- CPCSC · LIVE
Level 1 self-assessment available via CanadaBuys; requirements in select defense contracts since summer 2026.
- CPCSC · AHEAD
Level 2 third-party assessments planned for select contracts from spring 2027; SCC accreditation of certification bodies underway.
- CMMC · LIVE
Phase 1 active: Level 1 and Level 2 self-assessment requirements in solicitations, SPRS records, DFARS 252.204-7012 duties, and annual affirmations all in force.
- CMMC · SUSPENDED
Phase 2 transition suspended July 13, 2026, and made binding on contracting officers September 3; the November 10, 2026 date is not operative. The Reform Task Force report is with the CIO and unpublished; the Department has said a Level 2 update is coming in October. Separate rulemaking to move the program onto NIST SP 800-171 Revision 3 is in progress. The program rule and DFARS clauses are unchanged.
- CMMC · ENFORCEMENT
September 1, 2026: an aerospace supplier settled False Claims Act allegations over NIST SP 800-171 failures for about $2 million. The suspension paused certification, not liability.
- BOTH
No mutual recognition between the programs.
// COMPARISON · DEFENCE SUPPLY CHAIN · CANADA / UNITED STATES
CPCSC vs CMMC: same DNA, separate machinery
- Canada: CPCSC · PSPC · ITSP.10.171
- US: CMMC · DoD · NIST SP 800-171
- Mutual recognition: none to date
- Last verified: 2026-10-05
Canada and the United States now each run a mandatory cyber security certification for their defense supply chains. The 2 programs share a technical spine, the NIST SP 800-171 control set, and almost nothing else: different laws, different assessors, different portals, different timelines, and as of this page's verification date, no mutual recognition. A supplier selling into both markets complies with both, separately.
For the CPCSC program on its own, start with the CPCSC explainer.
// 01 · TWO HISTORIES
How did each program get here?
CMMC is the older program by 6 years, and CPCSC is openly modelled on it. Watching the American rollout, including its false starts, is part of why Canada's version launched with 3 levels instead of 5 and leaned on an existing standard rather than inventing one.
CMMC
- 2016–2017
The clauses arrive first. FAR 52.204-21 sets 15 basic safeguarding requirements for federal contract information; DFARS 252.204-7012 requires NIST SP 800-171 for CUI plus incident reporting. Compliance is self-attested, and enforcement is thin.
- Jan 2020
CMMC 1.0. DoD announces a 5-level certification model with third-party assessment for nearly everyone. Industry pushback on cost and complexity is immediate.
- Nov 2021
CMMC 2.0. The model is cut to 3 levels, aligned to NIST SP 800-171, with self-assessment restored for lower-risk contracts.
-
32 CFR Part 170 in effect. The program rule establishes the certification model, assessment processes, and the Cyber AB accreditation structure.
-
48 CFR acquisition rule in effect. DFARS 252.204-7021 makes CMMC status a condition of award; provision 252.204-7025 tells contracting officers to name the required level. Phase 1 of a planned 4-phase rollout begins.
-
Phase 2 suspended. The Department suspends the Phase 2 transition pending review. Phase 1 stays active; the underlying rules, self-assessments, SPRS obligations, and annual affirmations remain in force.
-
Suspension made binding. DFARS Class Deviation 2026-O0025 Revision 3 directs contracting officers to remove third-party CMMC requirements from solicitations and permits Level 1 and Level 2 self-assessments. The Reform Task Force's report reached the CIO around September 11; it hasn't been published. No replacement date announced.
CPCSC
- Fall 2023
Treasury Board approval. CPCSC is approved; Budget 2023 puts $25 million behind design and implementation through 2025–2026.
-
Phase 1 launches. Standards work for Levels 1 and 2 begins, along with the Level 1 self-assessment tool. The Standards Council of Canada opens applications for certification body accreditation.
-
ITSP.10.171 in effect. The Cyber Centre's Canadian adaptation of NIST SP 800-171 becomes the program's technical foundation. Same controls; Canadian terminology, policy references, and privacy framework.
-
Level 1 introduced. Formally announced, available through CanadaBuys since April 1. Annual self-assessment against 13 controls, with a signed attestation.
- Summer 2026
Level 1 in contracts. Requirements begin appearing in select defense contracts.
- Spring 2027
Level 2 in contracts (planned). Third-party assessments by SCC-accredited certification bodies scheduled to reach select contracts.
// 02 · WHERE THEY'RE THE SAME
What do CPCSC and CMMC have in common?
