The Study Guide to CPCSC Readiness. Free to read online or download.
Read it free// CPCSC · LEVEL 1 · LIVE SINCE APRIL 2026
CPCSC Level 1
- 13 requirements
- Annual self-assessment
- Result recorded in CanadaBuys
- In contracts since summer 2026
- Last verified: 2026-10-05
Level 1 is an annual self-assessment against 13 of ITSP.10.171's 98 requirements, done with PSPC's online tool, with the result and its expiry date confirmed in your CanadaBuys supplier profile. It's been available since April 1, 2026 and has appeared in select defense contracts since summer 2026. Most competently run networks already meet most of it; the exception is usually multifactor authentication.
// 01 · REQUIREMENTS
The 13 requirements
| Identifier | Requirement | What it asks at a small shop |
|---|---|---|
| 03.01.01 | Account management | Every account belongs to a named person or system, gets disabled when it should, and the list is current |
| 03.01.02 | Access enforcement | Permissions on systems holding Specified Information are set and enforced, not assumed |
| 03.01.20 | Use of external systems | Rules for personal devices and outside systems touching contract data, written down |
| 03.01.22 | Publicly accessible content | Someone checks what goes on the website and social posts before it does |
| 03.05.01 | User identification, authentication, and re-authentication | Unique logins, no shared accounts, re-authentication when it matters |
| 03.05.02 | Device identification and authentication | You know which devices are allowed to connect, and the network knows too |
| 03.05.03 | Multi-factor authentication | MFA on privileged and non-privileged accounts alike |
| 03.08.03 | Media sanitization | Drives and media are sanitized or destroyed before they leave, with a record |
| 03.10.01 | Physical access authorizations | An approved list of who may enter where the systems are, reviewed |
| 03.10.07 | Physical access control | Doors, visitors, keys, and output devices are actually controlled |
| 03.13.01 | Boundary protection | A firewall that monitors and controls traffic at the edge and between segments |
| 03.14.01 | Flaw remediation | Patches applied inside a defined window, with proof |
| 03.14.02 | Malicious code protection | Endpoint protection that's current, scanning, and blocking |
PSPC publishes the assessment criteria for each requirement as a Canadian version of NIST SP 800-171A Revision 3: the determination statements and the 3 methods (examine, interview, test). Read those before you attest; the wording there is what you're signing against.
// 02 · MFA
The MFA surprise
03.05.03 requires multifactor authentication for privileged and non-privileged accounts at Level 1. The American Level 1 has no MFA requirement at all, so a shop that cleared CMMC Level 1 on passwords is not at CPCSC Level 1 yet. Hardware keys are the option I push; authenticator apps are fine; SMS isn't.
// 03 · ATTESTATION
The signature
Nobody reviews your evidence at Level 1 by default, and PSPC reserves the right to look. The attestation is a signed representation in a federal procurement context, renewed every year. On the American side that exposure has a price tag: in September 2026 an aerospace supplier settled False Claims Act allegations over NIST SP 800-171 failures for about $2 million, while CMMC's certification phase was paused. Keep one dated artifact per requirement, in a folder per identifier, refreshed at each renewal.
// 04 · METHOD
The working method
- List the contracts carrying Specified Information clauses.
- Map where that data lives and draw the boundary around those systems.
- Answer the 13 against those systems only.
- Capture one dated evidence artifact per requirement.
- Fix gaps before attesting; Level 1 gaps are cheap.
- Record the result and expiry date in CanadaBuys.
- Re-run the assessment whenever the environment changes, and again before the expiry date.
The Standards Council of Canada states that a completed Level 1 self-assessment is a prerequisite for Level 2 certification, so this is everyone's first step.
// 05 · CANADABUYS
Filing it in CanadaBuys
The certification has to be in place at contract award, and proof of it goes in with the bid.
- Make sure the organization has an active CanadaBuys account and supplier profile.
- Read the Level 1 criteria and PSPC's CPCSC Level 1 Scoping Guide, and draw your boundary.
- Complete the self-assessment with PSPC's online tool. Assessing by another means is allowed, and you keep the results either way.
- Print or save the results page, which shows the expiry date, and file it with your evidence.
- Confirm the result and expiry date in the organizational supplier profile questionnaire in CanadaBuys.
- Include proof of the self-attestation and its expiry date with bids on contracts that require Level 1.
- Calendar the expiry with a month's lead time.
Portal screens change; follow CanadaBuys' current wording.
References
- Canadian Program for Cyber Security Certification: Level 1Public Services and Procurement Canadacanada.ca
- How to meet Level 1 requirementsPublic Services and Procurement Canadacanada.ca
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.
CPCSC Level 1 readiness
A review against all 13 control families, a written gap list in plain language, and the self-assessment record a supplier needs to attest in CanadaBuys.