Home/ Blog/ CPCSC explained
Blog · Frameworks

CPCSC explained: what Canadian defence suppliers need to know

Level 1 of the Canadian Program for Cyber Security Certification became available April 1, 2026, and select defence contracts start requiring it this summer. Here is what Levels 1, 2, and 3 actually require, who is in scope, and how to start preparing.

Frameworks · Published Jul 15, 2026 · 8 min read

If you sell to the Department of National Defence, or you sit anywhere in a defence prime’s supply chain, a new acronym now matters to your business: CPCSC, the Canadian Program for Cyber Security Certification. It is Canada’s answer to a problem the United States addressed years earlier with CMMC — how to verify, rather than simply require, that suppliers handling sensitive government information actually have adequate cybersecurity controls in place. Level 1 became available to suppliers on April 1, 2026, and Public Services and Procurement Canada has said Level 1 requirements will start appearing in select defence contracts this summer.

Who is actually in scope

CPCSC applies to organizations in the Canadian defence industrial base — the requirement flows down contractually from prime contractors to subcontractors, component suppliers, and service providers anywhere in the chain. It is not limited to whoever signs directly with DND. The program protects a specific category the government calls “designated information” — certain types of sensitive information that is not formally classified but still requires protection under the program.

The practical trigger is contractual, not aspirational: if you are bidding on, or already working under, a defence contract that specifies a CPCSC Level 1 requirement, you will need to complete the self-assessment and confirm the results — including the assessment’s expiration date — in your organizational supplier profile in CanadaBuys. Self-assessment is required at contract award, not at the bidding stage, which gives suppliers a window to prepare once they know a contract requires it.

Level 1, 2, and 3: what actually differs

Level 1

CPCSC Level 1 is a self-assessment against 13 security requirements and controls, grouped into 6 general cyber hygiene practices, drawn from the Canadian Centre for Cyber Security’s publication ITSP.10.171 (Protecting specified information in non-Government of Canada systems and organizations). You assess your own implementation status against those 13 controls annually, using the government’s online self-assessment tool, and confirm the result in CanadaBuys. No external assessor reviews your evidence at this level.

Level 2 and Level 3

Level 2 is a different exercise entirely: a self-assessment against 98 controls, verified by a third-party assessment organization (C3PAO) accredited by the Standards Council of Canada, every three years with annual confirmation in between. It is planned to start appearing in select defence contracts in spring 2027, and applies to contracts involving controlled Defence information or more complex sensitive work. Level 3, the highest tier, expands to 200 controls and moves to direct assessment by the Department of National Defence itself, reserved for the highest-risk scenarios: weapons systems, critical infrastructure, and information shared with Five Eyes partners. Both higher levels are understood to align to the more advanced NIST SP 800-171 and NIST SP 800-172 control baselines — the same standards underpinning CMMC’s higher tiers in the US.

The rollout so far

Public Services and Procurement Canada made Level 1 available to suppliers on April 1, 2026. Level 1 requirements are being introduced into select defence contracts starting summer 2026 — not retroactively into every existing contract at once, but progressively as new solicitations and contract actions specify it. If you have not seen a CPCSC clause in your own contracts yet, that does not mean you will not; it means your specific contract has not reached that point in the rollout.

The CMMC overlap Canadian-American suppliers should not ignore

If your organization supplies both DND and the US Department of Defense, you are almost certainly looking at both CPCSC and CMMC obligations, and there is no automatic equivalence between them today — a CMMC certification does not currently substitute for CPCSC certification, or vice versa. Canada has signalled it intends to work toward mutual recognition for organizations with aligned scopes, but until that materializes, treat the two as separate requirements that happen to share a lot of underlying control structure, since both trace back to NIST SP 800-171 at their higher tiers.

Where to start

Start with the government’s own online self-assessment tool to walk through the 13 Level 1 controls and see where you actually stand — it is free and designed for exactly this purpose. In parallel, map which systems, personnel, and data stores handle designated information; certification work done against the wrong boundary is work you will redo. If your contracts point toward Level 2 or 3 eventually, a solid Level 1 foundation first avoids backfilling basic hygiene gaps mid-assessment later, which is the least efficient point to discover them.

Sources: Public Services and Procurement Canada (canada.ca) and the Canadian Centre for Cyber Security. Level 2 and Level 3 guidance is still being rolled out — confirm current requirements for your specific contract against official PSPC/CCCS guidance before making certification commitments.

Sentrix maintains a native CPCSC framework mapped to Level 1 controls today, with Level 2/3 mapping and a built-in CMMC crosswalk for dual-market suppliers. See the full CPCSC framework page for how the platform handles scope determination, evidence collection, and assessment prep.

See how Sentrix maps to CPCSC Level 1 and Level 2.

We walk through scope determination and control mapping live in the demo.