If you sell to Canada's Department of National Defence, or to a prime contractor that does, you have probably run into the term CPCSC in a bid document and wondered what it actually requires. CPCSC stands for the Canadian Program for Cyber Security Certification. It is Canada's answer to the United States' CMMC program, and it is becoming a condition of doing business in the federal defence supply chain. This guide explains what it is, who needs it, what the work involves, and the realistic timeline, without the jargon.
What CPCSC actually is
CPCSC is a certification framework that verifies a contractor's cybersecurity controls before it can handle certain categories of DND information. It is built on ITSP.10.171, which is the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171 Revision 3, the American standard for protecting Controlled Unclassified Information. If your organization already has exposure to US federal contracting or CMMC, the control language will feel familiar. If you do not, think of it as a formal checklist of security practices, access control, incident response, system monitoring, and so on, that DND wants proof you follow before it lets you near sensitive but unclassified information.
The program has two levels, and the difference between them matters a lot for planning.
- Level 1 covers 13 controls drawn from ITSP.10.171. It is self-assessed, meaning your organization attests to compliance rather than bringing in an outside auditor. Level 1 becomes active April 1, 2026, and DND has signalled it will be mandatory in select contracts starting summer 2026.
- Level 2 covers the full set of 97 controls from ITSP.10.171 and requires third-party assessment by an accredited body, similar to how a SOC 2 audit works. Level 2 is scheduled for April 2027.
In practice, most defence suppliers will need to clear Level 1 first and then build toward Level 2 as contracts require it. We break down the Level 1 control set and how to approach it in our CPCSC Level 1 guide, which is worth reading before you start any assessment work.
Who actually needs this
CPCSC is not limited to companies that sell directly to DND. If you are a subcontractor, a software vendor, a manufacturer, or a services firm anywhere in a defence prime's supply chain, and you touch information the prime considers sensitive, you can be required to certify. This includes small and mid-sized Canadian firms that may never have thought of themselves as "defence contractors" but supply parts, software, or IT services to one.
A common misconception is that CPCSC only applies to companies handling classified information. It does not. The scope is Controlled Unclassified Information, which covers a much wider range of everyday business data, technical drawings, personnel records, logistics data, and more, than most companies assume. If your contract or your prime's flowdown clauses mention protecting DND information, assume CPCSC applies to you until you confirm otherwise.
What the work actually involves
At Level 1, you are implementing and documenting 13 specific security practices and then attesting that you meet them. That typically means:
- Mapping where DND-related information lives in your environment
- Reviewing access controls, so only authorized people can reach that information
- Confirming basic technical safeguards are in place, such as identification and authentication practices, media protection, and physical security
- Documenting your practices so the self-assessment holds up if it is later reviewed
Level 2 is a heavier lift. Ninety-seven controls means a much broader set of technical, administrative, and physical safeguards, plus the added step of a third-party assessor validating your work. Organizations that have been through a SOC 2 audit will recognize the shape of this process, though the control content is different. If you are already working toward SOC 2 or another compliance framework, there is real overlap you can leverage rather than starting from zero. Our compliance readiness services are built around finding that overlap so you are not duplicating effort across frameworks.
Realistic timeline
This is where CPCSC gets time-sensitive. Level 1 goes live April 1, 2026, and DND has already indicated it will start appearing as a mandatory requirement in select contracts by summer 2026. That is not a distant deadline. If you have not started mapping your environment against the 13 Level 1 controls, now is the time, because self-assessment still requires real implementation work, evidence gathering, and internal sign-off before you can attest with confidence. Level 2, with its 97 controls and third-party assessment requirement, arrives April 2027. That sounds far off, but third-party assessments require scheduling with accredited assessors, and organizations that wait until late 2026 to start preparing risk finding themselves in a queue with everyone else in the supply chain.
Common misconceptions worth clearing up
A few things trip people up consistently. First, CPCSC is not optional if your contract requires it, and "we will get to it later" is not a strategy once a bid depends on certification. Second, Level 1 self-assessment does not mean informal or unverifiable. DND can request evidence, and a self-assessment built on assumptions rather than documented practice will not survive scrutiny. Third, CPCSC and CMMC are related but not identical. If you already hold CMMC certification, it will inform your CPCSC work, but it is not a direct substitute.
Where to start
If you sell into the defence supply chain, or you suspect a prime contractor's flowdown clauses might pull you in, the first step is a gap assessment against the Level 1 control set. That tells you exactly where you stand and how much work is realistically ahead of you before the summer 2026 mandate window opens. Traztech works with Canadian companies navigating CPCSC, SOC 2, and related compliance requirements, mapping practical implementation paths rather than generic checklists. If you want a straight answer on where your organization stands and what CPCSC Level 1 will actually take, get in touch and we will walk through it with you.