Experiencing a security incident? Call us 24/7: +1 (855) 736-8749
Home/ CPCSC Certification
Defence supply chain · Level 1 available now

CPCSC certification support (Canadian Program for Cyber Security Certification)

Level 1 requirements are being introduced into select defence contracts starting summer 2026. Sentrix structures your process - from gap analysis to evidence - so your self-assessment is solid and your organization stays eligible for federal opportunities.

PSPC · National Defence · accredited by the Standards Council of Canada (SCC)
readiness-scorecard · sample.pdf
CONFIDENTIAL REPORT

Level 1 self-assessment - sample

ITSP.10.171
Access control75%
On track3 / 4
ID & authentication67%
1 gap2 / 3
Media & physical100%
On track3 / 3
Systems & comms67%
1 gap2 / 3
10 of 13 controls in place View full self-assessment →
13 controls, 3 levels Level 1 available since April 2026
Why this matters

CPCSC eligibility isn’t a one-time checkbox.

Requirements are rolling out in phases, levels compound as contracts get more sensitive, and preparing under contract pressure costs more than preparing early.

Contracts are the leverage

Level 1 is being introduced into select defence contracts starting summer 2026 - staying eligible means demonstrating compliance, not promising it.

Levels compound

13 controls at Level 1 becomes 98 at Level 2 and 200 at Level 3, based on the sensitivity of the contract - the requirements only grow from here.

CMMC doesn’t carry over automatically

CPCSC and CMMC rest on the same technical controls, but they are not officially equivalent - recognition is assessed case by case.

Delaying costs more

Preparing under pressure, on tight deadlines, with a contract at stake, is a worse position than preparing before requirements appear in tenders.

What sets this apart

We implement the missing technical controls - not just document them.

A gap report alone doesn’t get you compliant. We work directly with your IT teams to put access management, boundary protection, patching, and malware controls in place, then support you through the self-assessment or the accredited body’s assessment itself.

  • Access control & identification - account management, MFA, access enforcement.
  • System & communications protection - boundary protection, patching, malware defence.
  • Media & physical protection - sanitization, physical access control.
  • Support through your self-assessment or third-party assessment.
sample gap findings
High
Multi-factor authentication (03.05.03) is not enforced for privileged and remote access accounts.
Implement MFA across privileged and remote access before the self-assessment is filed.
High
Boundary protection (03.13.01) rules allow broader network access than the scope requires.
Tighten boundary protection rules and document segmentation for the assessment record.
Medium
Flaw remediation (03.14.01) exists on paper but patch cycles are inconsistent across systems.
Formalize a patch management cadence with evidence of consistent application.
Low
Media sanitization (03.08.03) procedures are undocumented for decommissioned devices.
Document and apply sanitization procedures before devices leave the sensitive-data boundary.

What is CPCSC?

The Canadian Program for Cyber Security Certification (CPCSC, or PCCC in French) is led by Public Services and Procurement Canada (PSPC) and National Defence. It sets the cybersecurity standards defence contractors must meet to protect sensitive unclassified information and ensure interoperability with Canada’s allies, notably Five Eyes partners.

The program is built on Canada’s industrial cybersecurity standard (ITSP.10.171), developed by the Canadian Centre for Cyber Security. Technically, this standard is closely aligned with the US NIST SP 800-171 and 800-172 publications, which also underpin the American CMMC program. This alignment is meant to limit overlap and preserve Canadian suppliers’ access to international defence markets.

In practical terms: if your organization handles sensitive government information under defence contracts, or wants to enter the Canadian defence supply chain, CPCSC will become a condition of access to those contracts.

13 controls

Security controls assessed at Level 1.

Annual self-assessment

Mandatory for Level 1.

Available since April 2026

For suppliers; introduced into select contracts starting summer 2026.

Based on ITSP.10.171

Aligned with NIST SP 800-171 / 800-172.

Led by PSPC

And National Defence, with accreditation by the Standards Council of Canada (SCC).

The three certification levels

CPCSC’s mandatory requirements are organized into three progressive levels, based on the sensitivity of the information handled and the contract’s risk level.

Level 1 · Self-assessment

13 controls

Annual self-assessment by the supplier, using an online tool provided by the Government of Canada. Available to suppliers since April 1, 2026; introduced into select defence contracts starting summer 2026. Applies to lower-risk situations: administrative or operational support, basic IT services without sensitive data, limited network integration, etc.

