The Canadian Program for Cyber Security Certification (CPCSC): A Guide to Cybersecurity Compliance for Canada’s Federal Supply Chain

The Canadian Program for Cyber Security Certification (CPCSC): A Guide to Cybersecurity Compliance for Canada’s Federal Supply Chain

Person typing on computer with digital icons

The Canadian Program for Cyber Security Certification (CPCSC) is rapidly emerging as a foundational requirement for organizations looking to do business with the Government of Canada, particularly within the defence and sensitive information supply chain. A symbol of reliability, CPCSC represents a structural shift in how cybersecurity is enforced, with procurement increasingly playing a key role. 

Organizations that do not align with CPCSC risk exclusion from federal contracts, while those that prepare early stand to gain a competitive advantage, increased trust, and a stronger internal security posture. CPCSC is not a one-time certification; it is an operational capability that integrates governance, risk management, and technical controls into a cohesive, auditable program. 

CPCSC at a Glance 

  • What it is: A federal cybersecurity certification program  
  • Why it matters: It is increasingly required to access and maintain government contracts 
  • Who oversees it: Public Services and Procurement Canada (PSPC) 
  • What it involves: Controls, assessments, and ongoing compliance 
  • What’s at risk: Contract eligibility, reputation, and partner trust 

Who This Applies To 

CPCSC primarily applies to organizations that supply (or plan to supply) the Government of Canada. Key industries include defence, aerospace, and critical infrastructure contractors. It is relevant to small and mid-sized businesses entering regulated supply chains. CPCSC is of particular interest to executives responsible for risk, compliance, and revenue growth. Additionally, it is vital for IT and cybersecurity leaders supporting government facing operations. 

Why CPCSC Exists 

Cybersecurity threats have evolved beyond isolated breaches to encompass broader risks targeting supply chains, critical infrastructure, and national security assets. Governments globally are responding by embedding cybersecurity requirements directly into procurement frameworks. This allows government departments to prioritize information security from the outset, adopting a preventive approach that mitigates problems before they arise. 

Canada’s CPCSC is part of this broader movement, aligning conceptually with global programs such as the U.S. Cybersecurity Maturity Model Certification. The goal is to ensure every organization handling sensitive government information meets a minimum, verifiable level of cybersecurity maturity. It establishes a consistent standard compatible with the requirements of international bodies and partner governments. 

 

Overview of CPCSC 

CPCSC is a Canadian certification program designed to protect sensitive government data. It is managed by Public Services and Procurement Canada, a branch of the Government of Canada that serves as the purchasing agent for other federal departments. CPCSC is also influenced by the needs of the Department of National Defence and the Communications Security Establishment, as these organizations often deal with particularly sensitive information. 

CPCSC helps prevent unauthorized disclosure of Controlled Unclassified Information and other protected data, referred to as “specified information” by the Canadian Centre for Cyber Security. Confidentiality of specified information is a key part of many federal contracts, meaning there may be both professional and legal obligations that government partners are expected to uphold. 

According to the Government, certification includes: 

  • cybersecurity controls, 
  • cybersecurity risk assessments, 
  • contractual clauses, and 
  • accredited third-party assessors.

The program protects sensitive but non-classified information, supports Canadian industry in accessing international procurement, increases the cybersecurity standards of the Canadian defence sector, improves the reliability of the Canadian Armed Forces’ supplier system, and enhances Canadian industry’s participation in cybersecurity certification.  

CPCSC Levels and Maturity Model 

There are three certification levels within the CPCSC model. These include the following: 

Level 1 – Foundational 

Level 1 (introduced in April 2026) requires an annual self-assessment against 13 foundational cybersecurity controls, establishing a baseline level of cyber hygiene for organizations handling Government of Canada information. These controls relate to managing who has access to computer systems; controlling how computer information is used; verifying system users and equipment; securing data and devices; and defending systems from hackers and other cyber threats.  

Level 2 – Intermediate  

Level 2 will require an annual affirmation as well as tri-annual assessments conducted by a third party accredited by the Standards Council of Canada, the official accreditation body for the CPCSC. This level will include 98 controls related to formalized processes, risk management, and alignment with recognized standards. 

Level 3 – Advanced  

Level 3 will require an annual affirmation and cybersecurity assessments completed by the Department of National Defence. There will be 200 controls, primarily addressing factors such as continuous monitoring, mature governance, and audit-ready capabilities. 

 

Control Domains 

Each CPCSC level includes cybersecurity controls that set the standard for protecting government information in non-government systems. These standards were adapted by the Canadian Centre for Cyber Security from established international practices. Tailored for a Canadian context, the controls span governance, risk management, access control, asset management, data protection, logging and monitoring, incident response, and third-party risk.  

Level 1, the only level released at the time of writing, includes the following controls: 

  • Account management – keeping a list of user accounts and their level of access, adding or removing accounts when members change roles, avoiding shared accounts, and setting quarterly reminders to review accounts. 
  • Access enforcement – determining access required for each job on a “need to know basis,” only giving administrator-level access to those who need it, and reviewing access permissions to shared files. 
  • Use of external systems using only approved devices, creating a list of systems that may be used for handling specified information, ensuring staff avoid the use of personal emails or devices when accessing government data, and learning where cloud data is stored. 
  • Publicly accessible content  preventing the public from accessing specified information, ensuring employees know what level of protection information requires, reviewing content before publishing, and double-checking earlier publications for accidental leaks. 
  • User identification and authentication– using private login information unique to each employee, requiring secure passwords, and enabling screen locks if devices are inactive. 
  • Device identification and authentication– ensuring devices are approved before they connect to secure systems, developing a list of verified devices, and blocking unauthorized attempts to connect. 
  • Multifactor authentication– enabling multifactor authentication for accounts or systems related to specified information. 
  • Media sanitization– wiping and destroying devices capable of storing data before throwing them out. 
  • Physical access authorizations – creating a list of people with access to secure areas and revoking access when their position changes. 
  • Physical access control – using locks to control entry, ensuring visitors sign in and are monitored when accessing data, and securely storing printed information. 
  • Boundary protection– controlling online traffic through a firewall, blocking unnecessary connections, and ensuring public and private computer systems are separate. 
  • Flaw remediation – patching systems promptly and installing regular security updates. 
  • Malicious code protection– using credible antivirus programs, turning on automatic scanning, and rapidly responding to threats. 

