Home/ CPCSC Certification
Services · Compliance

CPCSC certification support (Canadian Program for Cyber Security Certification)

Level 1 requirements are being introduced into select defence contracts starting summer 2026. Sentrix structures your process — from gap analysis to evidence — so your self-assessment is solid and your organization stays eligible for federal opportunities.

What is CPCSC?

The Canadian Program for Cyber Security Certification (CPCSC, or PCCC in French) is led by Public Services and Procurement Canada (PSPC) and National Defence. It sets the cybersecurity standards defence contractors must meet to protect sensitive unclassified information and ensure interoperability with Canada’s allies, notably Five Eyes partners.

The program is built on Canada’s industrial cybersecurity standard (ITSP.10.171), developed by the Canadian Centre for Cyber Security. Technically, this standard is closely aligned with the US NIST SP 800-171 and 800-172 publications, which also underpin the American CMMC program. This alignment is meant to limit overlap and preserve Canadian suppliers’ access to international defence markets.

In practical terms: if your organization handles sensitive government information under defence contracts, or wants to enter the Canadian defence supply chain, CPCSC will become a condition of access to those contracts.

13 controls

Security controls assessed at Level 1.

Annual self-assessment

Mandatory for Level 1.

Available since April 2026

For suppliers; introduced into select contracts starting summer 2026.

Based on ITSP.10.171

Aligned with NIST SP 800-171 / 800-172.

Led by PSPC

And National Defence, with accreditation by the Standards Council of Canada (SCC).

The three certification levels

CPCSC’s mandatory requirements are organized into three progressive levels, based on the sensitivity of the information handled and the contract’s risk level.

Level 1 · Self-assessment

13 controls

Annual self-assessment by the supplier, using an online tool provided by the Government of Canada. Available to suppliers since April 1, 2026; introduced into select defence contracts starting summer 2026. Applies to lower-risk situations: administrative or operational support, basic IT services without sensitive data, limited network integration, etc.

Level 2 · External assessment

98 controls

Assessment conducted by an accredited third-party certification body (C3PAO) accredited by the Standards Council of Canada, every three years, with annual confirmation. Planned to be introduced into select defence contracts starting spring 2027. Applies to contracts involving controlled Defence information or more complex sensitive work.

Level 3 · Government assessment

200 controls

Assessment conducted directly by National Defence, every three years, with annual confirmation. Reserved for the highest-risk scenarios: weapons systems, critical infrastructure, information shared with Five Eyes partners.

Levels 2 and 3 are still being developed. Timelines and details will be clarified by PSPC and the SCC as the rollout continues.

What Level 1 covers: 13 controls, 6 best practices

Level 1’s 13 controls (drawn from the ITSP.10.171 standard) group into fundamental cyber-hygiene practices. Our support helps you assess each one and document its implementation.

Access control

Managing who can access systems

  • Account management (03.01.01)
  • Access enforcement (03.01.02)
  • Use of external systems (03.01.20)
  • Publicly accessible content (03.01.22)

Identification and authentication

Verifying users and devices

  • User identification and authentication (03.05.01)
  • Device identification and authentication (03.05.02)
  • Multi-factor authentication (03.05.03)

Media and physical protection

Protecting data and equipment

  • Media sanitization (03.08.03)
  • Physical access authorizations (03.10.01)
  • Physical access control (03.10.07)

System and communications protection

Defending systems against cyber threats

  • Boundary protection (03.13.01)
  • Flaw remediation (03.14.01)
  • Malicious code protection (03.14.02)

Control codes follow the Canadian ITSP.10.171 standard. Official titles may evolve between versions of the program.

Who this support is for

CPCSC concerns organizations that are part of the Canadian defence supply chain, or plan to enter it.

  • Defence sector contractors and subcontractors who must demonstrate compliance to remain eligible for federal contracts.
  • Engineering, manufacturing, and aerospace companies supporting defence programs.
  • IT and OT service providers whose systems interact with defence-related data or environments.
  • Technology suppliers and publishers handling sensitive unclassified government information.
  • Suppliers already engaged with US CMMC who want to align both frameworks and avoid duplicating effort.
  • Proactive organizations not yet in scope who want to prepare before requirements appear in tenders.

What you get

Scoping

Identifying the systems, environments, and processes that handle sensitive information, and spotting segmentation or isolation opportunities to limit your exposure and the assessment’s scope.

Gap analysis

An assessment of your current posture against ITSP.10.171 requirements, prioritized by risk and effort, with the target level (1, 2, or 3) clearly established.

Documentation and evidence

Writing or adapting the expected policies, procedures, and supporting evidence, at the level of detail required to support your self-assessment or a third-party assessment — not generic templates.

Implementation of missing controls

Working with your IT teams to put in place required technical controls: access management, multi-factor authentication, network boundary protection, flaw remediation, malware protection, and more.

Action plan (POA&M)

A prioritized corrective action plan to close remaining gaps and build a realistic roadmap toward assessment readiness.

Assessment preparation

Support completing the Level 1 self-assessment in the government’s tool, or preparing for an assessment by an accredited body (Level 2) or by National Defence (Level 3).

Our four-step approach

CPCSC compliance is not something you improvise: it takes a progressive, structured, and rigorously documented approach. We support you end to end.