- The same control set. ITSP.10.171 is a deliberate Canadian adaptation of NIST SP 800-171 Revision 3 with no substantive technical changes; the document says so itself. It carries 98 requirements across 17 families, with the identifiers NIST withdrew in Revision 3 kept as not allocated so numbering lines up across the border, and it uses organization-defined parameters, the bracketed values a supplier sets and records in its system security plan unless a contract specifies them. Work done implementing 800-171 controls transfers technically in both directions.
- The same target data class. Both programs protect sensitive but unclassified government information on supplier systems. Canada calls it Specified Information; the US calls it Controlled Unclassified Information. In both cases the contract identifies data that needs safeguarding once it leaves government networks.
- Certification as a condition of award. Both programs enforce through procurement: certification is a gate on contract eligibility, named per solicitation, flowed down to subcontractors handling the protected data.
- A 3-level structure with self-assessment at the bottom. Both start with an annual self-assessment and attestation for basic safeguarding, move to third-party assessment in the middle tier, and reserve government-led assessment for the most sensitive work.
- Signed attestations with teeth. Both rely on an accountable signature. In the US that's the affirming official filing in SPRS, with False Claims Act exposure behind it, and a September 2026 settlement of about $2 million over 800-171 failures shows the exposure is priced. In Canada, misrepresenting compliance in a federal contract context carries its own legal exposure.
- Five Eyes convergence as the point. Both governments frame their program as raising the defense industrial base's floor while keeping suppliers interoperable with allied procurement.
// 03 · WHERE THEY DIVERGE
Where do CPCSC and CMMC differ?
- No mutual recognition. The one everyone asks about first. A CMMC certificate doesn't satisfy a CPCSC clause, and a CPCSC certification doesn't satisfy DFARS 252.204-7021. Cross-border suppliers run both processes and pay both assessment costs. The technical overlap shrinks the implementation work and leaves the administrative load untouched.
- Different legal machinery. CMMC lives in US federal rulemaking: 32 CFR Part 170 for the program, the 48 CFR acquisition rule and DFARS clauses for contracts. CPCSC lives in Canadian procurement policy under PSPC, with requirements articulated in RFPs and contract clauses.
- Different assessor structures. CMMC third-party assessments run through C3PAOs accredited under the Cyber AB structure. CPCSC Level 2 assessments run through certification bodies accredited by the Standards Council of Canada. Separate accreditations, separate assessor markets, separate scheduling queues.
- Different level arithmetic. CMMC Level 1 is 15 requirements; CPCSC Level 1 is 13. CMMC Level 2 is the full 110 controls of NIST SP 800-171; CPCSC Level 2 assesses 98 controls under ITSP.10.171. CMMC Level 3 adds 24 enhanced requirements from NIST SP 800-172; CPCSC Level 3 is 130-plus controls assessed by National Defence. The sets are close cousins, and scoping against the wrong document still wastes real hours.
- Different middle tiers. CMMC Level 2 splits into self-assessment for some contracts and C3PAO certification for others, decided by the solicitation. CPCSC Level 2 as published is a third-party assessment, full stop, every 3 years with annual affirmations.
- Different rollout positions. CMMC has been enforceable in contracts since November 2025, with its Phase 2 expansion suspended since July 2026 pending review. CPCSC Level 1 entered contracts in summer 2026, with Level 2 still ahead. One program is mid-course-correction and the other is early in its rollout; both are contractually real today.
- Data residency and sovereignty pressure. Canadian contracts bring Canadian data governance: TBS policy, PIPEDA, and, contract by contract, expectations about where Specified Information can live and who can touch it. US-cloud-first architectures that sailed through a CMMC scope can need rework under Canadian clauses.
