Overview
The Canadian Program for Cyber Security Certification (CPCSC) sets cyber security requirements for companies that work on Canadian defence contracts, and it's led by Public Services and Procurement Canada (PSPC) and National Defence. Its standard is Canadian. The Canadian Centre for Cyber Security wrote ITSP.10.171, a Canadian version of NIST SP 800-171 Revision 3 with no substantial technical changes. The program was introduced to the public on March 12, 2025, and Budget 2023 set aside $25 million over three years to build it.
There are 3 levels. Level 1 is an annual self-assessment against 13 controls using an online tool from the Cyber Centre, and it became available to suppliers on April 1, 2026. Level 2 covers 98 controls and requires an external assessment by a certification body accredited by the Standards Council of Canada every three years, plus an annual affirmation. Level 3 is for the highest-risk work. National Defence will assess it every three years against a larger control set drawn from NIST SP 800-171 and 800-172, and PSPC pages describe it as 130+ or 200 controls.
The rollout is phased. PSPC says Level 1 will appear in select defence contracts beginning summer 2026 and is checked at contract award rather than during bidding. Level 2 will be added to select contracts beginning in spring 2027, and between April 2027 and March 2028 Level 2 or 3 requirements will be phased into select defence contracts. Canada may accept a valid US CMMC status case by case after confirming that the assessment covers the required scope, but there's no formal reciprocity agreement. Contract documents state which level applies, so suppliers should read each solicitation's security requirements.
Who it applies to in Canada
Suppliers and subcontractors bidding on or holding Canadian defence contracts that name a CPCSC level, from administrative service providers up to firms handling controlled defence information or weapon systems work.
It's a made-in-Canada requirement in federal defence procurement, run by PSPC and National Defence. Certification bodies for Level 2 are accredited by the Standards Council of Canada, and the controls mirror those behind the US CMMC program.
Controls at a glance
CPCSC requirements come from ITSP.10.171, which keeps the 17 NIST SP 800-171 Revision 3 families, and each level applies a larger share of them.
Level 1 access control (4 controls)
- Manage user accounts
- Give people only the access they need
- Use only approved systems and devices
- Keep sensitive information off public systems
Level 1 identification and authentication (3 controls)
- Use individual accounts and strong passwords
- Approve devices before they connect
- Turn on multi-factor authentication
Level 1 media, physical, network, and integrity (6 controls)
- Wipe or destroy old devices and media
- Keep a list of people allowed in secure areas
- Control physical entry to facilities
- Use basic network protections at boundaries
- Apply security updates promptly
- Run antivirus and anti-malware software
Level 2 (98 controls from ITSP.10.171)
- All 17 families, including audit and incident response
- Configuration management and maintenance
- Personnel security and awareness training
- Risk assessment and security monitoring
- Supply chain risk management
- External assessment every three years plus annual affirmation
Applies to contracts with controlled defence information or more complex cyber-sensitive work.
Level 3 (enhanced controls)
- Level 2 controls plus enhanced requirements
- Enhanced requirements drawn from NIST SP 800-172
- Assessment by National Defence every three years
- Annual affirmation between assessments
- Reserved for the highest-risk defence work
PSPC pages give the Level 3 count as 130+ and as 200 controls; confirm in the contract.
Certification and assessment
For Level 1, suppliers complete the Cyber Centre's online self-assessment, save the results page with its expiry date, and add proof of self-attestation to their CanadaBuys profile. Level 2 suppliers will be assessed by an SCC-accredited third party, and Level 3 suppliers by National Defence, each with an annual affirmation in between.
Dates to know
- 2024-11-18
- PSPC publishes the CPCSC request for information summary report
- 2025-03-12
- CPCSC officially introduced to the public
- 2025-04-02
- Cyber Centre releases the first version of ITSP.10.171
- 2026-04-01
- Level 1 self-assessment becomes available to suppliers
- 2026-04-14
- Government announces Level 1 for select defence contracts beginning summer 2026
In this hub
CPCSC levels and requirements
What each of the 3 CPCSC levels requires, how many controls apply, and how ITSP.10.171 sets the technical baseline.
CPCSC timeline and contract requirements
When each CPCSC level enters Canadian defence contracts, based on dates published by PSPC.
How CPCSC certification works
The steps for Level 1 self-assessment today and the roles of the Standards Council of Canada and National Defence for Levels 2 and 3.
CPCSC and CMMC compared
How Canada's program lines up with the US Cybersecurity Maturity Model Certification, where they differ, and what case-by-case acceptance means.
Resources
Official texts and free tools for CPCSC. Links open the publisher’s site.
- Cyber security certification for defence suppliers in Canada, Public Services and Procurement Canada
- ITSP.10.171 Protecting controlled information in non-Government of Canada systems and organizations, Canadian Centre for Cyber Security
- How to meet Level 1 certification requirements, Public Services and Procurement Canadaguidance
- CPCSC Level 1 self-assessment tool, Canadian Centre for Cyber Securitytool
- Additional information and support, Public Services and Procurement Canadaguidance
Need help? Browse the directory or read the guides.
References
- Program overview, Cyber security certification for defence suppliers in Canada, Public Services and Procurement Canada
- Backgrounder, Canadian Program for Cyber Security Certification Level 1, Public Services and Procurement Canada
- Government of Canada introduces Level 1 of Canadian Program for Cyber Security Certification, Public Services and Procurement Canada
- Additional information and support, Public Services and Procurement Canada
- ITSP.10.171 Protecting controlled information in non-Government of Canada systems and organizations, Canadian Centre for Cyber Security
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.