Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

How Long Does CPCSC Take? A Realistic Timeline

From a cold start with no prior compliance work, most Canadian defence contractors need three to six months to reach CPCSC Level 1 self-assessment readiness, and nine to fourteen months to reach Level 2 third-party certification. The exact number depends on how many of the controls you already have in place and how fast your team can move on remediation.

CPCSC (the Canadian Program for Cyber Security Certification) is Canada's adaptation of the US CMMC framework, built on ITSP.10.171, which itself maps to NIST SP 800-171 Revision 3. Level 1 covers 13 controls and became available for self-assessment in April 2026. It becomes mandatory for select Department of National Defence (DND) contracts in summer 2026. Level 2, with 97 controls, requires third-party assessment starting April 2027. If you supply DND or work anywhere in the defence supply chain, the timeline questions are no longer hypothetical.

Phase 1: Scoping and Gap Assessment (Weeks 1 to 4)

Every realistic CPCSC timeline starts with scoping. You need to know exactly which systems, networks, and data flows touch controlled information before you can assess anything against ITSP.10.171. Companies that skip this step end up remediating controls that were never in scope, which is the single biggest source of wasted effort we see.

  • Identify where Controlled Unclassified Information (or its Canadian equivalent) lives across your environment
  • Map that scope against the 13 Level 1 controls or the full 97-control Level 2 set
  • Run a gap assessment against ITSP.10.171 to see what you already satisfy through existing security practices

Firms already running a decent security baseline, endpoint management, access controls, basic logging, often clear this phase in two to three weeks. Firms starting from scratch, particularly smaller manufacturers and subcontractors who have never had a formal information security program, can take a full month just to inventory their environment. Our CPCSC Level 1 guide walks through the 13 controls in detail if you want to self-check before engaging anyone.

Phase 2: Remediation and Control Implementation (Weeks 4 to 16)

This is where most of the timeline variance lives. Gap assessments routinely turn up the same handful of missing pieces: multi-factor authentication that is not universally enforced, incident response plans that exist on paper but were never tested, asset inventories that are out of date, and access reviews that happen informally instead of on a documented cadence.

For Level 1's 13 controls, a small to mid-size contractor with reasonable IT hygiene can typically close gaps in six to eight weeks. Level 2's 97 controls are a different scale of work. Expect four to six months of sustained remediation, particularly around configuration management, system and communications protection, and the documentation burden that comes with a System Security Plan (SSP) and Plan of Action and Milestones (POA&M) for anything not yet fully implemented.

Phase 3: Documentation, SSP, and POA&M (Weeks 12 to 20)

CPCSC assessors, whether it is your own team for Level 1 self-assessment or a certified third-party assessor organization for Level 2, are not just checking whether controls exist. They are checking whether you can prove it. That means:

  • A System Security Plan describing how each control is implemented in your specific environment
  • A Plan of Action and Milestones tracking any control not yet fully in place, with dates
  • Evidence artifacts: configuration exports, policy documents, training records, log samples

This phase overlaps heavily with remediation rather than following it in strict sequence. Companies that write documentation as they implement controls, instead of trying to reconstruct it afterward, consistently finish four to six weeks faster.

Phase 4: Level 1 Self-Assessment Submission

Level 1 does not require an external assessor. Once your 13 controls are implemented and documented, you self-assess and submit. From a cold start, companies with dedicated internal ownership of the process reach submission in three to four months. Companies juggling CPCSC alongside other priorities, which describes most small and mid-size defence suppliers, more realistically land at five to six months.

The main thing that stalls Level 1 timelines is not technical difficulty, it is sequencing. Teams that wait for a procurement deadline to start scoping consistently run out of runway. Given that mandatory Level 1 compliance for select DND contracts lands in summer 2026, starting now rather than in Q4 is the difference between a controlled rollout and a scramble.

Phase 5: Level 2 Third-Party Certification (Months 6 to 14)

Level 2 adds a mandatory external assessment, which introduces scheduling dependencies you cannot fully control. After remediation and documentation are complete, expect:

  • Four to eight weeks to select and schedule a certified third-party assessor
  • Two to four weeks for the assessment itself, longer for complex or multi-site environments
  • Two to six weeks for remediation of any findings and re-verification before certification is issued

Add it up and a company starting Level 2 preparation with zero prior compliance work should plan for nine to fourteen months end to end. Companies that already hold ISO 27001, SOC 2, or a mature NIST 800-171 program routinely compress this to six to eight months, because the bulk of the technical and documentation work already exists and just needs to be mapped to ITSP.10.171 terminology and evidence formats.

What Actually Compresses the CPCSC Timeline

A few factors separate companies that hit their target date from ones that miss it by a quarter or more:

  • Existing security maturity. Prior SOC 2, ISO 27001, or even a disciplined internal security program cuts remediation time substantially, since many controls overlap directly.
  • Dedicated ownership. A single accountable person or small team driving the process beats a distributed "everyone owns a piece" model every time. Diffuse ownership is the most common cause of stalled timelines we see.
  • Scoping discipline. Tightly scoping which systems actually touch controlled information, rather than defaulting to "the whole network," shrinks both the control count and the evidence burden.
  • Assessor scheduling for Level 2. Third-party assessor capacity is finite and demand will spike as the April 2027 mandatory date approaches. Booking early avoids a queue.
  • Writing documentation in parallel, not after. SSPs and POA&Ms written alongside implementation, instead of reconstructed at the end, save weeks.

Where Canadian Defence Contractors Stand Today

We work with defence suppliers and subcontractors across Toronto, Ottawa, and Waterloo, three regions with dense concentrations of aerospace, defence electronics, and dual-use technology firms feeding the DND and allied supply chains. The pattern is consistent regardless of city: firms that treat CPCSC as a compliance checkbox tend to underestimate the documentation phase, while firms that treat it as a security program upgrade, one that also happens to satisfy PIPEDA obligations and general due-diligence expectations from prime contractors, get more durable results and often move faster because the work has organizational buy-in beyond a single deadline.

Quebec-based suppliers have an added layer, since privacy program work for CPCSC evidence (access controls, data handling, breach response) should already be aligned with Law 25 obligations rather than built as a separate track.

Building a CPCSC Timeline That Fits Your Contract Deadlines

The honest answer to "how long does CPCSC take" is that it depends more on organizational readiness than on the framework itself. A company with clean scoping, an existing security baseline, and one accountable owner can hit Level 1 in three months. A company starting from zero, with controls scattered across departments and no one driving the process, should budget closer to six. Level 2 stretches that range further because of mandatory third-party assessment scheduling.

If you supply DND directly or sit anywhere in a defence prime's supply chain, the practical move is to start your gap assessment now, before the summer 2026 mandatory date for select contracts forces a rushed timeline. See our compliance solutions for how we structure CPCSC engagements alongside other frameworks, and contact traztech to scope your CPCSC timeline and get a realistic date on the calendar.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on locking down your startup without a big security team. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation