CPCSC certification support (Canadian Program for Cyber Security Certification)
Level 1 requirements are being introduced into select defence contracts starting summer 2026. Sentrix structures your process — from gap analysis to evidence — so your self-assessment is solid and your organization stays eligible for federal opportunities.
What is CPCSC?
The Canadian Program for Cyber Security Certification (CPCSC, or PCCC in French) is led by Public Services and Procurement Canada (PSPC) and National Defence. It sets the cybersecurity standards defence contractors must meet to protect sensitive unclassified information and ensure interoperability with Canada’s allies, notably Five Eyes partners.
The program is built on Canada’s industrial cybersecurity standard (ITSP.10.171), developed by the Canadian Centre for Cyber Security. Technically, this standard is closely aligned with the US NIST SP 800-171 and 800-172 publications, which also underpin the American CMMC program. This alignment is meant to limit overlap and preserve Canadian suppliers’ access to international defence markets.
In practical terms: if your organization handles sensitive government information under defence contracts, or wants to enter the Canadian defence supply chain, CPCSC will become a condition of access to those contracts.
13 controls
Security controls assessed at Level 1.
Annual self-assessment
Mandatory for Level 1.
Available since April 2026
For suppliers; introduced into select contracts starting summer 2026.
Based on ITSP.10.171
Aligned with NIST SP 800-171 / 800-172.
Led by PSPC
And National Defence, with accreditation by the Standards Council of Canada (SCC).
The three certification levels
CPCSC’s mandatory requirements are organized into three progressive levels, based on the sensitivity of the information handled and the contract’s risk level.
13 controls
Annual self-assessment by the supplier, using an online tool provided by the Government of Canada. Available to suppliers since April 1, 2026; introduced into select defence contracts starting summer 2026. Applies to lower-risk situations: administrative or operational support, basic IT services without sensitive data, limited network integration, etc.
98 controls
Assessment conducted by an accredited third-party certification body (C3PAO) accredited by the Standards Council of Canada, every three years, with annual confirmation. Planned to be introduced into select defence contracts starting spring 2027. Applies to contracts involving controlled Defence information or more complex sensitive work.
200 controls
Assessment conducted directly by National Defence, every three years, with annual confirmation. Reserved for the highest-risk scenarios: weapons systems, critical infrastructure, information shared with Five Eyes partners.
Levels 2 and 3 are still being developed. Timelines and details will be clarified by PSPC and the SCC as the rollout continues.
What Level 1 covers: 13 controls, 6 best practices
Level 1’s 13 controls (drawn from the ITSP.10.171 standard) group into fundamental cyber-hygiene practices. Our support helps you assess each one and document its implementation.
Access control
Managing who can access systems
- Account management (03.01.01)
- Access enforcement (03.01.02)
- Use of external systems (03.01.20)
- Publicly accessible content (03.01.22)
Identification and authentication
Verifying users and devices
- User identification and authentication (03.05.01)
- Device identification and authentication (03.05.02)
- Multi-factor authentication (03.05.03)
Media and physical protection
Protecting data and equipment
- Media sanitization (03.08.03)
- Physical access authorizations (03.10.01)
- Physical access control (03.10.07)
System and communications protection
Defending systems against cyber threats
- Boundary protection (03.13.01)
- Flaw remediation (03.14.01)
- Malicious code protection (03.14.02)
Control codes follow the Canadian ITSP.10.171 standard. Official titles may evolve between versions of the program.
Who this support is for
CPCSC concerns organizations that are part of the Canadian defence supply chain, or plan to enter it.
- Defence sector contractors and subcontractors who must demonstrate compliance to remain eligible for federal contracts.
- Engineering, manufacturing, and aerospace companies supporting defence programs.
- IT and OT service providers whose systems interact with defence-related data or environments.
- Technology suppliers and publishers handling sensitive unclassified government information.
- Suppliers already engaged with US CMMC who want to align both frameworks and avoid duplicating effort.
- Proactive organizations not yet in scope who want to prepare before requirements appear in tenders.
What you get
Scoping
Identifying the systems, environments, and processes that handle sensitive information, and spotting segmentation or isolation opportunities to limit your exposure and the assessment’s scope.
Gap analysis
An assessment of your current posture against ITSP.10.171 requirements, prioritized by risk and effort, with the target level (1, 2, or 3) clearly established.
Documentation and evidence
Writing or adapting the expected policies, procedures, and supporting evidence, at the level of detail required to support your self-assessment or a third-party assessment — not generic templates.
Implementation of missing controls
Working with your IT teams to put in place required technical controls: access management, multi-factor authentication, network boundary protection, flaw remediation, malware protection, and more.
Action plan (POA&M)
A prioritized corrective action plan to close remaining gaps and build a realistic roadmap toward assessment readiness.
Assessment preparation
Support completing the Level 1 self-assessment in the government’s tool, or preparing for an assessment by an accredited body (Level 2) or by National Defence (Level 3).
Our four-step approach
CPCSC compliance is not something you improvise: it takes a progressive, structured, and rigorously documented approach. We support you end to end.
1. Identify
2. Analyze
3. Remediate
4. Assess
CPCSC and CMMC: two frameworks, one shared goal
CPCSC and the American CMMC program both aim to strengthen defence supply chain cybersecurity. They are not officially equivalent, but they rest on the same technical controls: the 172 controls of the NIST SP 800-171 and 800-172 publications. On a case-by-case basis, Canada may accept a valid CMMC certification if its scope matches CPCSC requirements, which can avoid maintaining two separate certifications. If you supply both markets, we help you align the two frameworks and optimize your effort.
Canada’s acceptance of a CMMC certification is assessed case by case; Canada reserves the right to verify compliance with specific controls.
Why prepare now
As CPCSC requirements appear in procurement processes, prepared organizations will be best positioned to seize business opportunities. Delaying preparation means risking having to comply under pressure, on tight deadlines, with the contract at stake.
Complying with CPCSC means:
- Access public and defence-related contracts with the Government of Canada.
- Protect the sensitive information you handle and strengthen your partners’ trust.
- Structure your cybersecurity around an internationally recognized framework, aligned with NIST and CMMC.
- Reduce your risk and better control remediation costs by acting early rather than urgently.
Why trust Sentrix with your CPCSC journey
Cybersecurity and compliance expertise
A specialized team mastering the frameworks at the core of CPCSC: ITSP.10.171, NIST SP 800-171 / 800-172, and related frameworks (ISO 27001, etc.).
End-to-end support
From scoping to assessment prep, including control implementation and documentation management — we stay by your side at every step.
Scalable, pragmatic approach
A compliance path adapted to your current maturity, the nature of your contracts, and your technical and budget constraints.
Current with the program’s evolution
CPCSC is rolling out in phases and its requirements are evolving. We actively track guidance from PSPC, the SCC, and the Canadian Centre for Cyber Security so your process reflects the current state of expectations.
We prepare — we do not certify. Level 2 assessments are conducted by third-party bodies accredited by the Standards Council of Canada; Level 3 assessments are conducted by National Defence.
Frequently asked questions
Is CPCSC mandatory?
Which level applies to me?
How long does it take to prepare?
What is the difference between CPCSC and NIST SP 800-171?
I already have CMMC certification. Do I need to go through CPCSC too?
Are foreign companies affected?
Who conducts the assessment?
Let’s talk about your CPCSC journey.
Whether you’re already facing a contractual requirement or just want to check your readiness — a first conversation costs nothing and helps determine the target level and how we can support you.