CPCSC guide
CPCSC guide: levels, self-assessment and CMMC comparison
The Canadian Program for Cyber Security Certification (CPCSC) in four pages: Level 1 checklist, Level 1, Level 2 and a comparison with the US CMMC program.
What this guide covers
The Canadian Program for Cyber Security Certification (CPCSC) verifies, rather than simply requires, that suppliers in the Canadian defence supply chain adequately protect sensitive information. It is administered by Public Services and Procurement Canada (PSPC) with National Defence, rests on the Canadian standard ITSP.10.171 from the Canadian Centre for Cyber Security, and has three levels: 13 controls in an annual self-assessment, 98 controls assessed by a third-party certification body accredited by the Standards Council of Canada (SCC), and 200 controls assessed by the government. The result is confirmed in your supplier profile on CanadaBuys.
This guide is written for suppliers, subcontractors and software vendors that supply or want to supply Canada’s Department of National Defence, and for Canadian-American suppliers that also have to deal with CMMC.
The pages of the guide
- CPCSC self-assessment: check your Level 1 readiness: the 13 controls as plain-language questions, with their ITSP.10.171 code and the expected evidence.
- CPCSC Level 1: requirements, 13 controls and self-assessment preparation: the 4 control families, the evidence to prepare, the steps through to CanadaBuys.
- CPCSC Level 2: requirements, 98 controls and third-party assessment preparation: scope, evidence, plan of action and how the assessment unfolds.
- CPCSC vs CMMC: differences and requirements for Canadian-American suppliers: comparison table and evidence reusable across both programs.
Going further
The CPCSC framework page summarizes the framework; the article CPCSC explained puts it in context. Our CPCSC certification support covers gap analysis, implementation of the missing controls and preparation of your file, from Level 1 to Level 2.
Let’s talk about your CPCSC journey
A first conversation lets us determine your level and scope, and assess how we can support you. No commitment. Contact us.
CPCSC guide · Level 1
CPCSC self-assessment: check your Level 1 readiness
Checklist of the 13 CPCSC Level 1 controls: one plain-language question per control, with its ITSP.10.171 code and the evidence you are expected to have.
Learn more →
CPCSC guide · Level 1
CPCSC Level 1: 13 controls and self-assessment
Level 1 of the Canadian Program for Cyber Security Certification is an annual self-assessment against 13 ITSP.10.171 controls: requirements, evidence, steps.
Learn more →
CPCSC guide · Level 2
CPCSC Level 2: 98 controls and third-party assessment
CPCSC Level 2 covers contracts involving controlled defence information: 98 ITSP.10.171 controls and an assessment by a body accredited by the SCC.
Learn more →
CPCSC guide · Comparison
CPCSC vs CMMC: differences for defence suppliers
Compare CPCSC and CMMC: authorities, Canadian and US markets, levels, assessments, ITSP.10.171 and NIST SP 800-171, and the evidence reusable across both.
Learn more →
Frequently asked questions
- What is the CPCSC?
- The Canadian Program for Cyber Security Certification (CPCSC) verifies, rather than simply requires, that Canadian defence suppliers adequately protect sensitive information. It is administered by Public Services and Procurement Canada (PSPC) with National Defence and rests on the ITSP.10.171 standard of the Canadian Centre for Cyber Security. It has three levels of 13, 98 and 200 controls.
- Which CPCSC level applies to my organization?
- The level is determined by the sensitivity of your contracts. Level 1 targets lower-risk situations: administrative or operational support, basic IT services without sensitive data. Level 2 targets contracts involving controlled defence information. Level 3 is assessed by the government. Your contract specifies the required level.
- How does the assessment work at each level?
- At Level 1, you complete an annual self-assessment against 13 controls in the Government of Canada online tool and confirm the result in your supplier profile on CanadaBuys. At Level 2, a third-party certification body accredited by the Standards Council of Canada assesses 98 controls every three years, with annual confirmation. At Level 3, the assessment is conducted by the government.
Let's talk about your compliance program.
Last updated: 2026-09-17
