Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Buyer’s guide · 2026

Top CPCSC readiness
providers in Canada.

Level 1 becomes mandatory in select Department of National Defence contracts in Summer 2026. Here is who offers readiness work, what each one publishes, what it costs, and how to tell which level you actually need.

CPCSC Level 1 becomes a mandatory requirement in select Department of National Defence contracts in Summer 2026. Level 2, which is externally assessed, follows behind it. If you supply the Government of Canada and you are not certified at the level your contracts require, you do not get to bid.

That deadline has produced a market. PwC Canada launched a dedicated readiness service and put out a press release about it. Several Canadian security firms have stood up CPCSC practices. This guide is our attempt to make the choice legible: how to evaluate a provider, who is actually offering the work, what it costs, and where each option including ours is the wrong answer.

We rank ourselves in this list. We have put ourselves where we think we belong rather than at the top, and every firm here gets the same treatment: what they do well, who they suit, and what to watch for.

First, the thing most buyers get wrong

CPCSC is not one certification. It is three levels, and the level you need is set by the contract, not by your ambition.

Level 1 covers 13 security requirements across 6 control families and is a self-assessment. You attest, you submit, nobody visits. It is a few weeks of honest work for most SMBs.

Level 2 covers all 98 requirements in ITSP.10.171 across 17 control families and is assessed by an accredited third party. It is a programme, not a project, and the runway is measured in quarters.

The expensive mistake is buying Level 2 effort for a Level 1 obligation, or discovering at bid time that the contract needs Level 2 and you scoped for Level 1. Before you speak to any provider, establish which of your contracts carry which requirement. A provider who does not ask that question in the first conversation is not paying attention.

The second mistake is treating CPCSC as a documentation exercise. ITSP.10.171 is CCCS guidance derived from NIST SP 800-171 Revision 3. The requirements are technical and operational, and at Level 2 an assessor will look for evidence the controls ran, not statements that they exist.

How to evaluate a CPCSC provider

Seven criteria, in the order they matter. Apply them to us as readily as to anyone else.

1. Do they establish your level before quoting? The single best signal. Scope determines everything downstream, and a quote issued before the contract review is a guess.

2. Can they draw the boundary? CPCSC applies to the systems that handle federal Specified Information, not automatically to your whole company. A provider who can help you narrow the boundary defensibly will save you more money than any discount, because every system inside it carries 98 requirements at Level 2.

3. Do they do the remediation, or only tell you about it? There is a real difference between a gap assessment and a programme. Assessment-only engagements are cheaper and leave you holding the work.

4. Do they understand the CMMC relationship? CPCSC and the US CMMC programme both trace to NIST SP 800-171. If you sell on both sides of the border, a provider who scopes them together saves you doing the same control work twice.

5. Are they independent of the assessment? A certification body assesses. A readiness firm prepares. The same organisation should not do both for you, and any provider blurring that line is worth questioning.

6. Do they publish a price? Not every firm can, and complex scopes genuinely vary. But a published floor tells you the engagement is productized rather than open-ended, and it lets you compare without three discovery calls.

7. Canadian presence and defence familiarity. This is Canadian federal procurement. Familiarity with the contracting environment matters more here than in a commercial SOC 2.

Who offers CPCSC readiness in Canada

Listed with what each publishes about itself. Facts taken from their own pages in August 2026; pricing is shown where a firm publishes it and marked as not disclosed where it does not.

FirmLevelsModelPublished priceBest fit
PwC CanadaReadiness and advisoryBig 4 advisoryNot disclosedLarge primes, complex group structures
Kobalt.ioLevel 1 and Level 2Managed programmeUSD $5,000 L1; from $4,500/mo L2SMBs wanting a run-for-you programme
Truvo CyberAll levels, Level 2 emphasisAssess, build, operateNot disclosedDual CPCSC and CMMC scope
PlurilockReadiness servicesFull-spectrum security vendorNot disclosedBuyers wanting tooling and readiness together
traztechLevel 1 and Level 2Fixed-scope readinessFrom $3,000 gap analysisSMB suppliers needing a defined scope and price

PwC Canada

What they do well. PwC launched a dedicated CPCSC Readiness and Advisory Service and has the bench to handle a large supplier with multiple business units and a complicated contract portfolio. Their published approach starts with confirming scope by identifying affected contracts, data flows and business units, which is the right first step.

