36 / 58CPCSC Certification Support

CPCSC certification support, before Level 1 gates your next contract award

CPCSC certification support for Canadian defence suppliers, from the Level 1 self-assessment through to ITSP.10.171 gap closure.

  • CCIE Security-led engineering
  • Control work, not a findings report
  • Canadian data residency available
THE WORK

CPCSC certification support, three pillars, one operator.

One Canadian team does the Canadian defence supply chain cyber work: closing the control gaps, standing behind the self-assessment, and getting you ready for Level 2.

  1. 1

    Level 1 self-assessment

    The annual self-assessment done properly, with a configuration and a ticket behind every answer you sign, not a policy document nobody operates.

  2. 2

    ITSP.10.171 controls

    Canada's adaptation of NIST SP 800-171, closed by engineers rather than written up in a findings report. Identity, logging, segmentation and media handling get built.

  3. 3

    Level 2 readiness

    The CPCSC levels get harder fast. Level 1 you sign yourself, Level 2 an accredited third party assesses every three years, and nobody crams that. We build for it early.

THE PROOF

Built to last. Evidence over promises.

Level 1 became a contract-award requirement on select defence contracts in summer 2026, and Level 2 reaches select contracts in spring 2027. The runway is about two quarters.

IN PRODUCTION

A self-assessment a Canadian reviewer could check.

We answered the self-assessment honestly and failed our own review. Half the controls were policies with nothing running behind them. SMEnode closed the technical gaps, and now every answer we sign has a configuration and a ticket behind it.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

CPCSC certification in Canada, made real.

I run this practice, so this is the engineer's read of the programme, written by the person who'd scope your environment.

Which standard CPCSC actually runs on.

The Canadian Program for Cyber Security Certification is real, its dates have already started, and most suppliers we meet still treat it as a 2027 problem. Start with the standard, because the internet gets this wrong. CPCSC is built on ITSP.10.171, the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171 (source: Canadian Centre for Cyber Security; PSPC). It's a different document from the general Canadian small-business baseline, and different again from the risk-management framework Canadian assessments have cited for over a decade. Getting that wrong costs months, because the control sets don't map cleanly onto each other and a gap review against the wrong catalogue has to be redone.

Level 1 is a self-assessment, and you sign it.

Level 1 sounds easier than it is. You sign it, which makes it an attestation about your own systems, renewed annually. The failure we see most often is a control answered yes on the strength of a policy document with nothing running behind it. Risk sits in three places: answers given by somebody who doesn't operate the systems, scope drawn around the whole company instead of the environment that touches Government of Canada controlled information, and evidence that exists only in one person's memory.

The calendar is the reason to move.

The defence procurement cyber timetable has already started. Level 1 became available to suppliers in April 2026 and a contract-award requirement on select defence contracts through summer 2026, and in this phase it applies at award rather than during bidding. Level 2 reaches select contracts in spring 2027 and needs an external assessment every three years by a body the Standards Council of Canada accredits, the only Canadian accreditation body offering that accreditation. Level 3 is assessed by National Defence itself, which is why some suppliers go looking for this as DND cyber certification.

Liste de contrôles
THE METHOD

How our CPCSC and Canadian defence supply chain work runs.

Four steps, and step 01 decides how much of this you have to do at all. Scope is the whole negotiation. A supplier who draws the boundary around the one segment that handles controlled information does a fraction of the work of one who scopes the entire company, and both answers can be defensible. We argue that line before anybody touches a control.

  1. Étape 01

    Scope the environment

    Which systems, people and sites actually touch Government of Canada controlled information, drawn tightly and written down so a reviewer can follow the reasoning rather than guess at it.

  2. Étape 02

    Gap it against ITSP.10.171

    Every control assessed against what's running, not what's written, with each gap ranked by whether it blocks an award or simply needs closing before the next annual cycle.

  3. Étape 03

    Close the gaps

    Our engineers do the configuration work. Identity, logging, segmentation and media handling get built, and the policy gets written to match what now exists.

  4. Étape 04

    File it, then aim at Level 2

    The self-assessment submitted with evidence behind every answer, a renewal calendar, and the delta between where you are and what an accredited assessor will want in 2027.

QUESTIONS

CPCSC questions, answered straight.

Answers first, including which standard this actually uses. An architect takes the call, not a salesperson.

ITSP.10.171, published by the Canadian Centre for Cyber Security, which is Canada's adaptation of NIST SP 800-171. This matters because two other documents get named by mistake. The general Canadian small-business baseline is a separate certification with a separate purpose. And the framework Canadian risk assessments have cited since 2012 is a different family of document again. A gap review against the wrong one is work you pay for twice.

Same lineage, different programme, and you can't substitute one for the other. CMMC and CPCSC both descend from NIST SP 800-171, so the control work overlaps heavily and a supplier who has done the American programme is a long way along. What differs is who runs it, who accredits the assessors, the level definitions and the timetable. If you sell into both defence markets, we'll map the overlap so you build once.

To win, in this phase. Certification isn't required during bidding, it's required at contract award on the contracts that carry it, which is a genuine piece of breathing room and also a trap. Suppliers hear "not needed to bid" and defer, then win work they can't accept on schedule. The safe read is that you need it before you'd be awarded anything, not before you'd submit.

No, and at Level 2 nobody who built your controls can. The Standards Council of Canada accredits the third-party assessment organisations, and Level 3 is assessed by National Defence directly. We prepare you, close the gaps, and stand behind the evidence. For Level 1 you sign your own self-assessment, and our job is making sure every answer on it is defensible.

Someone inside your organisation signs it, which makes it an attestation about systems you operate rather than a report a consultant hands you. An answer that turns out to be a policy with nothing running behind it is one you can't defend at award or at the annual renewal. We keep a configuration reference and a ticket behind every yes, so the person signing can check it first.

When you have no defence work and no bid pipeline into it, because this only has value against contracts that carry the requirement. When nobody will own the annual renewal, since a self-assessment is a recurring obligation rather than a project. And when your scope decision is still open, because gapping the wrong environment is the most expensive mistake available here.

PARLONS-EN

Un spécialiste chevronné répond en moins d'une heure, 24/7.