CPCSC guide · Level 2
CPCSC Level 2: 98 controls and third-party assessment
CPCSC Level 2 covers contracts involving controlled defence information: 98 ITSP.10.171 controls and an assessment by a body accredited by the SCC.
CPCSC Level 2 is the next step for suppliers whose contracts involve controlled defence information or more complex, sensitive work. Unlike Level 1, the assessment is no longer a self-assessment: it is conducted by a third-party certification body accredited by the Standards Council of Canada (SCC), every three years, with annual confirmation between cycles. Level 2 is expected to be integrated into certain defence contracts from spring 2027, according to the schedule published by Public Services and Procurement Canada (PSPC).
Who does Level 2 apply to?
Level 2 targets suppliers whose activity goes beyond the basic administrative support covered by Level 1:
- defence contractors and subcontractors handling controlled defence information;
- engineering, manufacturing and aerospace companies integrated into defence programs;
- IT and OT service providers whose systems host or transmit more sensitive data;
- organizations already certified at Level 1 whose contract is moving to a wider scope.
The 98 controls
Level 2 counts 98 controls, including the 13 of Level 1, aligned with NIST SP 800-171 through the Canadian standard ITSP.10.171. Rather than listing all 98 lines here, these are the domains covered:
Access and identity management
Extended access control, privileged account management, separation of duties.
System and network protection
Segmentation, traffic monitoring, configuration management, encryption.
Incident and continuity management
Detection, incident response, continuity and recovery plans.
Governance and risk assessment
Documented policies, periodic risk assessment, staff training.
For a control-by-control gap analysis, see our CPCSC certification support.
Determine the scope
Before any assessment, you must precisely delimit which systems, users and data in your organization handle controlled defence information. Clear network segmentation can significantly reduce the scope, and therefore the effort, of the assessment. A poorly defined scope is the most frequent cause of delays in Level 2 projects.
Prepare the evidence
Each of the 98 controls must be backed by concrete evidence: signed policies, exported configurations, activity logs, remediation tickets, test reports. The assessing body expects a structured file where each control is clearly linked to its evidence, not a pile of generic documents.
Fix the gaps
Once the gaps against the 98 controls are identified, they must be fixed and documented in a plan of action (POA&M) before the assessment. This plan prioritizes the fixes by risk and effort, and serves as the roadmap to assessment readiness.
How does the assessment unfold?
- Preparation: final scoping, verification that the evidence is complete and current.
- Document review: the assessing body examines the policies, procedures and evidence submitted.
- Technical checks: practical validation of the implementation of critical controls.
- Handling of residual gaps: any non-conformity found must be fixed within the deadlines set by the body.
- Remediation and confirmation: once the fixes are validated, certification is issued for three years, with annual confirmation.
CPCSC Level 2 and ITSP.10.171 / NIST
The 98 Level 2 controls are aligned with NIST SP 800-171 through the Canadian standard ITSP.10.171. This technical harmonization makes it easier to reuse evidence for suppliers already engaged in the US CMMC, but it is not an automatic official equivalence between the two programs: each framework keeps its own recognition process. See our CPCSC vs CMMC comparison for the details.
Going further
- CPCSC Level 1: 13 controls and self-assessment
- CPCSC self-assessment checklist
- CPCSC framework page and the article CPCSC explained
Let’s talk about your CPCSC Level 2 journey
A first conversation lets us frame your scope and assess the real effort before you commit. No commitment. Contact us.
Frequently asked questions
- Who does CPCSC Level 2 apply to?
- Suppliers whose activity goes beyond the basic administrative support covered by Level 1: contractors and subcontractors handling controlled defence information, engineering, manufacturing and aerospace companies integrated into defence programs, IT and OT service providers hosting more sensitive data, and Level 1 certified organizations whose contract is moving to a wider scope.
- Who conducts the assessment, and how often?
- Unlike Level 1, the assessment is no longer a self-assessment: it is conducted by a third-party certification body accredited by the Standards Council of Canada (SCC), every three years, with annual confirmation between cycles. Once the corrections are validated, certification is issued for three years. Level 2 is expected to be integrated into certain defence contracts from spring 2027.
- Why does scope matter so much at Level 2?
- You must precisely delimit which systems, users and data in your organization handle controlled defence information. Clear network segmentation can significantly reduce the scope, and therefore the effort, of the assessment. A poorly defined scope is the most frequent cause of delays in Level 2 projects; it is the first step before any evidence collection.
- Is Level 2 equivalent to the US CMMC?
- No. The 98 controls are aligned with NIST SP 800-171 through the Canadian standard ITSP.10.171, which makes it easier to reuse evidence for suppliers already engaged in CMMC. This technical harmonization is not, however, an automatic official equivalence: each framework keeps its own recognition process.
Related pages
CPCSC guide · Level 1
CPCSC self-assessment: check your Level 1 readiness
Checklist of the 13 CPCSC Level 1 controls: one plain-language question per control, with its ITSP.10.171 code and the evidence you are expected to have.
CPCSC guide · Level 1
CPCSC Level 1: 13 controls and self-assessment
Level 1 of the Canadian Program for Cyber Security Certification is an annual self-assessment against 13 ITSP.10.171 controls: requirements, evidence, steps.
CPCSC guide · Comparison
CPCSC vs CMMC: differences for defence suppliers
Compare CPCSC and CMMC: authorities, Canadian and US markets, levels, assessments, ITSP.10.171 and NIST SP 800-171, and the evidence reusable across both.
Let's talk about your compliance program.
Last updated: 2026-09-17
