CPCSC readiness assessments for consultants
Updated Lire en français
The Canadian Program for Cyber Security Certification (CPCSC) sets cyber security requirements for suppliers on Canadian defence contracts that involve sensitive information. It has three levels. Level 1 is an annual self-assessment against 13 controls and launched in April 2026. Level 2 adds an external assessment by an accredited certification body against 98 controls and is expected in select contracts from spring 2027. Consultants help suppliers scope the environment, test each control against evidence and close gaps before a contract or assessor asks.
The three levels at a glance
| Level | Who assesses | Controls | Status as of September 2026 |
|---|---|---|---|
| Level 1 | The supplier, as an annual self-assessment | 13 | Launched April 2026; required in select defence contracts |
| Level 2 | A certification body accredited through the Standards Council of Canada, every three years, plus an annual affirmation | 98 | To be added to select contracts in spring 2027 |
| Level 3 | National Defence, plus an annual affirmation | 130+ | In development; no date announced |
The controls come from ITSP.10.171, published by the Canadian Centre for Cyber Security. The Cyber Centre describes it as a Canadian version of NIST SP 800-171 with no substantial technical changes, organized into the same 17 families. Level 3 draws on the enhanced requirements adapted from NIST SP 800-172.
A contract states which level applies. Level 1 is confirmed at contract award rather than at bidding, so suppliers who wait for a specific contract leave little time to fix gaps.
The 13 Level 1 controls and the evidence that supports them
Each Level 1 control keeps its ITSP.10.171 identifier. The evidence column is our guidance on what an assessor usually needs to see. It is a starting point for the evidence request, not an official checklist.
| Control | What to request from the supplier |
|---|---|
| 03.01.01 Account management | An export of user and service accounts with owners, plus records of recent joiner, mover and leaver changes |
| 03.01.02 Access enforcement | Role or group definitions and a sample showing access matches each person’s job |
| 03.01.20 Use of external systems | The rule for personal devices and outside systems, and how it is enforced |
| 03.01.22 Publicly accessible content | Who may publish to public sites and how content is reviewed before release |
| 03.05.01 User identification and authentication | Identity provider settings showing unique accounts and no shared logins |
| 03.05.02 Device identification and authentication | Device inventory and the control that stops unknown devices from connecting |
| 03.05.03 Multifactor authentication | MFA policy and an export showing which accounts are enrolled and which are exempt |
| 03.08.03 Media sanitization | Disposal procedure and certificates or logs for wiped or destroyed media |
| 03.10.01 Physical access authorizations | The list of people with physical access and how it is approved and reviewed |
| 03.10.07 Physical access control | Badge, key or visitor records for areas that hold sensitive information |
| 03.13.01 Boundary protection | Firewall or network diagrams and the rule set at the edge of the environment |
| 03.14.01 Flaw remediation | Patch reports showing how quickly critical updates are applied |
| 03.14.02 Malicious code protection | Endpoint protection console export showing coverage and update status |
A policy on its own shows intent. For most of these controls the supplier also needs a record showing the control operating, such as an export, log or ticket.
Preparing a supplier for Level 2
Level 2 moves from 13 controls to 98 and from self-assessment to an independent assessor. Readiness work usually runs in this order:
- Define the boundary. Identify every system, person and service provider that handles, stores, transmits or protects the specified information. A smaller, well-documented boundary makes every later step cheaper.
- Assess each control against evidence. Record what the evidence demonstrates and what it leaves unresolved, family by family.
- Plan remediation. Rank the gaps by effort and by how likely they are to block certification.
- Reassess before the certification body arrives. Rerun the assessment on updated evidence and show the client what changed.
If your firm also plans to act as an assessor, check the certification body’s impartiality rules before taking on readiness work for the same supplier.
How Control+s supports CPCSC readiness
Control+s includes CPCSC Level 1 and the full ITSP.10.171 catalogue, so you can run a Level 1 check now and a Level 2 readiness assessment on the same evidence.
- Scoping questions capture the defence contract or bid behind the requirement, where protected information lives, and the systems in scope.
- Evidence mapping. Upload the supplier’s exports, policies and screenshots once. Each file is linked to the controls it supports, and each control is assessed against its own requirement.
- Scores with reasons. Every control gets a maturity score from 0 to 5 with a rationale that cites the evidence, plus the gaps that remain. You review the reasoning and override any score; your override stays in place when new evidence arrives.
- Client-ready outputs. Share a CPCSC Level 1 snapshot with the supplier through a password-protected, expiring link, or generate a report with the gap register and remediation guidance.
- Cross-framework reuse. Suppliers that also sell into the United States can add CMMC or NIST SP 800-171 to the same assessment and reuse the evidence.
Control+s does not certify suppliers. It prepares the assessment so the final judgment, and the deliverable, stay yours.
Frequently asked questions
How many controls are in CPCSC Level 1?
Level 1 has 13 controls taken from ITSP.10.171, covering account management, access enforcement, external systems, publicly accessible content, identification and authentication, multifactor authentication, media sanitization, physical access, boundary protection, flaw remediation and malicious code protection. Suppliers complete a self-assessment every year.
When does CPCSC Level 2 start?
The Government of Canada says Level 2 will be added to select defence contracts in spring 2027. Level 2 requires an external assessment every three years by a certification body accredited through the Standards Council of Canada, plus an annual affirmation, against 98 controls.
Is CPCSC the same as CMMC?
They are closely related but separate programs. CMMC is the United States Department of Defense program built on NIST SP 800-171. CPCSC is Canada's program for defence suppliers, built on ITSP.10.171, which the Canadian Centre for Cyber Security describes as a Canadian version of NIST SP 800-171 with no substantial technical changes. Evidence often overlaps, but each program has its own levels, assessors and contract rules.
Can a consultant certify a supplier for CPCSC?
No. Level 1 is a self-assessment by the supplier, Level 2 certification comes from an accredited certification body, and Level 3 assessments are conducted by National Defence. Consultants help suppliers get ready by scoping the environment, assessing each control against evidence and planning remediation.
Does Control+s certify suppliers?
No. Control+s is an assessment tool for consultants and internal teams. It organizes evidence, scores each control with a cited rationale for the assessor to review, and produces readiness deliverables. It does not issue certifications.
Sources
- Government of Canada: Canadian Program for Cyber Security Certification, program overview
- Government of Canada: Meeting Level 1 certification requirements
- PSPC backgrounder: Canadian Program for Cyber Security Certification Level 1 (April 2026)
- Canadian Centre for Cyber Security: ITSP.10.171, Protecting specified information in non-Government of Canada systems and organizations
- Standards Council of Canada: CPCSC accreditation scheme
- NIST SP 800-171 Rev. 3