// CPCSC · LEVEL 2 · SELECT CONTRACTS FROM SPRING 2027

CPCSC Level 2

  • 98 requirements
  • Third-party assessment
  • Every 3 years plus annual affirmation
  • Planned spring 2027
  • Last verified: 2026-10-05

Level 2 assesses all 98 ITSP.10.171 requirements. Assessments are done by certification bodies accredited through the Standards Council of Canada, using assessors certified under the program, on a 3-year cycle with an annual affirmation in between. PSPC plans to put Level 2 into select contracts from spring 2027, and a completed Level 1 self-assessment is a prerequisite.

// WARN

The assessment methodology, the list of accredited certification bodies, the fee structures, and the rules for gaps found at assessment had not been published as of this page's verification date. That last one matters: there's no published position on whether a supplier can be certified with open items under a plan of action and milestones (a POA&M), which items would qualify, or how long it would have to close them. CMMC allows limited POA&Ms closed within 180 days; don't assume Canada will match that. What follows is the announced structure plus the way accredited certification bodies already work under other schemes. Check the updates log before booking anything.

// 01 · SCALE

The jump from 13 to 98

Level 1 asks whether you do sensible things. Level 2 asks you to prove it to a stranger: written policies, procedures people follow, a system security plan that matches the running network, evidence for every requirement, and a scope tight enough that the assessment doesn't wander across the whole business. Governance fails small shops more often than technology does. Firewalls get budget; documented procedures, separation of duties, and evidence habits are what the assessor reads first.

// 02 · THE ASSESSMENT

What assessors do

They sample and they triangulate. For each requirement: read what the SSP claims, ask the person responsible what happens, then ask for the artifact that shows it happening. When the 3 agree, the requirement closes quickly. When they don't, the pulling starts, and neighbouring requirements get pulled too. Interviews reach past IT to the engineer handling drawings, the office manager onboarding new hires, and the shop lead whose crew uses the enclave workstations.

// 03 · COMMON FINDINGS

The findings that show up first

  • MFA on the main paths and missing on a secondary one
  • Log review that exists on paper only
  • Access lists with departed staff still on them
  • SSP claims the evidence can't back
  • Remediation registers whose dates keep sliding
  • Specified Information found outside the agreed boundary

Every one of these is findable in your own rehearsal. Found by you, it's a task; found by the assessor, it's a result.

// 04 · SCHEDULE

The calendar math

MilestoneTarget if you want spring 2027 contracts
Contract-readyQ2 2027
Assessment completeQ1 2027
Certification body engagedQ4 2026
Internal rehearsalQ3 to Q4 2026
RemediationNow through Q3 2026, longer if the gap register says so
Gap assessmentNow

A contained shop with current infrastructure is looking at roughly 6 months of part-time effort. A flat network with shared admin accounts and no logging is looking at 18 months and some capital. Measuring optimistically doesn't change the number.

References

  1. Cyber security certification for defence suppliers in Canada: Program overviewModified 2026-09-29
    Public Services and Procurement Canadacanada.ca
  2. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  3. CPCSC accreditation scheme
    Standards Council of Canadascc-ccn.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.