// CPCSC · FAQ
CPCSC questions, answered
Last verified: 2026-10-05
Is CPCSC mandatory?
Contract by contract, yes. There's no blanket deadline; when a defense solicitation names a CPCSC level, meeting it is a condition of eligibility for that award.
Who needs it?
Any supplier whose systems store, process, or transmit Specified Information under a Department of National Defence contract, at any tier of the supply chain. Company size and the share of revenue from defense work don't matter.
What are the 3 levels?
Level 1 is an annual self-assessment against 13 ITSP.10.171 requirements with a signed attestation. Level 2 is a third-party assessment of all 98 requirements every 3 years, with an annual affirmation. Level 3 is assessed by National Defence against 130-plus controls.
When does Level 2 start?
PSPC plans to put Level 2 into select contracts from spring 2027. A completed Level 1 self-assessment is a prerequisite.
Does Level 1 require MFA?
Yes. Requirement 03.05.03 calls for multifactor authentication on privileged and non-privileged accounts. The American CMMC Level 1 has no MFA requirement.
Does a CMMC certificate satisfy CPCSC?
Not automatically. The programs share the NIST SP 800-171 lineage, but there's no mutual recognition. PSPC may accept a valid CMMC certification case by case at Level 1, after confirming the assessment covers the required scope; Level 2 and Level 3 recognition hasn't been announced. Implementation work carries over; attestations, portals, and assessments mostly don't.
Does my prime's certification cover me?
No. The requirement flows down with the data, and each supplier holding Specified Information attests or certifies on its own account.
Where do I file the Level 1 attestation?
Complete the self-assessment with PSPC's online tool, save the results page with its expiry date, and confirm the result and expiry date in the organizational supplier profile questionnaire in CanadaBuys. Proof goes in with bids on contracts that require Level 1, and the certification has to be in place at contract award.
What is ITSP.10.171?
The Canadian Centre for Cyber Security's adaptation of NIST SP 800-171 Revision 3, and the technical standard behind CPCSC. The second release, dated October 28, 2025, is current.
Do I need to buy tools to get certified?
Not before you've scoped. Map where Specified Information lives and run a gap assessment first; most small shops find their biggest costs are documentation and architecture, not software.
How often does this page change?
Whenever the program does. See the updates log.
References
- Cyber security certification for defence suppliers in Canada: Program overviewPublic Services and Procurement Canadacanada.ca
- How to meet Level 1 requirementsPublic Services and Procurement Canadacanada.ca
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.