Framework · CPCSC

CPCSC certification: required to stay in the Canadian defence supply chain.

The Canadian Programme de cybersécurité de la chaîne d’approvisionnement is moving toward mandatory enforcement for defence contractors and critical infrastructure suppliers. Organizations that are not preparing now will face disqualification from federal contracts. Sentrix is the only GRC platform with native CPCSC support, pre-built control sets, and a crosswalk to CMMC for dual-market suppliers.

Native
CPCSC is a first-class framework in Sentrix—not a custom mapping on top of a US-built platform
3
CPCSC certification levels—Level 1 self-assessment, Level 2 third-party, Level 3 government assessment
Canadian
Data residency guaranteed—all compliance evidence stored in Canada as required for defence data
CMMC
Crosswalk—Canadian-American defence suppliers pursue both certifications from one evidence program
What CPCSC requires

Level 1 self-assessment. Level 2 third-party. Level 3 government. One program.

CPCSC applies to organizations in the Canadian defence supply chain. Level 1 (13 controls) is a self-assessment available since April 2026, with select contracts requiring it starting summer 2026. Level 2 (98 controls) and Level 3 (200 controls) add third-party and government-led assessment for more sensitive contracts, aligned to NIST SP 800-171/800-172 via Canada’s own ITSP.10.171 standard—mirroring the approach taken by CMMC in the United States. Organizations supplying both DND and DoD may need both certifications—Sentrix helps you align the two.

  • Level 1: annual self-assessment—access control, authentication, physical protection, system protection (13 controls)
  • Level 2: third-party assessment by a CCC-accredited C3PAO, every 3 years (98 controls)
  • Level 3: direct National Defence assessment for the highest-risk contracts (200 controls)
  • Scope determination: which systems handle sensitive unclassified information

CPCSC Level 2 · Control domain coverage

CONTINUOUS EVIDENCE
Access control✓ PASS
Audit & accountability✓ PASS
Configuration management▲ 2 gaps
Identification & authentication✓ PASS
Incident response✓ PASS
System & communications protection✓ PASS
Full CPCSC capabilities

The only GRC platform built natively for Canadian defence supply chain compliance.

Native CPCSC framework

CPCSC Level 1 and Level 2 control sets pre-built and maintained by our compliance team. Framework updates reflected automatically—no manual re-mapping when CCCS guidance evolves.

Scope determination support

Identify which systems, personnel, and data stores fall within CPCSC scope. Protected and Classified information flow mapping with boundary documentation required for assessment.

CMMC dual-certification

Canadian suppliers with US DoD contracts need both CPCSC and CMMC. Sentrix maps the substantial overlap between the two frameworks and manages both from one evidence program, eliminating duplicate work.

Canadian data residency

All compliance evidence stored in Canadian data centres. Required for defence contractors handling Protected B and higher classification information under Treasury Board policies.

Assessment-ready evidence

Whether you are self-attesting at Level 1 or preparing for a Level 2 third-party assessment, Sentrix assembles your evidence package in the format assessors expect.

CCCS baseline crosswalk

Sentrix maps CPCSC controls to the Canadian Centre for Cyber Security’s baseline security controls, giving you a single view of your CCCS and CPCSC posture simultaneously.

See your CPCSC readiness against your real infrastructure.

We map your controls to CPCSC Level 1 and Level 2 live in the demo.