
By Krikor Tengerian · Co-founder, SecuritAI Technologies Ltd. · September 2026 · 11 min read
Your bid team just read a clause in a National Defence contract and stopped. It asks for CPCSC Level 1, and nobody in the company has heard of it. This CPCSC Level 1 checklist walks through all 13 controls you have to attest to, the proof each one asks for, and where the attestation goes once you are finished.
Most Canadian suppliers meet this program the same way. It arrives inside a contract rather than inside a security plan, and the first person to read it is whoever handles proposals.
Here is the part people get wrong. Nobody certifies you at Level 1. Public Services and Procurement Canada, which leads the Canadian Program for Cyber Security Certification, describes Level 1 as an annual cyber security self-assessment covering 13 controls, while Level 2 requires external assessments led by an accredited certification body and Level 3 requires assessments conducted by National Defence. At Level 1 you assess yourself, you attest, and you own that attestation. There is no assessor booked into your calendar, which sounds like the easy version and is actually where the risk sits, because nothing tells you when your answer is wrong.
The controls are not invented by the procurement side of government. They come from the Canadian Centre for Cyber Security publication ITSP.10.171, Protecting specified information in non-Government of Canada systems and organizations. The Cyber Centre states plainly that this publication is a Canadian version of NIST SP 800-171 and that there are no substantial technical changes between the two, with the differences reflecting Canadian regulatory context. Its second release is dated October 28, 2025, and it organizes requirements into 17 families.
Level 1 takes 13 of those requirements. That is the whole scope. If you have been quoted a project that treats Level 1 as a full ITSP.10.171 implementation, the scope has been inflated.
The trigger matters as much as the content. The Government of Canada introduced Level 1 on April 14, 2026 and said it would appear in select defence contracts beginning in summer 2026. During this first phase, certification is not required while you bid. It is required on contract award. That single detail changes who needs to act and when, because a supplier can win the work and then discover the attestation is due.
Every hour you spend on the 13 controls is wasted if you have not decided what they apply to. The program's own Level 1 scoping guide defines specified information as Government of Canada information that must be protected when it is handled, processed, or stored by a non-government organization, and the Cyber Centre defines it as any information other than classified that a government authority identifies and qualifies in a contract as requiring safeguarding.
Read that twice. The contract tells you what is specified information. Not your policy, not your judgment about sensitivity.
The scoping guide asks you to trace the information through its life, meaning received, created, edited, stored, printed, emailed, transferred, backed up and destroyed, then list every asset that touches it. Laptops and desktops, phones and tablets, file shares and cloud storage, servers and applications, backup media, and printers or scanners that can store information all count.
The guide also closes the door most suppliers try to walk through. You cannot exclude a device because someone thinks it is not important. Exclusion means showing the asset cannot reach specified information at all.
Two honest ways to make Level 1 smaller: put specified information in fewer places on purpose, and stop it reaching personal devices. Both shrink the assessment permanently. Neither is a trick.
The controls sit in six families. Work through them in this order, because the access ones set up everything after.
Score yourself as you go. Mark each control implemented, partial, or not started, and write the reason next to every partial. The count at the end is the finding. Thirteen implemented means you attest and move on. Three partials means you have work with a date on it, and you now know exactly which three.
03.01.01 Account management. Define which account types are allowed, create and disable accounts through a written process, name who is authorized and at what level, and disable accounts that are expired, inactive or no longer needed. Keep the account list, the disable records and the leaver notifications.
03.01.02 Access enforcement. Approved authorizations for access to specified information are actually enforced by the system, not just written in a policy. Keep the access control policy, the configuration settings behind it, and the authorization list.
03.01.20 Use of external systems. Decide which external systems your people may use for this information, set the security conditions first, and confirm those conditions are met before anyone processes specified information there. Restrict portable storage on external systems. This is the control that catches personal cloud accounts and the drive somebody bought at a service station.
03.01.22 Publicly accessible content. Train the people who post publicly so specified information never reaches a public page, review public content for it, and remove it if it turns up. Keep the training records and the review notes.
03.05.01 User identification and authentication. Every user is uniquely identified and authenticated, and processes running for a user are tied back to that user. Shared logins fail this control, which is why marketing and sales accounts are so often the first gap found.
03.05.02 Device identification and authentication. Named devices or device types are uniquely identified and authenticated before they connect. This one exposes plan limits more than budgets. Entry tier productivity subscriptions frequently have no device conditional access at all, so meeting it means moving up a plan rather than writing a procedure.
03.05.03 Multi-factor authentication. Strong multi-factor authentication for privileged accounts, and for non-privileged accounts. Keep the configuration screen, the account list and the audit records.
One warning that costs real money if you miss it. Sending accounts and integration accounts break when multi-factor authentication is switched on without preparation. Move those to modern authentication first, then enable it, then document them as monitored service accounts. Do it in the other order and you take your own mail flow down on a Friday.
03.08.03 Media sanitization. Media holding specified information is sanitized before disposal, before it leaves your control, or before reuse. Keep the procedure and the sanitization records. A signed certificate of destruction from whoever takes your old drives satisfies most of this.
