A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →CPCSC Level 1 is the entry tier of the Canadian Program for Cyber Security Certification, the federal programme that will require defence suppliers to be certified against cyber security requirements to bid on certain contracts. Level 1 covers a foundational set of controls for suppliers handling less sensitive information, with higher levels for more sensitive data. It is Canada's counterpart to the United States' CMMC model.
The entry-level controls are foundational and overlap with baseline programmes like CyberSecure Canada and the groundwork of SOC 2 or ISO 27001. A supplier that has done any of that work is usually most of the way there.
Because the required level follows the contract, the practical first step is understanding which level a target opportunity demands before scoping anything. Certifying higher than you need adds cost without winning more work.
traztech delivers compliance and certification readiness for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
CPCSC Level 1 comes up for companies that want to sell into the federal defence supply chain, where certification is becoming a condition of bidding rather than a nice-to-have. The level required depends on the sensitivity of the information a contract involves. We approach it through compliance and certification readiness.
For most suppliers the Level 1 controls are foundational security hygiene, so the work overlaps with what a SOC 2 or ISO 27001 effort already produces. Treating it as part of a broader programme avoids building a one-off just to clear a procurement gate.
The Canadian Program for Cyber Security Certification, a federal programme requiring defence supply-chain suppliers to be certified against cyber security requirements. It is structured in levels, with the required level tied to the sensitivity of the information involved.
CPCSC is Canada's counterpart to the US CMMC model and is designed to align with it, so suppliers that work across both markets face similar foundational expectations at the entry tier.
Free PDFs, no card
SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.