From consultation to launch
PSPC ran a request for information on the program in May 2024. Responses came from 91 organizations, including contractors, consultants, and service providers, and the summary report published on November 18, 2024 stressed the importance of alignment with the US Cybersecurity Maturity Model Certification. Alignment was the main ask. Budget 2023 had already allocated $25 million over three years to set the program up, and the CPCSC was officially introduced to the public on March 12, 2025.
Progress was slower than first planned. A PSPC evaluation covering April 2023 to June 2025 found that only 5 of 26 planned deliverables were completed on time and that, at that point, no contracts had been identified for piloting the program.
Level 1 in contracts
Level 1 became available to suppliers on April 1, 2026. On April 14, 2026, the government announced that Level 1 would be required in select defence contracts beginning summer 2026. PSPC says the self-assessment is required at contract award and not during the bidding process. Its Level 1 page also asks suppliers to show proof of self-attestation and the expiry date in their CanadaBuys profile and when they submit a bid. Completing it early avoids delays.
Levels 2 and 3
The Level 1 backgrounder says Level 2 will be added to select defence contracts beginning in spring 2027. PSPC also gives a fiscal-year view. From April 2026 to March 2027, Level 1 tools are available and Level 1 to 3 requirements may be identified in select contracts as early as summer 2026. From April 2027 to March 2028, the requirement to hold Level 2 or 3 certification will be gradually incorporated into select defence contracts.
No date has been published for the first Level 3 assessments by National Defence. Phrases like "may be identified" and "gradually incorporated" mean suppliers shouldn't expect a single cut-over date.
- Level 1 self-assessment opens on April 1, 2026
- Level 1 appears in select defence contracts from summer 2026
- Level 2 is added to select defence contracts from spring 2027
- Level 2 or 3 is phased into select contracts from April 2027 to March 2028
Which contracts carry which level
PSPC hasn't published a list of contract types mapped to levels. It gives examples instead. Administrative or business support contracts, basic IT services with no sensitive data, and suppliers with limited network integration fit self-assessment. Work with controlled defence information or more complex cyber-sensitive tasks fits Level 2, while weapon systems, military platforms, critical infrastructure access, and Five Eyes partner information fit Level 3.
The level is set in the solicitation. Primes should expect to pass requirements down to subcontractors that handle the same information, since ITSP.10.171 applies to non-Government of Canada systems that process, store, or transmit controlled information.
What to do now
Suppliers active in defence procurement can complete Level 1 now, keep the evidence, and renew it each year. Firms likely to handle controlled defence information can measure themselves against all of ITSP.10.171 so that a Level 2 assessment in 2027 or later isn't a surprise. CMMC holders have one more step. They should contact the program, as PSPC recommends.
Resources
- Cyber security certification for defence suppliers in Canada, Public Services and Procurement Canada
- ITSP.10.171 Protecting controlled information in non-Government of Canada systems and organizations, Canadian Centre for Cyber Security
- How to meet Level 1 certification requirements, Public Services and Procurement Canada
- CPCSC Level 1 self-assessment tool, Canadian Centre for Cyber Security
- Additional information and support, Public Services and Procurement Canada
References
- Additional information and support, Public Services and Procurement Canada
- Government of Canada introduces Level 1 of Canadian Program for Cyber Security Certification, Public Services and Procurement Canada
- Canadian Program for Cyber Security Certification RFI summary report, CanadaBuys
- Evaluation of the Canadian Program for Cyber Security Certification, Public Services and Procurement Canada
General information, reviewed 2026-10-11. Not legal advice.