03.10.01 Physical access authorizations. Maintain an approved list of who may enter, issue credentials, review the list on a set schedule, and remove people who no longer need access.
03.10.07 Physical access control. Enforce those authorizations at the door, log entry and exit, escort visitors, secure keys and access devices, and control who can reach output devices such as printers. Co-working space is not an automatic failure here, but it does mean your evidence is the building's access record plus your own control over the equipment.
03.13.01 Boundary protection. Monitor and control communications at the external edge of the system and at key internal interfaces, separate publicly accessible components from internal networks, and route external connections through managed boundary devices. A properly configured firewall with its rule set documented carries most of this.
03.14.01 Flaw remediation. Identify, report and correct system flaws, and install security relevant software and firmware updates inside a timeframe you have actually defined. The defined timeframe is the part teams skip. "We patch regularly" is not an answer to this control.
03.14.02 Malicious code protection. Protection at system entry and exit points, updated as new releases arrive, scanning on a set frequency with real time scanning at endpoints, and configured to block or quarantine what it finds.
This is where the checklist stops being a form and starts being a filing problem. The program's guidance on how to meet Level 1 requirements lists the evidence suppliers keep: account lists, device inventories, access review notes, security policies, training records, update logs, visitor logs, firewall documentation and multi-factor authentication configuration. It sets retention at the duration of your attestation cycle, or at least one year.
So the question Level 1 really asks is not whether you have multi-factor authentication. It is whether you can show, twelve months from now, that you had it on the day you attested. That is an evidence problem, and it is the same problem underneath every framework a Canadian buyer asks about.
Most teams can answer the thirteen questions in an afternoon. Far fewer can open a folder and produce the account list, the access review and the firewall configuration as they stood on the day they signed. If you got to this paragraph and thought about where those files actually are, that is the gap, and it is the part worth fixing before the attestation rather than after. You can walk your own thirteen controls with us and see what the evidence trail looks like when it is held for you: book a walkthrough and we will use your scope, not a demo tenant.
The Cyber Centre hosts a self-assessment tool for CPCSC. You are allowed to attest without it, though the guidance encourages using it because it carries the assessment guidance with it, and the sitting typically takes under an hour once your preparation is done.
The output does not stay with you. You provide proof of self-attestation and its expiry date to your CanadaBuys supplier profile and again when you submit a bid. If your CanadaBuys profile is stale, fix that before you start the assessment, because that profile is where a contracting authority looks.
That is the part worth sitting with. Nobody audits your answers at Level 1, so the assessment feels light while you are doing it. What you are actually producing is a signed statement, carrying your name and an expiry date, sitting on a government supplier profile, saying thirteen specific things about your systems are true. The easy version and the exposed version are the same version. A control you marked implemented because it felt close enough is a sentence you have put your signature under.
Being straight about our role. We are not an assessor and we do not issue a CPCSC certificate. At Level 1 nobody does, because the attestation is yours. What we build is the software that holds your 13 control statements, the evidence behind each one, and the date each piece was collected, so next year's attestation is a review rather than a rebuild. Our CPCSC readiness pages show how the controls and evidence are tracked.
If you are earlier than this and still deciding whether the program applies to you, start with what CPCSC is and whether your company needs it, then the deadline guide for defence suppliers. If you sell to government more broadly, what compliance you need to sell to government in Canada covers the wider set.
If you want to work the thirteen controls as a scored self-assessment rather than a reading list, that is what our CPCSC Level 1 readiness check does. It walks the same controls in the same order and tells you where you stand at the end. The rest of our checklists and framework guides sit in the resource library.
Is CPCSC Level 1 a certification issued by an auditor?
No. Public Services and Procurement Canada describes Level 1 as an annual cyber security self-assessment. You assess your own 13 controls and attest to the result. External assessment by an accredited certification body begins at Level 2, and National Defence conducts the assessments at Level 3.
How many controls are in CPCSC Level 1?
Thirteen, drawn from ITSP.10.171 and grouped into six families: access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity.
Do I need CPCSC Level 1 before I can bid?
Not during the current phase. The Government of Canada said when it introduced Level 1 in April 2026 that certification is not required during bidding, only on contract award, with the requirement appearing in select defence contracts from summer 2026. Your attestation and its expiry date are recorded on your CanadaBuys supplier profile.
What is specified information?
Government of Canada information that must be protected when a non-government organization handles, processes or stores it. The Cyber Centre describes it as information other than classified that a government authority identifies and qualifies in a contract as requiring safeguarding. Your contract defines it for you, which is why scoping starts with the contract clauses rather than with your asset list.
How long do I keep the evidence?
For the duration of your attestation cycle, or at least one year, according to the program guidance on meeting Level 1 requirements. That includes account lists, device inventories, access review notes, policies, training records, update logs, visitor logs, firewall documentation and multi-factor authentication configuration.
SecuritComply makes it simple, 17 frameworks, Canadian data residency, 50 to 70% less than typical US quotes.
Start Free →