CPCSC guide · Comparison
CPCSC vs CMMC: differences for defence suppliers
Compare CPCSC and CMMC: authorities, Canadian and US markets, levels, assessments, ITSP.10.171 and NIST SP 800-171, and the evidence reusable across both.
The Canadian Program for Cyber Security Certification (CPCSC) and the US Cybersecurity Maturity Model Certification (CMMC) answer the same need in two different countries: verifying, rather than simply requiring, that defence suppliers adequately protect sensitive information. Both programs rest on very similar technical controls, the CPCSC through the Canadian standard ITSP.10.171 and CMMC through NIST SP 800-171 and 800-172, but they remain two distinct certification processes, run by two different governments, with no automatic mutual recognition today.
Comparison table
| Aspect | CPCSC (Canada) | CMMC (United States) |
|---|---|---|
| Authority | Public Services and Procurement Canada (PSPC), National Defence | Department of Defense (DoD) |
| Target market | Canadian defence supply chain | US defence supply chain |
| Levels | 3 levels (13, 98, 200 controls) | 3 levels (increasing controls with sensitivity) |
| Technical foundation | ITSP.10.171 (Canadian Centre for Cyber Security) | NIST SP 800-171 / 800-172 |
| Assessment type | Self-assessment (L1), third party accredited by the SCC (L2), government (L3) | Self-assessment (L1), accredited third party C3PAO (L2), government (L3) |
| Frequency | Annual (L1) or every 3 years with annual confirmation (L2/L3) | Annual (L1) or every 3 years (L2/L3) |
| Evidence management | Government of Canada self-assessment tool, CanadaBuys supplier profile | SPRS (Supplier Performance Risk System), SSP, POA&M |
Do I need CPCSC, CMMC or both?
- You only supply Canada’s Department of National Defence: CPCSC alone applies, at the level determined by the sensitivity of your contracts.
- You only supply the US Department of Defense: CMMC alone applies.
- You supply both markets: you generally have to obtain both certifications separately. Canada may, case by case, recognize a valid CMMC certification if its scope matches the CPCSC requirements, but this is not automatic and must be confirmed with the Canadian authority for your contract.
Which controls overlap?
Since the CPCSC and CMMC both rest on very similar control families (access management, authentication, system protection, incident response, physical protection), a good part of the technical work done for one directly benefits the other. We do not put forward a precise overlap percentage here, as it varies with the level targeted in each program, but in practice most of the basic controls (account management, multi-factor authentication, network boundary protection) are interchangeable from one program to the other.
Reuse the same evidence
Concretely, these are the categories of evidence that generally serve both programs at once:
- multi-factor authentication (MFA) configuration and logs;
- export of the list of active accounts and their access rights;
- register of patches and security updates;
- network boundary protection rules (firewall, segmentation);
- documented security policies and procedures;
- system activity and monitoring logs.
Preparing for both programs
For suppliers selling to both Canada’s Department of National Defence and the US DoD, the challenge is to build one evidence file that serves both programs rather than two parallel files. Our CPCSC certification support starts from that principle. See also the CPCSC framework page, the CMMC framework page and the article CPCSC explained.
Going further
- CPCSC Level 1: 13 controls and self-assessment
- CPCSC Level 2: 98 controls and third-party assessment
- CPCSC self-assessment checklist
Let’s talk about your CPCSC and CMMC coverage
A first conversation lets us frame your obligations on each market and spot the evidence you can already reuse. No commitment. Contact us.
Frequently asked questions
- Do I need CPCSC, CMMC or both?
- If you only supply Canada’s Department of National Defence, CPCSC alone applies, at the level determined by the sensitivity of your contracts. If you only supply the US Department of Defense, CMMC alone applies. If you supply both markets, you generally have to obtain both certifications separately, with no automatic mutual recognition today.
- Does Canada recognize a CMMC certification?
- Canada may, case by case, recognize a valid CMMC certification if its scope matches the CPCSC requirements. It is not automatic: recognition has to be confirmed with the Canadian authority for your contract. The two programs remain two distinct certification processes, run by two different governments.
- Which controls overlap between CPCSC and CMMC?
- Both programs rest on very similar control families: access management, authentication, system protection, incident response, physical protection. We do not put forward a precise overlap percentage, which varies with the level targeted in each program, but most of the basic controls, such as account management, multi-factor authentication and network boundary protection, are interchangeable.
- Which evidence serves both programs?
- Multi-factor authentication configuration and logs, the export of the list of active accounts and their access rights, the register of patches and security updates, network boundary protection rules (firewall, segmentation), documented security policies and procedures, and system activity and monitoring logs. A good part of the technical work done for one program directly benefits the other.
Related pages
CPCSC guide · Level 1
CPCSC self-assessment: check your Level 1 readiness
Checklist of the 13 CPCSC Level 1 controls: one plain-language question per control, with its ITSP.10.171 code and the evidence you are expected to have.
CPCSC guide · Level 1
CPCSC Level 1: 13 controls and self-assessment
Level 1 of the Canadian Program for Cyber Security Certification is an annual self-assessment against 13 ITSP.10.171 controls: requirements, evidence, steps.
CPCSC guide · Level 2
CPCSC Level 2: 98 controls and third-party assessment
CPCSC Level 2 covers contracts involving controlled defence information: 98 ITSP.10.171 controls and an assessment by a body accredited by the SCC.
Let's talk about your compliance program.
Last updated: 2026-09-17
