Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

CPCSC for Canadian Defence Suppliers: What You Must Produce

A Canadian defence supplier bidding on DND work must produce a completed CPCSC self-assessment (13 controls at Level 1, live April 2026) or a third-party Level 2 assessment (97 controls, mandatory April 2027) mapped to ITSP.10.171, Canada's adaptation of NIST SP 800-171 Revision 3, along with a System Security Plan and evidence artifacts for every control claimed.

What CPCSC Actually Is and Why It Exists Now

The Canadian Program for Cyber Security Certification is Ottawa's answer to a problem it can no longer defer: controlled unclassified information sitting in the IT environments of thousands of small and mid-sized defence suppliers, most of whom have never had a cybersecurity audit in their existence. CPCSC borrows the tiered logic of the US CMMC program but is built around ITSP.10.171, the Canadian Centre for Cyber Security's own adaptation of NIST SP 800-171 Revision 3. If your American parent company or prime contractor has already gone through CMMC, the control language will feel familiar. If this is your first exposure to a formal cybersecurity framework, the volume of documentation required will surprise you.

The program exists because DND contracts routinely flow controlled information, technical drawings, supply chain data, personnel details, down through multiple tiers of subcontractors. A single unpatched VPN appliance at a fourth-tier machine shop is now a national procurement risk, and Ottawa has decided to close that gap with a certification requirement rather than a policy memo.

Level 1: The 13 Controls You Must Self-Assess Starting April 2026

Level 1 is the entry tier and applies to suppliers handling lower-sensitivity federal contract information. It is a self-assessment, not a third-party audit, but "self-assessment" does not mean informal. You are attesting, likely under a contractual certification clause, that your organization meets 13 specific safeguarding controls drawn from ITSP.10.171. Expect the usual basics done properly: access control tied to individual accounts, media handling and disposal procedures, physical protection of systems that process contract information, and basic system and communications protections like boundary firewalls and encrypted remote access.

The self-assessment window opens in April 2026, and by summer 2026 DND is expected to make Level 1 mandatory for select solicitations, meaning some suppliers will need a completed, dated self-assessment on file before they can even submit a bid. That is a narrow runway if you are starting from zero. For a full control-by-control breakdown of what Level 1 requires and how to document it, see our CPCSC Level 1 guide.

Level 2: The 97-Control Bar Coming April 2027

Level 2 is where CPCSC stops being a checklist and becomes a program. Ninety-seven controls across fourteen ITSP.10.171 families, covering everything from incident response and configuration management to risk assessment, security awareness training, and system integrity monitoring. Unlike Level 1, Level 2 is expected to require third-party assessment for suppliers handling more sensitive controlled information, which means external evidence review, not just an internal signature.

April 2027 sounds distant until you count backward. A genuine Level 2 program, policies written, controls implemented, evidence collected over a real operating period, typically takes nine to eighteen months to stand up properly. Suppliers who wait until the mandate date to start will be assessing against a moving target with no runway left to fix gaps the assessor finds.

What You Must Actually Produce to Bid

This is the part contracting officers care about and the part suppliers underestimate. A CPCSC self-assessment or certification is not a single signed form. To be bid-ready you need to produce, and be able to hand over on request:

  • A System Security Plan (SSP) that describes your IT environment, where controlled information lives, and how each applicable control is implemented
  • A Plan of Action and Milestones (POA&M) for any control not yet fully met, with realistic remediation dates
  • Evidence artifacts per control: configuration screenshots, access review logs, training completion records, vendor contracts for managed services, incident response test records
  • A completed self-assessment score or, at Level 2, a completed third-party assessment report
  • An internal record of who attested and when, since this becomes a contractual representation

Most suppliers we talk to in Toronto, Waterloo, and Ottawa's defence and advanced manufacturing corridors already have pieces of this scattered across IT tickets, email threads, and a firewall vendor's dashboard. The work is not usually building new security controls from scratch, it is consolidating scattered practice into a defensible, auditable record that maps cleanly to ITSP.10.171 control language.

The Timeline Pressure Nobody Is Talking About

Two dates matter and they are closer together than the headline framing suggests. Level 1 self-assessment goes live April 2026 and becomes mandatory for select DND solicitations by summer 2026, a gap of only a few months. Suppliers who treat "self-assessment" as low-stakes and put it off until a contract deadline forces the issue will find themselves attesting to controls they have not actually verified, which is a compliance risk in its own right if a prime or DND ever audits the claim.

Level 2 preparation should start now, not in 2027, precisely because third-party assessment capacity across Canada is limited and will get tighter as the mandate date approaches. Every defence-sector supplier in Canada is reading the same procurement notices on the same schedule. Assessor calendars will fill first with the suppliers who moved early.

How This Fits With PIPEDA and Existing Canadian Obligations

CPCSC does not replace your existing obligations under PIPEDA or, if you operate in Quebec, Law 25. It sits alongside them. A defence supplier handling both controlled contract information and Canadian personal data needs a security program that satisfies ITSP.10.171 control objectives while still meeting privacy-law breach notification and consent requirements. Suppliers who build their CPCSC evidence base with this overlap in mind avoid duplicating work later when a customer or regulator asks for privacy documentation separately from defence compliance documentation.

Where Suppliers Get Stuck

The recurring failure pattern we see is not technical, it is documentation and ownership. A supplier has reasonable technical controls in place but no one has written the SSP, no one owns the POA&M, and evidence lives in individual employees' inboxes rather than a controlled repository. When an assessor or a prime's compliance team asks for proof, the scramble begins. The fix is straightforward but takes real calendar time: assign an internal control owner, build the SSP against the actual ITSP.10.171 control list rather than a generic template, and start collecting evidence now so you have a real operating history to show, not a program built the week before assessment.

If you are bidding into DND-adjacent work from Vancouver, Calgary, Montreal, or anywhere else in the Canadian defence supply chain, the sequencing question is the same everywhere: get Level 1 self-assessment done well before the summer 2026 mandate, and start Level 2 groundwork now so April 2027 is a formality rather than a fire drill. Our broader compliance advisory work covers exactly this kind of framework mapping and evidence-program buildout for Canadian suppliers navigating multiple overlapping obligations at once.

traztech helps Canadian defence suppliers build CPCSC-ready security programs before the mandate dates hit, not after. Contact us to scope your Level 1 or Level 2 readiness timeline.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on locking down your startup without a big security team. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation