CPCSC certification: required to stay in the Canadian defence supply chain.
The Canadian Programme de cybersécurité de la chaîne d’approvisionnement is moving toward mandatory enforcement for defence contractors and critical infrastructure suppliers. Organizations that are not preparing now will face disqualification from federal contracts. Sentrix is the only GRC platform with native CPCSC support, pre-built control sets, and a crosswalk to CMMC for dual-market suppliers.
Level 1 self-assessment. Level 2 third-party. Level 3 government. One program.
CPCSC applies to organizations in the Canadian defence supply chain. Level 1 (13 controls) is a self-assessment available since April 2026, with select contracts requiring it starting summer 2026. Level 2 (98 controls) and Level 3 (200 controls) add third-party and government-led assessment for more sensitive contracts, aligned to NIST SP 800-171/800-172 via Canada’s own ITSP.10.171 standard—mirroring the approach taken by CMMC in the United States. Organizations supplying both DND and DoD may need both certifications—Sentrix helps you align the two.
- Level 1: annual self-assessment—access control, authentication, physical protection, system protection (13 controls)
- Level 2: third-party assessment by a CCC-accredited C3PAO, every 3 years (98 controls)
- Level 3: direct National Defence assessment for the highest-risk contracts (200 controls)
- Scope determination: which systems handle sensitive unclassified information
CPCSC Level 2 · Control domain coverage
CONTINUOUS EVIDENCEThe only GRC platform built natively for Canadian defence supply chain compliance.
Native CPCSC framework
CPCSC Level 1 and Level 2 control sets pre-built and maintained by our compliance team. Framework updates reflected automatically—no manual re-mapping when CCCS guidance evolves.
Scope determination support
Identify which systems, personnel, and data stores fall within CPCSC scope. Protected and Classified information flow mapping with boundary documentation required for assessment.
CMMC dual-certification
Canadian suppliers with US DoD contracts need both CPCSC and CMMC. Sentrix maps the substantial overlap between the two frameworks and manages both from one evidence program, eliminating duplicate work.
Canadian data residency
All compliance evidence stored in Canadian data centres. Required for defence contractors handling Protected B and higher classification information under Treasury Board policies.
Assessment-ready evidence
Whether you are self-attesting at Level 1 or preparing for a Level 2 third-party assessment, Sentrix assembles your evidence package in the format assessors expect.
CCCS baseline crosswalk
Sentrix maps CPCSC controls to the Canadian Centre for Cyber Security’s baseline security controls, giving you a single view of your CCCS and CPCSC posture simultaneously.
Need hands-on support with your certification? See our CPCSC certification support service
Further reading: CPCSC explained—what Canadian defence suppliers need to know
See your CPCSC readiness against your real infrastructure.
We map your controls to CPCSC Level 1 and Level 2 live in the demo.