CPCSC guide · Level 1
CPCSC self-assessment: check your Level 1 readiness
Checklist of the 13 CPCSC Level 1 controls: one plain-language question per control, with its ITSP.10.171 code and the evidence you are expected to have.
How does the CPCSC self-assessment work?
This checklist restates the 13 CPCSC Level 1 controls as plain-language questions. For each one, note whether the measure is in place, partially in place or absent. The result is an estimate meant to show where you stand before you complete the official self-assessment in the Government of Canada tool; it does not replace it.
The questions cover the 4 control families of Level 1, drawn from the ITSP.10.171 standard: access control, identification and authentication, media and physical protection, system and communications protection. Each question shows the control code and the gap to fix if the answer is no; under each family, the evidence the self-assessment tool will ask you to confirm. The details of the controls are on the page CPCSC Level 1: 13 controls and self-assessment.
The 13 questions
Access control
| No. | Question | ITSP.10.171 control | Gap to fix if the answer is no |
|---|---|---|---|
| 1 | Do you run a formal process for creating, changing and removing user accounts? | 03.01.01 | Formal user account management |
| 2 | Are your employees’ access rights limited to what their role strictly requires? | 03.01.02 | Least-privilege enforcement |
| 3 | Do you control the use of external systems (personal devices, third-party cloud services) to access your data? | 03.01.20 | Control of external systems |
| 4 | Do you check that only content intended for the public is actually publicly accessible (website, cloud shares, etc.)? | 03.01.22 | Control of publicly accessible content |
Expected evidence: Export of the list of active accounts and their rights, access revocation policy when an employee leaves.
Identification and authentication
| No. | Question | ITSP.10.171 control | Gap to fix if the answer is no |
|---|---|---|---|
| 5 | Does every user have a unique, verified identity to access your systems? | 03.05.01 | Unique user identification |
| 6 | Are the devices that connect to your systems identified and authenticated before access? | 03.05.02 | Device identification and authentication |
| 7 | Is multi-factor authentication (MFA) enabled for privileged and remote access? | 03.05.03 | Multi-factor authentication (MFA) on privileged and remote access |
Expected evidence: Screenshot of the multi-factor authentication configuration on remote and privileged access.
Media and physical protection
| No. | Question | ITSP.10.171 control | Gap to fix if the answer is no |
|---|---|---|---|
| 8 | Do you have a procedure for sanitizing media (disks, USB keys, etc.) before disposal or reassignment? | 03.08.03 | Media sanitization procedure |
| 9 | Are physical access authorizations to your premises documented and limited to authorized staff? | 03.10.01 | Documented physical access authorizations |
| 10 | Do you actually control who can enter your premises (badges, logs, surveillance)? | 03.10.07 | Physical access control to premises |
Expected evidence: Written procedure for sanitizing media taken out of service, log of physical access to the premises.
System and communications protection
| No. | Question | ITSP.10.171 control | Gap to fix if the answer is no |
|---|---|---|---|
| 11 | Are your network boundaries (firewalls, gateways) configured to block unauthorized traffic? | 03.13.01 | Network boundary protection |
| 12 | Do you apply security patches on a regular, documented schedule? | 03.14.01 | Security patch management and application |
| 13 | Is malware protection (antivirus/EDR) deployed and up to date on your systems? | 03.14.02 | Malware protection |
Expected evidence: Firewall or network gateway rules, log of applied patches, antivirus/anti-malware configuration.
What if you are not ready?
A weak result is nothing unusual at this stage: most suppliers doing this self-assessment for the first time have at least a few gaps. What matters is fixing them before you submit your official self-assessment, not after. Our CPCSC certification support covers implementing the missing controls and preparing your complete file.
Going further
- CPCSC Level 1: requirements, 13 controls and self-assessment preparation
- CPCSC Level 2: 98 controls and third-party assessment
- CPCSC vs CMMC
- CPCSC framework page and the article CPCSC explained
Ready to fix your CPCSC gaps?
We support you from gap analysis to the submission of your self-assessment. Contact us.
Frequently asked questions
- Does this self-assessment replace the official government tool?
- No. This checklist gives you a quick estimate of your readiness before you complete the official self-assessment in the Government of Canada tool, which remains the only recognized submission for your CanadaBuys supplier profile. It helps you see where you stand and spot your gaps before the official submission, not after.
- How long does the self-assessment take?
- Allow 5 to 10 minutes to answer the 13 questions if you already know the general state of your security practices. Gathering the expected evidence for each control family and then fixing the gaps you identify takes longer: from a few days to a few weeks depending on your starting maturity, before you submit the official self-assessment.
- What if several measures are only partially in place or missing?
- A weak result is nothing unusual at this stage: most suppliers doing this self-assessment for the first time have at least a few gaps. What matters is fixing them before you submit your official self-assessment. Our CPCSC certification support covers implementing the missing controls and preparing your complete file.
Related pages
CPCSC guide · Level 1
CPCSC Level 1: 13 controls and self-assessment
Level 1 of the Canadian Program for Cyber Security Certification is an annual self-assessment against 13 ITSP.10.171 controls: requirements, evidence, steps.
CPCSC guide · Level 2
CPCSC Level 2: 98 controls and third-party assessment
CPCSC Level 2 covers contracts involving controlled defence information: 98 ITSP.10.171 controls and an assessment by a body accredited by the SCC.
CPCSC guide · Comparison
CPCSC vs CMMC: differences for defence suppliers
Compare CPCSC and CMMC: authorities, Canadian and US markets, levels, assessments, ITSP.10.171 and NIST SP 800-171, and the evidence reusable across both.
Let's talk about your compliance program.
Last updated: 2026-09-17
