Sentrix

Services · Compliance

CPCSC certification support (Levels 1, 2 and 3)

CPCSC is becoming a contractual requirement for defence suppliers. Sentrix structures your process at Levels 1, 2 and 3, from gap analysis to evidence.

Why this matters

CPCSC eligibility isn't a one-time checkbox. Requirements are rolling out in phases, levels compound as contracts get more sensitive, and preparing under contract pressure costs more than preparing early.

Contracts are the leverage

According to PSPC, Level 1 is being introduced into select defence contracts starting summer 2026; staying eligible means demonstrating compliance, not promising it.

Levels compound

13 controls at Level 1 becomes 98 at Level 2 and 200 at Level 3, based on the sensitivity of the contract; the requirements only grow from here.

CMMC doesn't carry over automatically

CPCSC and CMMC rest on aligned technical controls, but they are not officially equivalent; recognition is assessed case by case.

Delaying costs more

Preparing under pressure, on tight deadlines, with a contract at stake, is a worse position than preparing before requirements appear in tenders.

What sets this apart

We implement the missing technical controls, not just document them. A gap report alone doesn't get you compliant. We work directly with your IT teams to put access management, boundary protection, patching and malware controls in place, then support you through the self-assessment or the accredited body's assessment itself.

  • Access control and identification: account management, MFA, access enforcement.
  • System and communications protection: boundary protection, patching, malware defence.
  • Media and physical protection: sanitization, physical access control.
  • Support through your self-assessment or third-party assessment.

Sample gap findings

Illustrative examples, with ITSP.10.171 control codes; they do not describe a specific client.

  • High: multi-factor authentication (03.05.03) is not enforced for privileged and remote access accounts. Action: implement MFA across privileged and remote access before the self-assessment is filed.
  • High: boundary protection (03.13.01) rules allow broader network access than the scope requires. Action: tighten the rules and document segmentation for the assessment record.
  • Medium: flaw remediation (03.14.01) exists on paper but patch cycles are inconsistent across systems. Action: formalize a patch management cadence with evidence of consistent application.
  • Low: media sanitization (03.08.03) procedures are undocumented for decommissioned devices. Action: document and apply sanitization procedures before devices leave the sensitive-data boundary.

What is CPCSC?

The Canadian Program for Cyber Security Certification (CPCSC, or PCCC in French) is led by Public Services and Procurement Canada (PSPC) and National Defence. It sets the cybersecurity standards defence contractors must meet to protect sensitive unclassified information and ensure interoperability with Canada's allies, notably Five Eyes partners.

The program is built on Canada's industrial cybersecurity standard (ITSP.10.171), developed by the Canadian Centre for Cyber Security. Technically, this standard is closely aligned with the US NIST SP 800-171 and 800-172 publications, which also underpin the American CMMC program. This alignment is meant to limit overlap and preserve Canadian suppliers' access to international defence markets.

In practical terms: if your organization handles sensitive government information under defence contracts, or wants to enter the Canadian defence supply chain, CPCSC will become a condition of access to those contracts. The CPCSC framework page summarizes the program; the CPCSC guide details the self-assessment and the levels.

The three certification levels

CPCSC's mandatory requirements are organized into three progressive levels, based on the sensitivity of the information handled and the contract's risk level. The control counts and dates below are those published by PSPC.

Level 1: self-assessment, 13 controls

Annual self-assessment by the supplier, using an online tool provided by the Government of Canada. Available to suppliers since April 1, 2026; introduced into select defence contracts starting summer 2026. Applies to lower-risk situations: administrative or operational support, basic IT services without sensitive data, limited network integration. See the 13 Level 1 controls and evidence.

Level 2: external assessment, 98 controls

Assessment conducted by a certification body or third-party assessment organization accredited through the Standards Council of Canada (SCC), every three years, with annual confirmation. Planned to be introduced into select defence contracts starting spring 2027. Applies to contracts involving controlled Defence information or more complex sensitive work. See Level 2 preparation.

Level 3: government assessment, 200 controls

Assessment conducted directly by National Defence, every three years, with annual confirmation. Reserved for the highest-risk scenarios: weapons systems, critical infrastructure, information shared with Five Eyes partners.

Levels 2 and 3 are still being developed. Timelines and details will be clarified by PSPC and the SCC as the rollout continues.

