// CPCSC · SCOPE OF THE PROGRAM
Does CPCSC apply to you?
Last verified: 2026-10-05
The program doesn't care whether you think of yourself as a defense company. It reads the data flow. If Specified Information from a Department of National Defence contract reaches your systems, directly or through a prime, you're in the program at whatever level that contract names.
// 01 · THE TEST
Work it in order. Do you hold, or plan to bid, a contract connected to National Defence, directly or as a subcontractor? Does that contract identify Specified Information in its clauses or its security requirements checklist? Does any of that information touch your systems: the file server, email, laptops, a cloud tenant, the backups? Three yeses put you in. Company size, revenue share, and tier never enter the test.
// 02 · FLOW-DOWN
A prime's certification doesn't cover its subcontractors. When Specified Information moves down the chain, the safeguarding requirement moves with it, and each supplier holding the data attests or certifies on its own account. Expect primes to ask subs for CPCSC status the way they already ask for insurance certificates; some already do, and a sub with a completed Level 1 attestation and a credible Level 2 plan is easier to keep on the bid team.
// 03 · BOUNDARY CASES
- The integrator installing cameras and access control at a defense facility. If commissioning laptops hold facility drawings, device schedules, or network documentation identified as Specified Information, you're in. Most integrators who look find exactly that in their project folders.
- The machine shop cutting parts from a prime's drawings 3 tiers below DND. The drawings are the textbook case; the ERP, the engineer's workstation, the email the drawing arrived in, and the backup of all 3 are in scope.
- The software subcontractor. Requirements documents, interface specs, and test data on your systems can all be Specified Information, even if your code runs somewhere else.
- The MSP. Not a defense supplier itself, but if it administers the systems where a client's Specified Information lives, its access, tooling, and people sit inside that client's scope. See MSPs and integrators.
- The commodity vendor selling unmodified products off a price list without receiving technical data generally sits outside. Re-run the test the day customization starts.
// 04 · MISTAKES
The 2 most common mistakes
The volume excuse: we only hold a handful of drawings. The program has no volume threshold, and one drawing on one laptop puts that laptop in the question. Volume decides scoping cost, which is a different page.
The Controlled Goods confusion. Controlled Goods Program registration governs who may examine or possess controlled technical data; CPCSC governs how the systems holding contract data are secured. They overlap on the same drawings and satisfy nothing about each other.
References
- Cyber security certification for defence suppliers in Canada: Program overviewPublic Services and Procurement Canadacanada.ca
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.