INDUSTRIES

Defence and Aerospace IT

Your prime pushes its obligations down the contract, and a US-controlled data boundary changes your architecture, not just your paperwork. A cloud region in the wrong country can put you offside on a file you've already won. We name the regime that binds you, then point you at the service that answers it.

WHAT APPLIES

Which rules apply to you?

  • CMMC

    Applies conditionally

    The level your contract names, not the level you'd prefer. It's assessed against the control set underneath it, and a self-declaration stops being enough at Level 2.

  • NIST SP 800-171

    Applies conditionally

    The control set CMMC is built on. Map it once and it carries into most other frameworks you'll be asked about.

  • ITAR and the Controlled Goods Program

    Applies now

    Registration under the Defence Production Act is mandatory before anyone examines, possesses or transfers controlled goods in Canada. Technical data counts, so a drawing sitting on a laptop is in scope.

  • CPCSC

    Applies conditionally

    The Canadian Programme for Cyber Security Certification, which federal defence supply-chain contracts increasingly name.

  • Flow-down from your prime

    Applies now

    Your prime's obligation becomes yours by contract. Your subcontractors' obligations become yours again, and nobody sends you a reminder.

TECHNOLOGY

Whose kit does this run on?

The platforms we design, build and support. Named because a buyer with an estate already standardised on one of them needs to know before the first call, not after it.

Cisco, Palo Alto, Fortinet, F5, VMware, Azure

QUESTIONS

What buyers in this sector ask.

Partly. Phase 2 was suspended on 2026-07-13, and on 2026-09-03 it became a class deviation, which is a regulatory instrument rather than a memo and is harder to reverse. Third-party certification for Levels 2 and 3 is off. Phase 1 self-assessment, SPRS reporting and DFARS 252.204-7012 all remain in place.

Read your subcontract, not the news. The clause your prime flowed down names a standard and sometimes a date, and it stays a term of your contract until somebody issues a modification. Several suppliers stood down in July on the strength of a headline. They're the ones scrambling when the prime asks for a current score.

Often not, and the answer turns on where the data physically sits and who can reach it, rather than on what the vendor's marketing says. Controlled goods obligations were not suspended, not paused, and not under review. They are the steadiest thing on this page, and the easiest to get wrong.

The same way you'd want to be asked: an inventory, evidence rather than attestation, and a record you can show a prime without a scramble. Your obligation reaches your suppliers, and theirs reaches further again, which is the part most defence supply chain cyber programmes discover late.

If you need a C3PAO assessment, we can't be that and build your controls at the same time. We build and evidence. Someone independent assesses, whenever the programme decides what assessment means again. Ask any supplier which of the two they are before you scope the work.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.