CPCSC Level 1 Readiness Assessment

Identify CPCSC Level 1 gaps before self-assessment sign-off.

Built for defence contractors pursuing CPCSC Level 1, our assessment tool helps you identify compliance gaps, get remediation recommendations, and generate a detailed report outlining the practical steps needed to strengthen your cybersecurity posture.

< 10 min
Guided Assessment

Scored
By Control Area

6
Control Areas

Scorecard
Output at the End

CPA-Led
Assurance Lens

72%

Partially Ready

Sample readiness result

CPCSC Level 1 readiness map

AC
Access Control
78%
IA
Identification & Authentication
70%
MP
Media Protection
58%
PP
Physical Protection
82%
SC
System & Communications Protection
74%
SI
System & Information Integrity
68%

Use the scorecard to identify control gaps, evidence needs, and remediation priorities before formal procurement or self-attestation activities.

How it works

In three steps, move from uncertainty to a strategic roadmap for CPCSC Level 1.

The Readiness Assessment is designed to help suppliers move from general concern to a practical readiness roadmap.

01

Answer practical readiness questions

Complete a short assessment based on CPCSC Level 1 cyber hygiene areas. No jargon, no trick questions.

02

See your readiness profile

View your overall score, domain-level gaps, and areas that may need evidence, documentation, or control improvement.

03

Build your readiness roadmap

Use your results to prioritize remediation, prepare documentation, and decide whether you need advisory support before contract award.

Assessment scope

Know the key CPCSC Level 1 areas that matter before you are questioned by a customer or contracting authority

The Readiness Assessment covers the control areas most likely to require
documentation, evidence, or remediation work before self-assessment.

AC

Access Control

Confirm that user accounts, permissions, and access changes are managed intentionally.

IA

Identification & Authentication

Evaluate whether users and systems are properly authenticated before accessing sensitive information.

MP

Access Control

Confirm that user accounts, permissions, and access changes are managed intentionally.

PP

Physical Protection

Assess whether facilities, offices, devices, and restricted areas are protected from unauthorized access.

SC

SC

System & Communications Protection

Understand whether sensitive information is protected when transmitted, stored, or accessed across networks and cloud systems.

SI

SI

System & Information Integrity

Check whether systems are patched, monitored, protected from malware, and reviewed for vulnerabilities.

Why SAV

We provide professional-led CPCSC readiness, not just checkbox compliance.

SAV brings an assurance-grade lens to CPCSC readiness. Our team combines CPA audit discipline, ISO certification experience, cybersecurity advisory, SOC reporting, IT risk assessments, and practical evidence readiness support.

01

Assurance-grade evidence

SAV approaches CPCSC readiness with the discipline of a CPA audit and ISO certification body. We focus on documentation, evidence, control design, and practical readiness.

02

Framework integration

We help map CPCSC expectations to ISO 27001, SOC 2, CyberSecure Canada, CMMC, NIST, and existing governance programs so teams avoid duplicate work.

03

Practical remediation

Our recommendations are designed for real businesses, not theoretical control libraries. We prioritize what reduces risk and supports procurement readiness.

04

Canadian context

We understand Canadian public-sector expectations, supplier obligations, and the importance of clear, defensible security documentation.

Need more than a score?

If CPCSC could affect your contract eligibility, SAV can help you confirm scope,
identify control gaps, prepare evidence, and build a practical remediation plan.

FAQ

Common CPCSC readiness questions.

Answers to common questions about CPCSC readiness, self-assessment support, and how SAV can help.

Is this the official Government of Canada CPCSC self-assessment?

No. This is a readiness and planning tool created by SAV Associates to help organizations understand potential gaps before completing formal self-assessment or procurement requirements.

CPCSC Level 1 focuses on foundational cyber hygiene controls for suppliers that may handle sensitive, unclassified Government of Canada information.

SAV can support readiness, gap assessment, remediation planning, documentation, evidence preparation, and framework mapping. Formal certification requirements should be confirmed against current Government of Canada guidance.

Existing ISO 27001, SOC 2, CyberSecure Canada, CMMC, or NIST-aligned controls may help reduce duplicate work. SAV can map existing controls to CPCSC expectations and identify remaining gaps.

Ready to check your readiness?

The CPCSC Level 1 Readiness Assessment takes less than 10 minutes. Get your
scorecard, see your top gaps, and walk away with a 30-day action plan.