// CPCSC TEMPLATES · 01 OF 14

Level 1 requirements and evidence checklist

Last verified: 2026-10-05

The 13 ITSP.10.171 requirements CPCSC Level 1 assesses, from PSPC's Level 1 criteria, with the evidence an assessor's examine, interview, and test methods will reach for.

Download as Markdown

Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.

TPL-01 Static template

Preparation, before the 13:

  • Contracts reviewed for Specified Information clauses
  • Data flow mapped; system boundary drawn and dated
  • Evidence folder started, one subfolder per requirement
  • Results page with expiry date saved; result and expiry confirmed in the CanadaBuys profile; renewal calendared

Requirements and evidence:

  • 03.01.01 Account management · account list with owners; inactivity and notification periods set; disabled accounts recorded
  • 03.01.02 Access enforcement · group permissions on enclave shares; screenshots dated
  • 03.01.20 Use of external systems · policy on personal and external systems; agreements where used
  • 03.01.22 Publicly accessible content · review record of website and social posts
  • 03.05.01 User identification and authentication · unique IDs; no shared logins; re-authentication rules
  • 03.05.02 Device identification and authentication · device list; 802.1X or equivalent where used
  • 03.05.03 Multi-factor authentication · MFA enrolment list covering privileged and non-privileged accounts
  • 03.08.03 Media sanitization · sanitization and destruction log with evidence
  • 03.10.01 Physical access authorizations · approved access list; review date; removals recorded
  • 03.10.07 Physical access control · door control, visitor log, key control, output devices
  • 03.13.01 Boundary protection · firewall rule set; managed interfaces; segmentation diagram
  • 03.14.01 Flaw remediation · patch windows defined; patch reports
  • 03.14.02 Malicious code protection · endpoint console screenshot: current, scanning, blocking

References

  1. How to meet Level 1 requirementsModified 2026-09-29
    Public Services and Procurement Canadacanada.ca
  2. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.