CPCSC Level 1 for Canadian Defence Suppliers (2026): The 13-Control Guide

Tags:

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.

Public Services and Procurement Canada introduced CPCSC Level 1 on April 14, 2026; it becomes a contract-award gate on select federal defence procurements in summer 2026. Canadian businesses selling into national defence supply chains, even three tiers down, fall inside the supplier population. Level 1 is an annual self-assessment against 13 baseline controls, attested by the supplier at award.

Most managed Microsoft 365 tenants already cover the technical floor. The binder is where suppliers fall behind.

Key Takeaways

  • CPCSC Level 1 is an annual self-assessment against 13 baseline controls drawn from ITSP.10.171, the Canadian adaptation of NIST SP 800-171.
  • Scope reaches every Canadian supplier handling specified information: sensitive, unclassified defence data, including sub-contractors several tiers deep.
  • Across Fusion Computing’s 2026 Canadian defence-supplier engagements (anonymized client data), roughly 9 of 13 controls are typically already met by a managed Microsoft 365 stack; 4 are supplier-internal policy work.
  • The filing itself takes under an hour with a documented evidence binder; readiness preparation for a 25-person SMB runs 30 to 60 days.
  • CPCSC L1 maps closely to CMMC Level 1, and Ottawa may recognize a valid CMMC certificate case by case after confirming scope.

Book a CPCSC Readiness Consultation

What is the Canadian Program for Cyber Security Certification (CPCSC)?

According to PSPC (2026), CPCSC is the official cyber security certification for defence suppliers in Canada, built on a standard developed by the Canadian Centre for Cyber Security. Level 1 is an annual self-assessment against 13 controls that verifies basic cyber hygiene before a contract is finalized.

CPCSC is a procurement framework that gates select Canadian defence work on supplier cyber hygiene. Three tiers are planned; Level 1 is the entry point and the only one active in 2026.

Level 1 is a yearly exercise completed in-house, with no third-party assessor involved. The 13 controls trace to ITSP.10.171, the Canadian adaptation of NIST SP 800-171; each control expands into the lettered assessment objectives set out in the Level 1 criteria document. See related context in 2026 Canadian cyber takeaways.

Who needs CPCSC Level 1, and when

PSPC (2026) defines the protected asset as specified information: sensitive, non-classified government data on supplier systems, including contract details not meant for public release and controlled goods material. Compliance is checked at award rather than during bidding, so a firm can bid without Level 1 but cannot be awarded until the attestation is in place.

CPCSC Level 1 applies to any Canadian supplier handling unclassified-but-sensitive federal defence data, regardless of company size. The list runs deeper than most owners expect:

  • Prime defence contractors bidding directly on DND and other defence awards.
  • Tier-1 sub-contractors manufacturing components or fabricating parts for a prime.
  • Tier-2 and tier-3 suppliers several hops removed, including engineering firms, CAD bureaus, calibration labs, and logistics partners.
  • IT and professional-services firms with access to a prime’s defence-related systems.

An Ontario machine shop fabricating brackets for a DND platform is in scope. So is a Vancouver engineering firm holding a sub-contract, and a Hamilton MSP managing a defence supplier’s tenant. An inaccurate or missing filing blocks the deal. If your firm sits anywhere in that chain, book a CPCSC readiness consultation before the summer gate reaches your bids.

CITATION CAPSULE

Public Services and Procurement Canada introduced CPCSC Level 1 on April 14, 2026, applying to organizations of all sizes that sell into Canada’s defence supply chain (Government of Canada news release, 2026). The Canadian Centre for Cyber Security publishes the underlying baseline standard that defines the supplier control set (CCCS, 2026).

The 13 controls inside CPCSC Level 1

The CPCSC program overview (2026) groups the 13 Level 1 controls into six cyber-hygiene best practices: managing who can access systems, controlling how systems and data are used, verifying users and devices, protecting data and equipment, and defending systems from cyber threats. The control set maps one-to-one onto the table below, from access control through system integrity.

The 13 Level 1 controls cover six ITSP.10.171 families: Access Control, Identification and Authentication, Media Protection, Physical Protection, System and Communications Protection, and System and Information Integrity. An MSP-served Canadian SMB is typically 70 percent aligned on day one.

