// CPCSC LEVEL 2 · HANS STUDY · ONTARIO, CANADA

CPCSC Level 2: preparing for spring 2027

CPCSC Level 2 is a 98-control assessment, carried out by a third party accredited by the Standards Council of Canada, phasing into select defence contracts from spring 2027. Last verified against PSPC, 2026-10-01.

What Level 2 asks for

98 controls, drawn from ITSP.10.171, the Cyber Centre's adaptation of NIST SP 800-171 for CPCSC. Where Level 1 is a self-assessment a supplier attests to in CanadaBuys, Level 2 is assessed by a third-party certification body accredited by the Standards Council of Canada, not by the supplier itself. PSPC's published materials on the certification body process and the assessment cadence are still coming out ahead of the spring 2027 start, so this page will update as those details are confirmed.

Who it reaches

Level 2 is expected to apply where a contract involves controlled defence information rather than the lower-sensitivity material that sets the Level 1 floor. As with Level 1, the level that applies to a given contract is decided through a contract cyber security risk assessment and stated in the RFP and the contract clauses, not chosen by the supplier. A supplier already named at Level 1 on one contract can still be named at Level 2 on another, depending on what each contract exposes.

How preparation works

The practical starting point is the same technical baseline that supports NIST SP 800-171 and CMMC Level 2 readiness: network segmentation, identity and access management, logging, backup and recovery, and endpoint and server hardening, mapped against the 98 controls rather than invented from scratch. Preparation is scoped to the organization and the contract in front of it, since enclave size, existing infrastructure, and how much specified information is in scope all change the work. No CPCSC engagements have been completed to date; this preparation work draws on NIST SP 800-171 and CMMC readiness work with small defence suppliers since 2019.

References

  1. Cyber security certification for defence suppliers in Canada: Program overviewModified 2026-09-29
    Public Services and Procurement Canadacanada.ca
  2. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  3. CPCSC accreditation scheme
    Standards Council of Canadascc-ccn.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.

Start before the assessment is booked

A scoping call covers what Level 2 would mean for a specific contract and where the gaps are likely to sit.