CPCSC Compliance: What Canadian Defence Suppliers Must Do Before the Summer Deadline
CPCSCDefenceCanadian Compliance

CPCSC Compliance: What Canadian Defence Suppliers Must Do Before the Summer Deadline

By Krikor Tengerian · Co-founder, SecuritAI Technologies Ltd. · July 2026 · 7 min read

CPCSC compliance is about to decide who wins Canadian defence work and who gets screened out before their bid is even read. In April 2026, Public Services and Procurement Canada introduced Level 1 of the Canadian Program for Cyber Security Certification, and Level 1 requirements are set to appear in select Department of National Defence contracts starting this summer. Certification is attested at contract award, and there is no grace period. If your company machines parts, writes software, ships electronics, or provides services anywhere in the defence supply chain, this affects you directly.

This guide covers why the program exists, what CPCSC compliance actually requires at Level 1, the deadlines that matter, and the fastest realistic path to getting certified before your next bid.

Why CPCSC compliance exists: attackers target the supply chain

Adversaries rarely attack a defence prime head on. Primes have security teams, budgets, and monitoring. The soft target is the 40 person machine shop, the specialist electronics firm, or the logistics provider three tiers down that holds drawings, specifications, and contract information with a fraction of the defences.

This is not theoretical. Ransomware has repeatedly halted manufacturers, including the 2020 EKANS attack that forced Honda to pause production at plants around the world. When the victim is a defence supplier, the damage goes beyond downtime. Sensitive government information can be exposed, and every contractor upstream inherits the risk.

Canada's answer is CPCSC. Instead of trusting each supplier's self description, the government now requires proof. The controls come from ITSP.10.171, the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171, which sets out how to protect sensitive government information on non government systems. CPCSC compliance is the mechanism that turns those controls into a condition of doing defence business.

What CPCSC compliance requires at Level 1

Level 1 is an annual self assessment against 13 controls from ITSP.10.171. You attest to the result, and that attestation is checked at contract award. The 13 controls are solid cyber hygiene, grouped into six areas:

  • Access control. Manage accounts through their whole life cycle, enforce least privilege access by role, control the use of external systems for federal work, and control what federal information appears on public sites.
  • Identification and authentication. Give every user a unique verified identity, allow only known devices to connect, and enforce multifactor authentication before access.
  • Media protection. Sanitize or destroy storage media before disposal or reuse.
  • Physical protection. Keep an authorized persons list and control and escort access to your facilities.
  • System and communications protection. Monitor and control communications at your network boundary.
  • System and information integrity. Identify, report, and correct system flaws, and block malicious code at endpoints.

None of these controls is exotic. The hard part is proving all 13 at once, with evidence, on a deadline. Most small and mid sized suppliers discover their gaps only when a bid is already on the line, and that is exactly the scenario CPCSC compliance is designed to prevent.

The deadlines that matter

Two dates should drive your planning:

  • Summer 2026. Level 1 requirements begin appearing in select DND contracts. Attestation happens at contract award with no grace period, so a supplier who starts after seeing the requirement in a tender has already lost the timing battle.
  • 2027 and beyond. Level 2 raises the bar to roughly 98 controls from ITSP.10.171 and moves from self assessment to assessment involving a certification body. Suppliers handling more sensitive information should treat Level 1 as the floor and begin building toward Level 2 now.

The pattern from similar programs in the United States is clear. Requirements start in select contracts, then spread. Waiting to see whether your contracts are affected is a bet against the direction the entire program is moving.

How to get CPCSC compliance done before your next bid

Here is the practical sequence we recommend to defence suppliers:

  • Run a gap assessment against the 13 controls this week. You cannot plan remediation until you know where you stand. Our free 10 minute CPCSC readiness check scores you against all 13 controls and shows exactly which ones you would pass or fail today.
  • Fix the fast gaps first. Multifactor authentication, account reviews, and endpoint malware protection are usually quick wins that close several controls at once.
  • Write down what you already do. Many suppliers actually perform the controls but have no policies or records to prove it. An attestation without evidence behind it is a liability, so document as you go.
  • Assign one owner per control area. The six areas above map naturally to whoever runs IT, operations, and facilities. Controls without owners drift.
  • Keep the evidence current. Level 1 is annual, and Level 2 is coming. Treat CPCSC compliance as a system you maintain, not a binder you produce once.

If your shop floor runs industrial or OT equipment, remember that boundary protection and malicious code controls extend to those environments too. For suppliers who want managed help on that side, our sister company Secur-IT Data Solutions provides managed cybersecurity services in Toronto and the GTA, including OT security for manufacturers.

How SecuritComply helps

SecuritComply is a Canadian GRC platform built for exactly this problem. For CPCSC compliance it gives you the full Level 1 workflow in one place: the 13 ITSP.10.171 controls in plain English, a guided self assessment with status tracking per control, an evidence store so every answer is backed by proof, gap analysis that turns failures into assigned tasks, and an attestation report ready for contract award. When Level 2 arrives, the same platform carries your evidence forward to the larger control set.

We use the platform ourselves for our own certification work, so the workflow you get is the one we trust with our own defence supply chain readiness. You can see the details on our CPCSC compliance page, and if you are still deciding whether the program applies to you, start with What is CPCSC and does my Canadian company need it.

Frequently asked questions

Is CPCSC compliance mandatory for all Canadian defence suppliers?

Level 1 requirements are being introduced in select DND contracts starting summer 2026, and coverage is expected to expand. If you sell to DND directly or supply a defence prime, you should assume your contracts will carry the requirement and prepare now.

How long does Level 1 take for a small supplier?

It depends entirely on your gaps. A supplier that already enforces MFA, patching, and access reviews can often complete the self assessment and evidence in weeks. A supplier starting from scratch on several controls should budget a few months, which is exactly why starting before a bid appears matters.

What is the difference between CPCSC Level 1 and Level 2?

Level 1 is an annual self assessment against 13 controls from ITSP.10.171. Level 2 covers roughly 98 controls and involves assessment beyond self attestation. Level 2 is expected to become a requirement for suppliers handling more sensitive information starting in 2027.

Does CPCSC compliance replace ISO 27001 or SOC 2?

No. CPCSC is specific to Canadian defence procurement. The good news is the controls overlap heavily with ISO 27001 and SOC 2, so work you have done for those frameworks counts toward CPCSC, and a platform that maps controls across frameworks saves you from doing the same work twice.

References

Ready to get compliant?

SecuritComply makes it simple, 17 frameworks, Canadian data residency, 50 to 70% less than typical US quotes.

Start Free →