// WHO IT’S FOR
It’s written for the person who found out on a Tuesday. The network admin keeping the business running who just got forwarded a solicitation with a certification clause in it. The office manager handed “compliance” because nobody else put their hand up. The IT lead at a 30-person shop expected to become a certification program on top of everything else. Plain language, sized for evenings and stolen Friday afternoons, built on scenarios inspired by ISO 27001, PCI-DSS, and CMMC readiness engagements with real suppliers.
// WHAT’S INSIDE
Twelve chapters in the order you’d actually work: what CPCSC is and why Ottawa built it, the 3 levels, whether the program applies to you, how it compares with CMMC and where the overlap saves you effort, the Level 1 controls and the attestation you’re signing, scoping an enclave that keeps assessment costs sane, running a gap assessment worth trusting, the technical work family by family, documentation that survives an assessor, Level 2 preparation, small shop realities including the MSP conversation, and staying certified after the first attestation. Study Notes from the field throughout, plus a Level 1 readiness checklist and a Canada-US terminology translation table in the appendices.
// FORMATS
Free digital PDF, ISBN 978-1-0680175-2-0, tagged and searchable, 60 pages: Download the PDF.
EPUB, ISBN 978-1-0680175-3-7, free on Apple Books, Kobo, and Google Play, and on Kindle.
Paperback, 8.5 × 11, 72 pages, ISBN 978-1-0680175-1-3, from Amazon.
First edition, revision 1.3, October 1, 2026, including the September 29, 2026 program changes. DOI 10.5281/zenodo.23145960.
Licensed CC BY-ND 4.0: share it freely with credit, unmodified.
// THE LIVING COMPANION
A printed book can’t chase a moving program, so this one doesn’t pretend to. The companion pages carry the current program state with a last-verified date: the CPCSC hub and CPCSC vs CMMC. The policy templates and checklists from the appendices are at CPCSC templates as editable downloads.
// CONTENTS
- 1 What CPCSC is and why Ottawa built it
- 2 The 3 levels, plainly
- 3 Does this apply to you
- 4 CPCSC, CMMC, and ITSP.10.171
- 5 Level 1: the 13 requirements and the attestation you’re signing
- 6 Scoping: where Specified Information lives
- 7 Running your own gap assessment
- 8 The technical work, control family by control family
- 9 Documentation that survives an assessor
- 10 Level 2 prep: what third-party assessment looks like
- 11 Small shop realities: MSPs, cloud, cost, and sequencing
- 12 Staying certified: life after the first attestation
- A to E Appendices: Level 1 checklist, Canada and US terminology table, sources, templates, and the full ITSP.10.171 requirement index