Control ID What it requires Evidence
Account management 03.01.01 Inventory accounts; add, disable, and review on join and exit Entra ID user export, joiner-mover-leaver records
Access enforcement 03.01.02 Least-privilege access by role Conditional Access policy export, group access matrix
Use of external systems 03.01.20 Approved systems only for federal work Approved-systems list, cloud vendor security notes
Publicly accessible content 03.01.22 Control federal information on public sites Public-information release log signed by leadership
User identification and authentication 03.05.01 Unique accounts, verified identities Unique account list
Device identification and authentication 03.05.02 Only known devices connect Intune device join and compliance records
Multifactor authentication 03.05.03 MFA enforced before access Phishing-resistant MFA enforcement report
Media sanitization 03.08.03 Sanitize media before disposal or reuse End-of-life device log with serial numbers
Physical access authorizations 03.10.01 Authorized-person list for facilities Server-room list, keycard access roster
Physical access control 03.10.07 Control and escort facility access Visitor sign-in log, badge policy
Boundary protection 03.13.01 Monitor and control communications at the boundary Firewall config export, VPN posture
Flaw remediation 03.14.01 Identify, report, and correct system flaws Patch SLA report, 30-day cadence
Malicious code protection 03.14.02 Block malicious code at endpoints EDR coverage report across all endpoints

Technical implementation is basic on a managed Microsoft 365 Business Premium tenant. Suppliers fail on the binder: policy PDFs, Conditional Access screenshots, joiner-mover-leaver workflow, and visitor log. Fusion Computing recommends pairing Level 1 prep with a documented incident response plan.

CPCSC Level 1 vs CMMC Level 1 (US DoD): how they overlap

According to federal guidance (2026), CPCSC aligns with US CMMC requirements without duplicating the American certification system: both countries use the same technical controls, and the Government of Canada may accept a supplier’s valid CMMC certification case by case after confirming the assessment covers the required scope. Dual-market suppliers should still expect Canadian paperwork, because attestation records live in CanadaBuys, not SPRS.

Suppliers selling into both Canadian and US defence markets share DNA across the two programs but face different standards, scopes, and certification paths.

Dimension CPCSC L1 (Canada) CMMC L1 (US DoD)
Foundational standard ITSP.10.171 / NIST SP 800-171 NIST SP 800-171 Revision 2
Control count 13 17
Assessment path Annual self-assessment Annual self-assessment
Filed at Contract award; attestation recorded in CanadaBuys Contract award via SPRS
Cross-recognition May accept valid CMMC certification case by case No CPCSC recognition published
Data sovereignty Canadian jurisdiction explicit Not addressed

Three implications matter for dual-market suppliers. CPCSC and CMMC L1 share NIST SP 800-171 ancestry, so assessment evidence often repackages across both filings. Recognition runs one way for now: PSPC may accept a valid CMMC certification after confirming scope, with proof sent in and verification handled by the contract technical authority. ISO 27001:2022 alignment helps because management-system controls overlap, but it does not replace either filing.

“We chose Fusion after evaluating several MSPs and have been extremely pleased. They have been a key partner in helping us strengthen our cybersecurity while keeping the business running smoothly.”

Nick Efthimiadis, MD Charlton. Quote shared with permission.

The CPCSC Level 1 self-assessment process

The Level 1 guidance (2026) puts the online self-assessment at under an hour once policies are reviewed, ending in a results page with an expiry date the supplier must keep. The attestation and expiry are then confirmed in the CanadaBuys supplier profile before bidding on, or working under, a defence contract that requires Level 1.

The online tool is encouraged rather than mandatory; a supplier may attest by other means, but stays responsible for retaining the results. The lifecycle has 4 phases:

  1. Scope. Define the boundary using the CPCSC Scoping Guide. For most SMBs that covers the production tenant, CAD systems, and file shares with in-scope work product.
  2. Self-assess. Walk all 13 controls and their assessment objectives. Mark each Met, Not Met, or Not Applicable with a recorded justification.
  3. Attest. Do so at contract award and record the result and expiry date in your CanadaBuys profile. A supplier may bid without certification but cannot be awarded.
  4. Renew. Repeat annually; maintain the binder so renewal is a 30-minute exercise.

The Scoping Guide carries weight. Too wide inflates the paperwork load; too narrow risks an audit finding.

Evidence package: what assessors look for

The same supplier guidance (2026) makes each organization responsible for retaining its self-assessment results, however they were produced, and calls for short written rules covering password control, approved systems, access granting, hardware onboarding, and destruction of old media. The folder holding those artifacts is what answers a procurement officer’s questions later.

