Resources · Article
CPCSC explained for Canadian defence suppliers
Level 1 of the Canadian Program for Cyber Security Certification has been available since April 1, 2026. What Levels 1, 2 and 3 require, and where to start.
By Sentrix · Published 2026-07-15
In short
CPCSC, the Canadian Program for Cyber Security Certification, is Canada's answer to a problem the United States addressed years earlier with CMMC: how to verify, rather than simply require, that suppliers handling sensitive government information actually have adequate cybersecurity controls in place. Level 1 became available to suppliers on April 1, 2026, and Public Services and Procurement Canada has said Level 1 requirements would start appearing in select defence contracts in summer 2026. This article explains what Levels 1, 2 and 3 require, who is in scope, and where to start.
If you sell to the Department of National Defence, or you sit anywhere in a defence prime's supply chain, this acronym now matters to your business. If you need help getting there, Sentrix offers dedicated CPCSC certification support.
Who is actually in scope
CPCSC applies to organizations in the Canadian defence industrial base. The requirement flows down contractually from prime contractors to subcontractors, component suppliers, and service providers anywhere in the chain. It is not limited to whoever signs directly with DND. The program protects a specific category the government calls "designated information": certain types of sensitive information that is not formally classified but still requires protection under the program.
The practical trigger is contractual, not aspirational: if you are bidding on, or already working under, a defence contract that specifies a CPCSC Level 1 requirement, you will need to complete the self-assessment and confirm the results, including the assessment's expiration date, in your organizational supplier profile in CanadaBuys. Self-assessment is required at contract award, not at the bidding stage, which gives suppliers a window to prepare once they know a contract requires it.
Level 1, 2, and 3: what actually differs
Level 1
CPCSC Level 1 is a self-assessment against 13 security requirements and controls drawn from the Canadian Centre for Cyber Security's publication ITSP.10.171 (Protecting specified information in non-Government of Canada systems and organizations). You assess your own implementation status against those 13 controls annually, using the government's online self-assessment tool, and confirm the result in CanadaBuys. No external assessor reviews your evidence at this level.
See the detailed breakdown of the 13 Level 1 controls and the self-assessment.
Level 2 and Level 3
Level 2 is a different exercise entirely: a self-assessment against 98 controls, verified by a third-party assessment organization accredited by the Standards Council of Canada, every three years with annual confirmation in between. It is planned to start appearing in select defence contracts in spring 2027, and applies to contracts involving controlled Defence information or more complex sensitive work. Level 3, the highest tier, expands to 200 controls and moves to direct assessment by the Department of National Defence itself, reserved for the highest-risk scenarios: weapons systems, critical infrastructure, and information shared with Five Eyes partners. Both higher levels are understood to align to the more advanced NIST SP 800-171 and NIST SP 800-172 control baselines, the same standards underpinning CMMC's higher tiers in the US.
See the detailed breakdown of the 98 Level 2 controls.
The rollout so far
Public Services and Procurement Canada made Level 1 available to suppliers on April 1, 2026. Level 1 requirements are being introduced into select defence contracts starting summer 2026, not retroactively into every existing contract at once, but progressively as new solicitations and contract actions specify it. If you have not seen a CPCSC clause in your own contracts yet, that does not mean you will not; it means your specific contract has not reached that point in the rollout.
The CMMC overlap Canadian-American suppliers should not ignore
If your organization supplies both DND and the US Department of Defense, you are almost certainly looking at both CPCSC and CMMC obligations, and there is no automatic equivalence between them today: a CMMC certification does not currently substitute for CPCSC certification, or vice versa. Canada has signalled it intends to work toward mutual recognition for organizations with aligned scopes, but until that materializes, treat the two as separate requirements that happen to share a lot of underlying control structure, since both trace back to NIST SP 800-171 at their higher tiers. The guide's CPCSC vs CMMC page compares the two programs point by point.
Where to start
Start with the government's own online self-assessment tool to walk through the 13 Level 1 controls and see where you actually stand; it is free and designed for exactly this purpose. In parallel, map which systems, personnel, and data stores handle designated information; certification work done against the wrong boundary is work you will redo. If your contracts point toward Level 2 or 3 eventually, a solid Level 1 foundation first avoids backfilling basic hygiene gaps mid-assessment later, which is the least efficient point to discover them.
Level 2 and Level 3 guidance is still being rolled out: confirm current requirements for your specific contract against official PSPC and Canadian Centre for Cyber Security guidance before making certification commitments.
Need hands-on help with your Level 1 self-assessment or Level 2/3 preparation? See our CPCSC certification support service and the CPCSC framework page.
Sources
Frequently asked questions
- Who does CPCSC apply to?
- CPCSC applies to organizations anywhere in the Canadian defence industrial base. The requirement flows down contractually from prime contractors to subcontractors, component suppliers and service providers throughout the chain, not just to whoever signs directly with the Department of National Defence. The trigger is a contract that specifies a CPCSC requirement.
- What is the difference between CPCSC Level 1, 2 and 3?
- Level 1 is an annual self-assessment against 13 controls with no external review. Level 2 is a self-assessment against 98 controls, verified every three years by a third-party assessment organization accredited by the Standards Council of Canada, with annual confirmation. Level 3 expands to 200 controls with direct assessment by the Department of National Defence, reserved for the highest-risk scenarios.
- When did CPCSC Level 1 become available?
- Level 1 became available to suppliers on April 1, 2026. Public Services and Procurement Canada is introducing it into select defence contracts starting summer 2026, progressively as new solicitations and contract actions specify it, not retroactively into every existing contract. Level 2 is planned to appear in select contracts in spring 2027.
- Does a CMMC certification satisfy CPCSC requirements?
- Not automatically. There is currently no equivalence between CPCSC and the US CMMC, even though both trace back to NIST SP 800-171 at their higher tiers. Canada has signalled intent to work toward mutual recognition for organizations with aligned scopes, but until that materializes, suppliers in both markets should treat them as separate requirements.
- How should a supplier start preparing?
- Start with the government's free online self-assessment tool to walk through the 13 Level 1 controls and see where you stand. In parallel, map which systems, personnel and data stores handle designated information, since certification work done against the wrong boundary has to be redone. A solid Level 1 foundation avoids backfilling basic hygiene gaps in the middle of a Level 2 assessment.
Related pages
Resources · Article
ISO 27001:2022 clauses that lead to certification
It is clauses 4 through 10, not Annex A, that determine whether you get ISO 27001 certified. The seven certifiable clauses in plain language, for the audit.
Resources · Article
Law 25: the five gaps that persist
Most Law 25 obligations have been in force since September 2023. Five gaps still come up in personal information protection programs; here is how to close them.
Let's talk about your compliance program.
Last updated: 2026-09-17
