Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
/var/www/traztech.ca/html/blog/post.php on line 12748
22; color:
Warning: Undefined array key "Compliance" in /var/www/traztech.ca/html/blog/post.php on line 12748
;">Compliance

How to Get CPCSC: A Step-by-Step Guide

If you sell into Canada's defence supply chain, CPCSC is no longer a "someday" item on your compliance roadmap. The Canadian Program for Cyber Security Certification went live for Level 1 on April 1, 2026, and select DND contracts will require it starting summer 2026. If you're waiting for a contracting officer to ask for it before you start, you're already behind. Here's what the process actually looks like, step by step, with timelines you can plan around.

Step 1: Figure out which level applies to you

CPCSC has two tiers, and confusing them wastes months.

  • Level 1 covers 13 controls from ITSP.10.171 and is self-assessed. You attest to your own compliance, no external auditor required. This is the tier live now and mandatory in select DND contracts this summer.
  • Level 2 covers all 97 controls in ITSP.10.171 and requires third-party assessment. It doesn't become mandatory until April 2027, but the assessor capacity to deliver it is going to be scarce as that deadline approaches.

ITSP.10.171 is Canada's adaptation of NIST SP 800-171 Rev 3, so if you've already worked through US federal contracting requirements, a lot of the control language will look familiar. If you haven't, don't assume Level 1 is trivial just because it's self-assessed. Self-assessed doesn't mean self-graded on the honour system forever. Your customer, or a future auditor, can still ask for evidence.

Step 2: Determine your applicability and contract exposure

Before you touch a single control, find out whether CPCSC actually applies to your contracts, and at which level. Not every DND procurement will carry the requirement immediately, and the rollout is being staged by contract type and sensitivity of the data involved. Pull your active and upcoming DND-related contracts and check for CPCSC language or flow-down clauses. If you're a subcontractor, check whether the prime is passing the requirement down to you. This step alone determines whether you're racing a summer 2026 deadline or have more runway toward Level 2 in 2027.

Step 3: Scope your environment

Identify where controlled information actually lives and moves in your organization. That means mapping the systems, networks, and third-party services that touch relevant data, not your entire IT estate. Over-scoping is the single biggest cause of blown timelines and budgets in every framework we've worked with, and CPCSC is no exception. A tight, accurate scope keeps Level 1 to weeks instead of months.

Step 4: Gap-assess against the controls

With scope defined, walk each applicable control and document where you stand today: in place, partially in place, or not started. For Level 1's 13 controls, this is a manageable exercise for most small and mid-sized suppliers, especially if you already have basic security hygiene (access control, patching, logging) in place. For Level 2's full 97-control set, expect the gap assessment itself to take real effort, since it spans policy, technical configuration, and physical or personnel controls.

We've put together a control-by-control breakdown for the self-assessed tier if you want to work through this yourself before engaging anyone: our CPCSC Level 1 guide walks through all 13 controls in plain language.

Step 5: Remediate the gaps

This is where most of your calendar time goes. Typical remediation work for Level 1 includes tightening access controls, formalizing incident response procedures, enabling audit logging, and documenting configuration baselines. None of these are exotic, but they take time to implement properly and even more time to document in a way that will hold up to scrutiny. Budget several weeks for a small organization with reasonable existing controls, longer if you're starting from a thin security program.

Step 6: Document and attest (Level 1) or prepare for assessment (Level 2)

For Level 1, self-assessment means you formally attest that each control is met, backed by evidence you can produce if asked. Build your evidence package as you remediate, not after. Screenshots, policy documents, and configuration exports collected in the moment save you from a scramble later.

For Level 2, you'll need to prepare for a third-party assessor the same way you would for a SOC 2 audit or CMMC assessment: organized evidence, a system security plan, and staff who can speak to how controls actually operate day to day. Given assessor capacity constraints heading into the April 2027 deadline, book your assessment window early rather than waiting until the year mark.

Step 7: Submit and maintain

Once attested (Level 1) or assessed (Level 2), you're not done. Controls need to stay in place, not just get implemented once for the audit. Build a lightweight recurring review into your operations, quarterly for Level 1, more structured for Level 2, so you're not starting from zero at renewal.

Realistic timelines

For a small to mid-sized supplier with basic security practices already in place, Level 1 typically runs four to eight weeks from kickoff to attestation: a week or two for scoping and gap assessment, several weeks for remediation, and a final week for documentation and attestation. Organizations with weaker existing controls, or larger, more complex environments, should plan for longer.

Level 2 is a different order of effort given the jump from 13 to 97 controls plus the third-party assessment itself. If Level 2 applies to you, start scoping now rather than waiting for 2027 to feel close.

Where a partner actually helps

You can run Level 1 self-assessment on your own, and plenty of suppliers will. Where outside help pays off is in getting scope right the first time (so you're not remediating systems that were never in play), knowing which control interpretations hold up under scrutiny, and building an evidence package that doesn't need to be redone for Level 2 later. If DND compliance sits inside a broader push into regulated markets, it's worth looking at your compliance posture holistically rather than framework by framework. Our compliance advisory work covers exactly this kind of cross-framework planning, so CPCSC work you do now sets up cleanly for whatever comes next.

Get started

The summer 2026 mandatory window for Level 1 is close enough that "we'll get to it" is no longer a safe plan if DND contracts are part of your revenue. If you want a second set of eyes on your scoping or a hand through remediation and attestation, get in touch and we'll walk through where your organization stands today.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on the unglamorous side of building a startup. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation