Sentrix

Breakdown · CPCSC

CPCSC Level 1: preparing the self-assessment

Level 1 of the Canadian Program for Cyber Security Certification rests on an annual self-assessment based on ITSP.10.171. What to prepare beforehand.

By Sentrix · Published 2026-09-20

The Canadian Program for Cyber Security Certification (CPCSC) has left the announcement phase. Since April 2026, Level 1 exists, the self-assessment tool is online, and defence suppliers know they will have to show their result at contract award. The question is no longer "when", it is "what do I need to have on hand before opening the tool".

What the official pages say

The Public Services and Procurement Canada (PSPC) news release of April 14, 2026 announces the launch of Level 1. Suppliers must meet all Level 1 criteria and attest to their compliance through a self-assessment. Certification will be required from summer 2026, at contract award and not during the bidding process. The program relies on ITSP.10.171 for the protection of designated information, and PSPC states that it was designed around the standards of Canada's international partners, with requirements harmonized with those of the United States.

The program overview describes three levels. Level 1, available since April 2026, requires an annual self-assessment covering thirteen controls. Level 2 will require external assessments led by an accredited certification body, plus an annual affirmation, on ninety-eight controls. Level 3 will require assessments conducted by National Defence, on two hundred controls. Levels 2 and 3 are under development, with no announced date. The Canadian standard is adapted from NIST publications 800-171 and 800-172.

The "Meet Level 1 certification requirements" page details the process: gather the information (where Government information is stored, which systems access it, what protections exist), establish written policies (passwords, approved systems, user access, device integration, media destruction), complete the online tool, keep the results page with its expiry date for the attestation cycle or at least one year, then confirm the result and the date in the CanadaBuys supplier profile. A scoping guide helps define what goes into the self-assessment.

On the Canadian Centre for Cyber Security side, ITSP.10.171 came into effect on April 2, 2025, with a second version published on October 28, 2025. It presents itself as a Canadian version of NIST SP 800-171, organizes its requirements into seventeen families, and defines designated information as any information other than classified that a Government of Canada authority designates and mentions in a contract as requiring safeguarding.

Why it matters

A self-assessment that can be completed in less than an hour has a downside: it is quickly completed badly. The supplier who ticks "yes" without knowing where designated information sits in its systems exposes itself to two problems. The first is contractual, since the attestation is reported in CanadaBuys and binds the enterprise. The second is structural: Level 2, when it arrives, will be assessed by a third party on a broader base of controls, and an organization that cheated on its scope at Level 1 will start over.

Scope is the real subject. ITSP.10.171 protects a category of information defined by the contract, not the whole enterprise. Knowing which workstations, which file shares, which mailboxes and which subcontractors touch that information is what makes the thirteen controls verifiable. It is also what keeps the scope small, and therefore the effort reasonable.

What we think at Sentrix

Level 1 is prepared like a mini security program, not like a form.

  1. Trace designated information: which contracts mention it, where it comes in, where it is stored, who accesses it, where it goes out. A simple network diagram and a list of in-scope assets are enough, as the PSPC scoping guide asks.
  2. Reduce the scope before assessing it: isolate designated information in a dedicated space (share, tenant, project) rather than letting the whole estate into the self-assessment.
  3. Write the policies the PSPC page names: passwords, approved systems, access, devices, media destruction. Short, dated, approved by management. For ISO 27001:2022, these are controls 5.15, 5.17, 7.10 and 8.1.
  4. Build an evidence file per control before opening the tool: configuration capture, register extract, procedure. That file is what Level 2 will demand from an external assessor, and what ITSP.10.171-01 already describes as assessment methods: examine, interview, test.
  5. Put the deadline in the compliance calendar: the results page carries an expiry date, the self-assessment is annual, and the CanadaBuys profile must stay current. The Sentrix platform calendar and our CPCSC compliance service exist for that.

The next step

Before logging into the tool, do the scope exercise on one page: contracts concerned, systems, people, subcontractors. If the page fills in without hesitation, the self-assessment will be honest and fast. If not, start there. Our CPCSC guide details the levels, and we can be reached through the contact page.

Sources

Frequently asked questions

Who must obtain CPCSC Level 1, and from when?
Suppliers that handle designated Government of Canada information under defence contracts. According to the Public Services and Procurement Canada news release of April 14, 2026, certification will be required from summer 2026, at contract award and not during the bidding process. Level 1 is proven by an annual self-assessment; Levels 2 and 3 are still under development.
What does the Level 1 self-assessment cover?
Thirteen controls, according to the program overview published by PSPC, drawn from ITSP.10.171 of the Canadian Centre for Cyber Security, the Canadian version of NIST SP 800-171. The online tool produces a results page with an expiry date, to be kept for the attestation cycle or at least one year, and reported in the CanadaBuys supplier profile. PSPC states that the tool can be completed in less than an hour if the preparation is done.
Does a supplier certified under CMMC in the United States have to redo everything?
No, but it still has to go through the Canadian program. According to the PSPC news release, the CPCSC was designed around the standards of Canada's international partners and harmonizes its requirements with those of the United States. ITSP.10.171 is presented by the Canadian Centre for Cyber Security as a Canadian version of NIST SP 800-171. The evidence can be reused; the attestation itself remains Canadian.

Let's talk about your compliance program.

Last updated: 2026-09-20