home / frameworks / cpcsc / levels-and-requirements

// CPCSC hub

CPCSC levels and requirements

What each of the 3 CPCSC levels requires, how many controls apply, and how ITSP.10.171 sets the technical baseline.

One standard, three levels

Every CPCSC level uses one standard. ITSP.10.171, Protecting controlled information in non-Government of Canada systems and organizations, is published by the Canadian Centre for Cyber Security. It's a Canadian version of NIST SP 800-171 Revision 3, and the Cyber Centre says there are no substantial technical changes between the two. The main edits reflect Canadian laws, policies, and terminology. The first release came out on April 2, 2025, and a second release followed in October 2025.

ITSP.10.171 keeps the 17 families of the NIST source, from access control and audit and accountability through to supply chain risk management. What changes is scope. The levels differ in how many requirements apply and who checks them. A Level 1 supplier works with a small subset, while a Level 3 supplier faces the full set plus enhanced protections drawn from NIST SP 800-172.

Level 1

Level 1 is an annual self-assessment against 13 controls, and it has been available since April 1, 2026. PSPC groups them into 6 practices. Access control has 4 controls (manage accounts, grant only needed access, use approved systems and devices, and keep sensitive information off public systems). Identification and authentication has 3 (individual accounts with strong passwords, device approval before connection, and multi-factor authentication). Media protection, physical protection, systems and communications protection, and system and information integrity account for the other 6.

PSPC says the assessment can take under an hour for a supplier that already knows the standard and has its evidence ready. Suppliers use a self-assessment tool hosted by the Cyber Centre. Keep the evidence. It must be retained for the attestation cycle, or at least one year.

  • Access control (4 controls)
  • Identification and authentication (3 controls)
  • Media protection (1 control)
  • Physical protection (2 controls)
  • Systems and communications protection (1 control)
  • System and information integrity (2 controls)

Level 2

Level 2 covers 98 controls from ITSP.10.171. It requires an external assessment led by a certification body accredited by the Standards Council of Canada, repeated every three years, with an annual affirmation in between. PSPC links Level 2 to contracts involving controlled defence information or more complex cyber-sensitive work. Level 2 is still under development, so the assessment procedure and certificate format haven't been published on the program pages.

Level 3

Level 3 is for the highest-risk scenarios. The PSPC backgrounder gives examples such as work on weapon systems or military platforms, access to critical infrastructure, and handling of information from Five Eyes partners. National Defence, not a private body, will carry out the assessments every three years, again with an annual affirmation. The control count isn't settled in public material yet. The program overview page lists 130+ controls, while the additional information page lists 200, so suppliers should rely on the contract and the final program guidance.

How risk sets the level

The backgrounder gives low-risk examples. These include administrative or business support contracts, unclassified non-technical communications, basic IT services with no sensitive data, suppliers with limited network integration, and prototype or concept talks without technical specifications. Higher-risk work moves to external or government assessment, and the contracting authority decides which level a contract carries.

  • Administrative or business support contracts usually fit Level 1
  • Controlled defence information points to Level 2
  • Weapon systems, critical infrastructure access, or Five Eyes information points to Level 3

Resources

All CPCSC resources

References

  1. Program overview, Cyber security certification for defence suppliers in Canada, Public Services and Procurement Canada
  2. How to meet Level 1 certification requirements, Public Services and Procurement Canada
  3. Protecting controlled information in non-Government of Canada systems and organizations (ITSP.10.171), Canadian Centre for Cyber Security
  4. Backgrounder, Canadian Program for Cyber Security Certification Level 1, Public Services and Procurement Canada