Built for defence contractors pursuing CPCSC Level 1, our assessment tool helps you identify compliance gaps, get remediation recommendations, and generate a detailed report outlining the practical steps needed to strengthen your cybersecurity posture.
Partially Ready
Use the scorecard to identify control gaps, evidence needs, and remediation priorities before formal procurement or self-attestation activities.
The Readiness Assessment is designed to help suppliers move from general concern to a practical readiness roadmap.
Complete a short assessment based on CPCSC Level 1 cyber hygiene areas. No jargon, no trick questions.
View your overall score, domain-level gaps, and areas that may need evidence, documentation, or control improvement.
Use your results to prioritize remediation, prepare documentation, and decide whether you need advisory support before contract award.
The Readiness Assessment covers the control areas most likely to require
documentation, evidence, or remediation work before self-assessment.
AC
Confirm that user accounts, permissions, and access changes are managed intentionally.
IA
Evaluate whether users and systems are properly authenticated before accessing sensitive information.
MP
Confirm that user accounts, permissions, and access changes are managed intentionally.
PP
Assess whether facilities, offices, devices, and restricted areas are protected from unauthorized access.
SC
Understand whether sensitive information is protected when transmitted, stored, or accessed across networks and cloud systems.
SI
Check whether systems are patched, monitored, protected from malware, and reviewed for vulnerabilities.
SAV brings an assurance-grade lens to CPCSC readiness. Our team combines CPA audit discipline, ISO certification experience, cybersecurity advisory, SOC reporting, IT risk assessments, and practical evidence readiness support.
SAV approaches CPCSC readiness with the discipline of a CPA audit and ISO certification body. We focus on documentation, evidence, control design, and practical readiness.
We help map CPCSC expectations to ISO 27001, SOC 2, CyberSecure Canada, CMMC, NIST, and existing governance programs so teams avoid duplicate work.
Our recommendations are designed for real businesses, not theoretical control libraries. We prioritize what reduces risk and supports procurement readiness.
We understand Canadian public-sector expectations, supplier obligations, and the importance of clear, defensible security documentation.
If CPCSC could affect your contract eligibility, SAV can help you confirm scope,
identify control gaps, prepare evidence, and build a practical remediation plan.
Answers to common questions about CPCSC readiness, self-assessment support, and how SAV can help.
No. This is a readiness and planning tool created by SAV Associates to help organizations understand potential gaps before completing formal self-assessment or procurement requirements.
CPCSC Level 1 focuses on foundational cyber hygiene controls for suppliers that may handle sensitive, unclassified Government of Canada information.
SAV can support readiness, gap assessment, remediation planning, documentation, evidence preparation, and framework mapping. Formal certification requirements should be confirmed against current Government of Canada guidance.
Existing ISO 27001, SOC 2, CyberSecure Canada, CMMC, or NIST-aligned controls may help reduce duplicate work. SAV can map existing controls to CPCSC expectations and identify remaining gaps.
The CPCSC Level 1 Readiness Assessment takes less than 10 minutes. Get your
scorecard, see your top gaps, and walk away with a 30-day action plan.
Complete the guided readiness workflow. Your scorecard will show overall readiness, domain-level results, top gaps, and recommended next steps.