home / frameworks / cpcsc / certification-process

// CPCSC hub

How CPCSC certification works

The steps for Level 1 self-assessment today and the roles of the Standards Council of Canada and National Defence for Levels 2 and 3.

Level 1 self-assessment step by step

Level 1 is done online through the Cyber Centre's self-assessment tool. The supplier answers for each control. PSPC says suppliers must meet and attest to all Level 1 criteria, so a partial result doesn't qualify. At the end, the tool shows a results page with an expiry date, and the supplier is asked to print or save it for future reference.

Proof of self-attestation and the expiry date then go into the supplier's CanadaBuys profile and into bids. Evidence that supports the answers, such as account lists, MFA settings, patch records, and visitor logs, should be kept for the attestation cycle or at least one year. Repeat the assessment every year.

  • Read the 13 Level 1 controls in ITSP.10.171
  • Close gaps before starting the tool
  • Complete the online self-assessment
  • Save the results page and expiry date
  • Add proof to the CanadaBuys profile and bids
  • Keep evidence and renew annually

Preparing evidence for Level 1

A self-assessment is only as good as the records behind it. For access control, keep a current list of user accounts, the approvals for each, and notes showing that leavers were removed. For identification and authentication, keep screenshots or exports showing that multi-factor authentication is on and that unknown devices can't connect. Patch reports cover updates. Anti-malware console views cover the rest of system and information integrity.

Physical controls need simple paper trails. A list of people allowed into secure areas, a visitor log, and a description of locks or badge readers will usually do. For media protection, record how old laptops, drives, and phones were wiped or destroyed, and by whom. Store all of it in one place. That makes the annual renewal faster, and it gives the supplier something to show if a contracting authority asks how an answer was reached.

Level 2 and the Standards Council of Canada

Level 2 assessments will be led by certification bodies accredited by the Standards Council of Canada (SCC), Canada's national accreditation body. SCC has set up an accreditation program for third-party assessment organizations based on ITSP.10.171. Organizations that want to become Level 2 assessors are directed by PSPC to contact SCC at [email protected]. Certificates will last three years. The supplier will also make an annual affirmation in between.

PSPC hasn't yet published the full Level 2 procedure, such as how scoping, evidence sampling, or remediation windows will work. Capacity is a concern too. The program's own evaluation flagged a risk that low industry demand could limit the number of accredited third-party assessor organizations available to suppliers. Suppliers planning for 2027 should check the program pages and the SCC directory of accredited organizations before booking an assessment.

Level 3 and National Defence

At Level 3, National Defence conducts the assessment itself every three years, with an annual affirmation from the supplier in the years between assessments. This mirrors the US approach of government-led assessment for the highest tier. Scheduling details aren't public yet.

Support for suppliers

PSPC points suppliers to Procurement Assistance Canada for help with federal bidding and to the Cyber Centre for guidance on the controls. The Cyber Centre's publications on the baseline controls for small and medium organizations and its Top 10 IT security actions cover much of the same ground as Level 1. They're free. Questions about the program go to the CPCSC contact page on canada.ca.

Resources

All CPCSC resources

References

  1. How to meet Level 1 certification requirements, Public Services and Procurement Canada
  2. CPCSC self-assessment tool, Canadian Centre for Cyber Security
  3. Additional information and support, Public Services and Procurement Canada
  4. Program overview, Cyber security certification for defence suppliers in Canada, Public Services and Procurement Canada