CPCSC Level 1 checklist: the 13 controls

Level 1's 13 controls, drawn from the ITSP.10.171 standard, group into fundamental cyber-hygiene practices. Our support helps you assess each one and document its implementation. You can also start with the online self-assessment, one question per control.

Access control: managing who can access systems

  • Account management (03.01.01)
  • Access enforcement (03.01.02)
  • Use of external systems (03.01.20)
  • Publicly accessible content (03.01.22)

Identification and authentication: verifying users and devices

  • User identification and authentication (03.05.01)
  • Device identification and authentication (03.05.02)
  • Multi-factor authentication (03.05.03)

Media and physical protection: protecting data and equipment

  • Media sanitization (03.08.03)
  • Physical access authorizations (03.10.01)
  • Physical access control (03.10.07)

System and communications protection: defending systems against cyber threats

  • Boundary protection (03.13.01)
  • Flaw remediation (03.14.01)
  • Malicious code protection (03.14.02)

Control codes follow the Canadian ITSP.10.171 standard. Official titles may evolve between versions of the program.

How to complete the CPCSC Level 1 self-assessment

  1. Scope the systems and environments in question.
  2. Assess each of the 13 controls one by one.
  3. Collect evidence of implementation.
  4. Remediate identified gaps.
  5. Document your progress.
  6. Submit the self-assessment in the government tool and affirm it in CanadaBuys.

Who this support is for

CPCSC concerns organizations that are part of the Canadian defence supply chain, or plan to enter it.

  • Defence sector contractors and subcontractors who must demonstrate compliance to remain eligible for federal contracts.
  • Engineering, manufacturing and aerospace companies supporting defence programs.
  • IT and OT service providers whose systems interact with defence-related data or environments.
  • Technology suppliers and publishers handling sensitive unclassified government information.
  • Suppliers already engaged with US CMMC who want to align both frameworks and avoid duplicating effort.
  • Proactive organizations not yet in scope who want to prepare before requirements appear in tenders.
  • Foreign companies that wish to participate in Canadian defence supply chain contracts covered by CPCSC requirements.

CPCSC applies regardless of company size: a small subcontractor and a large prime both need to meet the level required by their contract. Level 1's 13 controls were scoped to be achievable without an in-house security team, and our process is built for suppliers without dedicated compliance staff.

What you get

Scoping

Identifying the systems, environments and processes that handle sensitive information, and spotting segmentation or isolation opportunities to limit your exposure and the assessment's scope.

Gap analysis

An assessment of your current posture against ITSP.10.171 requirements, prioritized by risk and effort, with the target level (1, 2 or 3) clearly established.

Documentation and evidence

Writing or adapting the expected policies, procedures and supporting evidence, at the level of detail required to support your self-assessment or a third-party assessment, not generic templates.

Implementation of missing controls

Working with your IT teams to put in place required technical controls: access management, multi-factor authentication, network boundary protection, flaw remediation, malware protection.

Action plan (POA&M)

A prioritized corrective action plan to close remaining gaps and build a realistic roadmap toward assessment readiness.

Assessment preparation

Support completing the Level 1 self-assessment in the government's tool, or preparing for an assessment by an accredited body (Level 2) or by National Defence (Level 3).

Our four-step approach

  1. Identify. Which systems handle sensitive information, what boundaries are involved, and whether certain environments should be segmented or isolated to limit exposure.
  2. Analyze. Where you stand against ITSP.10.171 requirements, what gaps remain, and which certification level you're targeting.
  3. Remediate. Prioritized corrective actions to strengthen the protection of your access, logs and sensitive data, implemented with your teams.
  4. Assess. Validating the evidence and supporting you through the annual self-assessment, an accredited body's assessment, or the government assessment.

CPCSC and CMMC: differences, alignment and recognition

CPCSC and the American CMMC program both aim to strengthen defence supply chain cybersecurity. They are not officially equivalent, but they rest on aligned technical controls: ITSP.10.171 on one side, the NIST SP 800-171 and 800-172 publications on the other. On a case-by-case basis, Canada may accept a valid CMMC certification if its scope matches CPCSC requirements, which can avoid maintaining two separate certifications; Canada nevertheless reserves the right to verify compliance with specific controls. If you supply both markets, we help you align the two frameworks and optimize your effort.

