Sentrix

CPCSC guide · Level 2

CPCSC Level 2: 98 controls and third-party assessment

CPCSC Level 2 covers contracts involving controlled defence information: 98 ITSP.10.171 controls and an assessment by a body accredited by the SCC.

CPCSC Level 2 is the next step for suppliers whose contracts involve controlled defence information or more complex, sensitive work. Unlike Level 1, the assessment is no longer a self-assessment: it is conducted by a third-party certification body accredited by the Standards Council of Canada (SCC), every three years, with annual confirmation between cycles. Level 2 is expected to be integrated into certain defence contracts from spring 2027, according to the schedule published by Public Services and Procurement Canada (PSPC).

Who does Level 2 apply to?

Level 2 targets suppliers whose activity goes beyond the basic administrative support covered by Level 1:

  • defence contractors and subcontractors handling controlled defence information;
  • engineering, manufacturing and aerospace companies integrated into defence programs;
  • IT and OT service providers whose systems host or transmit more sensitive data;
  • organizations already certified at Level 1 whose contract is moving to a wider scope.

The 98 controls

Level 2 counts 98 controls, including the 13 of Level 1, aligned with NIST SP 800-171 through the Canadian standard ITSP.10.171. Rather than listing all 98 lines here, these are the domains covered:

Access and identity management

Extended access control, privileged account management, separation of duties.

System and network protection

Segmentation, traffic monitoring, configuration management, encryption.

Incident and continuity management

Detection, incident response, continuity and recovery plans.

Governance and risk assessment

Documented policies, periodic risk assessment, staff training.

For a control-by-control gap analysis, see our CPCSC certification support.

Determine the scope

Before any assessment, you must precisely delimit which systems, users and data in your organization handle controlled defence information. Clear network segmentation can significantly reduce the scope, and therefore the effort, of the assessment. A poorly defined scope is the most frequent cause of delays in Level 2 projects.

Prepare the evidence

Each of the 98 controls must be backed by concrete evidence: signed policies, exported configurations, activity logs, remediation tickets, test reports. The assessing body expects a structured file where each control is clearly linked to its evidence, not a pile of generic documents.

Fix the gaps

Once the gaps against the 98 controls are identified, they must be fixed and documented in a plan of action (POA&M) before the assessment. This plan prioritizes the fixes by risk and effort, and serves as the roadmap to assessment readiness.

How does the assessment unfold?

  1. Preparation: final scoping, verification that the evidence is complete and current.
  2. Document review: the assessing body examines the policies, procedures and evidence submitted.
  3. Technical checks: practical validation of the implementation of critical controls.
  4. Handling of residual gaps: any non-conformity found must be fixed within the deadlines set by the body.
  5. Remediation and confirmation: once the fixes are validated, certification is issued for three years, with annual confirmation.

CPCSC Level 2 and ITSP.10.171 / NIST

The 98 Level 2 controls are aligned with NIST SP 800-171 through the Canadian standard ITSP.10.171. This technical harmonization makes it easier to reuse evidence for suppliers already engaged in the US CMMC, but it is not an automatic official equivalence between the two programs: each framework keeps its own recognition process. See our CPCSC vs CMMC comparison for the details.

Going further

Let’s talk about your CPCSC Level 2 journey

A first conversation lets us frame your scope and assess the real effort before you commit. No commitment. Contact us.

Frequently asked questions

Who does CPCSC Level 2 apply to?
Suppliers whose activity goes beyond the basic administrative support covered by Level 1: contractors and subcontractors handling controlled defence information, engineering, manufacturing and aerospace companies integrated into defence programs, IT and OT service providers hosting more sensitive data, and Level 1 certified organizations whose contract is moving to a wider scope.
Who conducts the assessment, and how often?
Unlike Level 1, the assessment is no longer a self-assessment: it is conducted by a third-party certification body accredited by the Standards Council of Canada (SCC), every three years, with annual confirmation between cycles. Once the corrections are validated, certification is issued for three years. Level 2 is expected to be integrated into certain defence contracts from spring 2027.
Why does scope matter so much at Level 2?
You must precisely delimit which systems, users and data in your organization handle controlled defence information. Clear network segmentation can significantly reduce the scope, and therefore the effort, of the assessment. A poorly defined scope is the most frequent cause of delays in Level 2 projects; it is the first step before any evidence collection.
Is Level 2 equivalent to the US CMMC?
No. The 98 controls are aligned with NIST SP 800-171 through the Canadian standard ITSP.10.171, which makes it easier to reuse evidence for suppliers already engaged in CMMC. This technical harmonization is not, however, an automatic official equivalence: each framework keeps its own recognition process.

Let's talk about your compliance program.

Last updated: 2026-09-17