If you sell into Canada's defence supply chain, CPCSC is no longer a "someday" compliance project. The Canadian Program for Cyber Security Certification has real dates attached to it now, and the first one is close. This checklist covers what's actually required at each level, so you can figure out where your organization stands and what to do next.
What CPCSC is, in plain terms
CPCSC is Canada's answer to the US CMMC program. It sets cybersecurity requirements for contractors and subcontractors handling controlled information for the Department of National Defence. The technical baseline is ITSP.10.171, which is the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171 Revision 3. If your organization has already looked at US defence contracts, the control language will feel familiar. If you haven't, the checklist below breaks it into plain steps.
Level 1 checklist: 13 controls, self-assessed
Level 1 is the entry point. It applies to contractors handling less sensitive controlled information, it's self-assessed (no third-party auditor required at this level), and it becomes mandatory in select DND contracts starting summer 2026. The requirement goes live April 1, 2026. Here's what's actually on the list:
- Access control basics. Limit system access to authorized users, processes, and devices. This means named accounts, no shared logins, and access reviewed on a schedule rather than set once and forgotten.
- Authentication and identification. Uniquely identify every user and device before granting access. Multi-factor authentication belongs here for any remote or privileged access.
- Media protection. Control and sanitize media (USB drives, backups, decommissioned hardware) that contains controlled information before disposal or reuse.
- Physical protection. Limit physical access to systems and facilities where controlled information is processed or stored, including visitor logging.
- System and communications protection. Monitor and control communications at system boundaries, and segment networks so controlled information isn't sitting in a flat, unsegmented environment.
- System and information integrity. Identify, report, and correct system flaws in a defined timeframe, and maintain malware protection that's actually kept current.
Those six areas cover the 13 controls at Level 1. The bar is deliberately low: most of it is documented policy plus basic technical hygiene, not new tooling. The catch is the self-assessment has to be honest and evidenced. If you're preparing for the April 2026 deadline, our CPCSC Level 1 guide walks through each control with the specific evidence assessors and contracting officers expect to see.
Level 2 checklist: 97 controls, third-party assessed
Level 2 is a different scale of effort. It covers all 17 control families in ITSP.10.171, roughly 97 controls in total, and it requires assessment by an accredited third party rather than self-attestation. The requirement takes effect April 2027, which sounds far off but isn't once you account for assessor scheduling and remediation time. Level 2 builds on everything in Level 1 and adds:
- Audit and accountability. Centralized logging, log retention, and the ability to trace an action back to a specific user and timestamp.
- Configuration management. Baseline configurations for systems, change control processes, and restrictions on unauthorized software.
- Incident response. A documented, tested incident response capability, not just a policy document that's never been rehearsed.
- Risk assessment. Periodic assessment of risk to organizational operations and data, with findings that actually feed into remediation.
- Security assessment. Ongoing assessment of security controls, including plans of action for anything that doesn't pass.
- System and services acquisition. Security requirements built into the procurement and development lifecycle for systems and software.
- Personnel security. Screening prior to granting access to controlled information, and formal offboarding procedures when access needs to be revoked.
- Awareness and training. Role-based security training, not a single onboarding slide deck.
- Maintenance. Controlled and logged maintenance activities on systems that touch controlled information.
The jump from Level 1 to Level 2 is significant, both in control count and in the fact that a third party has to verify your evidence rather than take your word for it. Organizations that treat Level 1 as a checkbox exercise usually find Level 2 painful. Organizations that build a real control environment for Level 1 have a foundation they can extend.
How to use this checklist
A few practical notes on working through it:
- Start with a gap assessment. Map what you already have against the control list above before buying anything new. Most organizations already meet several controls partially through existing IT practices.
- Document as you go. Self-assessment at Level 1 still requires evidence. Policies, configuration screenshots, access review logs, keep them as you implement rather than trying to reconstruct them later.
- Don't wait for the mandatory date to start. Summer 2026 DND contracts will require Level 1 compliance already in place, not compliance in progress. If you're bidding on or renewing defence contracts, the planning window is now.
- Think about Level 2 even if you only need Level 1 today. If your roadmap includes larger DND contracts, architectural decisions you make for Level 1 (network segmentation, logging, identity management) are cheaper to build right once than to redo eighteen months later.
CPCSC sits alongside other frameworks Canadian companies are navigating right now, from SOC 2 for commercial buyers to sector-specific requirements. If you're mapping CPCSC against a broader compliance roadmap, our compliance advisory services page outlines how we help organizations sequence multiple frameworks without duplicating work.
Have questions about where your organization stands against Level 1 or Level 2, or need help building an evidence-ready control set before the mandatory date lands? Get in touch and we'll walk through your current environment and what CPCSC actually requires for your contracts.