Understanding the CPCSC: What the federal government now requires of defence supplier SMEs
Imagine a bid that is lost at the very last stage. Not because of the price. Not because of the technical offer. But because of a box that was left blank in the vendor profile. Was the CPCSC self-assessment completed? No.
But this scenario is no longer theoretical.
The Canadian Program for Cyber Security Certification (CPCSC) became a condition of award for some Government of Canada defence contracts this summer. If you do business directly or as a subcontractor with National Defence, you are now required to comply with some basic cyber security requirements.
What does CPCSC consist of?
The CPCSC is a new formal cyber security certification program for defence suppliers in Canada, under the responsibility of Public Services and Procurement Canada (PSPC) and National Defence. The certification program defines cyber security standards that entrepreneurs in the sector must meet to ensure the security of sensitive information.
To determine what a company must do to protect sensitive information, the program uses the Canadian Centre for Cyber Security’s ITSP.10.171 standard. This Canadian standard is largely based on the U.S. standard NIST SP 800-171, which defines the security measures that organizations outside the federal government must put in place to protect sensitive information in their systems.
For higher levels of protection, the program also uses NIST SP 800-172, which includes additional security requirements to address more advanced threats.
These same U.S. standards also form the basis of the U.S. Cybersecurity Maturity Model Certification (CMMC) program. This means that Canadian and U.S. requirements have a common basis, but have significant differences that will need to be adequately assessed by the company. There is also no reciprocity between Canadian and American certifications.
What information does the CPCSC protect?
The CPCSC does not cover all of a company’s information. It deals with what the government calls “specified information.”
There is a formal definition, taken directly from the Canadian Centre for Cyber Security’s ITSP.10.171 standard:
Specified information includes any information, other than classified, that a Government of Canada authority identifies and qualifies in a contract as requiring safeguarding.
Patrick Boucher
CISSP, CISA, CGEIT, ITIL, C|EH, CDPSE, CQI/IRCA (Principal Auditor), Consultant, BDC, and founding president, certi360
The term replaces controlled unclassified information (CUI) used in the equivalent U.S. standard.
Specifically, specified information may include:
- unclassified information related to the contract that is not intended for the general public, such as engineering drawings, manufacturing specifications or test results;
- information on controlled goods, such as components or equipment subject to the Controlled Goods List;
- information that is protected under the Government of Canada’s Protected A, B or C categories, such as financial data or personal information related to the contract.
The contract always specifies which of these categories applies. If this is not clear, ask the contracting authority directly rather than guessing.
What are the three CPCSC levels?
The CPCSC has three levels, but only the first level is currently active:
Level 1
Level 1 requires an annual self-assessment of 13 core cyber security controls. It has been available to suppliers since April 1, 2026. This is the level that is now required in some defence contracts. We will explain a little later in the text what this requirement entails.
Level 2
Will require an external assessment by a certification body accredited by the Standards Council of Canada, as well as annual confirmation. PSPC currently indicates that there will be 98 controls. It will apply to contracts requiring controlled information from National Defence or more sensitive work starting in spring 2027. The costs associated with achieving Level 2 have not yet been confirmed.
Level 3
This level is reserved for high-risk scenarios—weapon systems, critical infrastructure, information shared with Five Eyes partners. It will be assessed directly by National Defence, with approximately 200 controls, and will also include annual confirmation.
Levels 2 and 3 are still under development and the above figures may change. Level 1 is already very real and affects most SMEs in the National Defence supply chain.
Does the CPCSC pertain to you? Four questions to ask yourself
Before investing time in Level 1 of the CPCSC certification process, answer the following five questions:
- Do you have, or do you intend to have, a defence contract or subcontract with the Government of Canada?
- Have you identified which products or services will be offered?
- Does this contract contain specified information (see next section)? Refer to the contract, security clauses and handling instructions. If in doubt, ask the contracting authority.
- Do your systems, personnel or premises receive, store or transmit this information?
- Are you a subcontractor to a prime contractor who handles this information? Are you a level 1, 2 or 3 contractor? Subcontractors that handle the information must also hold the appropriate certification and determine the scope of action to be taken.
If you answered yes to any of these questions, the rest is relevant to you as you will likely require CPCSC Level 1 certification.
Level 1, in concrete terms: a self-assessment, not an audit
This is the most common question I get about the CPCSC. “Will an external auditor come to my offices?” My short answer is no, not at level 1. This is a self-assessment.
The company itself declares compliance by completing a self-assessment on a federal government site. The company must also be able to provide proof to show that each control is in place.
The external assessment by an accredited organization only happens in Level 2.
Level 1 covers 13 basic cyber hygiene controls:
- Account management
- Access application
- Use of external systems
- Content available to the public
- User identification and authentication
- Device identification and authentication
- Multifactor authentication
- Cleaning media
- Physical access permissions
- Physical access control
- Border protection
- Breach remediation
- Protection against malware
Detailed requirements for each control can be found on the PSPC website.
Nothing out of the ordinary from a technical standpoint. In fact, the U.S. Level 1 CMMC is much more comprehensive. Many of these measures are already part of routine cyber security practices. The challenge is mainly to confirm that they are being applied within the target scope and to retain the necessary proof.
For an SME starting from scratch, it is better to have several weeks of preparation. The real work is not in the self-assessment tool, it’s earlier, in the preparation phase. It’s also very important to be able to provide proof to support your answers. Applying for certification without being able to provide proof could result in exclusion from procurement processes due to misrepresentation.
You do not need a complex formal security program for Level 1. Rather, the objective is to be able to prove that the required controls are actually being applied and that your practices are documented. Upon completing the self-assessment, enter the proof and expiry date on your CanadaBuys vendor profile.
What is the scope? The question SMEs have the most trouble with
Before applying the 13 controls, it is necessary to delineate where they apply. This is the scope. It refers to everything in your organization that stores, transmits or processes the specified information, namely, people, locations and technology.
The scope may be company-wide or limited to a restricted enclave, such as a specific project team. It’s a business decision. A clear and defensible scope greatly simplifies the self-assessment. The broader the scope, the more systems, users, and processes to which the controls apply. Good scoping can therefore significantly reduce complexity and compliance costs.
One thing to remember is that a device or system cannot be excluded simply because it doesn’t seem important. The only criterion that matters is access to the specified information. This includes employees’ personal devices if they have access to specified information, mobile devices, even when used only for email, and even paper. A printer with scanning, storage and transmission functions can be in the scope.
PSPC has created a guide to help companies determine which parts of their business operations need to be assessed to meet PSPC-level requirements. Feel free to consult it on their website.
Do you already have U.S. CMMC certification?
The CPCSC is closely aligned with the U.S. CMMC program, but the two programs are not automatically interchangeable. Valid CMMC certification may be recognized by Canada on a case-by-case basis, after verifying the scope and, if necessary, certain specific controls.
If this is your situation, send your proof of CMMC certification to PSPC for verification.
Technical repositories are evolving on both sides of the border. The CMMC currently remains based on NIST SP 800-171 Revision 2, while Canada has adopted a standard derived from Revision 3.
As the CMMC and CPCSC programs do not have reciprocity, understanding differences and mapping requirements and controls becomes important. As the CPCSC is fully launched and increases in maturity, ensuring that you meet requirements on both sides of the border will become more important, if applicable.
Calendar: What changed in summer 2026
I see a synchronization pitfall. Many SMEs will wait for RFPs to obtain their CPCSC certification. The Level 1 self-assessment is required at contract award, not during the tendering process. In other words, when it’s time to sign, it’s no longer time to start your gap analysis. This is when you must already have proof of certification in hand.
Since Level 1 has been available since April 1, 2026 and there is nothing preventing a company from proactively completing it, the logic is simple. The SMEs that are doing this now are going to come prepared at the time of the award. Those who wait will watch contracts pass them by for reasons of compliance, and not because of price or competency.
What this means for you now
In practice, here’s where to start:
- Answer the five questions above honestly to determine if you are concerned.
- If you are, open or check your CanadaBuys account.
- Define the scoping: what systems, people, and locations actually affect the specified information.
- Review all 13 controls and honestly take note of what is compliant, partial or missing.
- Correct any discrepancies and document the necessary actions before finalizing the self-assessment.
- Complete the self-assessment and provide proof on your CanadaBuys profile, with a reminder before the expiry date.
- Make sure that your proof is properly documented and accessible for each requirement.
Avoid misrepresentations
A final word on the honesty of the process. The proof does not have to be complex. It must exist and correspond to your actual practices. A misrepresentation engages the organization, with real contractual and legal risks.
In short, CPCSC Level 1 does not require a sophisticated cyber security program. It uses clear, enforced and documented rules as well as time to prepare before the contract is on the table. Is your proof currently available?
Next step
You don’t know if your current practices cover the 13 CPCSC Level 1 controls? Not sure what level you will need? Would you like to better understand the different approaches regarding the defence industry? BDC’s Advisory Services teams assist SMEs in obtaining information security certifications, including ISO 27001. Contact us to talk to an advisor.