// CPCSC · LEVEL 1 · LIVE SINCE APRIL 2026

CPCSC Level 1

  • 13 requirements
  • Annual self-assessment
  • Result recorded in CanadaBuys
  • In contracts since summer 2026
  • Last verified: 2026-10-05

Level 1 is an annual self-assessment against 13 of ITSP.10.171's 98 requirements, done with PSPC's online tool, with the result and its expiry date confirmed in your CanadaBuys supplier profile. It's been available since April 1, 2026 and has appeared in select defense contracts since summer 2026. Most competently run networks already meet most of it; the exception is usually multifactor authentication.

// THE STUDY GUIDE · BOOK 3

The Study Guide to CPCSC Readiness. Free to read online or download.

Read it free

// 01 · REQUIREMENTS

The 13 requirements

IdentifierRequirementWhat it asks at a small shop
03.01.01Account managementEvery account belongs to a named person or system, gets disabled when it should, and the list is current
03.01.02Access enforcementPermissions on systems holding Specified Information are set and enforced, not assumed
03.01.20Use of external systemsRules for personal devices and outside systems touching contract data, written down
03.01.22Publicly accessible contentSomeone checks what goes on the website and social posts before it does
03.05.01User identification, authentication, and re-authenticationUnique logins, no shared accounts, re-authentication when it matters
03.05.02Device identification and authenticationYou know which devices are allowed to connect, and the network knows too
03.05.03Multi-factor authenticationMFA on privileged and non-privileged accounts alike
03.08.03Media sanitizationDrives and media are sanitized or destroyed before they leave, with a record
03.10.01Physical access authorizationsAn approved list of who may enter where the systems are, reviewed
03.10.07Physical access controlDoors, visitors, keys, and output devices are actually controlled
03.13.01Boundary protectionA firewall that monitors and controls traffic at the edge and between segments
03.14.01Flaw remediationPatches applied inside a defined window, with proof
03.14.02Malicious code protectionEndpoint protection that's current, scanning, and blocking

PSPC publishes the assessment criteria for each requirement as a Canadian version of NIST SP 800-171A Revision 3: the determination statements and the 3 methods (examine, interview, test). Read those before you attest; the wording there is what you're signing against.

// 02 · MFA

The MFA surprise

03.05.03 requires multifactor authentication for privileged and non-privileged accounts at Level 1. The American Level 1 has no MFA requirement at all, so a shop that cleared CMMC Level 1 on passwords is not at CPCSC Level 1 yet. Hardware keys are the option I push; authenticator apps are fine; SMS isn't.

// 03 · ATTESTATION

The signature

Nobody reviews your evidence at Level 1 by default, and PSPC reserves the right to look. The attestation is a signed representation in a federal procurement context, renewed every year. On the American side that exposure has a price tag: in September 2026 an aerospace supplier settled False Claims Act allegations over NIST SP 800-171 failures for about $2 million, while CMMC's certification phase was paused. Keep one dated artifact per requirement, in a folder per identifier, refreshed at each renewal.

// 04 · METHOD

The working method

  1. List the contracts carrying Specified Information clauses.
  2. Map where that data lives and draw the boundary around those systems.
  3. Answer the 13 against those systems only.
  4. Capture one dated evidence artifact per requirement.
  5. Fix gaps before attesting; Level 1 gaps are cheap.
  6. Record the result and expiry date in CanadaBuys.
  7. Re-run the assessment whenever the environment changes, and again before the expiry date.

The Standards Council of Canada states that a completed Level 1 self-assessment is a prerequisite for Level 2 certification, so this is everyone's first step.

// 05 · CANADABUYS

Filing it in CanadaBuys

The certification has to be in place at contract award, and proof of it goes in with the bid.

  1. Make sure the organization has an active CanadaBuys account and supplier profile.
  2. Read the Level 1 criteria and PSPC's CPCSC Level 1 Scoping Guide, and draw your boundary.
  3. Complete the self-assessment with PSPC's online tool. Assessing by another means is allowed, and you keep the results either way.
  4. Print or save the results page, which shows the expiry date, and file it with your evidence.
  5. Confirm the result and expiry date in the organizational supplier profile questionnaire in CanadaBuys.
  6. Include proof of the self-attestation and its expiry date with bids on contracts that require Level 1.
  7. Calendar the expiry with a month's lead time.

Portal screens change; follow CanadaBuys' current wording.

References

  1. Canadian Program for Cyber Security Certification: Level 12026-04-14
    Public Services and Procurement Canadacanada.ca
  2. How to meet Level 1 requirementsModified 2026-09-29
    Public Services and Procurement Canadacanada.ca
  3. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.