CPCSC

The Canadian Programme for Cyber Security Certification is becoming a condition of doing business with DND. We get suppliers ready early.

Typical duration
4–10 months
Primary audience
CISOs & Boards
You leave with
Certification readiness ahead of the contract clause, not after it.

Three phases, start to finish.

  1. 01 Level determination Which CPCSC level your contracts actually require, settled before you spend anything implementing one. Level determined against your contract requirements Scope boundary drawn to keep the assessment small Flow-down obligations to subcontractors identified early
  2. 02 Control implementation Controls implemented against CAN/DGSI 104 and NIST SP 800-171, with the evidence captured as the work happens. Implementation aligned to CAN/DGSI 104 and NIST SP 800-171 Evidence packages built for third-party assessment Supply-chain flow-down guidance for your subcontractors
  3. 03 Assessment readiness A full pre-assessment against the criteria your assessor will use — ahead of the contract clause rather than after it. Pre-assessment against the published assessment criteria Gaps closed and re-evidenced before the assessor arrives Certification readiness ahead of the contract clause

Why now

CPCSC introduces a certification requirement for suppliers handling protected information in Canadian defence procurement. Requirements flow down the supply chain, which means subcontractors are affected by contracts they never signed directly. Suppliers who start after the clause appears in a solicitation are already late.

What we do

  • Determine the level your contracts actually require, so you do not over-certify
  • Implement controls aligned to CAN/DGSI 104 and NIST SP 800-171
  • Design the boundary to keep the assessed environment small
  • Build evidence packages in the form a third-party assessor expects
  • Prepare flow-down guidance for your own subcontractors

CPCSC: the questions we get asked.

What is CPCSC?

The Canadian Programme for Cyber Security Certification introduces a cyber security certification requirement for suppliers handling protected information in Canadian defence procurement. It follows the pattern CMMC established in the United States: a long announcement period, then clauses appearing in solicitations faster than suppliers can certify.

We are a subcontractor, not a prime. Does CPCSC apply to us?

Very likely. Requirements flow down the supply chain, so the obligation reaches you through your customer’s contract — often with a deadline set by someone you have never spoken to. Suppliers who assume they are out of scope because they do not bid directly are the ones most often surprised.

How does CPCSC relate to CMMC?

Both are built on NIST SP 800-171 — CPCSC through ITSP.10.171 — so the underlying control work overlaps substantially. If you supply both Canadian and US defence you will need both certifications, but the gap assessment and most of the implementation are shared; only the assessment processes and the certification bodies differ.

When should we start?

Before the clause appears in a solicitation you want to bid on. CPCSC Level 1 self-assessment opened on 1 April 2026 and began appearing as a condition in selected contracts through summer 2026, so the runway is already short. Mapping where protected information lives is the work that determines cost, it is independent of which level you eventually need, and it cannot be compressed once a deadline exists.

Other lines of work

All services

Tell us what triggered the search. We will scope to that.

We reply to every assessment request within one business day.