home / frameworks / cpcsc

// Canadian certification programs

Canadian Program for Cyber Security Certification (CPCSC)

Canada's cyber security certification for defence suppliers, with 3 levels based on ITSP.10.171, a Canadian version of NIST SP 800-171. Level 1 self-assessment started in 2026, and third-party Level 2 assessments are planned from spring 2027.

Canada (federal)

Overview

The Canadian Program for Cyber Security Certification (CPCSC) sets cyber security requirements for companies that work on Canadian defence contracts, and it's led by Public Services and Procurement Canada (PSPC) and National Defence. Its standard is Canadian. The Canadian Centre for Cyber Security wrote ITSP.10.171, a Canadian version of NIST SP 800-171 Revision 3 with no substantial technical changes. The program was introduced to the public on March 12, 2025, and Budget 2023 set aside $25 million over three years to build it.

There are 3 levels. Level 1 is an annual self-assessment against 13 controls using an online tool from the Cyber Centre, and it became available to suppliers on April 1, 2026. Level 2 covers 98 controls and requires an external assessment by a certification body accredited by the Standards Council of Canada every three years, plus an annual affirmation. Level 3 is for the highest-risk work. National Defence will assess it every three years against a larger control set drawn from NIST SP 800-171 and 800-172, and PSPC pages describe it as 130+ or 200 controls.

The rollout is phased. PSPC says Level 1 will appear in select defence contracts beginning summer 2026 and is checked at contract award rather than during bidding. Level 2 will be added to select contracts beginning in spring 2027, and between April 2027 and March 2028 Level 2 or 3 requirements will be phased into select defence contracts. Canada may accept a valid US CMMC status case by case after confirming that the assessment covers the required scope, but there's no formal reciprocity agreement. Contract documents state which level applies, so suppliers should read each solicitation's security requirements.

Who it applies to in Canada

Suppliers and subcontractors bidding on or holding Canadian defence contracts that name a CPCSC level, from administrative service providers up to firms handling controlled defence information or weapon systems work.

It's a made-in-Canada requirement in federal defence procurement, run by PSPC and National Defence. Certification bodies for Level 2 are accredited by the Standards Council of Canada, and the controls mirror those behind the US CMMC program.

Controls at a glance

CPCSC requirements come from ITSP.10.171, which keeps the 17 NIST SP 800-171 Revision 3 families, and each level applies a larger share of them.

Level 1 access control (4 controls)

  • Manage user accounts
  • Give people only the access they need
  • Use only approved systems and devices
  • Keep sensitive information off public systems

Level 1 identification and authentication (3 controls)

  • Use individual accounts and strong passwords
  • Approve devices before they connect
  • Turn on multi-factor authentication

Level 1 media, physical, network, and integrity (6 controls)

  • Wipe or destroy old devices and media
  • Keep a list of people allowed in secure areas
  • Control physical entry to facilities
  • Use basic network protections at boundaries
  • Apply security updates promptly
  • Run antivirus and anti-malware software

Level 2 (98 controls from ITSP.10.171)

  • All 17 families, including audit and incident response
  • Configuration management and maintenance
  • Personnel security and awareness training
  • Risk assessment and security monitoring
  • Supply chain risk management
  • External assessment every three years plus annual affirmation

Applies to contracts with controlled defence information or more complex cyber-sensitive work.

Level 3 (enhanced controls)

  • Level 2 controls plus enhanced requirements
  • Enhanced requirements drawn from NIST SP 800-172
  • Assessment by National Defence every three years
  • Annual affirmation between assessments
  • Reserved for the highest-risk defence work

PSPC pages give the Level 3 count as 130+ and as 200 controls; confirm in the contract.

Certification and assessment

For Level 1, suppliers complete the Cyber Centre's online self-assessment, save the results page with its expiry date, and add proof of self-attestation to their CanadaBuys profile. Level 2 suppliers will be assessed by an SCC-accredited third party, and Level 3 suppliers by National Defence, each with an annual affirmation in between.

Dates to know

2024-11-18
PSPC publishes the CPCSC request for information summary report
2025-03-12
CPCSC officially introduced to the public
2025-04-02
Cyber Centre releases the first version of ITSP.10.171
2026-04-01
Level 1 self-assessment becomes available to suppliers
2026-04-14
Government announces Level 1 for select defence contracts beginning summer 2026

In this hub

Resources

Official texts and free tools for CPCSC. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Program overview, Cyber security certification for defence suppliers in Canada, Public Services and Procurement Canada
  2. Backgrounder, Canadian Program for Cyber Security Certification Level 1, Public Services and Procurement Canada
  3. Government of Canada introduces Level 1 of Canadian Program for Cyber Security Certification, Public Services and Procurement Canada
  4. Additional information and support, Public Services and Procurement Canada
  5. ITSP.10.171 Protecting controlled information in non-Government of Canada systems and organizations, Canadian Centre for Cyber Security