Canadian defence cybersecurity

Canada Just Made CPCSC Mandatory. Your Next Defence Contract Depends on It.

Level 1 certification is now entering select defence contracts. Here is what that means for your business and what you need to do before Summer 2026.

ArticleCPCSC Levels 1, 2 and 3Defence procurementCertification readiness
SC
Written bySanjay Chadha8 minute read

On April 14, 2026, the Government of Canada formally introduced Level 1 of the Canadian Program for Cyber Security Certification. Level 1 will be required in select defence contracts beginning in Summer 2026.

To become certified, suppliers must complete and attest to meeting all Level 1 criteria. For companies that have not started preparing, the deadline is closer than it looks.

The practical messageCPCSC is operational. Suppliers need to understand the level that applies, assess their current position, close gaps and prepare before the requirement appears in a contract or prime contractor onboarding process.

The Program at a Glance

Canada's defence supply chain has long relied partly on supplier self-declaration. That era is ending. CPCSC is the government's structured response to sustained cyberattacks targeting contractors and subcontractors that handle unclassified federal information.

The program is administered by Public Services and Procurement Canada, with support from National Defence, the Standards Council of Canada, the Canadian Centre for Cyber Security and Treasury Board Secretariat.

1

Level 1

Annual cybersecurity self-assessment against foundational requirements.

Mandatory in select defence contracts beginning Summer 2026.
2

Level 2

External assessment by an accredited certification body.

Designed for contracts involving controlled defence information and more complex cyber-sensitive work.
3

Level 3

Government-led assessment conducted by National Defence.

Reserved for the most sensitive programs and national security work.

If you handle sensitive unclassified government information, the central question is no longer whether certification will matter. It is whether you will be ready when a contract clause or prime contractor requirement reaches you.

How the Rollout Is Structured

The phased implementation matters because the sequencing is unforgiving. Each stage gives suppliers time to prepare, but only if they start before a contract is at risk.

March 2025

Phase 1 introduced the Canadian industrial cybersecurity standard, opened accreditation and released a Level 1 self-assessment tool.

April 2026

Level 1 became available to suppliers and the program moved into active implementation.

Summer 2026

Level 1 requirements begin appearing in select defence contracts.

Spring 2027

Level 2 requirements begin entering select contracts involving controlled defence information.

After 2027

Level 3 is introduced for the highest-risk programs involving weapons systems and Five Eyes-related work.

What this means for current bidsIf you plan to bid on defence work in the second half of 2026, your Level 1 assessment should already be underway. If you handle controlled defence information, Level 2 readiness should already be on your roadmap.

The Connection to CMMC

Canadian and American defence procurement are deeply connected. CPCSC was designed with that relationship in mind.

CPCSC

Canada's certification pathway for defence suppliers.

Shared
control base
CMMC

The United States certification pathway for defence suppliers.

Canadian industrial cybersecurity standards align with the 172 controls in NIST Special Publications 800-171 and 800-172, which also underpin the U.S. CMMC program. Canada may accept a contractor's valid CMMC status on a case-by-case basis.

For suppliers already pursuing U.S. defence work, CPCSC and CMMC readiness involve much of the same underlying work. Existing familiarity with NIST-aligned frameworks is a head start, but it is not a substitute for completing the CPCSC process.

Why This Is a Revenue Protection Issue

The immediate risk for defence suppliers is commercial. Once certification is required and a supplier cannot provide it, the consequences are direct.

Lost contract awards

A supplier that cannot demonstrate the required certification may lose work it has already competed to win.

Replacement by a prime

A subcontractor that cannot satisfy onboarding requirements may be replaced within the supply chain.

Reduced market access

Certification is becoming a baseline qualifier for Canadian and allied defence opportunities.

Cybersecurity compliance is therefore not only a technical or regulatory issue. It protects revenue, business relationships and access to long-term defence programs.

What the Certification Levels Actually Require

Level 1: self-assessment against foundational controls

Level 1 requires suppliers to identify the implementation status of 13 security requirements and controls. The Government of Canada provides an online self-assessment tool, but accurate completion still depends on having a clear, documented understanding of the organization's current cybersecurity posture.