This dossier separates a clean self-assessment from a procurement integrity risk. Reviewers expect documented, dated, executed artifacts mapped to each control’s ITSP.10.171 assessment objectives. The minimum binder includes:

  • Written Acceptable Use Policy and media-sanitization procedure
  • Joiner-mover-leaver workflow signed by HR
  • Visitor log template in active use, end-of-life device disposal form
  • MFA enforcement export and Conditional Access policy export
  • Patch SLA report covering the last 90 days, EDR coverage report

That file set is the supplier’s contract-defence record. If a procurement officer questions an attestation, it is what answers the question. Talk to Fusion about a dossier review before you file.

The 90-day CPCSC Level 1 readiness plan

According to Fusion Computing’s anonymized client data from 2026 defence-supplier engagements, a 25-person supplier with a managed tenant reaches filing readiness in 30 to 60 days. The FC internal benchmark from Q2 2026 puts the MSP-led phases at roughly half that calendar; policy sign-off on the owner side consumes the rest. We benchmarked the schedule below against those engagements.

An ordered 90-day plan turns the self-assessment into confirmation rather than discovery. It is what FC uses to close Level 1 inside one quarter.

Phase Action Owner Days
Days 1-15 Define assessment boundary, inventory accounts, devices, and systems MSP and supplier leadership 15
Days 16-30 Enforce phishing-resistant MFA, close standing local-admin accounts, tune Conditional Access MSP 15
Days 31-45 Verify EDR coverage, document 30-day patch SLA, export firewall config MSP 15
Days 46-60 Publish AUP, media-handling, visitor, and joiner-mover-leaver policies Supplier HR and leadership 15
Days 61-75 Document physical access, build server-room list, activate visitor log, EOL device form Supplier operations 15
Days 76-90 Run dry-run, assemble binder, complete the attestation, schedule annual review MSP and supplier 15

The first 45 days are MSP-led and move quickly. Days 46 to 75 drag because they wait on owner and HR sign-off. Map controls against ITSP.10.171 before the dry-run.

Talk to Fusion

Every engagement is run by a CISSP-led team at a Microsoft Solutions Partner.

Tools FC deploys for CPCSC alignment

Fusion Computing deploys a managed Microsoft stack that closes 9 of the 13 Level 1 controls, and vendor documentation maps each workload to what a reviewer wants: Entra ID exports for access control, Intune records for machine identity, Defender reports for malicious-code protection. The six tools below carry the tooling half of the paperwork, leaving leadership to sign the four policy controls no platform can cover.

  • Entra ID covers account management (03.01.01), access enforcement (03.01.02), user identification (03.05.01), and MFA (03.05.03) via user inventory, Conditional Access, and phishing-resistant MFA.
  • Defender for Endpoint handles malicious code protection (03.14.02) with EDR coverage reports across every managed machine.
  • Intune enrolls endpoints, supplies device identification records for 03.05.02, and enforces compliance baselines.
  • NinjaOne drives the 30-day patch SLA for flaw remediation (03.14.01) and produces the EOL disposal log for media sanitization (03.08.03).
  • Sentinel aggregates perimeter-monitoring data for boundary protection (03.13.01) and supports the yearly review.
  • Purview handles publicly accessible content logging (03.01.22).

Not sure which controls your current stack already closes? Call 416-566-2845 and ask for a CPCSC gap review.

Field note

Early 2026, a 35-person Ontario fabricator on a federal defence sub-contract called us six weeks before a contract-award gate. The technical posture was solid: Business Premium, Defender for Endpoint, MFA across the tenant. The team had assumed certification was an MSP deliverable. It is not.

What was missing was the supplier-side binder: a written AUP, a joiner-mover-leaver workflow signed by HR, a visitor log, and an end-of-life device form. We closed the technical evidence in eight working days. Their HR director wrote and signed the four policies in another twelve. They filed on day 26 and won the renewal.

The lesson: 9 of 13 controls are tooling. The other 4 are leadership signature, and that signature has to come from inside the supplier.

Mike Pearlstein, Fusion Computing

Common CPCSC mistakes Canadian suppliers make

The PSPC news release (2026) introducing Level 1 stresses a phased approach: during the initial phase, certification is checked only at contract award, giving suppliers a grace window during bidding. Across Fusion Computing’s 2026 defence-supplier engagements, six recurring errors burn exactly that window. Each is recoverable, but each delays a contract-award decision.

  • Drawing the boundary too wide. Pulling the entire tenant in when only a project-specific OU touches in-scope information.
  • Treating the MSP as the certification owner. The MSP closes controls; the supplier files the attestation and signs the policies.
  • Self-attesting before the policy binder exists. The assessment objectives map to documented artifacts; verbal practice fails an auditor cross-check.
  • Skipping physical protection. A locked server closet still counts as a server room and still needs an access list and a visitor log.
  • Assuming CMMC recognition is automatic. Ottawa accepts a valid CMMC certificate only case by case, after confirming scope; proof must be submitted for verification.
  • Filing once and forgetting. Level 1 recurs every year; skipped renewals lose contract eligibility on the next award cycle.

CITATION CAPSULE

NIST SP 800-171 is the parallel US standard CPCSC tracks; it defines protection requirements for controlled unclassified information that ITSP.10.171 adapts for Canada (NIST, 2024). CMMC 2.0 program documentation defines the parallel US procurement gate (US DoD, 2025); ISO 27001:2022 supplies the management-system control overlap suppliers can reuse (ISO, 2022).

Frequently asked questions

What is CPCSC Level 1?

CPCSC Level 1 is an annual cyber-security self-assessment against 13 baseline controls drawn from ITSP.10.171, the Canadian adaptation of NIST SP 800-171. It becomes required at contract award on select federal defence procurements beginning summer 2026.

Who must comply with CPCSC L1?

Any Canadian supplier handling unclassified-but-sensitive federal defence information, regardless of size: primes, sub-contractors several tiers deep, IT providers with access to defence systems, and professional-services firms in the supply chain.

How many controls are in CPCSC Level 1?

Thirteen baseline controls across six ITSP.10.171 families. Each control expands into the lettered assessment objectives set out in the Level 1 criteria document, the Canadian version of NIST SP 800-171A Rev. 3.

How long does the CPCSC L1 self-assessment take?

The filing itself takes under an hour using the online self-assessment tool when policies are documented and evidence is assembled. Readiness preparation typically runs 30 to 60 days for an SMB engaged with an MSP.

What does CPCSC L1 readiness cost a Canadian SMB?

An MSP-served Microsoft 365 Business Premium tenant runs CA$4,000 to CA$8,000 in MSP fees plus 15 to 25 hours of leadership time. Suppliers entering without a managed stack can exceed CA$25,000 total.

Does a CMMC L1 certificate satisfy CPCSC L1?

Sometimes. Both programs use the same technical controls, and Ottawa may accept a valid CMMC certification case by case after confirming the assessment covers the required scope; proof is submitted for verification. Without that recognition, the supplier completes the 13-control CPCSC self-assessment.

Does ISO 27001:2022 cover CPCSC L1?

ISO 27001:2022 covers the management-system overlap and shortens preparation, but ISO certification on its own is not accepted for CPCSC purposes.

Does the MSP file CPCSC certification on the supplier’s behalf?

An MSP can typically close 9 of the 13 controls and support evidence assembly. The filing itself is done by the supplier; the supplier signs the policies and owns the annual renewal.

Can a supplier bid on a defence contract before completing CPCSC Level 1?

Yes. During the initial phase, certification is required at contract award, not during bidding. A supplier can submit a bid while preparation work is underway, but the attestation and its expiry date must be confirmed in the CanadaBuys supplier profile for contracts that require Level 1.

What counts as specified information under CPCSC?

Specified information is sensitive, non-classified Government of Canada data handled on supplier systems. PSPC’s examples include unclassified contract details not intended for public release, controlled goods records, and protected material. The contract identifies what requires safeguarding.

What happens if a supplier files Level 1 incorrectly?

An inaccurate attestation is a procurement integrity risk. Suppliers can lose contract eligibility, face termination, or be referred for review. The fix is documented proof tied to the 13 controls and an honest self-assessment.

Is CPCSC Level 2 coming next?

Yes. Level 2 requires external assessments led by an accredited certification body plus an annual affirmation, against 98 controls. Level 3, assessed by National Defence against 200 controls, follows. PSPC says the remaining levels arrive in the coming years.

Related Resources

Last updated: July 2026.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Led by a CISSP-led team, Fusion supports organizations with 10 to 150 employees from Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611