Level 2 · External assessment

98 controls

Assessment conducted by an accredited third-party certification body (C3PAO) accredited by the Standards Council of Canada, every three years, with annual confirmation. Planned to be introduced into select defence contracts starting spring 2027. Applies to contracts involving controlled Defence information or more complex sensitive work.

Level 3 · Government assessment

200 controls

Assessment conducted directly by National Defence, every three years, with annual confirmation. Reserved for the highest-risk scenarios: weapons systems, critical infrastructure, information shared with Five Eyes partners.

Levels 2 and 3 are still being developed. Timelines and details will be clarified by PSPC and the SCC as the rollout continues.

What Level 1 covers: 13 controls, 6 best practices

Level 1’s 13 controls (drawn from the ITSP.10.171 standard) group into fundamental cyber-hygiene practices. Our support helps you assess each one and document its implementation.

Access control

Managing who can access systems

  • Account management (03.01.01)
  • Access enforcement (03.01.02)
  • Use of external systems (03.01.20)
  • Publicly accessible content (03.01.22)

Identification and authentication

Verifying users and devices

  • User identification and authentication (03.05.01)
  • Device identification and authentication (03.05.02)
  • Multi-factor authentication (03.05.03)

Media and physical protection

Protecting data and equipment

  • Media sanitization (03.08.03)
  • Physical access authorizations (03.10.01)
  • Physical access control (03.10.07)

System and communications protection

Defending systems against cyber threats

  • Boundary protection (03.13.01)
  • Flaw remediation (03.14.01)
  • Malicious code protection (03.14.02)

Control codes follow the Canadian ITSP.10.171 standard. Official titles may evolve between versions of the program.

Who this support is for

CPCSC concerns organizations that are part of the Canadian defence supply chain, or plan to enter it.

  • Defence sector contractors and subcontractors who must demonstrate compliance to remain eligible for federal contracts.
  • Engineering, manufacturing, and aerospace companies supporting defence programs.
  • IT and OT service providers whose systems interact with defence-related data or environments.
  • Technology suppliers and publishers handling sensitive unclassified government information.
  • Suppliers already engaged with US CMMC who want to align both frameworks and avoid duplicating effort.
  • Proactive organizations not yet in scope who want to prepare before requirements appear in tenders.

What you get

Scoping

Identifying the systems, environments, and processes that handle sensitive information, and spotting segmentation or isolation opportunities to limit your exposure and the assessment’s scope.

Gap analysis

An assessment of your current posture against ITSP.10.171 requirements, prioritized by risk and effort, with the target level (1, 2, or 3) clearly established.

Documentation and evidence

Writing or adapting the expected policies, procedures, and supporting evidence, at the level of detail required to support your self-assessment or a third-party assessment - not generic templates.

Implementation of missing controls

Working with your IT teams to put in place required technical controls: access management, multi-factor authentication, network boundary protection, flaw remediation, malware protection, and more.

Action plan (POA&M)

A prioritized corrective action plan to close remaining gaps and build a realistic roadmap toward assessment readiness.

Assessment preparation

Support completing the Level 1 self-assessment in the government’s tool, or preparing for an assessment by an accredited body (Level 2) or by National Defence (Level 3).

CPCSC and CMMC: two frameworks, one shared goal

CPCSC and the American CMMC program both aim to strengthen defence supply chain cybersecurity. They are not officially equivalent, but they rest on the same technical controls: the 172 controls of the NIST SP 800-171 and 800-172 publications. On a case-by-case basis, Canada may accept a valid CMMC certification if its scope matches CPCSC requirements, which can avoid maintaining two separate certifications. If you supply both markets, we help you align the two frameworks and optimize your effort.

Aspect CPCSC (Canada) CMMC (United States)
JurisdictionCanadaUnited States
SectorCanadian defence supply chainDepartment of Defense (DoD) contractors
Reference technical standardITSP.10.171 (based on NIST SP 800-171 / 800-172)NIST SP 800-171
Responsible authorityPSPC and National Defence; accreditation by the SCCUS Department of Defense
Levels3 levels (self-assessment, accredited third party, government)3 levels
Mutual recognitionCMMC recognition possible case by caseNo external recognition

Canada’s acceptance of a CMMC certification is assessed case by case; Canada reserves the right to verify compliance with specific controls.

