Sentrix

CPCSC guide · Level 1

CPCSC self-assessment: check your Level 1 readiness

Checklist of the 13 CPCSC Level 1 controls: one plain-language question per control, with its ITSP.10.171 code and the evidence you are expected to have.

How does the CPCSC self-assessment work?

This checklist restates the 13 CPCSC Level 1 controls as plain-language questions. For each one, note whether the measure is in place, partially in place or absent. The result is an estimate meant to show where you stand before you complete the official self-assessment in the Government of Canada tool; it does not replace it.

The questions cover the 4 control families of Level 1, drawn from the ITSP.10.171 standard: access control, identification and authentication, media and physical protection, system and communications protection. Each question shows the control code and the gap to fix if the answer is no; under each family, the evidence the self-assessment tool will ask you to confirm. The details of the controls are on the page CPCSC Level 1: 13 controls and self-assessment.

The 13 questions

Access control

No.QuestionITSP.10.171 controlGap to fix if the answer is no
1Do you run a formal process for creating, changing and removing user accounts?03.01.01Formal user account management
2Are your employees’ access rights limited to what their role strictly requires?03.01.02Least-privilege enforcement
3Do you control the use of external systems (personal devices, third-party cloud services) to access your data?03.01.20Control of external systems
4Do you check that only content intended for the public is actually publicly accessible (website, cloud shares, etc.)?03.01.22Control of publicly accessible content

Expected evidence: Export of the list of active accounts and their rights, access revocation policy when an employee leaves.

Identification and authentication

No.QuestionITSP.10.171 controlGap to fix if the answer is no
5Does every user have a unique, verified identity to access your systems?03.05.01Unique user identification
6Are the devices that connect to your systems identified and authenticated before access?03.05.02Device identification and authentication
7Is multi-factor authentication (MFA) enabled for privileged and remote access?03.05.03Multi-factor authentication (MFA) on privileged and remote access

Expected evidence: Screenshot of the multi-factor authentication configuration on remote and privileged access.

Media and physical protection

No.QuestionITSP.10.171 controlGap to fix if the answer is no
8Do you have a procedure for sanitizing media (disks, USB keys, etc.) before disposal or reassignment?03.08.03Media sanitization procedure
9Are physical access authorizations to your premises documented and limited to authorized staff?03.10.01Documented physical access authorizations
10Do you actually control who can enter your premises (badges, logs, surveillance)?03.10.07Physical access control to premises

Expected evidence: Written procedure for sanitizing media taken out of service, log of physical access to the premises.

System and communications protection

No.QuestionITSP.10.171 controlGap to fix if the answer is no
11Are your network boundaries (firewalls, gateways) configured to block unauthorized traffic?03.13.01Network boundary protection
12Do you apply security patches on a regular, documented schedule?03.14.01Security patch management and application
13Is malware protection (antivirus/EDR) deployed and up to date on your systems?03.14.02Malware protection

Expected evidence: Firewall or network gateway rules, log of applied patches, antivirus/anti-malware configuration.

What if you are not ready?

A weak result is nothing unusual at this stage: most suppliers doing this self-assessment for the first time have at least a few gaps. What matters is fixing them before you submit your official self-assessment, not after. Our CPCSC certification support covers implementing the missing controls and preparing your complete file.

Going further

Ready to fix your CPCSC gaps?

We support you from gap analysis to the submission of your self-assessment. Contact us.

Frequently asked questions

Does this self-assessment replace the official government tool?
No. This checklist gives you a quick estimate of your readiness before you complete the official self-assessment in the Government of Canada tool, which remains the only recognized submission for your CanadaBuys supplier profile. It helps you see where you stand and spot your gaps before the official submission, not after.
How long does the self-assessment take?
Allow 5 to 10 minutes to answer the 13 questions if you already know the general state of your security practices. Gathering the expected evidence for each control family and then fixing the gaps you identify takes longer: from a few days to a few weeks depending on your starting maturity, before you submit the official self-assessment.
What if several measures are only partially in place or missing?
A weak result is nothing unusual at this stage: most suppliers doing this self-assessment for the first time have at least a few gaps. What matters is fixing them before you submit your official self-assessment. Our CPCSC certification support covers implementing the missing controls and preparing your complete file.

Let's talk about your compliance program.

Last updated: 2026-09-17