The Canadian Program for Cyber Security Certification (CPCSC) is now a condition of award on Government of Canada defence contracts. Level 1 went live in April 2026. We get you certified-ready before the contract demands it.
Talk to a Virtual CISOCPCSC is Canada's cybersecurity certification for suppliers that bid on or work on Department of National Defence (DND) contracts. No certification, no contract.
Federal contract information — even below classified — carries strict handling rules. Certification keeps you eligible and out of breach territory.
Built on NIST SP 800-171 Rev 3. The work travels — it strengthens your security posture for every market, not just defence.
Your certification raises the floor for the whole Canadian defence supply chain — and hardens your own business against disruption.
Direct suppliers to the Canadian Armed Forces and federal defence agencies.
Components, logistics, or IT services anywhere inside a defence project's supply chain.
Anyone managing networks, data, or software tied to defence operations.
The level you need is set by the contract and the sensitivity of the data. Each higher level adds controls — and adds who checks your work.
You attest to your own posture each year. Live since April 2026 and already a condition of award on many contracts.
An accredited certification body verifies your program. Entering contracts in summer 2026 — and the assessor queue forms fast.
The Department of National Defence assesses you directly. Reserved for the most sensitive work.
Self-assessment is a condition of award on select DND contracts now.
Third-party assessments start entering contracts. Accredited assessors are limited.
DND-led assessments for the most sensitive programs.
Certification isn't one-and-done. The program has to keep holding up.
We map which controls apply to your contracts and show exactly where you stand today.
Gaps closed in priority order, with owners, dates, and budget-aware sequencing.
System Security Plan, Plan of Action & Milestones, and the proof artifacts assessors ask for.
You walk in ready — whether it's self-assessment, an accredited body, or DND.
Most suppliers have the controls. What they don't have is the documented proof an assessor will accept. That's what we build.
What you protect, how, and who is responsible — written the way assessors read it.
What isn't done yet, with realistic dates and named owners.
Logs, test results, training records, policies. The receipts that make a "yes" defensible.
Yes. Level 1 self-assessment went live on April 14, 2026, and is already a condition of award on select defence contracts. Level 2 third-party assessments begin entering contracts in summer 2026.
Level 1 is an annual self-assessment (13 controls). Level 2 adds an external assessment by an accredited certification body plus an annual affirmation (98 controls). Level 3 is an assessment led by the Department of National Defence plus an annual affirmation (200 controls). The level you need is set by the contract.
ITSP.10.171 — the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171 Rev 3. The Government has been explicit that there are no substantial technical differences between the two standards.
CMMC is built on NIST 800-171 Rev 2 (110 controls); CPCSC uses Rev 3. If you already hold CMMC, much of the work carries over — but it is not automatic, and the documentation differs.
For most defence contracts that involve sensitive data, yes — certification or recognized equivalency is a condition of award. Getting ready early is the difference between bidding and sitting out.
Get scoped and assessment-ready before the contract — and before the assessor queue.
Book a Call