CPCSC Cyber Security Certification for Canadian Defence Contractors

CPCSC cyber security certification is now part of how Canada picks its defence suppliers. If your company bids on Department of National Defence work, or supplies a firm with such contracts, you need to know what the program asks of you and when. This guide covers the three levels, the controls behind them, and the skills your team needs to prepare.
Not sure where your team stands? View government-ready certification tracks and build a plan before your next bid.
What CPCSC Is
CPCSC stands for the Canadian Program for Cyber Security Certification. Public Services and Procurement Canada runs it with support from National Defence and the Canadian Centre for Cyber Security. Its goal is to protect sensitive federal contract information below the classified level.
The program rests on Canada’s ITSP.10.171 standard. According to the Government of Canada program overview, the standard is closely adapted from two U.S. documents: NIST SP 800-171 and NIST SP 800-172. If you know the American CMMC model, you already know the shape of CPCSC.
The Three Levels
The program sorts suppliers into three levels. Each level matches the sensitivity of the information a contract involves.
- Level 1 covers 13 controls and relies on an annual self-assessment. It launched in April 2026.
- Level 2 covers 98 controls and calls for an external assessment by an accredited certification body, plus an annual affirmation. It remains under development.
- Level 3 covers more than 130 controls and calls for an assessment by National Defence. It also remains under development.
Your contract sets the level. Ask your contracting authority which one applies before you commit to a bid.
How This Differs From ITSG-33
Many government contractors know ITSG-33 and the Protected B control profile. Those govern systems you build or run for a department. CPCSC governs your own company environment, the place where you store and handle contract information. You answer to both when a contract touches both.
The Contract Security Program still handles personnel screening and facility clearances. CPCSC does not replace it. Treat the three as separate checklists: people, systems, and your company network.
What Level 1 Asks of You
Level 1 covers basic cyber hygiene. Expect questions on who has access to your systems, how you protect devices, how you manage passwords, and how you handle updates. You complete the self-assessment through a government tool and attest to the results each year.
Self-assessment does not mean easy. You attest in your company’s name. Gaps you ignore become a problem during a bid review. Fix them before you sign.
Why Level 2 Needs More Preparation
Level 2 brings outside assessors into your office. They check evidence, not promises. You need written policies, logs, access records, and proof your staff follow the process. Teams who build this evidence over months pass with less stress than teams who scramble in the final weeks.
Prime contractors carry extra weight here. Reports on the program describe a flow-down model, where a prime passes requirements to its subcontractors. If you sit in a supply chain, expect your customers to ask for your certification status.
Skills Your Team Needs
Meeting these controls takes people who understand access control, incident response, configuration management, and risk assessment. The NIST standards behind the program are public. The NIST SP 800-171 publication lists every requirement in plain language, and it makes a useful study text for your security lead.
Training turns this text into daily practice. Ultimate IT Courses delivers vendor-neutral cybersecurity training through Mile2, with hands-on labs in small classes. Browse the cybersecurity training programs to find courses on security fundamentals, risk, and defence. The wider certification catalogue shows vendor credentials such as CompTIA Security+ and CISSP, which many defence employers recognize.
A Practical Order of Work
Start with scope. List where contract information lives, who touches it, and which devices connect to it. Next, run the Level 1 self-assessment honestly and record every gap. Assign each gap to one owner with a due date. Then train the people who own the work, so the fixes last past the audit.
Your Next Step
Defence work rewards suppliers who prepare early. Check your contract level, map your gaps, and train your team before the assessor arrives. View government-ready certification tracks or explore cybersecurity training to start.