Best fit. Large primes, organisations with group structures, and anyone who needs the name on the engagement letter for internal reasons.

Caveats. No published pricing. Big 4 engagements generally start well above what an SMB supplier expects, and the person who scopes the work is frequently not the person who runs it.

Kobalt.io

What they do well. The most price-transparent provider in this list. They publish a Level 1 programme at USD $5,000 over roughly 30 days, and a Level 2 programme from $4,500 per month over twelve, including a GRC platform and a named team. Their public position that "most Canadian SMBs should start Level 1 immediately and plan the runway to Level 2" is sound advice.

Best fit. SMBs who want a managed programme with a monthly cadence and a platform included.

Caveats. Vancouver-based. Pricing is in USD, which is a real difference for a Canadian defence supplier budgeting in CAD. The Level 2 model is a twelve-month monthly commitment, which suits some buyers and not others.

Truvo Cyber

What they do well. Ottawa-based, which is meaningful for federal defence work, with CISSP and GIAC-credentialed leadership and stated experience across Canadian critical infrastructure. They scope CPCSC and CMMC together for suppliers selling into both countries, and publish an estimated four to six months from assessment to certification readiness.

Best fit. Suppliers with dual Canadian and US defence obligations.

Caveats. Pricing is quote-only. Their phased model runs into an ongoing "operate" stage, so establish early whether you are buying a project or a retainer.

Plurilock

What they do well. A full-spectrum security vendor rather than a pure compliance shop, so where a readiness assessment surfaces a technology gap they can implement as well as document.

Best fit. Organisations that expect to buy security tooling alongside the readiness work.

Caveats. No published CPCSC pricing. A vendor that also sells the remediation technology has an interest in what the assessment recommends, which is worth naming even where it is handled well.

traztech

What we do well. Fixed scope and published prices: CPCSC readiness starts from a $3,000 gap analysis, and every SKU is on our pricing page. We run Level 1 self-assessment and Level 2 readiness against ITSP.10.171, and we run CPCSC alongside SOC 2 or ISO 27001 where a supplier needs both, mapping the overlap once rather than twice. The work is led by a researcher with six published CVEs, including a CVSS 9.1 in the Mirai botnet. You also get traztech Workspace free, with the CPCSC control sets already loaded, and you keep it afterwards.

Best fit. Canadian SMB suppliers who want a defined scope, a number before committing, and somebody who will tell them Level 1 is sufficient when it is.

Physical scope is not a gap for us. Worth saying because most compliance shops are software-only: we run programmes where the facility is in scope. Our current dual-framework engagement covers a data centre operator's production campus, with physical and environmental controls, site access and equipment handling inside the boundary, and further sites entering as they reach production. That is the same class of work CPCSC asks for when Specified Information lives somewhere with a door on it. How that engagement is scoped.

Caveats, and we mean these. We are deliberately small. If you need a hundred-person engagement across multiple business units, PwC is a better call and we will say so. We do not issue certifications and we are not an accredited assessment body, so we prepare you and somebody else assesses you. And our published CPCSC work is readiness rather than a completed Level 2 certification, because the programme itself is new; if you want a provider who has already taken a supplier through a Level 2 assessment, ask every firm on this list for that specifically, including us.

What CPCSC readiness costs

Two numbers are public in this market: our gap analysis from $3,000, and Kobalt's Level 1 programme at USD $5,000. Everything else is quote-only, so treat the following as shape rather than as quotes.

Level 1 is a few weeks of work for a company with reasonable IT hygiene. The deliverables are a scoped boundary, a gap analysis against the 13 requirements, a System Security Plan, a Plan of Action and Milestones, and a submission-ready package. If somebody quotes you a six-figure Level 1 engagement, ask what they think the scope is.

Level 2 is a different animal. 98 requirements, an external assessor, and evidence that controls operated rather than exist. Budget for the readiness work, the remediation the assessment surfaces, and the assessment fee itself, which is paid to the certification body and is separate from anything a readiness firm charges you.

That last point catches people out and it is worth stating plainly: the assessment fee is not part of your readiness quote. Ask every provider what is excluded, because the answer differs.

