// CPCSC · GLOSSARY

Glossary and terminology

Last verified: 2026-10-05

The same ideas carry different names on each side of the border, and documentation written for one program reads wrong to an assessor on the other. Use the Canadian terms in Canadian documentation.

// 01 · SIDE BY SIDE

Canada and the United States

Canada (CPCSC)United States (CMMC)What it is
Specified Information (SI)Controlled Unclassified Information (CUI)Sensitive but unclassified government data a contract identifies as needing safeguarding on supplier systems
No separate category; ordinary contract information falls under the same clausesFederal Contract Information (FCI)Information provided by or generated for the government under contract; the CMMC Level 1 data class
CPCSCCMMCThe certification program
Public Services and Procurement CanadaDepartment of Defense, now Department of WarProgram owner
Department of National DefenceDIBCAC and the DoD CIOGovernment-led assessment at the top level
Canadian Centre for Cyber SecurityNISTAuthor of the technical standard
ITSP.10.171NIST SP 800-171The control standard; ITSP.10.171 adapts Revision 3
ITSP.10.033 (successor to ITSG-33 Annex 3A)NIST SP 800-53 Revision 5The full control catalogue the standard is tailored from
Level 1 criteria (Canadian version of 800-171A Revision 3)NIST SP 800-171AAssessment procedures
No separate Canadian document published yet; Level 3 adapts these directlyNIST SP 800-172Enhanced requirements for higher-sensitivity work
Standards Council of CanadaCyber ABAccredits the assessors
Accredited certification bodyC3PAOPerforms third-party assessments
CanadaBuys supplier portalSPRSWhere attestations and results are filed
Contract clauses in the RFP and contractDFARS 252.204-7021 and 252.204-7025How the required level reaches a contract
Contract Security ProgramNISPOM and DCSAPersonnel screening and facility security regime
Company Security OfficerFacility Security OfficerThe named security role inside the supplier
Controlled Goods ProgramITAR and EARControls on controlled technical data; separate from cyber certification
Not allocatedWithdrawnRequirement numbers removed in Revision 3

// 02 · DEFINITIONS

Terms

Attestation
the signed Level 1 statement, filed in CanadaBuys each year, that the 13 requirements are met on the systems in scope.
Annual affirmation
the yearly signed statement at Levels 2 and 3, between 3-year assessments, that the certified posture still holds.
Certification body
an organization accredited by the Standards Council of Canada to perform Level 2 assessments.
Determination statement
one scored line in the assessment procedures; a requirement is met when all of its determination statements are.
Enclave
a defined, separated part of the network where Specified Information lives, so the assessment covers the enclave instead of the whole company.
Flow-down
the requirement travelling with Specified Information from a prime to every subcontractor that receives it.
Organization-defined parameter
a value a requirement leaves to the organization, such as the inactivity period before an account is disabled; you set it, record it in the SSP, and defend it.
Plan of action and milestones
the remediation register of gaps in progress, each with a fix, an owner, and a date.
Specified Information
see the table.
System security plan
the document describing the scope, boundary, architecture, and how each requirement is met, which the assessment is built around.

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. Cyber security certification for defence suppliers in Canada: Program overviewModified 2026-09-29
    Public Services and Procurement Canadacanada.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.