CPCSC Level 1 Requirements: What Canadian Defence Suppliers Need to Know
If you bid on or work under Government of Canada defence contracts, the rules just changed. In April 2026, the federal government introduced Level 1 of the Canadian Program for Cyber Security Certification (CPCSC)—and beginning in summer 2026, it will be a condition of award on select defence contracts. This isn't another voluntary framework you can shelve. It's a gate. No certification, no contract.
The good news: Level 1 is the most accessible tier of the program, built to be reachable even by small and medium-sized suppliers. The catch: "accessible" still means proving—not claiming—that 13 specific controls are in place, every year, with evidence to back it up. Below is exactly what Level 1 requires, and how to get there without drowning your team in spreadsheets.
What is the CPCSC, and where does Level 1 fit?
The CPCSC is Canada's official cybersecurity certification program for defence suppliers, managed by Public Services and Procurement Canada (PSPC). It exists to protect Specified Information (SI)—sensitive, unclassified government information (contract details, controlled goods information, protected information) that lives on suppliers' systems—from the cyber threats increasingly aimed at Canada's defence supply chain.
The program has three certification levels, scaled to risk:
- Level 1 — an annual cyber security self-assessment against 13 controls. (Available now.)
- Level 2 — an external assessment led by an accredited certification body, plus an annual affirmation, against 98 controls.
- Level 3 — assessments conducted by National Defence, plus an annual affirmation, against 200 controls.
The 13 Level 1 controls are drawn from the Canadian Centre for Cyber Security's standard, ITSP.10.171 (Protecting specified information in non-Government of Canada systems and organizations)—the Canadian adaptation of the U.S. NIST SP 800-171. That alignment is deliberate, and it matters (more on that below).
Who needs Level 1—and when?
If your organization handles Specified Information in support of a Government of Canada defence contract, Level 1 applies to you. During the initial phase, the self-assessment is required at contract award—not during bidding—but PSPC is explicit that suppliers should pursue it proactively rather than scramble after a win. Over time, defence and other sensitive contracts will be certified under the CPCSC standard based on their risk level.
You'll also need an active CanadaBuys account: once you complete the self-assessment, you must record your self-attestation result and its expiry date in your organizational supplier profile, and again when you submit a bid.
The 13 Level 1 controls
The 13 controls group into six cyber hygiene best practices. None of them are exotic—this is foundational security done consistently and provably.
| # | Control | Best practice | Control ID |
|---|---|---|---|
| 1 | Account management | Access control — manage who can access systems | 03.01.01 |
| 2 | Access enforcement | Access control — manage who can access systems | 03.01.02 |
| 3 | Use of external systems | Access control — control how systems and data are used | 03.01.20 |
| 4 | Publicly accessible content | Access control — control how systems and data are used | 03.01.22 |
| 5 | User identification and authentication | Identification & authentication — verify users and devices | 03.05.01 |
| 6 | Device identification and authentication | Identification & authentication — verify users and devices | 03.05.02 |
| 7 | Multifactor authentication | Identification & authentication — verify users and devices | 03.05.03 |
| 8 | Media sanitization | Media protection — protect data and equipment | 03.08.03 |
| 9 | Physical access authorizations | Physical protection — protect data and equipment | 03.10.01 |
| 10 | Physical access control | Physical protection — protect data and equipment | 03.10.07 |
| 11 | Boundary protection | System & communications protection — defend against threats | 03.13.01 |
| 12 | Flaw remediation | System & information integrity — defend against threats | 03.14.01 |
| 13 | Malicious code protection | System & information integrity — defend against threats | 03.14.02 |
In plain terms, Level 1 asks you to: know who has accounts and limit them to least privilege; keep work off personal email, devices, and cloud; protect what's public-facing; verify users and devices and enforce MFA (especially on remote, cloud, and admin access); wipe media before disposal; control who can physically enter the spaces where SI lives; lock down your network boundary; patch known flaws; and run malware protection. The official guidance notes that, once you've reviewed your policies, the self-assessment itself can be completed in under an hour—if the controls are actually implemented.
