CPCSC readiness assessments for consultants

Updated Lire en français

The Canadian Program for Cyber Security Certification (CPCSC) sets cyber security requirements for suppliers on Canadian defence contracts that involve sensitive information. It has three levels. Level 1 is an annual self-assessment against 13 controls and launched in April 2026. Level 2 adds an external assessment by an accredited certification body against 98 controls and is expected in select contracts from spring 2027. Consultants help suppliers scope the environment, test each control against evidence and close gaps before a contract or assessor asks.

The three levels at a glance

Level Who assesses Controls Status as of September 2026
Level 1 The supplier, as an annual self-assessment 13 Launched April 2026; required in select defence contracts
Level 2 A certification body accredited through the Standards Council of Canada, every three years, plus an annual affirmation 98 To be added to select contracts in spring 2027
Level 3 National Defence, plus an annual affirmation 130+ In development; no date announced

The controls come from ITSP.10.171, published by the Canadian Centre for Cyber Security. The Cyber Centre describes it as a Canadian version of NIST SP 800-171 with no substantial technical changes, organized into the same 17 families. Level 3 draws on the enhanced requirements adapted from NIST SP 800-172.

A contract states which level applies. Level 1 is confirmed at contract award rather than at bidding, so suppliers who wait for a specific contract leave little time to fix gaps.

The 13 Level 1 controls and the evidence that supports them

Each Level 1 control keeps its ITSP.10.171 identifier. The evidence column is our guidance on what an assessor usually needs to see. It is a starting point for the evidence request, not an official checklist.

Control What to request from the supplier
03.01.01 Account management An export of user and service accounts with owners, plus records of recent joiner, mover and leaver changes
03.01.02 Access enforcement Role or group definitions and a sample showing access matches each person’s job
03.01.20 Use of external systems The rule for personal devices and outside systems, and how it is enforced
03.01.22 Publicly accessible content Who may publish to public sites and how content is reviewed before release
03.05.01 User identification and authentication Identity provider settings showing unique accounts and no shared logins
03.05.02 Device identification and authentication Device inventory and the control that stops unknown devices from connecting
03.05.03 Multifactor authentication MFA policy and an export showing which accounts are enrolled and which are exempt
03.08.03 Media sanitization Disposal procedure and certificates or logs for wiped or destroyed media
03.10.01 Physical access authorizations The list of people with physical access and how it is approved and reviewed
03.10.07 Physical access control Badge, key or visitor records for areas that hold sensitive information
03.13.01 Boundary protection Firewall or network diagrams and the rule set at the edge of the environment
03.14.01 Flaw remediation Patch reports showing how quickly critical updates are applied
03.14.02 Malicious code protection Endpoint protection console export showing coverage and update status

A policy on its own shows intent. For most of these controls the supplier also needs a record showing the control operating, such as an export, log or ticket.

Preparing a supplier for Level 2

Level 2 moves from 13 controls to 98 and from self-assessment to an independent assessor. Readiness work usually runs in this order:

  1. Define the boundary. Identify every system, person and service provider that handles, stores, transmits or protects the specified information. A smaller, well-documented boundary makes every later step cheaper.
  2. Assess each control against evidence. Record what the evidence demonstrates and what it leaves unresolved, family by family.
  3. Plan remediation. Rank the gaps by effort and by how likely they are to block certification.
  4. Reassess before the certification body arrives. Rerun the assessment on updated evidence and show the client what changed.

If your firm also plans to act as an assessor, check the certification body’s impartiality rules before taking on readiness work for the same supplier.

How Control+s supports CPCSC readiness

Control+s includes CPCSC Level 1 and the full ITSP.10.171 catalogue, so you can run a Level 1 check now and a Level 2 readiness assessment on the same evidence.

  • Scoping questions capture the defence contract or bid behind the requirement, where protected information lives, and the systems in scope.
  • Evidence mapping. Upload the supplier’s exports, policies and screenshots once. Each file is linked to the controls it supports, and each control is assessed against its own requirement.
  • Scores with reasons. Every control gets a maturity score from 0 to 5 with a rationale that cites the evidence, plus the gaps that remain. You review the reasoning and override any score; your override stays in place when new evidence arrives.
  • Client-ready outputs. Share a CPCSC Level 1 snapshot with the supplier through a password-protected, expiring link, or generate a report with the gap register and remediation guidance.
  • Cross-framework reuse. Suppliers that also sell into the United States can add CMMC or NIST SP 800-171 to the same assessment and reuse the evidence.

Control+s does not certify suppliers. It prepares the assessment so the final judgment, and the deliverable, stay yours.

Frequently asked questions

How many controls are in CPCSC Level 1?

Level 1 has 13 controls taken from ITSP.10.171, covering account management, access enforcement, external systems, publicly accessible content, identification and authentication, multifactor authentication, media sanitization, physical access, boundary protection, flaw remediation and malicious code protection. Suppliers complete a self-assessment every year.

When does CPCSC Level 2 start?

The Government of Canada says Level 2 will be added to select defence contracts in spring 2027. Level 2 requires an external assessment every three years by a certification body accredited through the Standards Council of Canada, plus an annual affirmation, against 98 controls.

Is CPCSC the same as CMMC?

They are closely related but separate programs. CMMC is the United States Department of Defense program built on NIST SP 800-171. CPCSC is Canada's program for defence suppliers, built on ITSP.10.171, which the Canadian Centre for Cyber Security describes as a Canadian version of NIST SP 800-171 with no substantial technical changes. Evidence often overlaps, but each program has its own levels, assessors and contract rules.

Can a consultant certify a supplier for CPCSC?

No. Level 1 is a self-assessment by the supplier, Level 2 certification comes from an accredited certification body, and Level 3 assessments are conducted by National Defence. Consultants help suppliers get ready by scoping the environment, assessing each control against evidence and planning remediation.

Does Control+s certify suppliers?

No. Control+s is an assessment tool for consultants and internal teams. It organizes evidence, scores each control with a cited rationale for the assessor to review, and produces readiness deliverables. It does not issue certifications.

Sources

  1. Government of Canada: Canadian Program for Cyber Security Certification, program overview
  2. Government of Canada: Meeting Level 1 certification requirements
  3. PSPC backgrounder: Canadian Program for Cyber Security Certification Level 1 (April 2026)
  4. Canadian Centre for Cyber Security: ITSP.10.171, Protecting specified information in non-Government of Canada systems and organizations
  5. Standards Council of Canada: CPCSC accreditation scheme
  6. NIST SP 800-171 Rev. 3

Bring your next assessment to Control+s.

Start free with two frameworks and five evidence files. Use your own material to inspect the mapping, reasoning, and results, and see how Control+s fits your engagements.

Help shape the product around real consulting work. We welcome teams who want to build their assessment workflow with us.

Running a larger program? .