Home / Industries We Serve
Industries · Defence Suppliers

CPCSC certification, without the scramble

The Canadian Program for Cyber Security Certification (CPCSC) is now a condition of award on Government of Canada defence contracts. Level 1 went live in April 2026. We get you certified-ready before the contract demands it.

Talk to a Virtual CISO
The Basics

What is CPCSC? And why it matters.

CPCSC is Canada's cybersecurity certification for suppliers that bid on or work on Department of National Defence (DND) contracts. No certification, no contract.

Protect Government of Canada data

Federal contract information — even below classified — carries strict handling rules. Certification keeps you eligible and out of breach territory.

Aligned to a global standard

Built on NIST SP 800-171 Rev 3. The work travels — it strengthens your security posture for every market, not just defence.

A stronger supply chain

Your certification raises the floor for the whole Canadian defence supply chain — and hardens your own business against disruption.

Who Must Comply

If you touch defence work, this is you.

Prime defence contractors

Direct suppliers to the Canadian Armed Forces and federal defence agencies.

Subcontractors & service providers

Components, logistics, or IT services anywhere inside a defence project's supply chain.

Technology & cyber firms

Anyone managing networks, data, or software tied to defence operations.

If you bid on — or already hold — Public Services and Procurement Canada (PSPC) defence contracts that involve sensitive data, CPCSC certification (or recognized equivalency) is mandatory. The required level depends on the contract.
The Three Levels

One program. Three levels of proof.

The level you need is set by the contract and the sensitivity of the data. Each higher level adds controls — and adds who checks your work.

Live now
Level 1

Self-assessment

13controls · annual self-assessment

You attest to your own posture each year. Live since April 2026 and already a condition of award on many contracts.

Level 2

Third-party certified

98controls · accredited assessor + annual affirmation

An accredited certification body verifies your program. Entering contracts in summer 2026 — and the assessor queue forms fast.

Level 3

National Defence assessed

200controls · DND-led assessment + annual affirmation

The Department of National Defence assesses you directly. Reserved for the most sensitive work.

CPCSC is built on ITSP.10.171 — the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171 Rev 3. The Government has stated there are no substantial technical differences between the two.
The Window

It's already happening. Move before the queue.

Live · Apr 2026

Level 1 at award

Self-assessment is a condition of award on select DND contracts now.

Summer 2026

Level 2 begins

Third-party assessments start entering contracts. Accredited assessors are limited.

Phasing in

Level 3

DND-led assessments for the most sensitive programs.

Every year

Re-affirm

Certification isn't one-and-done. The program has to keep holding up.

How We Help

From "where do we start?" to assessment-ready.

1

Scope & gap assessment

We map which controls apply to your contracts and show exactly where you stand today.

2

Remediation roadmap

Gaps closed in priority order, with owners, dates, and budget-aware sequencing.

3

Evidence & documentation

System Security Plan, Plan of Action & Milestones, and the proof artifacts assessors ask for.

4

Assessment readiness

You walk in ready — whether it's self-assessment, an accredited body, or DND.

The Evidence Binder

You don't fail on the tech. You fail on the paperwork.

Most suppliers have the controls. What they don't have is the documented proof an assessor will accept. That's what we build.

System Security Plan

What you protect, how, and who is responsible — written the way assessors read it.

Plan of Action & Milestones

What isn't done yet, with realistic dates and named owners.

Proof artifacts

Logs, test results, training records, policies. The receipts that make a "yes" defensible.

FAQ

CPCSC questions, answered straight.

Is CPCSC actually in effect yet?

Yes. Level 1 self-assessment went live on April 14, 2026, and is already a condition of award on select defence contracts. Level 2 third-party assessments begin entering contracts in summer 2026.

What are the three certification levels?

Level 1 is an annual self-assessment (13 controls). Level 2 adds an external assessment by an accredited certification body plus an annual affirmation (98 controls). Level 3 is an assessment led by the Department of National Defence plus an annual affirmation (200 controls). The level you need is set by the contract.

What standard is CPCSC based on?

ITSP.10.171 — the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171 Rev 3. The Government has been explicit that there are no substantial technical differences between the two standards.

How is it different from the U.S. CMMC?

CMMC is built on NIST 800-171 Rev 2 (110 controls); CPCSC uses Rev 3. If you already hold CMMC, much of the work carries over — but it is not automatic, and the documentation differs.

Do we have to be certified just to bid?

For most defence contracts that involve sensitive data, yes — certification or recognized equivalency is a condition of award. Getting ready early is the difference between bidding and sitting out.

The window is open now.

Get scoped and assessment-ready before the contract — and before the assessor queue.

Book a Call