Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

CPCSC Level 1 for Canadian Defence Suppliers: The 13 Requirements and the Self-Assessment

Direct answer: CPCSC Level 1 is the entry level of the Canadian Program for Cyber Security Certification, introduced by Public Services and Procurement Canada in April 2026 for companies that supply the Department of National Defence. It is an annual self-assessment against 13 security requirements drawn from ITSP.10.171, Canada's adaptation of NIST SP 800-171. Level 1 is required only where a contract says so, and it is required at contract award rather than at bid. The 13 requirements overlap heavily with CyberSecure Canada, so much of the work counts twice.

What CPCSC is

The Canadian Program for Cyber Security Certification was announced in March 2025 to protect sensitive, unclassified government information held by defence suppliers. It has three levels:

  • Level 1: an annual self-assessment by the supplier.
  • Level 2: an external assessment by an accredited certification body.
  • Level 3: an assessment by National Defence for the most sensitive work.

The original plan phased the levels into contracts over 2025 to 2027. In practice Level 1 was introduced in April 2026, later than first announced. The Government of Canada pages are the authority on which contracts include the requirement and when the higher levels arrive. We have not seen published dates for Level 2 and Level 3 in contracts, so we do not quote any.

The important procurement detail from the original announcement: certification is needed at contract award, not when you bid. That gives a supplier some room, but not much. A contract award is not the time to discover you do not have MFA on your email.

The standard behind it: ITSP.10.171

ITSP.10.171 is the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171 Revision 3, the US standard for protecting controlled unclassified information. The requirement identifiers follow the NIST numbering, which is why they look like 03.01.01. The first two digits after 03 name the family: 01 access control, 05 identification and authentication, 08 media protection, 10 physical protection, 13 system and communications protection, 14 system and information integrity.

Level 1 takes 13 requirements from six of those families. Level 2 is expected to cover the rest of the standard.

The 13 Level 1 requirements

The identifiers and names below are from the Government of Canada CPCSC Level 1 page. The notes after each are our practical reading of what an assessor will want to see.

Access control

  • 03.01.01 Account management. Every account is authorized, has an owner, and is removed when the person leaves or no longer needs it. Evidence: an account list reconciled against staff, and leaver tickets.
  • 03.01.02 Access enforcement. The system actually enforces who can reach what. Evidence: role or group configuration showing that sensitive folders and systems are restricted.
  • 03.01.20 Use of external systems. Rules for personal devices, home computers and outside services that touch contract information. Evidence: a written rule and the technical control that backs it, such as blocking unmanaged devices.
  • 03.01.22 Publicly accessible content. Nothing sensitive is posted publicly, and someone reviews what is. Evidence: a named reviewer and a check of the website and public repositories.

Identification and authentication

  • 03.05.01 User identification, authentication and re-authentication. Unique accounts, no shared logins, and sessions that require signing in again. Evidence: identity provider settings.
  • 03.05.02 Device identification and authentication. Only known devices connect. Evidence: a device inventory and the control that enforces it, such as device management or certificate-based Wi-Fi.
  • 03.05.03 Multi-factor authentication. MFA on accounts that reach contract information. Evidence: an MFA enrolment report with no gaps, or documented exceptions.

Media protection

  • 03.08.03 Media sanitization. Drives, laptops and removable media are wiped or destroyed before disposal or reuse. Evidence: a procedure and destruction or wipe records.

Physical protection

  • 03.10.01 Physical access authorizations. A list of who may enter the places where contract information is handled. Evidence: the authorized list and how it is maintained.
  • 03.10.07 Physical access control. Doors, locks or badges that enforce the list, and visitor handling. Evidence: badge system records or key logs, and a visitor log.

System and communications protection

  • 03.13.01 Boundary protection. Firewalls and controlled connections at the edge of your network and cloud. Evidence: firewall rules and a network diagram.