Scoping is the part everyone underestimates
Before you can attest to a single control, you have to define your scope: every system, device, cloud service, person, and facility that stores, transmits, or processes Specified Information. Get this wrong and your assessment is either dangerously narrow or impossibly broad. PSPC's scoping guide is clear: if your boundary is so small you can't honestly test a requirement, it's too narrow. Mapping where SI is received, created, stored, emailed, backed up, and destroyed—and keeping that map current—is where most suppliers lose time.
Already pursuing CMMC? You may be ahead.
The CPCSC was intentionally harmonized with the U.S. Cybersecurity Maturity Model Certification (CMMC). Both use the same technical controls, so suppliers don't have to maintain two separate standards. The Government of Canada may accept a valid CMMC certification on a case-by-case basis, once it confirms the assessment covers the required scope. For suppliers selling on both sides of the border, that's a real efficiency—build the program once, satisfy two regimes.
Where RESTIV fits
Here's the trap with Level 1: it looks like a one-hour annual form, so suppliers treat it like one. Then award day arrives and they're reconstructing account inventories, hunting for an MFA policy nobody wrote down, and trying to remember when laptops were last patched. A self-assessment is only as honest as the evidence behind it—and that evidence has to hold up not just at attestation, but for the audits and higher tiers that follow.
That's the problem RESTIV's Compliance Copilot was built to solve. Instead of a once-a-year fire drill, we make the 13 controls continuous and provable:
- Control mapping that does the translation for you. Compliance Copilot maps your existing security posture against ITSP.10.171, CMMC, NIST SP 800-171, ISO 27001, SOC 2, and more—so the work you do for CPCSC counts toward every other framework, automatically.
- Continuous evidence, not a snapshot. We continuously collect and monitor proof of control effectiveness—account reviews, MFA enforcement, patch status, malware protection—so your self-attestation reflects reality, every day, not just the day you signed it.
- Scoping and gap analysis up front. We help you draw the right boundary, inventory in-scope assets, and surface gaps before they become a failed control—or a lost contract.
- Batteries included. Unlike self-serve tools that hand you a dashboard and expect you to bring your own security team and toolchain, RESTIV delivers compliance as a managed outcome—ideal whether you're a green-field startup building a program from scratch or an established supplier preparing for Level 2 and 3.
The payoff is speed without shortcuts. For most SMEs, our highly automated platform can take you through CPCSC Level 1 in a single afternoon—and you walk away with a full, auditor-ready package of evidence and attestations, not just a signed form. That's the difference between checking a box and being able to prove it the day a contracting authority asks.
Level 1 is the floor, not the ceiling. Suppliers who treat it as a continuous program—rather than an annual checkbox—are the ones who'll move smoothly into Level 2's external assessments and stay eligible as more contracts fall under the CPCSC. The deadline is real, and summer 2026 is closer than it looks.
Compliance shouldn't be a bottleneck between you and the contract—it should be the reason you win it. RESTIV delivers the rigor of a traditional audit with the speed and continuity of AI and automation.
Bidding on Canadian defence work? Talk to RESTIV about getting CPCSC Level 1–ready—and building a compliance program that scales with the program's higher tiers.
Sources
- CPCSC Program Overview — three levels, control counts, the 13 Level 1 controls, governing departments.
- How to meet Level 1 requirements — self-assessment process, CMMC recognition, attestation in CanadaBuys.
- CPCSC Level 1 criteria — control IDs and assessment procedures (ITSP.10.171 / NIST SP 800-171A Rev. 3).
- Level 1 scoping guide — defining scope, in-scope assets, Specified Information.
- Government of Canada introduces CPCSC Level 1 (April 14, 2026) — summer 2026 contract requirement, phased rollout.