Who this applies to
Suppliers and subcontractors that handle information on federal defence contracts.
What to know
- The program has three levels. As published by the government, Level 1 is an annual self-assessment, Level 2 is an external assessment by an accredited body, and Level 3 is an assessment by National Defence.
- Public Services and Procurement Canada leads the program, and the Standards Council of Canada accredits the bodies that perform Level 2 assessments.
- The Canadian Centre for Cyber Security developed the underlying standard.
- Rollout is phased, so which level a contract needs depends on the contract.
What to do
- Read the security requirements in each contract to see which level applies.
- Do a gap assessment early. Evidence takes longer to collect than the fixes take to make.
- Check the government program page for the current status, because dates and requirements move.
This guide is a plain-language summary for general information. It is not legal advice and it does not replace the official source. Requirements change, so check the linked source before you act.