// CPCSC · UPDATES LOG
Program updates
Last verified: 2026-10-05
PSPC revises its program pages without press releases; the September 29, 2026 overview changed the Level 3 count with nothing announced. This log is how the hub stays honest about that. Newest first. Each entry says what changed and what it means for a supplier.
// LOG · NEWEST FIRST
-
Corrections. CMMC: PSPC may accept a valid CMMC certification case by case at Level 1, after confirming the assessment covers the required scope; earlier text said there was no recognition. Level 1 is required at contract award, with proof submitted with the bid. PSPC's Level 1 scoping guide is published. The Level 2 calendar is rebased on October 2026.
-
Verified. No CPCSC changes since September 29. CMMC review report still unpublished; the Department has said a Level 2 update is coming in October.
-
PSPC revised the program overview. Level 3 restated as 130-plus controls (earlier pages said 200), drawn from ITSP.10.171 plus enhancements adapted from NIST SP 800-172. Level 1 criteria published as a Canadian version of NIST SP 800-171A Revision 3. Levels 2 and 3 described as under development. The overview now names 8 federal bodies and their roles, 5 program outcomes, 4 working parts (controls, risk assessments, contract clauses, accredited third-party assessors), and a risk-based, adaptive approach. What it means: check any Level 3 figure you've seen against this date.
-
CMMC: a DFARS class deviation made the Phase 2 suspension binding on contracting officers, with third-party Level 2 requirements removed from solicitations and self-assessments permitted.
-
CMMC: an aerospace supplier settled False Claims Act allegations over NIST SP 800-171 failures for about $2 million. What it means: the attestation carries legal weight on both sides of the border.
-
CMMC: Phase 2 transition suspended pending departmental review; Phase 1 obligations stay in force.
- Summer 2026
CPCSC Level 1 requirements began appearing in select defense contracts.
-
PSPC formally announced CPCSC Level 1.
-
Level 1 self-assessment opened to suppliers through CanadaBuys.
-
CMMC: the 48 CFR acquisition rule took effect, making CMMC status a condition of award.
-
Cyber Centre published the second release of ITSP.10.171, the current version.
-
ITSP.10.171 first release took effect as the program's technical standard.
-
CPCSC Phase 1 launched; the Standards Council of Canada began accepting applications from prospective certification bodies.
-
CMMC: 32 CFR Part 170 took effect.
- Fall 2023
Treasury Board approved CPCSC; Budget 2023 identified $25 million for design and implementation through 2025 to 2026.
// COMING
Level 2 assessment methodology and certification body list · conditional certification rules · Level 3 criteria · PSPC position on fixed parameter values · CMMC review report and any Revision 3 rulemaking
References
- Cyber security certification for defence suppliers in Canada: Program overviewPublic Services and Procurement Canadacanada.ca
- Canadian Program for Cyber Security Certification: Level 1Public Services and Procurement Canadacanada.ca
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.