1. Identify
Which systems handle sensitive information? What technical and organizational boundaries are involved? Should certain environments be segmented or isolated to limit exposure? We clearly delimit the scope of the assessment.
2. Analyze
Where do you stand against ITSP.10.171 requirements? What gaps remain? Which certification level are you targeting? We produce a prioritized gap analysis.
3. Remediate
Which corrective actions should be prioritized? How do you strengthen the protection of your access, logs, and sensitive data? We implement the missing controls and structure the documentation with your teams.
4. Assess
Are you ready for the annual self-assessment (Level 1), assessment by an accredited body (Level 2), or government assessment (Level 3)? We validate the evidence and support you through to demonstrating compliance.

CPCSC and CMMC: two frameworks, one shared goal

CPCSC and the American CMMC program both aim to strengthen defence supply chain cybersecurity. They are not officially equivalent, but they rest on the same technical controls: the 172 controls of the NIST SP 800-171 and 800-172 publications. On a case-by-case basis, Canada may accept a valid CMMC certification if its scope matches CPCSC requirements, which can avoid maintaining two separate certifications. If you supply both markets, we help you align the two frameworks and optimize your effort.

Aspect CPCSC (Canada) CMMC (United States)
JurisdictionCanadaUnited States
SectorCanadian defence supply chainDepartment of Defense (DoD) contractors
Reference technical standardITSP.10.171 (based on NIST SP 800-171 / 800-172)NIST SP 800-171
Responsible authorityPSPC and National Defence; accreditation by the SCCUS Department of Defense
Levels3 levels (self-assessment, accredited third party, government)3 levels
Mutual recognitionCMMC recognition possible case by caseNo external recognition

Canada’s acceptance of a CMMC certification is assessed case by case; Canada reserves the right to verify compliance with specific controls.

Why prepare now

As CPCSC requirements appear in procurement processes, prepared organizations will be best positioned to seize business opportunities. Delaying preparation means risking having to comply under pressure, on tight deadlines, with the contract at stake.

Complying with CPCSC means:

  • Access public and defence-related contracts with the Government of Canada.
  • Protect the sensitive information you handle and strengthen your partners’ trust.
  • Structure your cybersecurity around an internationally recognized framework, aligned with NIST and CMMC.
  • Reduce your risk and better control remediation costs by acting early rather than urgently.

Why trust Sentrix with your CPCSC journey

Cybersecurity and compliance expertise

A specialized team mastering the frameworks at the core of CPCSC: ITSP.10.171, NIST SP 800-171 / 800-172, and related frameworks (ISO 27001, etc.).

End-to-end support

From scoping to assessment prep, including control implementation and documentation management — we stay by your side at every step.

Scalable, pragmatic approach

A compliance path adapted to your current maturity, the nature of your contracts, and your technical and budget constraints.

Current with the program’s evolution

CPCSC is rolling out in phases and its requirements are evolving. We actively track guidance from PSPC, the SCC, and the Canadian Centre for Cyber Security so your process reflects the current state of expectations.

We prepare — we do not certify. Level 2 assessments are conducted by third-party bodies accredited by the Standards Council of Canada; Level 3 assessments are conducted by National Defence.

Frequently asked questions

Is CPCSC mandatory?
CPCSC’s cybersecurity requirements are becoming mandatory contractual conditions for certain defence contracts. Level 1 (annual self-assessment) is being introduced into select contracts starting summer 2026, with higher levels to follow. If you want to stay eligible for targeted contracts, compliance is not optional.
Which level applies to me?
It depends on the sensitivity of the information handled and the risk level of the targeted contracts. Lower-risk situations fall under Level 1 (self-assessment). Contracts involving controlled Defence information fall under Level 2, and the highest-risk scenarios (weapons systems, critical infrastructure) fall under Level 3. We help you determine the right level as part of scoping.
How long does it take to prepare?
Duration varies by target level and your starting maturity. A compliance project generally takes a few months to a year, including diagnosis, remediation, and assessment prep. Organizations already aligned with NIST SP 800-171 / ITSP.10.171 can move faster.
What is the difference between CPCSC and NIST SP 800-171?
NIST SP 800-171 is a US technical standard. CPCSC is a Canadian certification program built on the Canadian ITSP.10.171 standard, itself technically aligned with NIST SP 800-171 and 800-172. CPCSC adds an assessment, accreditation, and government oversight mechanism specific to Canada.
I already have CMMC certification. Do I need to go through CPCSC too?
Not necessarily in full. On a case-by-case basis, Canada may accept a valid CMMC certification if its scope matches CPCSC requirements. We help you align the two frameworks to avoid duplicating your effort.
Are foreign companies affected?
Yes, as soon as they wish to participate in Canadian defence supply chain contracts covered by CPCSC requirements.
Who conducts the assessment?
Level 1 is a self-assessment conducted by the supplier. Level 2 is conducted by an accredited third-party certification body (C3PAO) accredited by the Standards Council of Canada. Level 3 is conducted directly by National Defence.

Let’s talk about your CPCSC journey.

Whether you’re already facing a contractual requirement or just want to check your readiness — a first conversation costs nothing and helps determine the target level and how we can support you.