CPCSC is the Canadian Program for Cyber Security Certification—a mandatory compliance requirement for DND defence suppliers. Learn what it is, why it exists, and how to prepare.
Credit card required to activate. 365-day evidence retention during 2026.
CPCSC is the Canadian Program for Cyber Security Certification, administered by the Department of National Defence and Public Services and Procurement Canada. It becomes mandatory for new DND contracts starting April 2026 (Phase 2, Level 1 self-assessment). The underlying standard is ITSP.10.171, Canada's adaptation of NIST SP 800-171 Rev 3, covering 97 controls across 17 families. CPCSC has three certification levels: Level 1 (13-control self-assessment), Level 2 (97-control third-party assessment), and Level 3 (advanced, government-led). Solymus produces audit-ready cryptographic evidence for every control, and verification is free and requires no account.
CPCSC stands for the Canadian Program for Cyber Security Certification. It is a three-tiered compliance certification framework designed by the Canadian Department of National Defence (DND) to protect "Controlled Information" within the Canadian defence supply chain. CPCSC is based on ITSP.10.171, Canada's adaptation of the NIST SP 800-171 Rev 3 security controls.
In simple terms: CPCSC is how the Canadian government ensures that companies handling sensitive defence data meet minimum cyber security standards. If you are a defence supplier working with DND contracts, CPCSC is mandatory.
The Canadian defence supply chain includes hundreds of prime contractors and thousands of subcontractors. Many handle "Controlled Information"—defence technical data, procurement plans, contract terms, security postures, and other information critical to Canada's military capability. If this information is compromised, stolen, or altered, it puts Canada's defence at risk.
CPCSC was created to:
Without CPCSC, every defence prime would have to conduct its own security assessment of every supplier—a fragmented, expensive process with zero consistency. CPCSC centralises this compliance requirement.
CPCSC has three certification levels. Each level requires progressively more controls, more rigorous assessment, and higher security maturity.
13 core controls across 6 families. You assess yourself. Mandatory at contract award starting April 2026.
Cost: Free on Solymus
97 full ITSP.10.171 controls. Certified by Standards Council of Canada (SCC) assessors. Required April 2027.
Cost: C$5K–10K/year
97 controls + 6 maturity domains. For highest-security contracts. Includes continuous monitoring.
Cost: C$5K–30K/year
CPCSC is not a separate framework—it is a certification program built on top of ITSP.10.171.
Think of it this way:
Standard published. Level 1 guidance available. Suppliers begin planning.
Level 1 is now mandatory. All DND defence primes must verify that all contractors have a Level 1 self-assessment. Level 2 assessor training begins.
Level 2 third-party certification required. Level 3 in high-sensitivity contracts. Early assessments begin.
CPCSC applies to anyone in the Canadian defence supply chain:
If your company has a DND contract or is on a defence prime's supplier list, CPCSC applies to you.
DND defence primes cannot award contracts to suppliers without Level 1 CPCSC certification (as of April 2026). Without certification, you lose the contract. Without the contract, your business is at risk.
This creates a compliance cascade:
There is no way around CPCSC if you work in the Canadian defence supply chain.
Preparing for CPCSC involves three steps:
Solymus automates this entire process. You upload evidence, Solymus maps it to controls, generates cryptographic receipts, and exports a compliance package ready for assessors.
If you are a Canadian defence supplier, here is what you should do now:
Start free with Solymus Level 1 today. Build your evidence chain and prepare for certification.
Everything you need to know about CPCSC compliance
CPCSC stands for Canadian Program for Cyber Security Certification. It is administered by the Department of National Defence (DND) and Public Services and Procurement Canada (PSPC).
Phase 2 begins April 2026 with mandatory Level 1 self-assessment at contract award. Phase 3 (April 2027+) introduces Level 2 third-party certification requirements for sub-tier suppliers.
No. CPCSC is Canadian (DND/PSPC, built on ITSP.10.171 / NIST SP 800-171 Rev 3). CMMC is American (DoD/DFARS, built on NIST SP 800-171 Rev 2). They are separate programs with separate assessors. See CPCSC vs CMMC.
Three. Level 1 is a 13-control self-assessment. Level 2 is a 97-control third-party assessment. Level 3 is an advanced, government-led assessment for the most sensitive defence contracts.
Any organization bidding on or performing Canadian Department of National Defence contracts that involve Controlled Information, including primes, sub-tier suppliers, and service providers. An estimated 600 primes plus 4,000+ suppliers are in scope.