// CPCSC · SCOPE OF THE PROGRAM

Does CPCSC apply to you?

Last verified: 2026-10-05

The program doesn't care whether you think of yourself as a defense company. It reads the data flow. If Specified Information from a Department of National Defence contract reaches your systems, directly or through a prime, you're in the program at whatever level that contract names.

// 01 · THE TEST

Work it in order. Do you hold, or plan to bid, a contract connected to National Defence, directly or as a subcontractor? Does that contract identify Specified Information in its clauses or its security requirements checklist? Does any of that information touch your systems: the file server, email, laptops, a cloud tenant, the backups? Three yeses put you in. Company size, revenue share, and tier never enter the test.

// 02 · FLOW-DOWN

A prime's certification doesn't cover its subcontractors. When Specified Information moves down the chain, the safeguarding requirement moves with it, and each supplier holding the data attests or certifies on its own account. Expect primes to ask subs for CPCSC status the way they already ask for insurance certificates; some already do, and a sub with a completed Level 1 attestation and a credible Level 2 plan is easier to keep on the bid team.

// 03 · BOUNDARY CASES

  • The integrator installing cameras and access control at a defense facility. If commissioning laptops hold facility drawings, device schedules, or network documentation identified as Specified Information, you're in. Most integrators who look find exactly that in their project folders.
  • The machine shop cutting parts from a prime's drawings 3 tiers below DND. The drawings are the textbook case; the ERP, the engineer's workstation, the email the drawing arrived in, and the backup of all 3 are in scope.
  • The software subcontractor. Requirements documents, interface specs, and test data on your systems can all be Specified Information, even if your code runs somewhere else.
  • The MSP. Not a defense supplier itself, but if it administers the systems where a client's Specified Information lives, its access, tooling, and people sit inside that client's scope. See MSPs and integrators.
  • The commodity vendor selling unmodified products off a price list without receiving technical data generally sits outside. Re-run the test the day customization starts.

// 04 · MISTAKES

The 2 most common mistakes

The volume excuse: we only hold a handful of drawings. The program has no volume threshold, and one drawing on one laptop puts that laptop in the question. Volume decides scoping cost, which is a different page.

The Controlled Goods confusion. Controlled Goods Program registration governs who may examine or possess controlled technical data; CPCSC governs how the systems holding contract data are secured. They overlap on the same drawings and satisfy nothing about each other.

References

  1. Cyber security certification for defence suppliers in Canada: Program overviewModified 2026-09-29
    Public Services and Procurement Canadacanada.ca
  2. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.