The Canadian Program for Cyber Security Certification (CPCSC) is Canada’s mandatory cyber security certification framework for defence contractors handling Controlled Information under Government of Canada procurement. Built on ITSP.10.171, the technical standard that mirrors NIST SP 800-171 Revision 3, CPCSC establishes two certification levels: Level 1 self-assessment for basic cyber hygiene and Level 2 third-party certification for higher-risk contracts. Officially launched on March 12, 2025, the program is led by Public Services and Procurement Canada (PSPC) and the Department of National Defence (DND), and sits inside Canada’s Defence Industrial Strategy backed by $81.8 billion in defence funding.
If you’re a Canadian defence contractor right now, this isn’t a “watch and wait” situation. This is a contract eligibility requirement. Miss it, and you’re off the bid list.

What Is CPCSC? Canada’s Cyber Security Certification Program Defined
The Canadian Program for Cyber Security Certification (CPCSC) is a government-mandated framework requiring defence suppliers to demonstrate they can protect Controlled Information (CI) and Designated Information (DI) within their systems and supply chains. Canada’s Budget 2023 allocated $25 million over three years to establish the program, with funding and authority to proceed confirmed in March 2023, according to Public Services and Procurement Canada’s CPCSC program announcement.
The goal is direct: close the security gaps in Canada’s defence supply chain before adversaries do it for us.
CPCSC applies at the contract level. If a procurement involves controlled or designated information, the contractor must hold the right certification level before award. No certification, no contract. That’s the mechanism.
Who Does CPCSC Apply To? Covered Contractors and Their Obligations
CPCSC applies to any organization bidding on Government of Canada defence contracts that involve Controlled Information (CI) or Designated Information (DI), with Department of National Defence (DND) contracts being the primary focus.
The scale of Canada’s defence industry makes this significant. According to Innovation, Science and Economic Development Canada’s 2024 state of the defence industry report, firms with fewer than 250 employees represented over 85% of firms in the Canadian defence industry in 2022. That means the majority of affected businesses are SMEs, not defence primes.

Most of them have never built a formal System Security Plan (SSP) in their lives. That’s the gap CPCSC is designed to force closed.
Subcontractors are not exempt either. If a prime passes controlled information down the supply chain, those subcontractors inherit the obligation. The certification requirement follows the data, not just the prime contract holder.
ITSP.10.171: The Technical Standard Powering CPCSC
ITSP.10.171 is the Canadian Security Establishment’s technical guidance document that forms the direct compliance framework for CPCSC, aligning Canadian defence cyber security requirements with NIST SP 800-171 Revision 3.
NIST SP 800-171 Revision 3 specifies 97 security controls across 17 families. ITSP.10.171 adapts those controls for the Canadian context, giving contractors a clear map of what they must implement to protect controlled information in non-federal systems.

The 17 control families cover the full security lifecycle:
- Access Control
- Awareness and Training
- Audit and Accountability
- Configuration Management
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Personnel Security
- Physical Protection
- Risk Assessment
- Security Assessment
- System and Communications Protection
- System and Information Integrity
- Planning
- Program Management
- Supply Chain Risk Management
If your gap assessment against ITSP.10.171 turns up weaknesses in access control or incident response, those aren’t just audit findings. They’re contract risks. Fix them first.
CPCSC Certification Levels: Level 1 Self-Assessment vs. Level 2 Third-Party Certification
CPCSC operates on two certification levels, each calibrated to the sensitivity of the information and the risk profile of the contract: Level 1 requires an annual self-assessment and attestation against ITSP.10.171 controls, while Level 2 requires a third-party assessment conducted by an accredited certification body.
Level 1 is the baseline. The contractor assesses their own systems, documents the results in a System Security Plan (SSP), and attests to compliance. It covers basic cyber hygiene. Fast to understand, but don’t underestimate the documentation burden.
Level 2 is where it gets serious. According to the Standards Council of Canada’s CPCSC accreditation scheme, the Standards Council of Canada (SCC) is the only accreditation body in Canada currently offering Third-Party Assessment Organization (3PAO) accreditation for CPCSC Level 2. That’s a narrow ecosystem right now. Getting into the queue matters.
Level 2 assessors will scrutinize your SSP, test your controls against ITSP.10.171, and verify evidence. Prepare your documentation before you book the assessment, not during it.
CPCSC vs. CMMC: What Cross-Border Suppliers Need to Know
CPCSC and the U.S. Cybersecurity Maturity Model Certification (CMMC) are deliberately aligned, both drawing from NIST SP 800-171 Revision 3 as their technical foundation, which means Canadian defence contractors already working under CMMC have a significant head start on CPCSC compliance.
The alignment is intentional. Nearly half (49%) of defence-related products and services from Canadian firms are sold abroad, with 69% going to the United States and Canada’s other Five Eyes partners, according to Canada’s Defence Industrial Strategy. Ottawa and Washington both need the same supply chain protected.

