// SECURITY AND COMPLIANCE · HANS STUDY · ONTARIO, CANADA
Security and compliance readiness
Hans Study provides independent readiness work for CPCSC, CMMC and NIST SP 800-171, and ISO 27001, alongside security assessments, reviews, and a written policy pack. No CPCSC engagements have been completed to date; the readiness work here is built from NIST SP 800-171 and CMMC readiness work with small defence suppliers since 2019.
Program status as of October 1, 2026
CPCSC Level 1 (13 controls, annual self-assessment) has been available to suppliers since April 1, 2026, and is required in select defence contracts from summer 2026, at contract award.
CPCSC Level 2 (98 controls, third-party assessment by an accredited certification body) phases into select contracts from spring 2027. CPCSC Level 3 (130+ controls) is assessed by National Defence. Controls for all 3 levels come from ITSP.10.171, and the level a given contract carries is set through a contract cyber security risk assessment and stated in the RFP and the contract clauses, not chosen by the supplier.
CMMC Phase 2 (the US third-party assessment requirement) was suspended on July 13, 2026, pending review. Phase 1 self-assessment and DFARS 252.204-7012 still apply.
Advise
CPCSC, explained →
What the Canadian Program for Cyber Security Certification is, the 3 levels, who it applies to, and how it compares with CMMC.
- CPCSC Level 1: the 13 controls, starting at $3,500
- CPCSC Level 2: preparing for spring 2027, scoped
CMMC and NIST SP 800-171 readiness →
Independent CMMC and NIST SP 800-171 consulting for the defence industrial base: architecture review, gap assessment, and the technical work an assessment checks.
Starting at $8,500.
ISO 27001 readiness →
Gap assessment and readiness work toward ISO/IEC 27001 for small and mid-size organizations.
Starting at $6,500.
Policy pack →
A written security policy set for a small organization, scoped to what an assessor or insurer actually asks to see.
Starting at $3,500.
Assess
Security assessments and reviews →
Vendor-agnostic security assessments and reviews: program and gap assessments, architecture, network hardening.
Find out which framework actually applies
Which program reaches your organization depends on your contracts, your customers, and your sector. A scoping call sorts that out before anything is quoted.