Framework · CPCSC
CPCSC: self-assessment, third party, National Defence
Canadian Program for Cyber Security Certification for defence suppliers: Levels 1, 2 and 3, ITSP.10.171 controls, accredited assessment and a crosswalk to CMMC.
The Canadian Program for Cyber Security Certification (CPCSC) applies to organizations in the Canadian defence supply chain. Level 1 is a self-assessment available since April 2026, with select contracts requiring it starting summer 2026. Levels 2 and 3 add third-party and government-led assessment for more sensitive contracts, aligned to NIST SP 800-171 and 800-172 via Canada's own ITSP.10.171 standard, mirroring the approach taken by CMMC in the United States. Organizations supplying both DND and the DoD may need both certifications.
Key facts
- 13 / 98 / 200: controls at Levels 1, 2 and 3.
- April 2026: Level 1 self-assessment available; required in select contracts starting summer 2026.
- Every 3 years: Level 2 assessment by a certification body accredited through the Standards Council of Canada.
- ITSP.10.171: the Canadian standard that aligns Levels 2 and 3 with NIST SP 800-171 and 800-172.
What CPCSC requires
- Level 1: annual self-assessment; access control, authentication, physical protection, system protection (13 controls)
- Level 2: third-party assessment by a certification body accredited through the Standards Council of Canada, every 3 years (98 controls)
- Level 3: direct National Defence assessment for the highest-risk contracts (200 controls)
- Scope determination: which systems, personnel and data stores handle sensitive unclassified information
- Level 2 domains: access control, audit and accountability, configuration management, identification and authentication, incident response, system and communications protection
- Evidence package in the format assessors expect, at Level 1 and Level 2 alike
What Sentrix provides for CPCSC
CPCSC control sets
Level 1 and Level 2 control sets pre-built and maintained by our team. Framework updates are reflected automatically when Canadian Centre for Cyber Security guidance evolves.
Scope determination support
Identify which systems, personnel, and data stores fall within CPCSC scope. Protected and Classified information flow mapping with the boundary documentation required for assessment.
Assessment-ready evidence
Whether you are self-attesting at Level 1 or preparing for a Level 2 third-party assessment, Sentrix assembles your evidence package in the format assessors expect.
CCCS baseline crosswalk
Sentrix maps CPCSC controls to the Canadian Centre for Cyber Security's baseline security controls, for a single view of your posture.
Crosswalks
- CMMC 2.0: substantial overlap for Canadian suppliers with US DoD contracts; both frameworks are managed from one evidence program.
- NIST SP 800-53: 800-171, which ITSP.10.171 aligns with, derives from 800-53.
- CAN/DGSI 104: the cybersecurity baseline for Canadian small and medium organizations.
- Law 25: for Québec suppliers that also handle personal information.
Further reading
The Sentrix CPCSC guide covers the self-assessment, the 13 Level 1 controls, the 98 Level 2 controls and the CPCSC vs CMMC comparison; the CPCSC certification support service covers preparation. Article: CPCSC explained, what Canadian defence suppliers need to know. Public body or Crown corporation: public sector solution.
See your CPCSC readiness against your real infrastructure.
Frequently asked questions
- What are the three CPCSC levels?
- Level 1 (13 controls) is an annual self-assessment covering access control, authentication, physical protection and system protection. Level 2 (98 controls) requires an assessment every three years by a certification body accredited through the Standards Council of Canada. Level 3 (200 controls) is assessed directly by National Defence for the highest-risk contracts.
- Does a CMMC certification satisfy CPCSC?
- No. CPCSC and CMMC both trace back to NIST SP 800-171 at their higher tiers, through Canada's ITSP.10.171 standard for CPCSC, and share substantial control overlap, but there is no formal equivalence between them. Organizations supplying both DND and the DoD may need both certifications; Sentrix manages both from one evidence program.
- When is CPCSC required in contracts?
- The Level 1 self-assessment has been available since April 2026, with select contracts requiring it starting summer 2026. Levels 2 and 3 apply to more sensitive contracts, with assessment by an accredited third party or by government. The first step is scope determination: which systems handle sensitive unclassified information.
Related pages
Framework · CMMC 2.0
CMMC 2.0: required to keep and win DoD contracts
US DoD Cybersecurity Maturity Model Certification: three levels, 110 NIST SP 800-171 practices at Level 2, triennial C3PAO assessment and SPRS score tracking.
Framework · CAN/DGSI 104
CAN/DGSI 104: the cybersecurity baseline for Canadian SMEs
Canada's baseline cyber security controls standard for SMEs: 18 main controls, 55 sub-controls, two levels, and the CyberSecure Canada certification program.
Framework · NIST SP 800-53
NIST SP 800-53: the control catalog behind FedRAMP and CMMC
NIST catalog of security and privacy controls for US federal information systems: 20 control families, three baselines, Revision 5, behind FedRAMP and CMMC.
Framework · Law 25
Law 25: PIAs, incidents, access and portability, documented
Québec's private-sector privacy law, in full force since September 2023: privacy impact assessments, confidentiality incidents, access rights and portability.
Let's talk about your compliance program.
Last updated: 2026-09-17