But there are real differences. CMMC uses its own terminology and certification infrastructure. CPCSC uses ITSP.10.171 and the SCC accreditation ecosystem. A CMMC Level 2 certification does not automatically satisfy CPCSC Level 2. Dual certification is the realistic path for cross-border suppliers, and a gap assessment against ITSP.10.171 is the fastest way to find out how far apart you actually are.
How to Achieve CPCSC Compliance: A Practical Roadmap
CPCSC compliance follows a logical sequence: scope your environment, assess your gaps, build your System Security Plan (SSP), remediate, and certify.
Start with scoping. Define exactly which systems process, store, or transmit controlled information. This sets your compliance boundary. Smaller scope means faster remediation. Many contractors over-scope on the first pass and waste months fixing systems that don’t touch CI at all.
Next, run a gap assessment against the ITSP.10.171 controls. Map your current state against all 97 controls under NIST SP 800-171 Revision 3. Document every gap in a Plan of Action and Milestones (POA&M). This document becomes the backbone of your remediation program.
Then build your SSP. The SSP describes how your systems implement each required control. It is the primary evidence document for both Level 1 self-assessment and Level 2 third-party certification. A weak SSP fails assessments. Write it as if the assessor knows nothing about your environment, because they won’t.
Remediate your POA&M gaps, validate your controls with internal testing, then engage an SCC-accredited 3PAO for Level 2. Do a mock audit first. It’s far cheaper to find problems yourself than to fail a formal assessment.
CPCSC Timeline and What Defence Contractors Must Do Now
CPCSC’s public launch came on March 12, 2025, when the Government of Canada introduced the program, opened the accreditation ecosystem, and began a pilot on select defence contracts through self-assessment, as detailed in the government’s official CPCSC launch announcement.
The program sits inside a much larger strategic commitment. The Defence Industrial Strategy, released February 17, 2026, is backed by $81.8 billion in defence funding and targets 125,000 new jobs and 240% growth in defence industry revenues, according to Prime Minister Carney’s DIS announcement. CPCSC isn’t a side initiative. It’s a foundational requirement for accessing that spending.
Canada’s National Cyber Threat Assessment 2025-2026 from the Canadian Centre for Cyber Security states that attacks against digital supply chains will almost certainly continue. That’s the threat context CPCSC was built to address. The program exists because the risk is real, not theoretical.
Do this before anything else: pull your active and pipeline defence contracts, identify which ones involve controlled or designated information, and determine which certification level each requires. That single step tells you exactly where you stand and how much time you have.

The contractors who act now will be positioned to bid on the largest defence procurement expansion in Canadian history. The ones who wait will be scrambling for SCC assessor availability while their competitors are already certified. Don’t be the second group.
If you want to get your security posture ready for CPCSC compliance, start with a thorough review of your current controls and documentation gaps. The path forward is clear. The only question is whether you start this week or next quarter.



