Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Rate your organization against representative NIST SP 800-171 practice families, the shared foundation of both the US CMMC and Canada's CPCSC. Pick your target level and get a readiness band scored against it, your biggest gaps, and how the programs compare. For the full requirement breakdown, see our CPCSC Level 1 and Level 2 guide.
Canada's entry tier: 13 requirements from 6 ITSP.10.171 families, Canada's adaptation of NIST SP 800-171. Self-assessed and attested annually through Canada Buys. Live since April 2026.
All 98 ITSP.10.171 requirements across 17 families, verified by a certification body accredited by the Standards Council of Canada, then affirmed annually. Expected in contracts from April 2027.
The US DoD tier: the 110 security requirements of NIST SP 800-171 checked against 320 objectives by a C3PAO on a three-year cycle, scored and affirmed in SPRS.
CMMC is the United States Department of Defense Cybersecurity Maturity Model Certification program. CPCSC is the Canadian Program for Cyber Security Certification, Canada's equivalent for its defence supply chain. Both build on the security requirements in NIST SP 800-171, so the underlying practices are largely shared. The differences are jurisdiction, who assesses you, and where you file: Canada Buys for CPCSC, SPRS for CMMC.
CPCSC Level 1 is a self-assessment against 13 requirements drawn from 6 of the 17 ITSP.10.171 control families, which are Canada's adaptation of NIST SP 800-171. The families in scope are access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity. You attest annually through Canada Buys.
CPCSC Level 2 covers all 98 ITSP.10.171 requirements across all 17 control families and is verified by a certification body accredited by the Standards Council of Canada rather than self-attested. It expects a defined assessment boundary, a System Security Plan, a Plan of Action and Milestones, and evidence an assessor can sample. Level 2 requirements are expected in contracts from April 2027. See our CPCSC guide for the full breakdown.
CMMC Level 2 covers the 110 security requirements of NIST SP 800-171, checked against 320 assessment objectives by a C3PAO on a three-year cycle, with a score and annual affirmation posted in SPRS. Because ITSP.10.171 is Canada's profile of the same standard, most of the underlying work is shared with CPCSC Level 2, which is why suppliers selling to both governments should run one program rather than two.
NIST SP 800-171 organizes its security requirements into 14 families, including Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, and System and Information Integrity, among others. This tool samples representative families so you can gauge readiness quickly. CPCSC Level 1 draws on 6 of them; Level 2 and CMMC Level 2 cover all of them.
No. This is a directional self-assessment. Certification is granted through the applicable program's assessment process, which at CPCSC Level 2 means an accredited certification body and at CMMC Level 2 means a C3PAO. Use this to prioritize before that assessment.
Yes, it is free with no signup and nothing you rate is sent anywhere. If you want help implementing the practices and preparing for a CMMC or CPCSC assessment at either level, our team runs the readiness process.
Not ready for a call yet?
A few short notes from Jacob on meeting NIST SP 800-171 for CMMC and CPCSC, at Level 1 and Level 2. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Want it done for you?
CPCSC Level 1 & 2 Readiness
We implement the NIST SP 800-171 practices and prepare you for self-attestation or an external assessment.
Explore CPCSC Level 1 & 2 Readiness →We implement the NIST SP 800-171 practices, build your System Security Plan and POA&M, and prepare you for a CMMC or CPCSC assessment at Level 1 or Level 2, as part of our broader compliance readiness work. Turn this readiness snapshot into a plan.
See CPCSC Level 1 & 2 Readiness Book a callThis gives you the shape of the problem. The full picture is all 110 requirements of CMMC Level 2, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.
No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.