Explainer · Defence
CPCSC or CMMC: selling to both defence supply chains
Canada's CPCSC and the U.S. CMMC share a family of standards, not a revision. Levels, recognition between the two programs and where a supplier should start.
By Sentrix · Published 2026-10-01
A machine shop on Montreal's South Shore delivers parts to a Canadian prime contractor and to an American one. The first contract mentions the Canadian Program for Cyber Security Certification (CPCSC). The second carries the CMMC clause of the United States Department of Defense (DoD). Two governments, two attestations, but one network and one IT team. The question is not which one to choose: it is which one to start with, and what can be reused.
What the official pages say
The CPCSC. The program overview from Public Services and Procurement Canada (PSPC), updated on September 29, 2026, describes three levels: an annual self-assessment at Level 1 (13 controls), launched in April 2026; external assessments led by an accredited certification body, plus an annual affirmation, at Level 2 (98 controls); assessments conducted by National Defence, plus an annual affirmation, at Level 3 (more than 130 controls). Levels 2 and 3 are under development.
Its standard, ITSP.10.171 from the Canadian Centre for Cyber Security, in effect since April 2, 2025, presents itself as a Canadian version of NIST SP 800-171 Revision 3, with no substantial technical changes, in 17 families of requirements. The news release of April 14, 2026 announces Level 1 in select defence contracts beginning in summer 2026, required upon contract award. The supplier support page expects Levels 2 and 3 to be gradually incorporated into select contracts between April 2027 and March 2028.
CMMC. The final rule at 32 CFR Part 170, published in the Federal Register on October 15, 2024 and effective since December 16, 2024, also defines three levels: at Level 1, an annual self-assessment of the 15 requirements of FAR clause 52.204-21, for Federal Contract Information (FCI); at Level 2, the 110 requirements of NIST SP 800-171 Revision 2, for Controlled Unclassified Information (CUI), by self-assessment or by a third-party assessor (C3PAO) every three years; at Level 3, 24 requirements selected from NIST SP 800-172, assessed by DIBCAC, a government body. The department's CIO site, which now presents itself under the name Department of War, states that Phase 1 began on November 10, 2025, that the suspension of the Phase 2 requirements was announced on July 13, 2026 and that implementation is paused in Phase 1.
Recognition. None of these pages announces mutual recognition. On the Canadian side, the news release speaks of a program designed to align with the standards of international partners and of harmonization with United States requirements. The practical instruction fits in one sentence of the support page: suppliers should review the ITSP.10.171 standard and contact the CPCSC if they are certified under CMMC. On the American side, the rule is plain: no partial exemption for foreign contractors, the same process for international contractors and subcontractors, and recognition of other nations' standards that goes through agreements between governments, outside the scope of the rule.
Why it matters
| Item | CPCSC (Canada) | CMMC (United States) |
|---|---|---|
| Base standard | ITSP.10.171, a Canadian version of NIST SP 800-171 Revision 3 | FAR 52.204-21, NIST SP 800-171 Revision 2, NIST SP 800-172 |
| Level 1 | 13 controls, annual self-assessment | 15 requirements, annual self-assessment |
| Level 2 | 98 controls, accredited certification body | 110 requirements, self-assessment or C3PAO |
| Level 3 | More than 130 controls, National Defence | 24 added requirements, DIBCAC |
Same tree, different branch. The CPCSC relies on Revision 3 of NIST SP 800-171; CMMC assesses Revision 2, and the U.S. rule states that Revision 3 is not currently applicable to it. So the numbers do not line up: 98 controls here, 110 requirements there. One piece of evidence serves both programs, but the mapping is done requirement by requirement, not level by level.
The protected information differs too. ITSP.10.171 covers specified information: any information, other than classified, that a Government of Canada authority identifies in a contract as requiring safeguarding. CMMC covers the FCI and CUI of DoD contracts. The same shop can therefore have two scopes on one network, and neither attestation replaces the other.
What we think at Sentrix
One security program, two attestations. In order:
- Read the contracts before the standards. On both sides, the required level is written in the solicitation or the contract.
- Draw two scopes. Where Canadian specified information lives, where FCI and CUI live. An isolated, documented space reduces the effort on both sides.
- Do both Level 1s now. Two annual self-assessments, of 13 controls and of 15 requirements: run together, they already produce the shared evidence file.
- Build on the strictest requirement per topic. If you handle CUI, start from the 110 requirements of Revision 2 and add what the 17 families of ITSP.10.171 ask for on top.
- Write to the CPCSC if you hold a CMMC status. That is PSPC's instruction. Ask for a written answer for your contract, and do not assume the reverse: the U.S. rule does not address acceptance of other nations' standards.
The next step
On one page, draw two columns: Canadian contracts, American contracts. For each, note the information involved, the level required and the date of the next self-assessment or affirmation. The nearest deadline decides where to start. Our CPCSC guide details the Canadian program, level by level.
Sources
- Public Services and Procurement Canada, Program overview (CPCSC)
- Public Services and Procurement Canada, Additional information and support for suppliers about cyber security (CPCSC)
- Public Services and Procurement Canada, Le gouvernement du Canada lance le niveau 1 du PCCC (news release, April 14, 2026)
- Canadian Centre for Cyber Security, Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)
- Federal Register (govinfo), Cybersecurity Maturity Model Certification (CMMC) Program, final rule 32 CFR Part 170, October 15, 2024
- Chief Information Officer, U.S. Department of War, About CMMC
Frequently asked questions
- Does Canada recognize a CMMC certification for the CPCSC?
- The official pages announce no automatic recognition. Public Services and Procurement Canada asks suppliers certified under CMMC to review the ITSP.10.171 standard and to contact the CPCSC. The news release of April 14, 2026 speaks of harmonization with United States requirements, not of equivalence. Until you have a written answer for your contract, plan for the Canadian self-assessment.
- Can a Canadian supplier be exempted from CMMC?
- No, according to the final rule at 32 CFR Part 170. It does not permit partial exemption for foreign contractors and applies the same process to international contractors and subcontractors. Any exemption would have to come from a government-to-government arrangement or agreement, which the rule places outside its scope. The requirements flow down to subcontractors whose systems process FCI or CUI.
- Are the CPCSC and CMMC built on the same standard?
- On the same family, not on the same revision. ITSP.10.171 presents itself as a Canadian version of NIST SP 800-171 Revision 3, in 17 families of requirements. CMMC Level 2 assesses the 110 requirements of Revision 2, and the U.S. rule states that Revision 3 is not currently applicable to it. Evidence can be reused; the mapping is done requirement by requirement.
Let's talk about your compliance program.
Last updated: 2026-10-01