// 04 · THE MATRIX
The full comparison matrix
| Attribute | CPCSC (Canada) | CMMC (United States) |
|---|---|---|
| Program owner | Public Services and Procurement Canada | US Department of Defense (now Department of War) |
| Legal basis | Treasury Board approval (fall 2023); procurement clauses in RFPs and contracts | 32 CFR Part 170 (program, eff. Dec 16, 2024); 48 CFR acquisition rule with DFARS 252.204-7021 and 252.204-7025 (eff. Nov 10, 2025) |
| Underlying standard | ITSP.10.171 (Cyber Centre; Canadian adaptation of NIST SP 800-171) | NIST SP 800-171 (plus SP 800-172 at Level 3) |
| Protected data | Specified Information (SI) | Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) |
| Levels | 3 | 3 |
| Level 1 | 13 controls; annual self-assessment and attestation | 15 requirements; annual self-assessment and affirmation (FCI) |
| Level 2 | 98 controls; third-party assessment every 3 years, plus annual affirmation | 110 controls; self-assessment or C3PAO certification every 3 years (per solicitation), plus annual affirmations |
| Level 3 | 130-plus controls; assessed by National Defence every 3 years, plus annual affirmation | Level 2 plus 24 enhanced requirements from SP 800-172; government-led assessment |
| Assessor accreditation | Certification bodies accredited by the Standards Council of Canada | C3PAOs accredited under the Cyber AB structure |
| Where attestations file | CanadaBuys supplier portal | SPRS, signed by an affirming official; systems carry a CMMC unique identifier |
| Contract mechanism | Required level named per solicitation in RFP and contract clauses | DFARS 252.204-7025 names the level; 252.204-7021 makes status a condition of award and ongoing performance |
| Conditional certification | POA&M-style conditional status: detailed rules not yet published at this page's verification date | Limited POA&Ms permitted at Levels 2 and 3, closed out within 180 days |
| Rollout status (Sep 2026) | Level 1 live, in select contracts since summer 2026; Level 2 planned for spring 2027; Level 3 in development | Phase 1 active since Nov 10, 2025; Phase 2 suspended Jul 13, 2026, made binding by class deviation Sep 3; Task Force report with the CIO, unpublished; no replacement date |
| Mutual recognition | None. Each program's certification satisfies only its own contracts. | None. Cross-border suppliers comply with both independently. |
Control counts reflect each program's published documents; both governments describe the underlying technical requirements as aligned. Numbers shift as standards revise, which is exactly why this page carries a verification date.
// 05 · WHAT TRANSFERS
If you've done one, what carries to the other?
Carries well: the implemented controls themselves. Access control, MFA, logging, configuration baselines, media handling, incident response; an environment built to 800-171 is substantially built for ITSP.10.171, and the reverse. Your system security plan structure carries too, along with the scoping discipline of confining protected data to a defined enclave. So does the organizational muscle: evidence habits, change control, and someone who owns the program.
Carries poorly: everything administrative. Attestations, portals, assessment contracts, affirmation calendars, and certificates are program-specific. Scope can also shift under Canadian data governance requirements, so an enclave design accepted in a CMMC assessment isn't automatically the enclave a Canadian contract accepts. Terminology needs translating in your documentation; an assessor reading your SSP shouldn't have to guess whether "CUI" means Specified Information here.
// 06 · CURRENT STATUS, BOTH SIDES
What's operative right now?
The defensible read on both programs in September 2026 is the same: keep implementing against the 800-171 control family and keep your attestations current; the phase schedules can move without you having to.
// 07 · FAQ
Frequently asked questions
Does a CMMC certificate satisfy CPCSC?
No. There's no mutual recognition between the programs as of September 2026. A CMMC certificate satisfies only DFARS clauses, and a CPCSC certification satisfies only Canadian contract clauses.
Are the CPCSC and CMMC controls the same?
Technically, yes in substance. ITSP.10.171 is a Canadian adaptation of NIST SP 800-171 with no substantive technical changes, so control implementation work transfers in both directions. The counts differ by revision: CPCSC Level 2 assesses 98 controls, CMMC Level 2 assesses 110.
Which should a cross-border supplier do first?
Whichever program's clause reaches your contracts first, but run both compliance calendars from the start. The implementation work overlaps heavily; the attestations, portals, and assessment engagements don't.
Is ITSP.10.171 different from NIST SP 800-171?
Only contextually. The Cyber Centre adapted 800-171 by swapping in Canadian terminology (Specified Information for CUI), Treasury Board policy references, and Canadian privacy framing, without substantive technical changes to the requirements.
// 08 · SOURCES
Both programs move. Where this page and an official publication disagree, the official publication wins; corrections welcome at contact@hans.study.
- PSPC, CPCSC Program Overview and Level 1 backgrounder (canada.ca)
- PSPC, Evaluation of the Canadian Program for Cyber Security Certification: Final Report (canada.ca)
- Canadian Centre for Cyber Security, ITSP.10.171
- 32 CFR Part 170, CMMC Program rule
- 48 CFR CMMC acquisition rule; DFARS 252.204-7012, -7021, -7025
- DoD CIO CMMC program materials, including the July 13, 2026 Phase 2 suspension memo
References
- Cyber security certification for defence suppliers in Canada: Program overviewPublic Services and Procurement Canadacanada.ca
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- CMMC Program 32 CFR Part 170 Final RuleU.S. Department of Defense / Federal Registerfederalregister.gov
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.