// CPCSC · MSPS AND INTEGRATORS
For MSPs and integrators
Last verified: 2026-10-05
Neither an MSP nor an integrator signs a CPCSC attestation for a client, but both can end up inside the client's scope. If you administer the systems that hold Specified Information, or carry the client's drawings on your commissioning laptops, the assessor will look at your access, your tools, and your people.
// 01 · WHO DOES WHAT
The responsibility matrix
"They handle our IT" is not a control description. Level 2 forces a written matrix: requirement by requirement, who operates the control, who holds the evidence, and what deliverable arrives on what cadence. Patching, firewall rules, log collection, MFA enrolment, and backup testing usually sit with the MSP; access reviews, training, and contract reporting usually sit with the client. Attach the matrix to the service contract. The shared responsibility matrix template is the starting point.
// 02 · REMOTE ACCESS
Remote access done properly
I've had MSPs tell me "this is how we do it" while their whole bench had a remote tool on every machine. That arrangement is very hard to defend against the access control and maintenance requirements, and it isn't role-based anything. Route remote support through a jump host with MFA on the session, which 03.07.05 requires for non-local maintenance. Keep admin work on separate admin workstations and never work under an admin account day to day. If a remote support tool stays, record sessions from the moment of login, because those tools get compromised and used to wipe fleets. Send the logs to a basic central log server; nobody is asking for a SIEM.
Then read 03.14.09, the one requirement Canada added to the NIST set. It wants administrative work done from a dedicated, hardened workstation isolated from other networks and from the internet, and remote administration from that workstation carried over a carrier private network such as VPLS or MPLS with VPN encryption, rather than an internet-exposed VPN. Most MSPs administer clients over the internet today, so this is the clause to raise with yours before Level 2, and to get an assessor's reading on once the methodology is published.
// 03 · ARM'S LENGTH
Who assesses the MSP's work
Your IT provider shouldn't be assessing its own work; some won't tell on themselves. Keep vulnerability scanning and configuration review at arm's length, and treat any provider that refuses configuration access or hides behind "proprietary" as a red flag. A sales-oriented assessment tool may tick a box. It's still a sales tool.
// 04 · QUESTIONS
Questions a client should ask its provider
- Which of our systems can your staff reach, from where, and through what?
- Is MFA enforced on every one of those paths?
- Are support sessions recorded, and where do the recordings and logs go?
- What screening have the technicians who can reach our enclave been through?
- What deliverable do we get for patching, firewall review, and backup testing, and how often?
- Will you give us, or our assessor, read access to switch and firewall configurations?
- What happens to our data, accounts, and access if we end the contract?
// 05 · INTEGRATORS
For integrators specifically
Facility drawings, device schedules, and network documentation for a defense site are often Specified Information under the site's contract. The commissioning laptop that carries them, the email they arrived in, and the cloud folder the project team shares are in scope. Treat project data like the enclave it is: encrypted laptops, a managed transfer path, a purge at project close checked against the retention clause, and a written list of who on the crew had access.
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- Cyber security certification for defence suppliers in Canada: Program overviewPublic Services and Procurement Canadacanada.ca
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.