// CPCSC · UPDATES LOG

Program updates

Last verified: 2026-10-05

PSPC revises its program pages without press releases; the September 29, 2026 overview changed the Level 3 count with nothing announced. This log is how the hub stays honest about that. Newest first. Each entry says what changed and what it means for a supplier.

// LOG · NEWEST FIRST

  1. Corrections. CMMC: PSPC may accept a valid CMMC certification case by case at Level 1, after confirming the assessment covers the required scope; earlier text said there was no recognition. Level 1 is required at contract award, with proof submitted with the bid. PSPC's Level 1 scoping guide is published. The Level 2 calendar is rebased on October 2026.

  2. Verified. No CPCSC changes since September 29. CMMC review report still unpublished; the Department has said a Level 2 update is coming in October.

  3. PSPC revised the program overview. Level 3 restated as 130-plus controls (earlier pages said 200), drawn from ITSP.10.171 plus enhancements adapted from NIST SP 800-172. Level 1 criteria published as a Canadian version of NIST SP 800-171A Revision 3. Levels 2 and 3 described as under development. The overview now names 8 federal bodies and their roles, 5 program outcomes, 4 working parts (controls, risk assessments, contract clauses, accredited third-party assessors), and a risk-based, adaptive approach. What it means: check any Level 3 figure you've seen against this date.

  4. CMMC: a DFARS class deviation made the Phase 2 suspension binding on contracting officers, with third-party Level 2 requirements removed from solicitations and self-assessments permitted.

  5. CMMC: an aerospace supplier settled False Claims Act allegations over NIST SP 800-171 failures for about $2 million. What it means: the attestation carries legal weight on both sides of the border.

  6. CMMC: Phase 2 transition suspended pending departmental review; Phase 1 obligations stay in force.

  7. Summer 2026

    CPCSC Level 1 requirements began appearing in select defense contracts.

  8. PSPC formally announced CPCSC Level 1.

  9. Level 1 self-assessment opened to suppliers through CanadaBuys.

  10. CMMC: the 48 CFR acquisition rule took effect, making CMMC status a condition of award.

  11. Cyber Centre published the second release of ITSP.10.171, the current version.

  12. ITSP.10.171 first release took effect as the program's technical standard.

  13. CPCSC Phase 1 launched; the Standards Council of Canada began accepting applications from prospective certification bodies.

  14. CMMC: 32 CFR Part 170 took effect.

  15. Fall 2023

    Treasury Board approved CPCSC; Budget 2023 identified $25 million for design and implementation through 2025 to 2026.

// COMING

Level 2 assessment methodology and certification body list · conditional certification rules · Level 3 criteria · PSPC position on fixed parameter values · CMMC review report and any Revision 3 rulemaking

References

  1. Cyber security certification for defence suppliers in Canada: Program overviewModified 2026-09-29
    Public Services and Procurement Canadacanada.ca
  2. Canadian Program for Cyber Security Certification: Level 12026-04-14
    Public Services and Procurement Canadacanada.ca
  3. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.