Sentrix

CPCSC guide · Level 1

CPCSC Level 1: 13 controls and self-assessment

Level 1 of the Canadian Program for Cyber Security Certification is an annual self-assessment against 13 ITSP.10.171 controls: requirements, evidence, steps.

If your organization supplies or wants to supply Canada’s Department of National Defence, CPCSC Level 1 is probably the first concrete cyber security requirement at your door. It is an annual self-assessment against 13 basic controls, completed by you with a Government of Canada tool, with no external assessor at this level. This page details the 13 controls, the evidence to prepare and the steps to complete it. For the program as a whole (levels, self-assessment, comparison with CMMC), see the CPCSC framework page.

What is CPCSC Level 1?

CPCSC Level 1 applies to lower-risk situations: administrative or operational support, basic IT services without sensitive data, limited network integration. It has been available to suppliers since April 1, 2026 and will be integrated into certain defence contracts from summer 2026, according to the schedule published by Public Services and Procurement Canada (PSPC). Unlike Levels 2 and 3, no external body is involved: you assess your own compliance with the 13 controls using the government’s online tool, then confirm the result in your supplier profile on CanadaBuys.

The 13 CPCSC Level 1 controls

The 13 controls come from the Canadian standard ITSP.10.171 and are grouped into 4 basic cyber hygiene families.

Access control

Manage who can access the systems.

  • Account management (03.01.01)
  • Access enforcement (03.01.02)
  • Use of external systems (03.01.20)
  • Publicly accessible content (03.01.22)

Identification and authentication

Verify users and devices.

  • User identification and authentication (03.05.01)
  • Device identification and authentication (03.05.02)
  • Multi-factor authentication (03.05.03)

Media and physical protection

Protect data and equipment.

  • Media sanitization (03.08.03)
  • Physical access authorizations (03.10.01)
  • Physical access control (03.10.07)

System and communications protection

Defend systems against cyber threats.

  • Boundary protection (03.13.01)
  • Flaw remediation (03.14.01)
  • Malicious code protection (03.14.02)

Control codes follow the Canadian standard ITSP.10.171.

What evidence should you prepare?

For each control, the self-assessment tool asks you to confirm its implementation. Keep this evidence at hand before you start:

  • Access control: export of the list of active accounts and their rights, access revocation policy when an employee leaves.
  • Identification and authentication: screenshot of the multi-factor authentication configuration on remote and privileged access.
  • Media and physical protection: written procedure for sanitizing media taken out of service, log of physical access to the premises.
  • System and communications protection: firewall or network gateway rules, log of applied patches, antivirus/anti-malware configuration.

How does the self-assessment work?

  1. Define the scope of the systems and environments covered by the contract.
  2. Assess each of the 13 controls in the government’s online tool.
  3. Document the implementation evidence for each control.
  4. Fix the gaps identified before submitting the result.
  5. Submit the self-assessment and confirm the result, including its expiry date, in your supplier profile on CanadaBuys.
  6. Keep the evidence file for the following annual self-assessment.

CPCSC Level 1 vs Level 2

AspectLevel 1Level 2
Controls1398
AssessorSelf-assessment by the supplierThird-party certification body accredited by the SCC
FrequencyAnnualEvery 3 years, with annual confirmation
Target sensitivityLower riskControlled defence information

Aiming for Level 2 next? See the 98 controls and CPCSC Level 2 preparation.

Check your readiness

Before submitting your self-assessment, check where you really stand on the 13 controls with the CPCSC self-assessment checklist. Our CPCSC certification support covers implementing the missing controls and preparing your file.

Let’s talk about your CPCSC Level 1 journey

A first conversation lets us determine your scope and assess how we can support you. No commitment. Contact us.

Frequently asked questions

Who has to complete the CPCSC Level 1 self-assessment?
Any supplier, subcontractor or software vendor that is part of the Canadian defence supply chain and whose contract requires CPCSC Level 1, whatever its size. Level 1 applies to lower-risk situations: administrative or operational support, basic IT services without sensitive data, limited network integration.
How many controls does Level 1 cover?
13 controls, drawn from the Canadian standard ITSP.10.171 and grouped into 4 basic cyber hygiene families: access control, identification and authentication, media and physical protection, system and communications protection. Each control carries a code, for example 03.05.03 for multi-factor authentication, which the self-assessment tool asks you to confirm.
How often must the self-assessment be redone?
Annually. The result, including its expiry date, must be confirmed in your supplier profile on CanadaBuys. Keep the evidence file built for the first self-assessment: it will be the basis for the following annual self-assessment and will save you from starting over when the contract requires a renewal.
How long does the CPCSC Level 1 self-assessment take?
Assessing the 13 controls themselves takes a few hours if your evidence is already organized. The upstream preparation, meaning gathering the evidence and fixing the gaps, varies from a few days to a few weeks depending on your starting maturity. That is why it pays to start with the checklist before opening the official tool.
Can a CMMC certification be reused for the CPCSC?
Not automatically, but the two programs rest on very similar technical controls, NIST SP 800-171 on one side and ITSP.10.171 on the other. Case by case, Canada may recognize a valid CMMC certification if its scope matches the CPCSC requirements; that recognition has to be confirmed with the Canadian authority for your contract.

Let's talk about your compliance program.

Last updated: 2026-09-17