Sentrix

CPCSC guide

CPCSC guide: levels, self-assessment and CMMC comparison

The Canadian Program for Cyber Security Certification (CPCSC) in four pages: Level 1 checklist, Level 1, Level 2 and a comparison with the US CMMC program.

What this guide covers

The Canadian Program for Cyber Security Certification (CPCSC) verifies, rather than simply requires, that suppliers in the Canadian defence supply chain adequately protect sensitive information. It is administered by Public Services and Procurement Canada (PSPC) with National Defence, rests on the Canadian standard ITSP.10.171 from the Canadian Centre for Cyber Security, and has three levels: 13 controls in an annual self-assessment, 98 controls assessed by a third-party certification body accredited by the Standards Council of Canada (SCC), and 200 controls assessed by the government. The result is confirmed in your supplier profile on CanadaBuys.

This guide is written for suppliers, subcontractors and software vendors that supply or want to supply Canada’s Department of National Defence, and for Canadian-American suppliers that also have to deal with CMMC.

The pages of the guide

Going further

The CPCSC framework page summarizes the framework; the article CPCSC explained puts it in context. Our CPCSC certification support covers gap analysis, implementation of the missing controls and preparation of your file, from Level 1 to Level 2.

Let’s talk about your CPCSC journey

A first conversation lets us determine your level and scope, and assess how we can support you. No commitment. Contact us.

Frequently asked questions

What is the CPCSC?
The Canadian Program for Cyber Security Certification (CPCSC) verifies, rather than simply requires, that Canadian defence suppliers adequately protect sensitive information. It is administered by Public Services and Procurement Canada (PSPC) with National Defence and rests on the ITSP.10.171 standard of the Canadian Centre for Cyber Security. It has three levels of 13, 98 and 200 controls.
Which CPCSC level applies to my organization?
The level is determined by the sensitivity of your contracts. Level 1 targets lower-risk situations: administrative or operational support, basic IT services without sensitive data. Level 2 targets contracts involving controlled defence information. Level 3 is assessed by the government. Your contract specifies the required level.
How does the assessment work at each level?
At Level 1, you complete an annual self-assessment against 13 controls in the Government of Canada online tool and confirm the result in your supplier profile on CanadaBuys. At Level 2, a third-party certification body accredited by the Standards Council of Canada assesses 98 controls every three years, with annual confirmation. At Level 3, the assessment is conducted by the government.

Let's talk about your compliance program.

Last updated: 2026-09-17