
By Krikor Tengerian · Co-founder, SecuritAI Technologies Ltd. · July 2026 · 7 min read
CPCSC compliance is about to decide who wins Canadian defence work and who gets screened out before their bid is even read. In April 2026, Public Services and Procurement Canada introduced Level 1 of the Canadian Program for Cyber Security Certification, and Level 1 requirements are set to appear in select Department of National Defence contracts starting this summer. Certification is attested at contract award, and there is no grace period. If your company machines parts, writes software, ships electronics, or provides services anywhere in the defence supply chain, this affects you directly.
This guide covers why the program exists, what CPCSC compliance actually requires at Level 1, the deadlines that matter, and the fastest realistic path to getting certified before your next bid.
Adversaries rarely attack a defence prime head on. Primes have security teams, budgets, and monitoring. The soft target is the 40 person machine shop, the specialist electronics firm, or the logistics provider three tiers down that holds drawings, specifications, and contract information with a fraction of the defences.
This is not theoretical. Ransomware has repeatedly halted manufacturers, including the 2020 EKANS attack that forced Honda to pause production at plants around the world. When the victim is a defence supplier, the damage goes beyond downtime. Sensitive government information can be exposed, and every contractor upstream inherits the risk.
Canada's answer is CPCSC. Instead of trusting each supplier's self description, the government now requires proof. The controls come from ITSP.10.171, the Canadian Centre for Cyber Security's adaptation of NIST SP 800-171, which sets out how to protect sensitive government information on non government systems. CPCSC compliance is the mechanism that turns those controls into a condition of doing defence business.
Level 1 is an annual self assessment against 13 controls from ITSP.10.171. You attest to the result, and that attestation is checked at contract award. The 13 controls are solid cyber hygiene, grouped into six areas:
None of these controls is exotic. The hard part is proving all 13 at once, with evidence, on a deadline. Most small and mid sized suppliers discover their gaps only when a bid is already on the line, and that is exactly the scenario CPCSC compliance is designed to prevent.
Two dates should drive your planning:
The pattern from similar programs in the United States is clear. Requirements start in select contracts, then spread. Waiting to see whether your contracts are affected is a bet against the direction the entire program is moving.
Here is the practical sequence we recommend to defence suppliers:
If your shop floor runs industrial or OT equipment, remember that boundary protection and malicious code controls extend to those environments too. For suppliers who want managed help on that side, our sister company Secur-IT Data Solutions provides managed cybersecurity services in Toronto and the GTA, including OT security for manufacturers.
SecuritComply is a Canadian GRC platform built for exactly this problem. For CPCSC compliance it gives you the full Level 1 workflow in one place: the 13 ITSP.10.171 controls in plain English, a guided self assessment with status tracking per control, an evidence store so every answer is backed by proof, gap analysis that turns failures into assigned tasks, and an attestation report ready for contract award. When Level 2 arrives, the same platform carries your evidence forward to the larger control set.
We use the platform ourselves for our own certification work, so the workflow you get is the one we trust with our own defence supply chain readiness. You can see the details on our CPCSC compliance page, and if you are still deciding whether the program applies to you, start with What is CPCSC and does my Canadian company need it.
Is CPCSC compliance mandatory for all Canadian defence suppliers?
Level 1 requirements are being introduced in select DND contracts starting summer 2026, and coverage is expected to expand. If you sell to DND directly or supply a defence prime, you should assume your contracts will carry the requirement and prepare now.
How long does Level 1 take for a small supplier?
It depends entirely on your gaps. A supplier that already enforces MFA, patching, and access reviews can often complete the self assessment and evidence in weeks. A supplier starting from scratch on several controls should budget a few months, which is exactly why starting before a bid appears matters.
What is the difference between CPCSC Level 1 and Level 2?
Level 1 is an annual self assessment against 13 controls from ITSP.10.171. Level 2 covers roughly 98 controls and involves assessment beyond self attestation. Level 2 is expected to become a requirement for suppliers handling more sensitive information starting in 2027.
Does CPCSC compliance replace ISO 27001 or SOC 2?
No. CPCSC is specific to Canadian defence procurement. The good news is the controls overlap heavily with ISO 27001 and SOC 2, so work you have done for those frameworks counts toward CPCSC, and a platform that maps controls across frameworks saves you from doing the same work twice.
SecuritComply makes it simple, 17 frameworks, Canadian data residency, 50 to 70% less than typical US quotes.
Start Free →