AspectCPCSC (Canada)CMMC (United States)
JurisdictionCanadaUnited States
SectorCanadian defence supply chainDepartment of Defense (DoD) contractors
Reference technical standardITSP.10.171 (aligned with NIST SP 800-171 / 800-172)NIST SP 800-171
Responsible authorityPSPC and National Defence; accreditation by the SCCUS Department of Defense
Levels3 levels (self-assessment, accredited third party, government)3 levels

Supplying both DND and DoD? See our CPCSC vs CMMC comparison and the controls you can reuse.

Why prepare now

As CPCSC requirements appear in procurement processes, prepared organizations will be best positioned to seize business opportunities. Delaying preparation means risking having to comply under pressure, on tight deadlines, with the contract at stake. Complying with CPCSC means:

  • access public and defence-related contracts with the Government of Canada;
  • protect the sensitive information you handle and strengthen your partners' trust;
  • structure your cybersecurity around a framework aligned with NIST and CMMC;
  • reduce your risk and better control remediation costs by acting early rather than urgently.

Why trust Sentrix with your CPCSC journey

Cybersecurity and compliance expertise

A specialized team mastering the frameworks at the core of CPCSC: ITSP.10.171, NIST SP 800-171 / 800-172, and related frameworks (ISO 27001, among others).

End-to-end support

From scoping to assessment prep, including control implementation and documentation management, we stay by your side at every step.

Scalable, pragmatic approach

A compliance path adapted to your current maturity, the nature of your contracts, and your technical and budget constraints.

Current with the program's evolution

CPCSC is rolling out in phases and its requirements are evolving. We actively track guidance from PSPC, the SCC and the Canadian Centre for Cyber Security so your process reflects the current state of expectations.

We prepare; we do not certify. Level 2 assessments are conducted by third-party bodies accredited by the Standards Council of Canada; Level 3 assessments are conducted by National Defence.

Where CPCSC fits

CPCSC should not be confused with CAN/DGSI 104 (CyberSecure Canada), a national certification mainly aimed at SMEs and built on a different standard. The Level 1 technical controls map to our identity and access, network security and vulnerability and patch management services; ISO 27001 certification support answers clients who also require an international certification.

Let's talk about your CPCSC journey.

Whether you're already facing a contractual requirement or just want to check your readiness, a first conversation costs nothing and helps determine the target level and how we can support you.

Contact us

Frequently asked questions

Is CPCSC mandatory?
CPCSC's cybersecurity requirements are becoming mandatory contractual conditions for certain defence contracts. According to PSPC, Level 1 (annual self-assessment) is being introduced into select contracts starting summer 2026, with higher levels to follow. If you want to stay eligible for targeted contracts, compliance is not optional; it has to be demonstrated, not promised.
Which level applies to me?
It depends on the sensitivity of the information handled and the risk level of the targeted contracts. Lower-risk situations fall under Level 1 (self-assessment). Contracts involving controlled Defence information fall under Level 2, and the highest-risk scenarios (weapons systems, critical infrastructure) fall under Level 3. We help you determine the right level as part of scoping.
I already have CMMC certification. Do I need to go through CPCSC too?
Not necessarily in full. CPCSC and CMMC are not officially equivalent, but they rest on aligned technical controls (ITSP.10.171 and NIST SP 800-171/800-172). On a case-by-case basis, Canada may accept a valid CMMC certification if its scope matches CPCSC requirements, and reserves the right to verify specific controls. We align the two frameworks to avoid duplicating your effort.
What evidence is required for CPCSC Level 1?
Evidence maps to the 13 Level 1 controls: your security policies and procedures, configuration screenshots or exports (firewall, antivirus, backups), your asset and account inventory, multi-factor authentication evidence, your patch log, network segmentation documentation, media sanitization evidence, and physical access control records.
How much does CPCSC readiness cost?
There is no fixed price: cost is driven by the target level, the scope of your environment, the number of gaps to remediate, remediation complexity and the type of assessment (self-assessment, accredited body or National Defence). We provide a precise estimate after the initial diagnostic, before you commit, and the scoping step is designed precisely to limit the assessment's scope.

Let's talk about your compliance program.

Last updated: 2026-09-17