System and information integrity

  • 03.14.01 Flaw remediation. Patching on a defined timeline. Evidence: patch reports from your device management tool and an exception list.
  • 03.14.02 Malicious code protection. Anti-malware or endpoint protection on every relevant device, kept current. Evidence: a console export reconciled to the device inventory.
Need CyberSecure Canada as well? We assess CPCSC Level 1 on the same engagement as CAN/DGSI 104, so evidence collected once covers both. CyberSecure Canada and CPCSC readiness

How the self-assessment works

Level 1 is a self-assessment, which is easy to misread as a form you tick. It is not. The assessment methods come from the NIST SP 800-171A approach: examine (look at documents and configuration), interview (ask the people who run the control), and test (try it). Each requirement breaks into assessment objectives, and a requirement is met only when every objective is.

Three practical points:

  • It is your company speaking. A self-assessment is a statement by your company to the Government of Canada. Have someone senior review it, and treat it with the same care as any other representation in a contract.
  • Keep the evidence behind every answer. If you are asked how you met 03.05.03, "we have MFA" is a claim. An enrolment report dated the week you assessed is evidence.
  • It is annual. The result has to be renewed each year, which means the controls have to keep operating, not just exist on the day you assessed.

Free weekly email

Get The Compliance Brief every Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Scoping: where contract information lives

The most useful thing a small supplier can do is decide where contract information is allowed to live. If it can be anywhere, every laptop, every shared drive and every personal phone is in scope. If it is confined to a defined set of accounts, devices and storage, the assessment covers that set.

Draw the boundary first, write it down, and make the technical controls enforce it. A separate tenant or a restricted site for defence work is common for exactly this reason. Then run the 13 requirements against the boundary rather than against the whole company.

How CPCSC Level 1 relates to CyberSecure Canada

They are different programmes with different owners. CPCSC is a defence procurement requirement run by Public Services and Procurement Canada. CyberSecure Canada is a voluntary certification for small and medium organizations against CAN/DGSI 104, audited by certification bodies accredited by the Standards Council of Canada. Holding one does not give you the other.

The control overlap is large. Account management and least privilege, MFA, patching, anti-malware and boundary protection are all baseline controls in CAN/DGSI 104. Media sanitization appears in its portable media clause. Where the two differ, CPCSC Level 1 is more specific about physical access and device identification, and CyberSecure Canada asks for organizational controls such as a named accountable leader, training, a risk assessment, an incident response plan and tested backups, which CPCSC Level 1 does not list.

For a defence supplier that also has commercial buyers asking for evidence, doing both at once is efficient. The evidence for the shared controls is collected once and mapped to both. Read our guide to CyberSecure Canada certification for the other half.

What drives the effort

  • Boundary. A tight, enforced boundary is the biggest single reduction in effort.
  • Identity. If MFA and unique accounts are already universal, three requirements are mostly paperwork. If not, they are a rollout.
  • Device management. Device identification, patching and anti-malware evidence all come from one place if devices are managed, and from nowhere if they are not.
  • Physical sites. An office with badge access and a visitor log is straightforward. A shop floor or shared building takes more thought.
  • Your IT provider. If a managed service provider operates your environment, their reports are your evidence.

Our CPCSC Level 1 check is from $1,500. It assesses each of the 13 requirements against your boundary and gives you a findings list and the evidence each answer needs. Where you also need CyberSecure Canada, we assess both in one engagement.

Frequently asked questions

Do I need CPCSC Level 1 to bid on a defence contract?

Only if the contract requires it, and the requirement applies at contract award rather than at bid. Read the solicitation, and check the Government of Canada CPCSC pages for current guidance, because the programme is still being phased in.

Is a self-assessment really enough?

For Level 1, yes, that is the design. It still has to be true. Keep evidence for every requirement, because a false attestation in a government contract is a far bigger problem than a gap you disclosed and fixed.

Does CyberSecure Canada certification satisfy CPCSC?

No. They are separate programmes. The work overlaps heavily, so preparing for one does most of the preparation for the other, but each has its own result.

How long does Level 1 take?

It depends on the boundary and on whether identity and device management are already in place. If they are, the work is mostly evidence. If they are not, the rollout sets the pace. We give you a range after the check rather than a date up front.

Supplying National Defence? We check the 13 Level 1 requirements against your boundary and map the same evidence to CyberSecure Canada where you need both.

CyberSecure Canada and CPCSCOr run the readiness checker

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.