These controls provide basic guidelines that CPCSC accredited organizations must follow to enact proper cybersecurity protocols. 

Business Impact of CPCSC Compliance for Government Contractors 

CPCSC will create significant opportunities for businesses looking to work with sensitive government data. It will help firms increase their credibility and improve their security practices, enabling them to access federal contracts more effectively. However, it could also introduce cost, complexity, and operational change as organizations seek to meet rigorous standards.  

With the Government of Canada announcing increased funding for defence industry contracts, these standards will be of great importance to businesses in relevant sectors, which may need to implement new security plans. Completing the CPCSC process will enable companies to become trusted partners in the defence and security supply chain, potentially increasing revenues and strengthening business relationships. 

Achieving CPCSC Certification 

Organizations seeking to align with the Government of Canada’s cybersecurity standards should develop a clear strategy to pursue CPCSC certification. The process for certification includes the following key steps: 

  1. Determine the required level – each level has specific standards, and different levels may be necessary depending on the type of information. 
  2. Conduct a gap assessment– determining a company’s cybersecurity targets will require an evaluation to recognize and address areas where more attention is needed. 
  3. Implement controls– each level has various controls that businesses will need to implement to achieve certification. 
  4. Develop documentation– account lists, training records, visitor logs, and other documents are part of meeting security standards. 
  5. Undergo an assessment– self assessments, accredited third-party assessments, and Department of Defence assessments are required depending on the CPCSC level. 
  6. Maintain compliance– CPCSC alignment is an ongoing process, as companies must continue to handle specified information with care during and after project lifecycles. 

Following these steps will help organizations meet cybersecurity goals and align with CPCSC expectations. 

Common Challenges 

While CPCSC standards build on existing best practices, organizations may find it challenging to meet certain criteria. For example, gathering appropriate documentation and ensuring executive alignment can be difficult for organizations that have not yet fully integrated cybersecurity approaches into their decision-making.  

Many organizations may also be inclined to treat CPCSC as a technical requirement rather than an enterprise initiative. Cybersecurity is best understood as a core part of business operations, affecting both day-to-day routines and company-wide strategies. 

Strategic Recommendations for Cybersecurity Readiness 

CPCSC compliance is not a temporary project; it is a constant commitment to cybersecurity excellence. Although Levels 2 and 3 have not yet been released, starting early and aligning with global frameworks will give an organization an advantage over companies that have not adopted these practices. Investing in cybersecurity and data governance techniques will provide greater reliability for clients, organizations, and partners while more effectively protecting confidential information. Contracting cybersecurity advisory services may be a useful means of addressing gaps and responding to evolving needs. 

What Should You Do Next? 

Preparing for CPCSC requirements will help your organization anticipate potential challenges and take a proactive approach to cybersecurity compliance. This includes confirming whether CPCSC applies to your operations and identifying the required certification level based on the sensitivity of your data. Additionally, conducting cybersecurity gap assessments and prioritizing remediation are also important steps. As part of this process, you should build the documentation and governance evidence needed to complete cybersecurity assessments. Early preparation can reduce cost, complexity, and compliance risk. 

How We Can Help 

Meeting CPCSC guidelines may be time-consuming and require cybersecurity expertise that organizations do not always have in-house. Accerta can support organizations with CPCSC preparations through:  

  • readiness and gap assessments, 
  • remediation roadmaps and prioritization, 
  • policy and documentation development, 
  • control implementation guidance, and 
  • audit preparation and assessment support. 

These services assist organizations looking to increase their capacity for cybersecurity risk management, helping them meet the latest standards. Contact us to learn more. 

Meeting CPCSC guidelines can be time-consuming and may require specialized cybersecurity expertise that organizations do not always have in-house. 

Organizations often prepare by focusing on areas such as: 

  • readiness and gap assessments, 
  • remediation roadmaps and prioritization, 
  • policy and documentation development, 
  • guidance on control implementation, and 
  • audit preparation and support. 

These approaches can help strengthen an organization’s capacity for cybersecurity risk management and support alignment with current standards. Organizations seeking to build or accelerate this work may also consider engaging external expertise for additional support. 

 

Conclusion 

In the information age, data security is a vital part of any organization’s operations, especially for those that work closely with government departments. CPCSC represents a fundamental shift in how cybersecurity is enforced within Canada’s federal ecosystem. Beyond simply ensuring compliance, meeting CPCSC standards is about enabling trust, ensuring resilience, and maintaining access to critical partnerships. New opportunities are developing in Canada’s defence sector and other industries that pride themselves on data safety. Adapting to expectations is part of a future-ready approach to technological and economic change. 

Little girl holding a bubble wand, showing it to an adult.
Older couple smiling at each other warmly.
Older couple smiling at each other warmly.

Innovation you can be confident in.

A boy being carried by his mother, a little girl on her father's back, both parents smiling at each other.
Woman typing on her laptop.
Search