CPCSC
Get Ahead of CPCSC Before It's Required in Your Contract.
Canada's new cybersecurity certification program for defence suppliers is here. 112Cyber helps organizations understand their CPCSC requirements, protect Specified Information (SI), implement ITSP.10.171 controls, and prepare for assessments.
Canada's Mandatory Cyber Standard for the Defence Industrial Base
The Canadian Program for Cyber Security Certification (CPCSC) establishes cybersecurity requirements for organizations working within Canada's defence supply chain.
Administered by Public Services and Procurement Canada (PSPC), CPCSC is designed to protect Specified Information (SI) handled by contractors and subcontractors on non-government systems. Requirements are based on ITSP.10.171, Canada's cybersecurity standard for protecting Specified Information based on NIST SP 800-171, and are being introduced into select defence contracts through a phased rollout.
For suppliers, that means cybersecurity readiness is becoming a condition of doing business on certain Government of Canada defence contracts. The level required will depend on the sensitivity of the information associated with your contract.
Requirements Scale With the Sensitivity of What You Handle
CPCSC uses three certification levels. Each introduces additional cybersecurity requirements and a different assessment process.
Level 1
- Self-assessed annually
- No external assessor required
- Establishes foundational cybersecurity practices
- Requirements begin appearing in select defence contracts in 2026
Level 2
- Assessed by an SCC-accredited certification body
- Full assessment every three years
- Annual affirmation between assessments
- Requirements begin appearing in select defence contracts in 2027
Level 3
- Assessed directly by the Department of National Defence
- Full assessment every three years
- Annual affirmation between assessments
- Designed for contracts involving the most sensitive information
- Introduced gradually as CPCSC implementation expands
CPCSC Advisory Support, Built on Our CMMC Experience
CPCSC readiness is more than checking off controls. You need to know where Specified Information (SI) enters your environment, which systems and people are in scope, what gaps exist, and how you'll demonstrate that requirements are being met.
CPCSC is based on CMMC, which 112Cyber has helped organizations navigate since the program's earliest days — and that experience translates directly into our ability to get organizations compliant. We've helped some of the largest defense contractors achieve compliance with the same framework CPCSC is based on, so our expertise is something proven that you can rely on.
Our CPCSC Services
Specified Information Mapping
Identify where Specified Information enters, moves through, and leaves your environment to establish an accurate CPCSC scope.
Gap Assessments
Evaluate your current cybersecurity posture against the requirements for your target CPCSC level and identify what needs to change.
Remediation Services
Turn identified gaps into action with hands-on support implementing the technical, administrative, and procedural requirements you need to meet.
Assessment Support
Prepare for your CPCSC assessment with evidence reviews, documentation support, mock assessment activities, and remediation of remaining gaps.
CPCSC Accelerator
Get ongoing support to build, manage, and maintain your compliance program instead of treating CPCSC as a one-time project.
Defence Cybersecurity Compliance Isn't New to Us
CPCSC may be new, but the work required to build an assessment-ready cybersecurity program isn't. 112Cyber brings hands-on experience helping defence contractors implement the rigorous cybersecurity requirements found in ITSP.10.171.
Proven Compliance Experience
We've supported numerous successful CMMC engagements, helping organizations move from initial scoping and gap assessments through remediation and assessment readiness.
Deep NIST 800-171 Expertise
ITSP.10.171 is nearly identical to NIST SP 800-171 Revision 3. Our experience implementing NIST-based cybersecurity requirements gives our team a strong technical foundation for helping organizations navigate CPCSC.
Hands-On Remediation
We don't hand you a gap report and leave the rest to your team. 112Cyber can help implement controls, develop documentation, prepare evidence, and close the gaps we identify.
Readiness and Technology Expertise
Compliance requirements have to work in the real world. Our team has experience across many industries and understands both the regulatory requirements and the technical environments where those requirements need to be implemented.
Support Beyond the Assessment
CPCSC isn't a one-time certification exercise. With recurring assessments and annual affirmations, organizations need processes that can sustain compliance over time. We help you build for what comes after the initial assessment, too.
Experience Across U.S. and Canadian Defence Requirements
For organizations operating in both defence supply chains, our experience across CMMC, NIST 800-171, and CPCSC can help identify overlap, reduce duplicated work, and make the most of cybersecurity investments you've already made.
Where CPCSC Stands Today, and What's Coming
CPCSC is rolling out in three phases. Here's what's already in effect and what to prepare for next.
Phase 1: Foundation Complete
- ITSP.10.171 published
- CPCSC program requirements developed
- Level 1 guidance released
- Certification and accreditation infrastructure established
Phase 2: Level 1 Rollout In progress
- Level 1 self-assessment became available April 1, 2026
- Level 1 requirements begin appearing in select defence contracts
- Suppliers can complete their self-assessment and record their status through CanadaBuys
- SCC accreditation process for Level 2 certification bodies underway
Phase 3: Level 2 and Level 3 Rollout Upcoming
- Level 2 third-party assessment requirements begin appearing in select defence contracts
- Accredited third-party assessments expand
- Level 3 requirements are introduced gradually
How CPCSC Maps to the CMMC Framework You Already Know
CPCSC is Canada's cybersecurity certification program, developed specifically for the Canadian defence supply chain. But organizations familiar with the U.S. Cybersecurity Maturity Model Certification (CMMC) program will recognize much of its technical foundation.
CPCSC enforces the security framework ITSP.10.171, which is based on CMMC's NIST 800-171 Revision 3. It contains the same 97 control requirements — just with Canadian-specific terminology — plus one Canadian-specific requirement.
That additional requirement, 03.14.09 Dedicated Administration Workstation, requires administrative and superuser activities to be performed from a dedicated, hardened workstation isolated from other functions and networks.
| CMMC (United States) | CPCSC (Canada) | |
|---|---|---|
| Governing Body | Department of War (DoW) | PSPC administers; DND is the client and assesses Level 3 |
| Protected Data | Controlled Unclassified Information (CUI) | Specified Information (SI) |
| Required Framework | NIST SP 800-171 | ITSP.10.171 |
| Assessor Accreditation | Cyber AB → C3PAO | Standards Council of Canada (SCC) → accredited certification body |
| Assessment Structure | Self, third-party, or government assessment depending on level | Self, third-party, or National Defence assessment depending on level |
For organizations that have already invested in NIST 800-171 or CMMC readiness, that overlap can provide a significant head start. But CPCSC remains its own program, with Canadian requirements, terminology, assessment processes, and oversight. If your organization already has a mature U.S. defence cybersecurity program, 112Cyber can help determine what carries over, what changes under CPCSC, and what gaps remain.
Don't Wait for CPCSC to Show Up in an RFP
Understanding your scope, implementing cybersecurity requirements, and preparing evidence takes time. Starting now gives your organization a clearer path to certification and helps prevent CPCSC requirements from becoming a barrier to your next defence opportunity.