Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Do You Actually Need CPCSC?

No, you do not need CPCSC unless you hold or are bidding on a Department of National Defence contract, or a contract with a prime contractor, that touches Federal Contract Information or Controlled Unclassified Information. If your revenue comes from commercial customers or non-defence government work, CPCSC is not a requirement, and chasing it now is usually a waste of budget better spent elsewhere.

That said, the answer is not always this clean. The Canadian Program for Cyber Security Certification is moving from voluntary to mandatory in stages through 2026 and 2027, and a lot of Ontario and Quebec suppliers who assume they are exempt are closer to the requirement than they think. Below is the honest breakdown of who needs it, who is over-buying, and what the actual timeline looks like.

What CPCSC Actually Is and Why It Exists

CPCSC is Canada's defence-sector cybersecurity certification program, modelled closely on the U.S. Cybersecurity Maturity Model Certification (CMMC). It maps to ITSP.10.171, which is the Canadian adaptation of NIST SP 800-171 Revision 3. The program has two tiers that matter for most businesses:

  • Level 1: 13 basic safeguarding controls, self-assessed. Live for self-assessment starting April 2026, becoming mandatory for select DND procurements in summer 2026.
  • Level 2: 97 controls aligned to ITSP.10.171, requiring a third-party assessment. Mandatory April 2027 for contracts involving Controlled Unclassified Information.

If you are unfamiliar with the control set itself, our CPCSC Level 1 guide breaks down all 13 controls in plain language.

Who Genuinely Needs CPCSC Right Now

You are in the "act now" category if any of the following is true:

  • You currently hold a DND prime contract or subcontract, or you are named on a bid that flows Federal Contract Information down through a prime.
  • You handle Controlled Unclassified Information (technical drawings, unclassified but sensitive defence data) as part of delivering a contract.
  • Your contracting officer or prime has already told you CPCSC will appear as a clause in an upcoming solicitation.
  • You are a defence-sector manufacturer, systems integrator, or IT services firm in the supply chain of a larger prime and renewal is coming up in the next 12 to 18 months.

For this group, waiting until the mandatory dates in 2026 and 2027 is a mistake. Level 2 assessments involve real lead time: documenting a System Security Plan, closing control gaps, and booking a third-party assessor once the assessor ecosystem matures. Starting the year before your contract renewal, not the month before, is the realistic timeline.

Who Is Over-Buying CPCSC

Here is where we see Canadian firms waste money. You probably do not need CPCSC yet if:

  • Your customers are entirely commercial, and you have no defence-sector pipeline in your business development plan.
  • You sell into other federal departments (not DND) and have not been told a CPCSC clause is coming.
  • You are a SaaS company selling to enterprise or mid-market customers where SOC 2 is the actual gate being asked for in security questionnaires.
  • You are pursuing CPCSC "to be safe" without a specific contract or bid in mind.

We have talked to founders in Toronto and Waterloo who assumed CPCSC was a general-purpose Canadian security credential because it gets bundled into compliance conversations alongside SOC 2 and ISO 27001. It is not. It is a defence procurement requirement tied specifically to DND and its supply chain. If your growth motion is U.S. enterprise SaaS deals, the certification your buyers actually ask for is SOC 2, not CPCSC. Our compliance solutions overview covers how SOC 2, ISO 27001, and CPCSC differ and which one maps to which buyer.

The Middle Ground: Prime Contractors and Subcontractors

A large share of confusion sits with subcontractors who are one or two steps removed from DND. If you supply parts, software, or services to a prime contractor in Ottawa, Montreal, or Calgary and that prime is defence-focused, CPCSC requirements flow down through your contract even if you never deal with DND directly. Ask your prime two direct questions: what CUI or FCI does our contract involve, and has a CPCSC clause been added or flagged for a future solicitation. Their answer, not a general read of the DND supplier list, should drive your timeline.

CPCSC Level 1 vs Level 2: Which One Applies to You

Level 1's 13 controls cover basic safeguarding: access control, identification, media protection, and physical security fundamentals. It is self-assessed, meaning no external auditor is required, but the attestation is still submitted and can be checked. Most FCI-handling subcontractors will land here first.

Level 2's 97 controls are a different order of effort. They require documented policies, a System Security Plan, and a third-party assessment against the full ITSP.10.171 control set. This tier applies to organizations handling CUI, typically primes and larger subcontractors with deeper access to sensitive program data. If your work only ever touches FCI, you likely stay at Level 1 indefinitely.

What to Do If You Are Not Sure Yet

If you cannot answer whether your contracts involve FCI or CUI, that is the first question to resolve, not the control mapping. Talk to your contracting officer or prime's security team before engaging a consultant or buying a compliance platform. A short scoping conversation costs nothing and prevents both of the expensive mistakes we see: certifying too late for a contract you were always going to need it for, and certifying an organization that will never touch a DND contract.

For Canadian technology and defence-adjacent firms across Toronto, Ottawa, Waterloo, Montreal, and Vancouver, this scoping question also needs to sit alongside your existing obligations under PIPEDA and, for Quebec-based operations, Law 25. CPCSC does not replace those requirements, it sits on top of them, so the control work often overlaps with privacy and general security hygiene you should already have in place.

Getting Started Without Over-Investing

If you have confirmed you need CPCSC, the practical path is: scope which level applies based on FCI versus CUI exposure, run a gap assessment against the relevant control set, and fix the gaps before your contract's mandatory date, not after. Do not buy a full Level 2 program if your contracts only ever expose Level 1 data. Do not delay past 2026 if a DND contract renewal is already on your calendar for 2027.

traztech works with Canadian defence-sector suppliers and their primes to scope CPCSC readiness honestly, telling you when you do not need it as readily as when you do. If you are unsure where your organization falls, get in touch and we will walk through your contract exposure before recommending any certification work.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on locking down your startup without a big security team. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation