Elevate Your Organization's Defense with Cybersecurity Awareness Training
Human error is the leading cause of data breaches. RiskAware’s Cybersecurity Awareness Training equips your team with the knowledge and skills to identify and prevent cyber threats before they become costly incidents. Our program covers:
Interactive Modules: Engaging content that makes learning effective and memorable.
Real-World Scenarios: Practical exercises that simulate actual threats to reinforce learning.
Regular Updates: Stay ahead of evolving cyber risks with constantly updated material.
Compliance Support: Ensure your organization meets regulatory requirements effortlessly.
Don’t wait for a breach to happen—get started today.
Services and Solutions Offered: Tailored cybersecurity services like Fractional CISO, Risk Management, and Automated Security protect your business from evolving threats.
Expertise and Experience: Led by industry veteran Michael Castro, our team brings over 20 years of executive-level cybersecurity leadership.
Track Record and Client Success: Trusted by top organizations like Deloitte and Hydro One, we’ve helped hundreds of clients successfully reduce cyber risks.
Elevate Your Organization's Defense with Cybersecurity Awareness Training
Human error is the leading cause of data breaches. RiskAware’s Cybersecurity Awareness Training equips your team with the knowledge and skills to identify and prevent cyber threats before they become costly incidents. Our program covers:
Interactive Modules: Engaging content that makes learning effective and memorable.
Real-World Scenarios: Practical exercises that simulate actual threats to reinforce learning.
Regular Updates: Stay ahead of evolving cyber risks with constantly updated material.
Compliance Support: Ensure your organization meets regulatory requirements effortlessly.
Don’t wait for a breach to happen—get started today.
Services and Solutions Offered: Tailored cybersecurity services like Fractional CISO, Risk Management, and Automated Security protect your business from evolving threats.
Expertise and Experience: Led by industry veteran Michael Castro, our team brings over 20 years of executive-level cybersecurity leadership.
Track Record and Client Success: Trusted by top organizations like Deloitte and Hydro One, we’ve helped hundreds of clients successfully reduce cyber risks.
Level 1 self-attestation required at contract award
Fixed-price engagement — know your cost upfront
Canadian firm — 25+ years experience
COMPLIANCE specialists ready
About CPCSC
Canada's Cybersecurity Standard for Defence Suppliers
The Canadian Program for Cyber Security Certification (CPCSC) requires all suppliers bidding on Department of National Defence contracts to meet minimum cybersecurity standards under ITSP.10.171. Managed by Public Services and Procurement Canada, the program aligns with Five Eyes best practices — including alignment with the US CMMC framework. Level 1 self-attestation is required at contract award, not during bidding. Non-compliant suppliers risk losing contract eligibility entirely.
Certification Structure
3 Certification Levels
Mandatory Now
Level 01
Basic Cyber Security
Annual self-assessment against 13 controls. Required at contract award. Results must be reflected in your CanadaBuys profile.
13 controls across 6 control families
Annual self-assessment via government tool
Results uploaded to CanadaBuys profile
Evidence retained by the supplier
CMMC certification may be accepted
Level 02
Advanced Cyber Security
External assessment led by an accredited certification body, plus annual affirmation. For higher-sensitivity defence contracts.
Enhanced control implementation
Independent certification process
Documentation and evidence preparation
Readiness for formal third-party assessment
Level 03
Highest Security Level
Assessment conducted by National Defence directly. Applies to highest-sensitivity requirements, plus annual affirmation.
Higher-assurance control requirements
Government-led assessment readiness
Stronger control maturity required
Ongoing compliance support
Level 1 in Detail
What the 13 Controls Actually Require
Level 1 has 13 specific controls across 6 practice areas. Most defence suppliers are partially compliant — but gaps in documentation and evidence are what fail the self-assessment.
Access Control
Manage and document all user accounts
Enforce least-privilege access to systems
Control use of external systems and devices
Manage publicly accessible content
Identification & Authentication
User identification and re-authentication
Device identification and authentication
Multi-factor authentication (MFA)
Media Protection
Sanitize or destroy media before disposal or reuse
The government's self-assessment tool can be completed in under an hour — if you already know where your Specified Information lives, which systems handle it, and have written policies in place. Most suppliers don't. That's the gap RiskAware closes. The tool is available at cyberpostureassessments.ops.cyber.gc.ca — but completing it without preparation risks a failed attestation on your CanadaBuys profile.
Our Methodology
4 Steps to CPCSC Level 1 Readiness
01
Scope & Segment
We identify where your Specified Information lives — which systems, devices, and cloud services handle it. We don't secure your whole operation if only a subset is in scope.