Level 2: accredited third-party verification

Level 2 assessments are performed by accredited third-party organizations through the Standards Council of Canada. This level applies when a contract involves controlled defence information or more complex cyber-sensitive work. Assessor capacity, scheduling and preparation all need to be considered well before a contract deadline.

Level 3: government-led assessment

Level 3 is conducted by the Government of Canada and applies to the highest-risk scenarios, including work involving weapons systems, critical infrastructure or sensitive Five Eyes information.

Where Most Suppliers Are Getting Stuck

The primary challenge is not unwillingness to comply. It is the gap between operating secure technology and demonstrating formal compliance.

Many suppliers have capable IT teams but limited experience mapping controls to NIST 800-171, documenting a System Security Plan or preparing for a formal third-party cybersecurity assessment.

Operational security and certification readiness are different disciplinesKeeping systems secure is essential. Certification also requires documented controls, evidence, assigned ownership, gap remediation and an assessment-ready environment.

What Suppliers Need to Do Before the Requirement Arrives

Step 1Identify the likely level

Review contracts, prime contractor expectations and the information your organization handles.

Step 2Assess your current position

Map existing controls against the applicable CPCSC and NIST requirements.

Step 3Close and document gaps

Create a remediation roadmap, assign owners and organize evidence.

Step 4Prepare for certification

Complete Level 1 accurately or begin planning for an accredited Level 2 assessment.

Certification may be required at contract award rather than throughout the bidding process. That can create a false sense of time. Winning a contract and then scrambling to certify is not a reliable strategy.

The Bottom Line

CPCSC is a present business requirement. Level 1 requirements begin appearing in select contracts in Summer 2026. Level 2 follows in 2027, and the accreditation infrastructure is coming online.

The suppliers that will compete effectively in Canada's defence procurement market are those treating cybersecurity certification as a business priority today, not a compliance task for later.

Need clarity on your CPCSC readiness?SC US can help defence suppliers understand the applicable level, assess their current control environment, build a remediation plan and prepare for certification.

More Blogs & Insights

CPCSC Certification Isn’t One-Size-Fits-All. Here’s How to Know Which Level You Need.

CPCSC Certification Isn’t One-Size-Fits-All. Here’s How to Know Which Level You Need.

CPCSC, Cybersecurity Certification Canada, Defence Supply Chain Security, Government of Canada Cybersecurity Requirements, CPCSC Level 1 Certification, Cyber Governance, Regulatory Compliance, Cybersecurity Compliance Frameworks, NIST 800-171, CMMC, Defence Contractor Cybersecurity, Cyber Risk Management, Supply Chain Risk, IT Audit, Cyber Resilience, Emerging Tech Risks

Canada Just Made CPCSC Mandatory. Your Next Defence Contract Depends on It

Canada Just Made CPCSC Mandatory. Your Next Defence Contract Depends on It

CPCSC, Cybersecurity Certification Canada, Defence Supply Chain Security, Government of Canada Cybersecurity Requirements, CPCSC Level 1 Certification, Cyber Governance, Regulatory Compliance, Cybersecurity Compliance Frameworks, NIST 800-171, CMMC, Defence Contractor Cybersecurity, Cyber Risk Management, Supply Chain Risk, IT Audit, Cyber Resilience, Emerging Tech Risks

Why Many Investors Pay More Tax Than They Need to Without Realising It

Why Many Investors Pay More Tax Than They Need to Without Realising It

Tax Compliance, Corporate Tax, Personal Tax, Tax Planning, Capital Gains Tax, CRA Regulations, Canadian Taxation, Tax Advisory, Tax Filing, Tax Optimization, Small Business Tax, HST/GST, Payroll Taxes, Cross-Border Tax, Tax Risk Management, Financial Reporting, Audit & Assurance

1 2 3 13

SAV Associates is on your Side

By partnering with SAV Associates, you gain access to a team of experts dedicated to ensuring your business’s financial health and compliance, allowing you to focus on achieving your business objectives.