Canadian defence cybersecurity
CPCSC Certification Is Not One-Size-Fits-All. Here Is How to Know Which Level You Need.
Not every defence supplier needs the same certification. Here is how Levels 1, 2 and 3 work, what each requires, and how to determine where your business fits.
CPCSC is organized into three certification levels based on the sensitivity of the information and defence work involved. Most suppliers will operate at Level 1 or Level 2. Level 3 is reserved for a narrow group of high-risk national security programs.
On April 14, 2026, the Government of Canada formally introduced Level 1 of the Canadian Program for Cyber Security Certification. Mandatory requirements begin appearing in select defence contracts in Summer 2026, with further requirements following in 2027.
The Three CPCSC Levels at a Glance
Level 1
Annual self-assessment against 13 foundational security controls.
For most suppliers participating in Government of Canada defence contracts.Level 2
Independent third-party assessment against 98 cybersecurity controls.
For controlled defence information and higher-stakes cyber-sensitive work.Level 3
Government-led assessment against 200 controls.
For weapons systems, critical infrastructure and the most sensitive programs.Level 1: The Baseline Every Defence Supplier Needs
Level 1 is the entry point. It became available to suppliers on April 1, 2026, and mandatory requirements begin appearing in select defence contracts starting in Summer 2026.
Suppliers complete an annual self-assessment confirming that they meet 13 security controls drawn from the Canadian industrial cybersecurity standard, ITSP.10.171. The controls are adapted from NIST Special Publication 800-171 and cover foundational practices such as access control, user verification, protection of data and equipment, external system connections and defence against common cyber threats.
Certification may be required at contract award rather than during bidding. That does not create a safe window to delay preparation. Completing the assessment before a requirement appears reduces the risk of winning work that cannot be finalized.
Level 2: Third-Party Verification for Higher-Stakes Work
Level 2 shifts the program from self-attestation to external validation. It is scheduled to enter select defence contracts beginning in Spring 2027.
An accredited third-party assessment organization evaluates whether the supplier has implemented the required cybersecurity controls. The assessment covers 98 controls, and certification must be renewed every three years with an annual affirmation between assessments.
Level 2 applies when a contract involves controlled defence information or more complex cyber-sensitive work. This can include subcontractors embedded in major defence programs, organizations handling sensitive procurement details, and companies building or maintaining systems connected to sensitive government infrastructure.
Organizations with existing ISO 27001, SOC 2 or NIST-aligned controls may already have a meaningful foundation. The remaining work often lies in documentation, evidence and formal assessment readiness.
Level 3: Reserved for the Highest-Risk Programs
Level 3 applies to a narrow set of defence work. Most suppliers in Canada's wider defence industrial base will never need it.
The assessment is conducted directly by National Defence and covers 200 controls. It applies to highly sensitive programs involving weapons systems, critical infrastructure or information shared with Five Eyes intelligence partners.
If Level 3 applies, it will be identified clearly in the RFP and contract clauses.
How to Figure Out Which Level Applies to You
The Government of Canada determines the required certification level on a contract-by-contract basis through a Cyber Security Risk Assessment. The required level will be stated in the RFP and contract documentation.
Level 1 is the likely baseline. Your annual self-assessment should be underway before the requirement appears.
Level 2 readiness should be on your roadmap now, ahead of the Spring 2027 implementation.
Confirm with the contracting authority whether Level 3 applies to your work.
Waiting for an RFP to identify the level is technically possible but commercially risky. The better approach is to assess against the level you are most likely to need and close gaps while there is still time to do so methodically.
The Levels Build on Each Other
CPCSC levels are additive. The 13 controls at Level 1 are included within the 98 controls at Level 2, and those 98 are included within the 200 controls at Level 3.
Work completed at one level becomes the foundation for the next. It is not discarded.
Suppliers that approach Level 1 with future Level 2 needs in mind will have a smoother transition. Building accurate documentation, control ownership and evidence practices now is less disruptive than retrofitting them under contract pressure later.
What Suppliers Should Do Now
Identify the type of defence work, information and prime contractor relationships involved.
Use contract language and information sensitivity to determine the most probable requirement.
Map existing controls and documentation against the applicable CPCSC requirements.
Assign owners, remediate weaknesses and organize evidence before the certification deadline.
The Bottom Line
Level 1 is already in effect, and Level 2 infrastructure is being established ahead of the 2027 mandate. For most Canadian defence suppliers, Level 1 is the immediate priority and Level 2 readiness is the medium-term priority.
The time to understand where your organization fits is before a contract clause forces the issue.
More Blogs & Insights
CPCSC Certification Isn’t One-Size-Fits-All. Here’s How to Know Which Level You Need.
CPCSC, Cybersecurity Certification Canada, Defence Supply Chain Security, Government of Canada Cybersecurity Requirements, CPCSC Level 1 Certification, Cyber Governance, Regulatory Compliance, Cybersecurity Compliance Frameworks, NIST 800-171, CMMC, Defence Contractor Cybersecurity, Cyber Risk Management, Supply Chain Risk, IT Audit, Cyber Resilience, Emerging Tech Risks
Canada Just Made CPCSC Mandatory. Your Next Defence Contract Depends on It
CPCSC, Cybersecurity Certification Canada, Defence Supply Chain Security, Government of Canada Cybersecurity Requirements, CPCSC Level 1 Certification, Cyber Governance, Regulatory Compliance, Cybersecurity Compliance Frameworks, NIST 800-171, CMMC, Defence Contractor Cybersecurity, Cyber Risk Management, Supply Chain Risk, IT Audit, Cyber Resilience, Emerging Tech Risks
Why Many Investors Pay More Tax Than They Need to Without Realising It
Tax Compliance, Corporate Tax, Personal Tax, Tax Planning, Capital Gains Tax, CRA Regulations, Canadian Taxation, Tax Advisory, Tax Filing, Tax Optimization, Small Business Tax, HST/GST, Payroll Taxes, Cross-Border Tax, Tax Risk Management, Financial Reporting, Audit & Assurance
SAV Associates is on your Side
By partnering with SAV Associates, you gain access to a team of experts dedicated to ensuring your business’s financial health and compliance, allowing you to focus on achieving your business objectives.