Why prepare now

As CPCSC requirements appear in procurement processes, prepared organizations will be best positioned to seize business opportunities. Delaying preparation means risking having to comply under pressure, on tight deadlines, with the contract at stake.

Complying with CPCSC means:

  • Access public and defence-related contracts with the Government of Canada.
  • Protect the sensitive information you handle and strengthen your partners’ trust.
  • Structure your cybersecurity around an internationally recognized framework, aligned with NIST and CMMC.
  • Reduce your risk and better control remediation costs by acting early rather than urgently.

Why trust Sentrix with your CPCSC journey

Cybersecurity and compliance expertise

A specialized team mastering the frameworks at the core of CPCSC: ITSP.10.171, NIST SP 800-171 / 800-172, and related frameworks (ISO 27001, etc.).

End-to-end support

From scoping to assessment prep, including control implementation and documentation management - we stay by your side at every step.

Scalable, pragmatic approach

A compliance path adapted to your current maturity, the nature of your contracts, and your technical and budget constraints.

Current with the program’s evolution

CPCSC is rolling out in phases and its requirements are evolving. We actively track guidance from PSPC, the SCC, and the Canadian Centre for Cyber Security so your process reflects the current state of expectations.

We prepare - we do not certify. Level 2 assessments are conducted by third-party bodies accredited by the Standards Council of Canada; Level 3 assessments are conducted by National Defence.

Built on shared technical ground

CPCSC sits alongside standards you may already know.

ITSP.10.171 is technically aligned with NIST SP 800-171 and 800-172, the same publications underpinning the American CMMC program.

ITSP.10.171 NIST SP 800-171 NIST SP 800-172 CMMC
Our four-step approach

A progressive, structured, and rigorously documented path.

01

Identify

Which systems handle sensitive information, what boundaries are involved, and whether certain environments should be segmented or isolated to limit exposure.

02

Analyze

Where you stand against ITSP.10.171 requirements, what gaps remain, and which certification level you’re targeting.

03

Remediate

Prioritized corrective actions to strengthen the protection of your access, logs, and sensitive data, implemented with your teams.

04

Assess

Validating the evidence and supporting you through the annual self-assessment, an accredited body’s assessment, or the government assessment.

CPCSC, by the numbers.

3
Certification levels
13
Level 1 controls assessed
98
Level 2 controls assessed
200
Level 3 controls assessed

Frequently asked questions

Is CPCSC mandatory?
CPCSC’s cybersecurity requirements are becoming mandatory contractual conditions for certain defence contracts. Level 1 (annual self-assessment) is being introduced into select contracts starting summer 2026, with higher levels to follow. If you want to stay eligible for targeted contracts, compliance is not optional.
Which level applies to me?
It depends on the sensitivity of the information handled and the risk level of the targeted contracts. Lower-risk situations fall under Level 1 (self-assessment). Contracts involving controlled Defence information fall under Level 2, and the highest-risk scenarios (weapons systems, critical infrastructure) fall under Level 3. We help you determine the right level as part of scoping.
How long does it take to prepare?
Duration varies by target level and your starting maturity. A compliance project generally takes a few months to a year, including diagnosis, remediation, and assessment prep. Organizations already aligned with NIST SP 800-171 / ITSP.10.171 can move faster.
What is the difference between CPCSC and NIST SP 800-171?
NIST SP 800-171 is a US technical standard. CPCSC is a Canadian certification program built on the Canadian ITSP.10.171 standard, itself technically aligned with NIST SP 800-171 and 800-172. CPCSC adds an assessment, accreditation, and government oversight mechanism specific to Canada.
I already have CMMC certification. Do I need to go through CPCSC too?
Not necessarily in full. On a case-by-case basis, Canada may accept a valid CMMC certification if its scope matches CPCSC requirements. We help you align the two frameworks to avoid duplicating your effort.
Are foreign companies affected?
Yes, as soon as they wish to participate in Canadian defence supply chain contracts covered by CPCSC requirements.
Who conducts the assessment?
Level 1 is a self-assessment conducted by the supplier. Level 2 is conducted by an accredited third-party certification body (C3PAO) accredited by the Standards Council of Canada. Level 3 is conducted directly by National Defence.

Let’s talk about your CPCSC journey.

Whether you’re already facing a contractual requirement or just want to check your readiness - a first conversation costs nothing and helps determine the target level and how we can support you.