Canadian defence cybersecurity

CPCSC Certification Is Not One-Size-Fits-All. Here Is How to Know Which Level You Need.

Not every defence supplier needs the same certification. Here is how Levels 1, 2 and 3 work, what each requires, and how to determine where your business fits.

ArticleCPCSC certification levelsDefence suppliersReadiness planning
SC
Written bySanjay Chadha7 minute read

CPCSC is organized into three certification levels based on the sensitivity of the information and defence work involved. Most suppliers will operate at Level 1 or Level 2. Level 3 is reserved for a narrow group of high-risk national security programs.

On April 14, 2026, the Government of Canada formally introduced Level 1 of the Canadian Program for Cyber Security Certification. Mandatory requirements begin appearing in select defence contracts in Summer 2026, with further requirements following in 2027.

The core questionThe certification level is determined by the contract and the information your organization handles. The practical task is to prepare for the level you are most likely to encounter before an RFP or contract deadline creates pressure.

The Three CPCSC Levels at a Glance

1

Level 1

Annual self-assessment against 13 foundational security controls.

For most suppliers participating in Government of Canada defence contracts.
2

Level 2

Independent third-party assessment against 98 cybersecurity controls.

For controlled defence information and higher-stakes cyber-sensitive work.
3

Level 3

Government-led assessment against 200 controls.

For weapons systems, critical infrastructure and the most sensitive programs.
Requirement
Level 1
Level 2
Level 3
Assessment
Annual self-assessment
Accredited third-party assessment
National Defence assessment
Controls
13 controls
98 controls
200 controls
Renewal
Annual
Every three years, with annual affirmation
Every three years, with annual affirmation
Typical scope
General defence suppliers
Controlled defence information
Highest-risk national security work

Level 1: The Baseline Every Defence Supplier Needs

Level 1 is the entry point. It became available to suppliers on April 1, 2026, and mandatory requirements begin appearing in select defence contracts starting in Summer 2026.

Suppliers complete an annual self-assessment confirming that they meet 13 security controls drawn from the Canadian industrial cybersecurity standard, ITSP.10.171. The controls are adapted from NIST Special Publication 800-171 and cover foundational practices such as access control, user verification, protection of data and equipment, external system connections and defence against common cyber threats.

Who typically needs Level 1?Practically every supplier participating in Government of Canada defence contracts should expect Level 1 to apply unless a contract specifies a higher level.

Certification may be required at contract award rather than during bidding. That does not create a safe window to delay preparation. Completing the assessment before a requirement appears reduces the risk of winning work that cannot be finalized.

Level 2: Third-Party Verification for Higher-Stakes Work

Level 2 shifts the program from self-attestation to external validation. It is scheduled to enter select defence contracts beginning in Spring 2027.

An accredited third-party assessment organization evaluates whether the supplier has implemented the required cybersecurity controls. The assessment covers 98 controls, and certification must be renewed every three years with an annual affirmation between assessments.

Level 2 applies when a contract involves controlled defence information or more complex cyber-sensitive work. This can include subcontractors embedded in major defence programs, organizations handling sensitive procurement details, and companies building or maintaining systems connected to sensitive government infrastructure.

Preparation is substantially more involvedLevel 2 requires a documented System Security Plan, a clear understanding of control implementation across all 98 requirements, organized evidence and sufficient time to schedule an accredited assessment body.

Organizations with existing ISO 27001, SOC 2 or NIST-aligned controls may already have a meaningful foundation. The remaining work often lies in documentation, evidence and formal assessment readiness.

Level 3: Reserved for the Highest-Risk Programs

Level 3 applies to a narrow set of defence work. Most suppliers in Canada's wider defence industrial base will never need it.

The assessment is conducted directly by National Defence and covers 200 controls. It applies to highly sensitive programs involving weapons systems, critical infrastructure or information shared with Five Eyes intelligence partners.

If Level 3 applies, it will be identified clearly in the RFP and contract clauses.

