// SECURITY AND COMPLIANCE · HANS STUDY · ONTARIO, CANADA

Security and compliance readiness

Hans Study provides independent readiness work for CPCSC, CMMC and NIST SP 800-171, and ISO 27001, alongside security assessments, reviews, and a written policy pack. No CPCSC engagements have been completed to date; the readiness work here is built from NIST SP 800-171 and CMMC readiness work with small defence suppliers since 2019.

Program status as of October 1, 2026

CPCSC Level 1 (13 controls, annual self-assessment) has been available to suppliers since April 1, 2026, and is required in select defence contracts from summer 2026, at contract award.

CPCSC Level 2 (98 controls, third-party assessment by an accredited certification body) phases into select contracts from spring 2027. CPCSC Level 3 (130+ controls) is assessed by National Defence. Controls for all 3 levels come from ITSP.10.171, and the level a given contract carries is set through a contract cyber security risk assessment and stated in the RFP and the contract clauses, not chosen by the supplier.

CMMC Phase 2 (the US third-party assessment requirement) was suspended on July 13, 2026, pending review. Phase 1 self-assessment and DFARS 252.204-7012 still apply.

Advise

CPCSC, explained →

What the Canadian Program for Cyber Security Certification is, the 3 levels, who it applies to, and how it compares with CMMC.

CMMC and NIST SP 800-171 readiness →

Independent CMMC and NIST SP 800-171 consulting for the defence industrial base: architecture review, gap assessment, and the technical work an assessment checks.

Starting at $8,500.

ISO 27001 readiness →

Gap assessment and readiness work toward ISO/IEC 27001 for small and mid-size organizations.

Starting at $6,500.

Policy pack →

A written security policy set for a small organization, scoped to what an assessor or insurer actually asks to see.

Starting at $3,500.

Assess

Security assessments and reviews →

Vendor-agnostic security assessments and reviews: program and gap assessments, architecture, network hardening.

Find out which framework actually applies

Which program reaches your organization depends on your contracts, your customers, and your sector. A scoping call sorts that out before anything is quoted.