// CPCSC · GLOSSARY
Glossary and terminology
Last verified: 2026-10-05
The same ideas carry different names on each side of the border, and documentation written for one program reads wrong to an assessor on the other. Use the Canadian terms in Canadian documentation.
// 01 · SIDE BY SIDE
Canada and the United States
| Canada (CPCSC) | United States (CMMC) | What it is |
|---|---|---|
| Specified Information (SI) | Controlled Unclassified Information (CUI) | Sensitive but unclassified government data a contract identifies as needing safeguarding on supplier systems |
| No separate category; ordinary contract information falls under the same clauses | Federal Contract Information (FCI) | Information provided by or generated for the government under contract; the CMMC Level 1 data class |
| CPCSC | CMMC | The certification program |
| Public Services and Procurement Canada | Department of Defense, now Department of War | Program owner |
| Department of National Defence | DIBCAC and the DoD CIO | Government-led assessment at the top level |
| Canadian Centre for Cyber Security | NIST | Author of the technical standard |
| ITSP.10.171 | NIST SP 800-171 | The control standard; ITSP.10.171 adapts Revision 3 |
| ITSP.10.033 (successor to ITSG-33 Annex 3A) | NIST SP 800-53 Revision 5 | The full control catalogue the standard is tailored from |
| Level 1 criteria (Canadian version of 800-171A Revision 3) | NIST SP 800-171A | Assessment procedures |
| No separate Canadian document published yet; Level 3 adapts these directly | NIST SP 800-172 | Enhanced requirements for higher-sensitivity work |
| Standards Council of Canada | Cyber AB | Accredits the assessors |
| Accredited certification body | C3PAO | Performs third-party assessments |
| CanadaBuys supplier portal | SPRS | Where attestations and results are filed |
| Contract clauses in the RFP and contract | DFARS 252.204-7021 and 252.204-7025 | How the required level reaches a contract |
| Contract Security Program | NISPOM and DCSA | Personnel screening and facility security regime |
| Company Security Officer | Facility Security Officer | The named security role inside the supplier |
| Controlled Goods Program | ITAR and EAR | Controls on controlled technical data; separate from cyber certification |
| Not allocated | Withdrawn | Requirement numbers removed in Revision 3 |
// 02 · DEFINITIONS
Terms
- Attestation
- the signed Level 1 statement, filed in CanadaBuys each year, that the 13 requirements are met on the systems in scope.
- Annual affirmation
- the yearly signed statement at Levels 2 and 3, between 3-year assessments, that the certified posture still holds.
- Certification body
- an organization accredited by the Standards Council of Canada to perform Level 2 assessments.
- Determination statement
- one scored line in the assessment procedures; a requirement is met when all of its determination statements are.
- Enclave
- a defined, separated part of the network where Specified Information lives, so the assessment covers the enclave instead of the whole company.
- Flow-down
- the requirement travelling with Specified Information from a prime to every subcontractor that receives it.
- Organization-defined parameter
- a value a requirement leaves to the organization, such as the inactivity period before an account is disabled; you set it, record it in the SSP, and defend it.
- Plan of action and milestones
- the remediation register of gaps in progress, each with a fix, an owner, and a date.
- Specified Information
- see the table.
- System security plan
- the document describing the scope, boundary, architecture, and how each requirement is met, which the assessment is built around.
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- Cyber security certification for defence suppliers in Canada: Program overviewPublic Services and Procurement Canadacanada.ca
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.