How to Figure Out Which Level Applies to You

The Government of Canada determines the required certification level on a contract-by-contract basis through a Cyber Security Risk Assessment. The required level will be stated in the RFP and contract documentation.

Question 1Do you participate in defence contracts?

Level 1 is the likely baseline. Your annual self-assessment should be underway before the requirement appears.

Question 2Do you handle controlled defence information?

Level 2 readiness should be on your roadmap now, ahead of the Spring 2027 implementation.

Question 3Do you support weapons or Five Eyes-linked programs?

Confirm with the contracting authority whether Level 3 applies to your work.

Waiting for an RFP to identify the level is technically possible but commercially risky. The better approach is to assess against the level you are most likely to need and close gaps while there is still time to do so methodically.

The Levels Build on Each Other

CPCSC levels are additive. The 13 controls at Level 1 are included within the 98 controls at Level 2, and those 98 are included within the 200 controls at Level 3.

Level 3200 controls and government-led assessment
Level 298 controls and accredited third-party assessment
Level 113 foundational controls and annual self-assessment

Work completed at one level becomes the foundation for the next. It is not discarded.

Suppliers that approach Level 1 with future Level 2 needs in mind will have a smoother transition. Building accurate documentation, control ownership and evidence practices now is less disruptive than retrofitting them under contract pressure later.

What Suppliers Should Do Now

Step 1Review likely contract exposure

Identify the type of defence work, information and prime contractor relationships involved.

Step 2Confirm your likely level

Use contract language and information sensitivity to determine the most probable requirement.

Step 3Assess current readiness

Map existing controls and documentation against the applicable CPCSC requirements.

Step 4Close gaps early

Assign owners, remediate weaknesses and organize evidence before the certification deadline.

The Bottom Line

Level 1 is already in effect, and Level 2 infrastructure is being established ahead of the 2027 mandate. For most Canadian defence suppliers, Level 1 is the immediate priority and Level 2 readiness is the medium-term priority.

The time to understand where your organization fits is before a contract clause forces the issue.

Not sure which CPCSC level applies?SC US can help your organization identify the likely requirement, assess current controls, prioritize remediation and prepare for the applicable certification process.

More Blogs & Insights

CPCSC Certification Isn’t One-Size-Fits-All. Here’s How to Know Which Level You Need.

CPCSC Certification Isn’t One-Size-Fits-All. Here’s How to Know Which Level You Need.

CPCSC, Cybersecurity Certification Canada, Defence Supply Chain Security, Government of Canada Cybersecurity Requirements, CPCSC Level 1 Certification, Cyber Governance, Regulatory Compliance, Cybersecurity Compliance Frameworks, NIST 800-171, CMMC, Defence Contractor Cybersecurity, Cyber Risk Management, Supply Chain Risk, IT Audit, Cyber Resilience, Emerging Tech Risks

Canada Just Made CPCSC Mandatory. Your Next Defence Contract Depends on It

Canada Just Made CPCSC Mandatory. Your Next Defence Contract Depends on It

CPCSC, Cybersecurity Certification Canada, Defence Supply Chain Security, Government of Canada Cybersecurity Requirements, CPCSC Level 1 Certification, Cyber Governance, Regulatory Compliance, Cybersecurity Compliance Frameworks, NIST 800-171, CMMC, Defence Contractor Cybersecurity, Cyber Risk Management, Supply Chain Risk, IT Audit, Cyber Resilience, Emerging Tech Risks

Why Many Investors Pay More Tax Than They Need to Without Realising It

Why Many Investors Pay More Tax Than They Need to Without Realising It

Tax Compliance, Corporate Tax, Personal Tax, Tax Planning, Capital Gains Tax, CRA Regulations, Canadian Taxation, Tax Advisory, Tax Filing, Tax Optimization, Small Business Tax, HST/GST, Payroll Taxes, Cross-Border Tax, Tax Risk Management, Financial Reporting, Audit & Assurance

SAV Associates is on your Side

By partnering with SAV Associates, you gain access to a team of experts dedicated to ensuring your business’s financial health and compliance, allowing you to focus on achieving your business objectives.