Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
home / guides / cpcsc level 1

CPCSC Level 1: the 13 controls, explained

What Canadian defence and government suppliers actually have to do to meet CPCSC Level 1, control by control.

Last reviewed July 2026 · by traztech, security & compliance for startups
Short answer

The Canadian Program for Cyber Security Certification (CPCSC) is the cyber-security requirement for suppliers bidding on federal contracts that carry it. Level 1 is the entry tier: 13 baseline controls from CCCS ITSP.10.171, which you self-assess and a senior official attests to. Level 1 self-assessment has been available since April 1, 2026 and starts appearing as a mandatory requirement in select defence contracts in Summer 2026, with Level 2 (97 controls, independently assessed) following in April 2027. No certification, no bid. ITSP.10.171 is Canada’s adaptation of NIST SP 800-171 Revision 3, the same standard behind the US CMMC program, so the two share a technical core.

13
Level 1 controls
Self
assessed and attested
ITSP.10.171
the control baseline

What CPCSC is, and why it gates the bid

CPCSC is the Government of Canada program that requires suppliers to demonstrate a baseline of cyber security before they can win contracts that reference it. The timeline is concrete: Level 1 self-assessment opened to suppliers on April 1, 2026, becomes a mandatory requirement in select Department of National Defence contracts through Summer 2026, and Level 2, which covers 97 controls and requires an independent third-party assessment, follows in April 2027. The practical point is simple: if a solicitation requires CPCSC and you are not certified at the required level, your bid is non-compliant. It is a gate, not a nice-to-have, and the window to get ahead of it is now.

CPCSC vs CMMC

If you have looked at the US Cybersecurity Maturity Model Certification (CMMC), CPCSC will feel familiar. Both are tiered supply-chain cyber programs that gate defence contracts. The differences that matter:

How Level 1 maps to ITSP.10.171

The 13 Level 1 controls are the baseline controls from CCCS ITSP.10.171, the Canadian Centre for Cyber Security guidance titled Baseline Cyber Security Controls for Small and Medium Organizations. ITSP.10.171 is Canada’s adaptation of NIST SP 800-171 Revision 3, so if you have already worked against ITSP.10.171 or the US standard, you have already done most of Level 1. The table below lists all 13 and what each one asks for in practice.

Completing the Level 1 self-assessment

Level 1 is a self-assessment, but self-assessed does not mean informal. The senior official who attests is putting their name to it, so the evidence has to be real. The path we run with clients:

What a Canadian defence supplier actually has to produce

For Level 1, the deliverable is a defensible self-assessment: the 13 controls implemented, documented, and backed by evidence, plus the senior-official attestation. In plain terms, you need to be able to show, for each control, that it exists, that it is configured correctly, and that it keeps running. That is the same readiness work we run for SOC 2, pointed at the CPCSC baseline.

The 13 CPCSC Level 1 controls

# Control area What Level 1 asks for
1 Incident response plan A written plan for detecting, responding to, and recovering from a cyber incident, with named roles.
2 Automated patching Operating systems and applications update automatically so known vulnerabilities are closed quickly.
3 Malware defences Anti-malware and endpoint protection enabled on devices and kept current.
4 Secure configuration Devices hardened from default settings, with unnecessary accounts, software, and services removed.
5 Strong authentication Strong, unique passwords and multi-factor authentication on important accounts.
6 Security awareness training Staff trained to recognize phishing and follow basic security practices.
7 Backup and encryption Data backed up regularly, backups tested, and sensitive data encrypted.
8 Mobile device security Phones and tablets that touch company data are secured, encrypted, and can be wiped remotely.
9 Perimeter defences Firewalls plus DNS, email, and web filtering to block common threats at the edge.
10 Cloud and outsourced IT Cloud services and IT providers configured securely, with responsibilities clearly divided.
11 Website security Public-facing websites kept patched and protected.
12 Access control People get only the access they need, and access is removed promptly when they leave.
13 Portable media USB and portable media use controlled to prevent data loss and malware.

Frequently asked

What is the CPCSC?

The Canadian Program for Cyber Security Certification is a Government of Canada program that requires suppliers to meet a baseline of cyber security to bid on contracts that reference it. It is being rolled out through federal procurement, beginning with defence.

What is the difference between CPCSC and CMMC?

CPCSC is the Canadian program for Government of Canada contracts; CMMC is the US Department of Defense program. Both ultimately trace to NIST SP 800-171: CPCSC Level 1 is built on CCCS ITSP.10.171, which is Canada’s adaptation of NIST SP 800-171 Revision 3, the same family the higher CMMC levels use. Both Level 1 tiers are self-assessed, so if you have done one you are most of the way to the other.

When does CPCSC take effect?

Level 1 self-assessment has been available to suppliers since April 1, 2026 and starts showing up as a mandatory requirement in select Department of National Defence contracts in Summer 2026. Level 2, which covers 97 controls and requires an independent third-party assessment, follows in April 2027. If you bid on federal defence work, the time to get ready is now.

What is ITSP.10.171?

ITSP.10.171 is CCCS guidance called Baseline Cyber Security Controls for Small and Medium Organizations. Its baseline controls are the source of the 13 CPCSC Level 1 controls.

Can traztech certify us?

No. At Level 1 the certification is a self-assessment attested by your own senior official, so no consultant issues it. What we do is the readiness: assess your 13 controls, close the gaps, build the evidence, and get you to a defensible attestation.

Who needs CPCSC Level 1?

Small and medium suppliers who want to bid on Government of Canada contracts, starting with defence, that require the entry tier. If your solicitations are starting to reference CPCSC, Level 1 is where most suppliers begin.

Related

Bidding on a contract that needs CPCSC?

We run CPCSC Level 1 readiness end to end: the 13 controls assessed, gaps closed, evidence built, and you ready to attest.

Book a strategy call

Want the human version?

Get Jacob's take, by email

Jacob sends a few short, practical notes on getting security and compliance right without the months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.