The timing question

Level 1 lands in select DND contracts in Summer 2026, and Level 2 obligations follow. Kobalt's public position is that programmes not started by Q3 2026 are unlikely to make an April 2027 Level 2 date. We would put it slightly differently: Level 1 is still achievable on a short runway, and Level 2 is not.

Two things drive that. Assessment capacity in Canada is limited and will not expand as fast as demand. And Level 2 evidence has to exist across a period, so a control implemented the month before assessment does not have the history an assessor wants to sample.

If you are bidding on defence work in the next eighteen months, the useful question is not "when should we start" but "which of our contracts require which level, and what is the longest runway among them".

Frequently asked questions

Is CPCSC mandatory?

For select Department of National Defence contracts, yes. Level 1 becomes a mandatory requirement in Summer 2026. Suppliers who do not meet the level their contract requires become ineligible to bid on or retain that work, which is why it is treated as a revenue risk rather than a compliance project.

What is the difference between CPCSC Level 1 and Level 2?

Level 1 covers 13 security requirements across 6 control families and is a self-assessment you attest to. Level 2 covers all 98 requirements in ITSP.10.171 across 17 families and is assessed by an accredited third party. Level 1 is a few weeks of work for most SMBs; Level 2 is a programme measured in quarters.

Is CPCSC the same as CMMC?

No, but they are close relatives. CPCSC is Canada's programme, built on CCCS ITSP.10.171, which is Canada's adaptation of NIST SP 800-171 Revision 3. CMMC is the US Department of Defense programme and also traces to NIST SP 800-171. If you sell into both countries, scoping them together avoids doing the same control work twice.

What is ITSP.10.171?

It is the CCCS guidance CPCSC is built on: Canada's adaptation of NIST SP 800-171 Revision 3, covering the requirements for protecting federal Specified Information on non-federal systems.

Do we need CPCSC for our whole company?

Usually not. It applies to the systems that handle federal Specified Information. Drawing that boundary narrowly and defensibly is the single highest-value decision in the programme, because every system inside it carries the full requirement set.

Can our readiness firm also certify us?

No, and you should be wary of any provider suggesting otherwise. A certification body performs the assessment. A readiness firm prepares you for it. Keeping those separate is what makes the certification worth holding.

How much does CPCSC readiness cost?

Few firms publish. Our gap analysis starts from $3,000 and Kobalt publishes a Level 1 programme at USD $5,000. Level 2 is materially more because it spans 98 requirements and an external assessment. In every case the assessment fee itself is paid to the certification body and sits outside the readiness quote.

How long does CPCSC certification take?

Level 1 is achievable in weeks for a company with reasonable IT hygiene. For Level 2, published estimates run from four to six months to readiness, before assessor scheduling. Assessment capacity in Canada is limited, so the practical constraint is often the queue rather than your control work.

Where to start

Whichever provider you choose, the first two steps are the same and neither costs anything. Establish which of your contracts carry which level. Then draw the boundary around the systems that actually handle Specified Information.

If you want to see where you stand before speaking to anybody, our free CMMC and CPCSC self-assessment runs your current position against the requirement families and gives you the gaps. It is free and it does not ask for anything. Our CPCSC guide covers the Level 1 controls in plain English, and CPCSC readiness is what we charge if you want the work done.

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

6
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
15+
Penetration testing engagements delivered
$11k
Taken off one client's audit quote by arriving ready

Published vulnerability research

Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.

That second one is the reason this belongs on a compliance page. An asset nobody thinks of as a computer, sitting on a flat network, taken down by a device that never had to authenticate. Auditors ask how controls fail. Finding out first-hand is what separates a policy that reads well from one that holds up when somebody asks for the evidence behind it.

A SOC 2 Type II built from nothing

Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.

The platform stayed at 99.9% uptime and sub-100ms latency throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to add to a system people are already depending on. That programme is why we sell fixed windows rather than open-ended retainers.

Recent engagements

For a Waterloo data centre operator we scoped and assessed SOC 2 Type II (Security, Availability and Confidentiality) against ISO 27001:2022 including the Climate Action Amendment, run together rather than one after the other. Scope covered the production campus, a datacenter platform, an AI compute platform and a self-hosted collaboration stack, written so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.

Before you go

Working through CPCSC?

A few short notes on what CPCSC actually asks for, how Level 1 differs from Level 2, and what the timeline really looks like. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.