09. Configuration management
Office PCs and shop PCs on the same flat network, built by whoever set up the last one, with no written baseline anywhere.
10. Incident response
A plan does not need to be long. It needs a name attached to it and a phone number to call, written down before the day it is needed.
11. Maintenance
An integrator or IT contractor with standing remote access from years ago, still enabled, is a frequent finding during a Level 1 review.
12. Personnel security
Basic screening before someone gets a badge or a login, and an off-boarding step that actually removes access the day someone leaves.
13. Risk assessment
Most shops have never written down what could go wrong on their network. Level 1 asks for that list once a year, not a consultant-grade risk register.
Who needs this
Suppliers with a current or prospective Government of Canada defence contract that names CPCSC Level 1, or that carries specified information at the level PSPC bands as low sensitivity: Protected A material, low-sensitivity technical data on dual-use goods, and routine procurement paperwork like purchase orders and delivery schedules. A contract does not have to look sensitive to carry the clause. Read how the contract cyber security risk assessment sets your level for how that gets decided.
What the readiness offer includes
A review against all 13 control families, a written gap list in plain language, and the self-assessment record a supplier needs to attest in CanadaBuys. The work does not include the certification body's own assessment at Level 2 and above, since Level 1 is a self-assessment and there is no third-party assessor to engage.
Starting at $3,500.
CAD, plus HST.
Remote delivery via the DHD, a remote access device. Terms apply.
References
- Canadian Program for Cyber Security Certification: Level 1Public Services and Procurement Canadacanada.ca
- How to meet Level 1 requirementsPublic Services and Procurement Canadacanada.ca
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.
Find out if your contract carries the clause
Bring the solicitation or the contract wording. A scoping call is enough to tell whether Level 1 applies and what a review would cover.