02
Gap Analysis
We map your environment against all 13 ITSP.10.171 Level 1 controls. You get a prioritized remediation plan — what's missing, what's close, what to fix first.
03
Policy & Evidence
Compliance is 50% technical, 50% documentation. We draft the written policies and evidence packages required to prove your controls are implemented.
04
Self-Assessment & CanadaBuys
We guide you through the government's online tool and uploading results to your CanadaBuys profile — the step most suppliers miss that invalidates their bid.
What We Deliver
Fixed-Price CPCSC Level 1 Readiness Assessment
Gap Assessment
Evaluate your current posture against all 13 Level 1 controls. Know exactly where you stand before touching the self-assessment tool.
Policy Development
Written rules for password control, user access, device use, and media disposal — the internal policies Level 1 requires you to have documented.
Implementation Support
Improve MFA, access management, patching, and boundary controls to close gaps before your formal attestation.
Self-Assessment Prep
Walk through the government's online tool with guidance. Avoid failed attestations. Get your CanadaBuys profile updated correctly.
Executive Advisory
Strategic guidance from experienced cybersecurity leaders — sequenced decisions, right-sized controls, and executive-level oversight.
Ongoing Compliance
CPCSC requires annual self-assessment. We provide ongoing vCISO support to keep you eligible for every RFP as requirements evolve.
Why RiskAware
Certified. Experienced. Canadian.
20+
Years in Cybersecurity
100+
Organizations Served
CISA CISSP CISM · C|CISO
Lead Assessor Credentials
LLM
Osgoode · Legal & Regulatory Depth
RiskAware is a Canadian cybersecurity consulting firm based in Markham, Ontario. We serve federal contractors, municipalities, and private-sector organizations across Canada, the US, and the Caribbean.
Ready to Get CPCSC Certified?
Book your free 30-minute readiness call. We'll tell you exactly where you stand and what it will take — no cost, no commitment.
Or call us: 1-844-404-RISK
Common Questions
Frequently Asked Questions
Level 1 self-attestation is required at contract award — not during the bidding process. However, your CanadaBuys organizational supplier profile must reflect a valid, current self-assessment. Beginning in summer 2026, suppliers bidding on new DND RFPs that include CPCSC clauses must have this in place before contract award.
The 13 controls cover: user account management, access enforcement, external system use, publicly accessible content, user/device identification and authentication, MFA, media sanitization, physical access authorizations, physical access controls, boundary protection, flaw remediation (patching), and malicious code protection. Full criteria are published at Canada.ca.
Yes — the government's online self-assessment tool is publicly available and can theoretically be completed in under an hour. The risk is completing it without proper preparation — a failed or inaccurate attestation on your CanadaBuys profile can disqualify your bids. RiskAware prepares you before you touch the tool.
Our CPCSC Level 1 Readiness Assessment is fixed price — you know the exact cost before we start. Pricing is based on your organization's size and current security posture, discussed on the free 30-minute call. Typical range is $4,000–$8,000 CAD depending on scope.
Possibly. The Government of Canada may accept a valid CMMC certification on a case-by-case basis, after confirming the assessment covers the required scope. Both programs use the same underlying technical controls. You must submit proof to PSPC for verification. RiskAware can help you navigate this process.
Typically 2–3 weeks from kick-off to final deliverable. We can expedite if you have a contract deadline. We start within days of your kick-off call.
Yes. If you bid on any DND contract that includes CPCSC clauses — regardless of company size — Level 1 applies. Small suppliers are not exempt. The program is designed to be achievable for SMBs, but you still need to meet all 13 controls and complete the annual self-assessment.
Yes. If you are a subcontractor handling Specified Information on behalf of a prime contractor, the requirements flow down to you. Subcontractors needing to prove Level 1 readiness to their prime partners are one of RiskAware's primary client groups.
Who We Serve
Defence Suppliers Across Canada
Prime Defence Contractors
Bidding directly on DND contracts requiring Level 1 attestation at contract award. Needs CanadaBuys profile updated and evidence retained.
Specialized Subcontractors
Needing to prove Level 1 readiness to their prime partners. CPCSC requirements flow down through the supply chain — no exemptions.
Aerospace & Tech Firms
Bridging the gap between US CMMC and Canadian CPCSC. Same technical controls, different attestation process — we handle both sides.
Get Started
Don't Let CPCSC Stall Your DND Contracts.
Book your free 30-minute readiness call. We'll tell you exactly where you stand, what it takes to get compliant, and what a fixed-price engagement looks like. No cost, no commitment.