Sentrix

CPCSC guide · Comparison

CPCSC vs CMMC: differences for defence suppliers

Compare CPCSC and CMMC: authorities, Canadian and US markets, levels, assessments, ITSP.10.171 and NIST SP 800-171, and the evidence reusable across both.

The Canadian Program for Cyber Security Certification (CPCSC) and the US Cybersecurity Maturity Model Certification (CMMC) answer the same need in two different countries: verifying, rather than simply requiring, that defence suppliers adequately protect sensitive information. Both programs rest on very similar technical controls, the CPCSC through the Canadian standard ITSP.10.171 and CMMC through NIST SP 800-171 and 800-172, but they remain two distinct certification processes, run by two different governments, with no automatic mutual recognition today.

Comparison table

AspectCPCSC (Canada)CMMC (United States)
AuthorityPublic Services and Procurement Canada (PSPC), National DefenceDepartment of Defense (DoD)
Target marketCanadian defence supply chainUS defence supply chain
Levels3 levels (13, 98, 200 controls)3 levels (increasing controls with sensitivity)
Technical foundationITSP.10.171 (Canadian Centre for Cyber Security)NIST SP 800-171 / 800-172
Assessment typeSelf-assessment (L1), third party accredited by the SCC (L2), government (L3)Self-assessment (L1), accredited third party C3PAO (L2), government (L3)
FrequencyAnnual (L1) or every 3 years with annual confirmation (L2/L3)Annual (L1) or every 3 years (L2/L3)
Evidence managementGovernment of Canada self-assessment tool, CanadaBuys supplier profileSPRS (Supplier Performance Risk System), SSP, POA&M

Do I need CPCSC, CMMC or both?

  • You only supply Canada’s Department of National Defence: CPCSC alone applies, at the level determined by the sensitivity of your contracts.
  • You only supply the US Department of Defense: CMMC alone applies.
  • You supply both markets: you generally have to obtain both certifications separately. Canada may, case by case, recognize a valid CMMC certification if its scope matches the CPCSC requirements, but this is not automatic and must be confirmed with the Canadian authority for your contract.

Which controls overlap?

Since the CPCSC and CMMC both rest on very similar control families (access management, authentication, system protection, incident response, physical protection), a good part of the technical work done for one directly benefits the other. We do not put forward a precise overlap percentage here, as it varies with the level targeted in each program, but in practice most of the basic controls (account management, multi-factor authentication, network boundary protection) are interchangeable from one program to the other.

Reuse the same evidence

Concretely, these are the categories of evidence that generally serve both programs at once:

  • multi-factor authentication (MFA) configuration and logs;
  • export of the list of active accounts and their access rights;
  • register of patches and security updates;
  • network boundary protection rules (firewall, segmentation);
  • documented security policies and procedures;
  • system activity and monitoring logs.

Preparing for both programs

For suppliers selling to both Canada’s Department of National Defence and the US DoD, the challenge is to build one evidence file that serves both programs rather than two parallel files. Our CPCSC certification support starts from that principle. See also the CPCSC framework page, the CMMC framework page and the article CPCSC explained.

Going further

Let’s talk about your CPCSC and CMMC coverage

A first conversation lets us frame your obligations on each market and spot the evidence you can already reuse. No commitment. Contact us.

Frequently asked questions

Do I need CPCSC, CMMC or both?
If you only supply Canada’s Department of National Defence, CPCSC alone applies, at the level determined by the sensitivity of your contracts. If you only supply the US Department of Defense, CMMC alone applies. If you supply both markets, you generally have to obtain both certifications separately, with no automatic mutual recognition today.
Does Canada recognize a CMMC certification?
Canada may, case by case, recognize a valid CMMC certification if its scope matches the CPCSC requirements. It is not automatic: recognition has to be confirmed with the Canadian authority for your contract. The two programs remain two distinct certification processes, run by two different governments.
Which controls overlap between CPCSC and CMMC?
Both programs rest on very similar control families: access management, authentication, system protection, incident response, physical protection. We do not put forward a precise overlap percentage, which varies with the level targeted in each program, but most of the basic controls, such as account management, multi-factor authentication and network boundary protection, are interchangeable.
Which evidence serves both programs?
Multi-factor authentication configuration and logs, the export of the list of active accounts and their access rights, the register of patches and security updates, network boundary protection rules (firewall, segmentation), documented security policies and procedures, and system activity and monitoring logs. A good part of the technical work done for one program directly benefits the other.

Let's talk about your compliance program.

Last updated: 2026-09-17