home / frameworks / cmmc / cmmc-for-canadian-suppliers

// CMMC hub

CMMC for Canadian suppliers

How CMMC reaches Canadian companies in the U.S. defence supply chain, and how it relates to Canada's CPCSC.

How CMMC reaches Canadian companies

CMMC is a U.S. contract requirement, not a Canadian law. It still reaches many Canadian firms. The DFARS clause 252.204-7021 flows down to subcontractors at every tier that will handle FCI or CUI, and U.S. primes pass it on to Canadian suppliers of parts, engineering, software, and services. In the preamble to the 2025 DFARS rule, the Department said that contracts subject to NIST SP 800-171 require the contractor, whether foreign or domestic, to secure its systems.

Canadian companies may also sell directly to the U.S. Department of Defense, often through the Canadian Commercial Corporation. The rules still apply. In that case the Canadian supplier still holds the information. CMMC applies to its systems, and the supplier is responsible for meeting the level named in the U.S. contract even though the Canadian Commercial Corporation is the prime contractor.

What Canadian suppliers need now

During Phase 1 and the Phase 2 suspension, most contracts ask for a Level 1 (Self) or Level 2 (Self) status. That means a current self-assessment score in SPRS, a CMMC unique identifier for each system in scope, and a yearly affirmation by a senior official. Canadian firms need a U.S. government entity identifier and SPRS access to post results, which takes time to set up.

Level 2 self-assessments use the 110 requirements of NIST SP 800-171 Rev. 2. Evidence matters. A false affirmation creates legal risk under the U.S. False Claims Act, so companies should be able to back each score with evidence.

  • Confirm whether you handle FCI, CUI, or both
  • Scope the systems and any cloud services that touch that data
  • Write a system security plan and score against Rev. 2
  • Post results in SPRS and plan for annual affirmations
  • Ask U.S. primes which level and assessment type they'll flow down

Can a Canadian firm get a C3PAO assessment

Yes. Canadian companies can hire an authorized C3PAO from the CMMC Marketplace, and C3PAO assessments remain available during the suspension. The DFARS rule preamble notes that 32 CFR part 170 does not preclude otherwise qualified foreign companies from becoming C3PAOs, although they must clear the Cyber AB's foreign ownership review and personnel checks. Check the Marketplace listing and ask whether the assessor can work on site in Canada before you sign.

Relationship with the CPCSC

Canada built its own program for its defence supply chain. The Canadian Program for Cyber Security Certification (CPCSC), run by Public Services and Procurement Canada, launched Level 1 on April 14, 2026, with Level 1 required in select National Defence contracts from summer 2026. Level 1 has 13 controls. Level 2 has 98 controls assessed by certification bodies accredited by the Standards Council of Canada, and Level 3 has more than 130 controls assessed by National Defence.

The two programs look alike, but they aren't interchangeable. PSPC's 2025 to 2026 evaluation of the CPCSC states that the CMMC final program rule would not allow bilateral reciprocity between another country's certification program and the U.S. Department of Defense. Industry told the evaluators it strongly preferred full reciprocity. There's also a version gap. CPCSC controls come from the Cyber Centre's ITSP.10.171, adapted from NIST SP 800-171 Rev. 3, while CMMC Level 2 still uses Rev. 2.

Running one program for both

Firms that supply both countries can save effort by building one control set. Starting from Rev. 3 and ITSP.10.171 covers most of Rev. 2, but the mapping isn't exact, so a crosswalk is still needed for CMMC. Keep separate evidence packages, because each program has its own scoring, reporting system, and assessors. Watch both timelines. The CMMC Phase 2 decision and the CPCSC Level 2 rollout, which PSPC has said will start in select contracts in spring 2027, may land within months of each other.

Resources

All CMMC resources

References

  1. DFARS: Assessing Contractor Implementation of Cybersecurity Requirements, 90 FR 43560, Federal Register via govinfo.gov
  2. Evaluation of the Canadian Program for Cyber Security Certification: Final report, Public Services and Procurement Canada
  3. CPCSC program overview, Public Services and Procurement Canada
  4. Government of Canada introduces Level 1 of the CPCSC (April 14, 2026), Public Services and Procurement Canada