// CPCSC LEVEL 1 · HANS STUDY · ONTARIO, CANADA

CPCSC Level 1: the 13 controls

CPCSC Level 1 is an annual self-assessment against 13 control families, available to suppliers since April 1, 2026, and required in select defence contracts from summer 2026, at contract award. Last verified against PSPC, 2026-10-01.

The 13 control families

These are the families PSPC lists for Level 1. The note beside each one is a general observation from readiness work with small suppliers, not a description of any one client; every engagement is scoped to the shop in front of it.

01. Access control

Shared logins on CNC and shop-floor PCs are the most common gap. One login per person, even on machines that never touch the internet.

02. Identification and authentication

A login prompt is not the same as identifying the person behind it. Shared service accounts and generic "operator" logins both fail this one.

03. Media protection

USB drives moving CAD files and NC programs between an air-gapped machine and the office network are the usual finding here.

04. Physical protection

A server or network closet behind an unlocked door in a shop is common, and it fails the control regardless of how good the network side looks.

05. System and communications protection

A consumer router at the edge, still on its default admin password, shows up more often than it should on a 30-person shop floor.

06. System and information integrity

Antivirus or endpoint protection that was installed once and never checked again is the typical state here, not malicious neglect, just no one owning it.

07. Awareness and training

One documented session a year, with a sign-in sheet, is usually enough to meet this at Level 1. Most shops have never done even that.

08. Audit and accountability

Few shop networks log anything beyond what the firewall keeps by default, and fewer still check those logs on a schedule.

09. Configuration management

Office PCs and shop PCs on the same flat network, built by whoever set up the last one, with no written baseline anywhere.

10. Incident response

A plan does not need to be long. It needs a name attached to it and a phone number to call, written down before the day it is needed.

11. Maintenance

An integrator or IT contractor with standing remote access from years ago, still enabled, is a frequent finding during a Level 1 review.

12. Personnel security

Basic screening before someone gets a badge or a login, and an off-boarding step that actually removes access the day someone leaves.

13. Risk assessment

Most shops have never written down what could go wrong on their network. Level 1 asks for that list once a year, not a consultant-grade risk register.

Who needs this

Suppliers with a current or prospective Government of Canada defence contract that names CPCSC Level 1, or that carries specified information at the level PSPC bands as low sensitivity: Protected A material, low-sensitivity technical data on dual-use goods, and routine procurement paperwork like purchase orders and delivery schedules. A contract does not have to look sensitive to carry the clause. Read how the contract cyber security risk assessment sets your level for how that gets decided.

What the readiness offer includes

A review against all 13 control families, a written gap list in plain language, and the self-assessment record a supplier needs to attest in CanadaBuys. The work does not include the certification body's own assessment at Level 2 and above, since Level 1 is a self-assessment and there is no third-party assessor to engage.

Starting at $3,500.

CAD, plus HST.

Remote delivery via the DHD, a remote access device. Terms apply.

References

  1. Canadian Program for Cyber Security Certification: Level 12026-04-14
    Public Services and Procurement Canadacanada.ca
  2. How to meet Level 1 requirementsModified 2026-09-29
    Public Services and Procurement Canadacanada.ca
  3. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.

Find out if your contract carries the clause

Bring the solicitation or the contract wording. A scoping call is enough to tell whether Level 1 applies and what a review would cover.