CPCSC Level 1 is mandatory at DND contract award — effective 2026. Don't let it stall your bids.
CPCSC Phase 2 — Mandatory Now

CPCSC Compliance for Canadian Defence Suppliers

RiskAware delivers fixed-price Level 1 gap assessments and self-attestation guidance. Know your gaps. Keep your DND contracts.

CISA CISSP CISM C|CISO 20+ Years Canadian
Book Your Free 30-Min Readiness Call

No cost. No commitment. 30 minutes.

Schedule Your Free Readiness Call

Pick a time that works for you
Level 1 self-attestation required at contract award
Fixed-price engagement — know your cost upfront
Canadian firm — 25+ years experience
COMPLIANCE specialists ready

Canada's Cybersecurity Standard for Defence Suppliers

The Canadian Program for Cyber Security Certification (CPCSC) requires all suppliers bidding on Department of National Defence contracts to meet minimum cybersecurity standards under ITSP.10.171. Managed by Public Services and Procurement Canada, the program aligns with Five Eyes best practices — including alignment with the US CMMC framework. Level 1 self-attestation is required at contract award, not during bidding. Non-compliant suppliers risk losing contract eligibility entirely.

3 Certification Levels

Level 02
Advanced Cyber Security

External assessment led by an accredited certification body, plus annual affirmation. For higher-sensitivity defence contracts.

  • Enhanced control implementation
  • Independent certification process
  • Documentation and evidence preparation
  • Readiness for formal third-party assessment
Level 03
Highest Security Level

Assessment conducted by National Defence directly. Applies to highest-sensitivity requirements, plus annual affirmation.

  • Higher-assurance control requirements
  • Government-led assessment readiness
  • Stronger control maturity required
  • Ongoing compliance support

What the 13 Controls Actually Require

Level 1 has 13 specific controls across 6 practice areas. Most defence suppliers are partially compliant — but gaps in documentation and evidence are what fail the self-assessment.

Access Control
Manage and document all user accounts
Enforce least-privilege access to systems
Control use of external systems and devices
Manage publicly accessible content
Identification & Authentication
User identification and re-authentication
Device identification and authentication
Multi-factor authentication (MFA)
Media Protection
Sanitize or destroy media before disposal or reuse
Physical Protection
Physical access authorizations documented
Physical access controls enforced
System & Communications
Boundary protection (firewalls, network segmentation)
System & Info Integrity
Flaw remediation (patching)
Malicious code protection (antivirus/EDR)

The government's self-assessment tool can be completed in under an hour — if you already know where your Specified Information lives, which systems handle it, and have written policies in place. Most suppliers don't. That's the gap RiskAware closes. The tool is available at cyberpostureassessments.ops.cyber.gc.ca — but completing it without preparation risks a failed attestation on your CanadaBuys profile.

4 Steps to CPCSC Level 1 Readiness

01
Scope & Segment

We identify where your Specified Information lives — which systems, devices, and cloud services handle it. We don't secure your whole operation if only a subset is in scope.

02
Gap Analysis

We map your environment against all 13 ITSP.10.171 Level 1 controls. You get a prioritized remediation plan — what's missing, what's close, what to fix first.

03
Policy & Evidence

Compliance is 50% technical, 50% documentation. We draft the written policies and evidence packages required to prove your controls are implemented.

04
Self-Assessment & CanadaBuys

We guide you through the government's online tool and uploading results to your CanadaBuys profile — the step most suppliers miss that invalidates their bid.

Fixed-Price CPCSC Level 1 Readiness Assessment

Gap Assessment

Evaluate your current posture against all 13 Level 1 controls. Know exactly where you stand before touching the self-assessment tool.

Policy Development

Written rules for password control, user access, device use, and media disposal — the internal policies Level 1 requires you to have documented.

Implementation Support

Improve MFA, access management, patching, and boundary controls to close gaps before your formal attestation.

Self-Assessment Prep

Walk through the government's online tool with guidance. Avoid failed attestations. Get your CanadaBuys profile updated correctly.

Executive Advisory

Strategic guidance from experienced cybersecurity leaders — sequenced decisions, right-sized controls, and executive-level oversight.

Ongoing Compliance

CPCSC requires annual self-assessment. We provide ongoing vCISO support to keep you eligible for every RFP as requirements evolve.

Certified. Experienced. Canadian.

20+
Years in
Cybersecurity
100+
Organizations
Served
CISA
CISSP
CISM · C|CISO
Lead Assessor
Credentials
LLM
Osgoode · Legal &
Regulatory Depth

RiskAware is a Canadian cybersecurity consulting firm based in Markham, Ontario. We serve federal contractors, municipalities, and private-sector organizations across Canada, the US, and the Caribbean.

Ready to Get CPCSC Certified?

Book your free 30-minute readiness call. We'll tell you exactly where you stand and what it will take — no cost, no commitment.

Or call us: 1-844-404-RISK

Frequently Asked Questions

Level 1 self-attestation is required at contract award — not during the bidding process. However, your CanadaBuys organizational supplier profile must reflect a valid, current self-assessment. Beginning in summer 2026, suppliers bidding on new DND RFPs that include CPCSC clauses must have this in place before contract award.
The 13 controls cover: user account management, access enforcement, external system use, publicly accessible content, user/device identification and authentication, MFA, media sanitization, physical access authorizations, physical access controls, boundary protection, flaw remediation (patching), and malicious code protection. Full criteria are published at Canada.ca.
Yes — the government's online self-assessment tool is publicly available and can theoretically be completed in under an hour. The risk is completing it without proper preparation — a failed or inaccurate attestation on your CanadaBuys profile can disqualify your bids. RiskAware prepares you before you touch the tool.
Our CPCSC Level 1 Readiness Assessment is fixed price — you know the exact cost before we start. Pricing is based on your organization's size and current security posture, discussed on the free 30-minute call. Typical range is $4,000–$8,000 CAD depending on scope.
Possibly. The Government of Canada may accept a valid CMMC certification on a case-by-case basis, after confirming the assessment covers the required scope. Both programs use the same underlying technical controls. You must submit proof to PSPC for verification. RiskAware can help you navigate this process.
Typically 2–3 weeks from kick-off to final deliverable. We can expedite if you have a contract deadline. We start within days of your kick-off call.
Yes. If you bid on any DND contract that includes CPCSC clauses — regardless of company size — Level 1 applies. Small suppliers are not exempt. The program is designed to be achievable for SMBs, but you still need to meet all 13 controls and complete the annual self-assessment.
Yes. If you are a subcontractor handling Specified Information on behalf of a prime contractor, the requirements flow down to you. Subcontractors needing to prove Level 1 readiness to their prime partners are one of RiskAware's primary client groups.

Defence Suppliers Across Canada

Prime Defence Contractors

Bidding directly on DND contracts requiring Level 1 attestation at contract award. Needs CanadaBuys profile updated and evidence retained.

Specialized Subcontractors

Needing to prove Level 1 readiness to their prime partners. CPCSC requirements flow down through the supply chain — no exemptions.

Aerospace & Tech Firms

Bridging the gap between US CMMC and Canadian CPCSC. Same technical controls, different attestation process — we handle both sides.

Don't Let CPCSC Stall Your DND Contracts.

Book your free 30-minute readiness call. We'll tell you exactly where you stand, what it takes to get compliant, and what a fixed-price engagement looks like. No cost, no commitment.

Or call: 1-844-404-RISK (7475)

Schedule Your Call