home / frameworks / cpcsc / cpcsc-vs-cmmc

// CPCSC hub

CPCSC and CMMC compared

How Canada's program lines up with the US Cybersecurity Maturity Model Certification, where they differ, and what case-by-case acceptance means.

Shared roots

Both programs exist to protect sensitive defence information held by private suppliers. PSPC says the CPCSC uses the same underlying technical controls as the US Cybersecurity Maturity Model Certification (CMMC), based on NIST SP 800-171 and 800-172. Both have 3 levels. In both, the lowest level is a self-assessment, the middle level relies on accredited third parties, and the top level is assessed by the defence department. Canadian industry pushed for this alignment, and it was the main theme of the 2024 request for information.

Where they differ

The standards aren't on the same revision. ITSP.10.171 is based on NIST SP 800-171 Revision 3. CMMC Level 2 is tied to NIST SP 800-171 Revision 2, which the US Department of War (formerly the Department of Defense) continues to require. CPCSC Level 1 has its own list of 13 controls, including multi-factor authentication, so it shouldn't be treated as a copy of CMMC Level 1.

The accreditation chain is separate too. In Canada, the Standards Council of Canada accredits Level 2 certification bodies. In the US, Level 2 assessments are done by certified third-party assessment organizations (C3PAOs) under the US program's own accreditation structure. Each program sets its own validity periods and affirmation rules.

  • ITSP.10.171 (Revision 3 base) versus NIST SP 800-171 Revision 2
  • SCC-accredited Level 2 bodies versus US C3PAOs
  • National Defence versus the US defence department at Level 3
  • Canadian defence contract clauses versus US DFARS clauses

Reciprocity

No formal reciprocity agreement exists. PSPC's evaluation of the program noted that the US final program rule would not allow bilateral reciprocity between another country's certification program and the US defence department. In practice, a CPCSC certificate won't satisfy a US contract that requires CMMC.

The other direction is more flexible. PSPC says Canada may accept a contractor's valid CMMC status on a case-by-case basis after confirming that the assessment covers the required scope. Suppliers send proof of CMMC certification to the program's email address listed on the Level 1 page.

CMMC status in 2026

CMMC is also in flux. Its rollout began with Phase 1 on November 10, 2025, and Phase 2, which would have required C3PAO assessments at award, was due on November 10, 2026. On July 13, 2026, the US Department of War suspended Phase 2 and later phases and set up a 60-day review by a CMMC Reform Task Force. Phase 1 self-assessments, DFARS 252.204-7012, and NIST SP 800-171 Revision 2 obligations stay in effect. Canadian firms that supply both countries should watch for the review's outcome, since changes to CMMC could affect how Canada treats CMMC status.

Planning for both

A firm serving both markets can build one control set and map it twice. Revisions 2 and 3 of NIST SP 800-171 share the same families, but Revision 3 reorganized and refined many requirements, so a crosswalk is needed rather than an assumption of equivalence. Keep separate evidence packages. Each program's assessors will look for their own requirement numbering.

Timing matters as well. CPCSC Level 2 enters Canadian contracts from spring 2027, and the CMMC Phase 2 date has been suspended, so neither program's third-party requirement is in force for most suppliers today.

Resources

All CPCSC resources

References

  1. Backgrounder, Canadian Program for Cyber Security Certification Level 1, Public Services and Procurement Canada
  2. Evaluation of the Canadian Program for Cyber Security Certification, Public Services and Procurement Canada
  3. Pentagon suspends CMMC Phase 2 requirements and launches review of cybersecurity certification program, WilmerHale
  4. Protecting controlled information in non-Government of Canada systems and organizations (ITSP.10.171), Canadian Centre for Cyber Security