Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

CPCSC vs CMMC: What Canadian Defence Suppliers Need to Know

If you have followed U.S. defence procurement, the Canadian Program for Cyber Security Certification (CPCSC) will feel familiar. It is deliberately modelled on the U.S. Cybersecurity Maturity Model Certification (CMMC). But familiar is not identical, and assuming the two are interchangeable is how Canadian suppliers waste money. Here is what carries over and what does not.

What they share

Both programs exist for the same reason: governments want their defence supply chains to protect sensitive but unclassified information, and self-policing did not work. Both are tied to the right to bid. No certification, no contract. Both use a tiered model where the level required scales with the sensitivity of the information. And both trace their controls back to the same root: NIST SP 800-171.

Because of that shared root, the underlying security practices overlap heavily. Access control, multi-factor authentication, media sanitization, boundary protection, and flaw remediation appear in both. If you have done CMMC work, most of the actual engineering transfers.

Where they differ

The standard. CMMC points at NIST SP 800-171 directly. CPCSC points at ITSP.10.171, the Canadian Centre for Cyber Security's own profile of 800-171. The control intent is nearly the same, but the document you cite in your evidence, and the language your assessor uses, is Canadian.

The governance. CMMC is administered through the U.S. Department of Defense and its accreditation body. CPCSC is run by Public Services and Procurement Canada, with certification bodies accredited by the Standards Council of Canada and the highest level assessed by National Defence. Different regulators, different accreditation chains.

The levels. CMMC has three levels. So does CPCSC, but the breakdown is its own: Level 1 is a 13-requirement self-assessment, Level 2 is an external assessment by an accredited certification body at 98 requirements, and Level 3 is a National Defence-led assessment at roughly 200 requirements.

The attestation platform. CMMC reporting flows through U.S. systems like SPRS. CPCSC Level 1 is attested through the Canada Buys procurement platform. Practically, this matters: your team needs to be set up in the Canadian system, not the American one.

Can one certification cover both?

Not automatically. A CMMC certification does not grant you CPCSC certification or vice versa. They are separate programs with separate attestations. However, because the control sets overlap so much, the evidence you build for one dramatically shortens the work for the other. A supplier that has done CMMC Level 2 is in a strong position to reach CPCSC Level 2, and most of the gap is mapping and re-documentation rather than new controls.

What this means if you sell to both governments

Build your control program once, to the stricter of the two standards that apply to you, and maintain a single evidence library. Then map that library to each program's requirements and complete each attestation in its own platform. Suppliers who treat CPCSC and CMMC as two entirely separate projects pay twice. Suppliers who treat them as one control program with two attestations pay once and a bit.

The Canadian side is the newer of the two and is rolling out in phases through 2026, so the window to get ahead of it is open now. We help Canadian suppliers get CPCSC-ready, and we reuse existing CMMC or SOC 2 evidence wherever it maps.

Selling to Canadian and U.S. defence?

We map your existing compliance evidence to CPCSC so you do not rebuild controls you already have. One control program, both attestations.

Talk to us

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on CMMC and CPCSC. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

6
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
15+
Penetration testing engagements delivered

Published vulnerability research

Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.

A SOC 2 Type II built from nothing

Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.