Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
/var/www/traztech.ca/html/blog/post.php on line 12748
22; color:
Warning: Undefined array key "Compliance" in /var/www/traztech.ca/html/blog/post.php on line 12748
;">Compliance

How Much Does CPCSC Cost in Canada? (2026)

If you sell into the Canadian defence supply chain, "how much does CPCSC cost" is the question that determines whether you start this quarter or next. The honest answer is that it depends heavily on your current state, your scope, and who you hire to get you there. But you can still get defensible numbers before you pick up the phone, and that is what this article gives you.

CPCSC (the Canadian Program for Cyber Security Certification) rolls out in two tiers. Level 1 covers the 13 controls in ITSP.10.171, is self-assessed, goes live April 1, 2026, and becomes mandatory in select DND contracts starting summer 2026. Level 2 covers all 97 controls in ITSP.10.171, requires third-party assessment, and lands in April 2027. ITSP.10.171 is Canada's adaptation of NIST SP 800-171 Rev 3, so if your business already touches US federal contracts or CMMC, a lot of the groundwork carries over. If it doesn't, you're starting closer to zero.

Level 1: what it typically costs

Level 1 is self-assessed, which keeps direct fees low, but "self-assessed" does not mean "free." Most of the cost is labour: gap assessment, control implementation, policy writing, and the internal hours it takes to actually operate the controls, not just document them. For a small to mid-sized supplier with reasonably modern IT (cloud email, managed endpoints, basic access controls already in place), a guided Level 1 engagement with a boutique consultancy typically lands in the low five figures CAD, done in four to eight weeks. Organizations starting from a weaker baseline, think shared admin logins, no formal asset inventory, no incident response plan, should expect the higher end of that range or beyond, because the work is remediation-heavy, not just paperwork.

We break down exactly what the 13 controls require and how the assessment works in our CPCSC Level 1 guide, which is worth reading before you get a quote from anyone, including us. It tells you what "done" looks like so you can sanity-check a proposal against actual scope instead of a vendor's day-rate math.

Level 2: what to expect starting to plan for now

Level 2 is a different order of magnitude. Ninety-seven controls, third-party assessment, and audit-grade evidence requirements push most engagements into the mid five figures to low six figures CAD, depending heavily on organization size, number of systems in scope, and how much of Level 1 you've already operationalized. Because Level 2 assessment is third-party and won't be mandatory until April 2027, there's no reason to rush into a full Level 2 engagement today. There's every reason to structure your Level 1 work so it feeds directly into Level 2 instead of getting rebuilt from scratch in twelve months.

Boutique consultancy vs. platform vs. solo consultant

The provider type you choose changes both the price and what you're actually buying.

  • Compliance platforms (software-led). These sell you a dashboard, control mapping, and evidence storage, usually as an annual subscription in the low to mid five figures CAD. That's often cheaper on paper, but you're doing the implementation work yourself unless you pay extra for advisory hours. Fine if you have an internal security lead who just needs tooling. Expensive by the hour if you don't.
  • Solo consultants and freelancers. Lower day rates, sometimes meaningfully cheaper overall, but capacity and continuity are real risks on a program with a hard regulatory deadline. One person out sick or overbooked can stall your timeline with no backup.
  • Boutique consultancies. Priced between the two, with the advantage of an actual delivery team and researcher-level expertise rather than a checklist. This matters more for CPCSC than it did for older frameworks, because ITSP.10.171 is new enough that generic templates and stale playbooks won't map cleanly to it yet.

None of these is automatically wrong for every business. A five-person shop with one contract at stake has different economics than a fifty-person supplier renewing across multiple DND relationships. The mistake is picking the provider type before you know your scope, not after.

How to scope without overpaying

Most CPCSC overspend comes from one of two mistakes: buying Level 2 effort for a Level 1 deadline, or paying for a full assessment before doing a proper gap analysis. A few things that keep cost proportional to actual risk:

  • Get the gap assessment priced and delivered separately from remediation and certification support. If a vendor won't unbundle it, that's a signal the quote is padded.
  • Confirm which of the 13 Level 1 controls you already satisfy. Most suppliers with modern cloud infrastructure and MFA already meet several of them. Paying full remediation rates for controls you've already implemented is the single easiest place to overpay.
  • Ask how the Level 1 work maps forward to Level 2. A provider who can't answer that is optimizing for a one-time engagement fee, not for your 2027 deadline.
  • Match scope to contract value. If Level 1 unlocks one contract this summer, don't let a vendor sell you a Level 2-grade program you don't need for another year.

Our compliance advisory work is built around that sequencing: assess first, remediate only what's actually missing, and build Level 1 evidence in a format that carries forward instead of getting thrown away when Level 2 arrives.

Get a real number, not a guess

Ranges are useful for budgeting, but the number that matters is the one specific to your systems, your contracts, and your timeline. If you're bidding into DND work this summer and need to know exactly what Level 1 will cost for your organization, contact traztech for a scoped quote. We'll tell you plainly if you're closer to done than you think, and just as plainly if you're not.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on the unglamorous side of building a startup. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation