Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

CPCSC Level 1

CPCSC Level 1 is the entry tier of the Canadian Program for Cyber Security Certification, the federal programme that will require defence suppliers to be certified against cyber security requirements to bid on certain contracts. Level 1 covers a foundational set of controls for suppliers handling less sensitive information, with higher levels for more sensitive data. It is Canada's counterpart to the United States' CMMC model.

In practice

The entry-level controls are foundational and overlap with baseline programmes like CyberSecure Canada and the groundwork of SOC 2 or ISO 27001. A supplier that has done any of that work is usually most of the way there.

Because the required level follows the contract, the practical first step is understanding which level a target opportunity demands before scoping anything. Certifying higher than you need adds cost without winning more work.

// how traztech helps

traztech delivers compliance and certification readiness for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

CPCSC Level 1 comes up for companies that want to sell into the federal defence supply chain, where certification is becoming a condition of bidding rather than a nice-to-have. The level required depends on the sensitivity of the information a contract involves. We approach it through compliance and certification readiness.

For most suppliers the Level 1 controls are foundational security hygiene, so the work overlaps with what a SOC 2 or ISO 27001 effort already produces. Treating it as part of a broader programme avoids building a one-off just to clear a procurement gate.

CPCSC Level 1: common questions

What is CPCSC?

The Canadian Program for Cyber Security Certification, a federal programme requiring defence supply-chain suppliers to be certified against cyber security requirements. It is structured in levels, with the required level tied to the sensitivity of the information involved.

How does Level 1 relate to CMMC?

CPCSC is Canada's counterpart to the US CMMC model and is designed to align with it, so suppliers that work across both markets face similar foundational expectations at the entry tier.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.