// CPCSC · LEVEL 3 · IN DEVELOPMENT

CPCSC Level 3

Last verified: 2026-10-05

Level 3 is the top tier, for the most sensitive work, and it's assessed by National Defence itself on a 3-year cycle with annual affirmations. On September 29, 2026, PSPC's program overview described it as 130-plus controls: the 98 of ITSP.10.171 plus enhanced requirements adapted from NIST SP 800-172. Earlier program pages and most secondary coverage said 200, so if you've seen that figure, it predates the revision.

The criteria, the exact enhanced requirement set, and the assessment method hadn't been published as of this page's verification date. If your work sits at this tier, you already have a security team and a relationship with the department; for everyone else, Level 3 is a horizon item, and the practical move is getting the Level 2 foundation right, since Level 3 builds on it rather than replacing it.

The American comparison: CMMC Level 3 adds 24 enhanced requirements from the same SP 800-172 to its Level 2 base, also government-assessed. CPCSC vs CMMC has the full table.

References

  1. Cyber security certification for defence suppliers in Canada: Program overviewModified 2026-09-29
    Public Services and Procurement Canadacanada.ca
  2. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.