CPCSC guide · Level 1
CPCSC Level 1: 13 controls and self-assessment
Level 1 of the Canadian Program for Cyber Security Certification is an annual self-assessment against 13 ITSP.10.171 controls: requirements, evidence, steps.
If your organization supplies or wants to supply Canada’s Department of National Defence, CPCSC Level 1 is probably the first concrete cyber security requirement at your door. It is an annual self-assessment against 13 basic controls, completed by you with a Government of Canada tool, with no external assessor at this level. This page details the 13 controls, the evidence to prepare and the steps to complete it. For the program as a whole (levels, self-assessment, comparison with CMMC), see the CPCSC framework page.
What is CPCSC Level 1?
CPCSC Level 1 applies to lower-risk situations: administrative or operational support, basic IT services without sensitive data, limited network integration. It has been available to suppliers since April 1, 2026 and will be integrated into certain defence contracts from summer 2026, according to the schedule published by Public Services and Procurement Canada (PSPC). Unlike Levels 2 and 3, no external body is involved: you assess your own compliance with the 13 controls using the government’s online tool, then confirm the result in your supplier profile on CanadaBuys.
The 13 CPCSC Level 1 controls
The 13 controls come from the Canadian standard ITSP.10.171 and are grouped into 4 basic cyber hygiene families.
Access control
Manage who can access the systems.
- Account management (03.01.01)
- Access enforcement (03.01.02)
- Use of external systems (03.01.20)
- Publicly accessible content (03.01.22)
Identification and authentication
Verify users and devices.
- User identification and authentication (03.05.01)
- Device identification and authentication (03.05.02)
- Multi-factor authentication (03.05.03)
Media and physical protection
Protect data and equipment.
- Media sanitization (03.08.03)
- Physical access authorizations (03.10.01)
- Physical access control (03.10.07)
System and communications protection
Defend systems against cyber threats.
- Boundary protection (03.13.01)
- Flaw remediation (03.14.01)
- Malicious code protection (03.14.02)
Control codes follow the Canadian standard ITSP.10.171.
What evidence should you prepare?
For each control, the self-assessment tool asks you to confirm its implementation. Keep this evidence at hand before you start:
- Access control: export of the list of active accounts and their rights, access revocation policy when an employee leaves.
- Identification and authentication: screenshot of the multi-factor authentication configuration on remote and privileged access.
- Media and physical protection: written procedure for sanitizing media taken out of service, log of physical access to the premises.
- System and communications protection: firewall or network gateway rules, log of applied patches, antivirus/anti-malware configuration.
How does the self-assessment work?
- Define the scope of the systems and environments covered by the contract.
- Assess each of the 13 controls in the government’s online tool.
- Document the implementation evidence for each control.
- Fix the gaps identified before submitting the result.
- Submit the self-assessment and confirm the result, including its expiry date, in your supplier profile on CanadaBuys.
- Keep the evidence file for the following annual self-assessment.
CPCSC Level 1 vs Level 2
| Aspect | Level 1 | Level 2 |
|---|---|---|
| Controls | 13 | 98 |
| Assessor | Self-assessment by the supplier | Third-party certification body accredited by the SCC |
| Frequency | Annual | Every 3 years, with annual confirmation |
| Target sensitivity | Lower risk | Controlled defence information |
Aiming for Level 2 next? See the 98 controls and CPCSC Level 2 preparation.
Check your readiness
Before submitting your self-assessment, check where you really stand on the 13 controls with the CPCSC self-assessment checklist. Our CPCSC certification support covers implementing the missing controls and preparing your file.
Let’s talk about your CPCSC Level 1 journey
A first conversation lets us determine your scope and assess how we can support you. No commitment. Contact us.
Frequently asked questions
- Who has to complete the CPCSC Level 1 self-assessment?
- Any supplier, subcontractor or software vendor that is part of the Canadian defence supply chain and whose contract requires CPCSC Level 1, whatever its size. Level 1 applies to lower-risk situations: administrative or operational support, basic IT services without sensitive data, limited network integration.
- How many controls does Level 1 cover?
- 13 controls, drawn from the Canadian standard ITSP.10.171 and grouped into 4 basic cyber hygiene families: access control, identification and authentication, media and physical protection, system and communications protection. Each control carries a code, for example 03.05.03 for multi-factor authentication, which the self-assessment tool asks you to confirm.
- How often must the self-assessment be redone?
- Annually. The result, including its expiry date, must be confirmed in your supplier profile on CanadaBuys. Keep the evidence file built for the first self-assessment: it will be the basis for the following annual self-assessment and will save you from starting over when the contract requires a renewal.
- How long does the CPCSC Level 1 self-assessment take?
- Assessing the 13 controls themselves takes a few hours if your evidence is already organized. The upstream preparation, meaning gathering the evidence and fixing the gaps, varies from a few days to a few weeks depending on your starting maturity. That is why it pays to start with the checklist before opening the official tool.
- Can a CMMC certification be reused for the CPCSC?
- Not automatically, but the two programs rest on very similar technical controls, NIST SP 800-171 on one side and ITSP.10.171 on the other. Case by case, Canada may recognize a valid CMMC certification if its scope matches the CPCSC requirements; that recognition has to be confirmed with the Canadian authority for your contract.
Related pages
CPCSC guide · Level 1
CPCSC self-assessment: check your Level 1 readiness
Checklist of the 13 CPCSC Level 1 controls: one plain-language question per control, with its ITSP.10.171 code and the evidence you are expected to have.
CPCSC guide · Level 2
CPCSC Level 2: 98 controls and third-party assessment
CPCSC Level 2 covers contracts involving controlled defence information: 98 ITSP.10.171 controls and an assessment by a body accredited by the SCC.
CPCSC guide · Comparison
CPCSC vs CMMC: differences for defence suppliers
Compare CPCSC and CMMC: authorities, Canadian and US markets, levels, assessments, ITSP.10.171 and NIST SP 800-171, and the evidence reusable across both.
Let's talk about your compliance program.
Last updated: 2026-09-17
