Articles

CPCSC Level 1 Requirements: What Canadian Defence Suppliers Need to Know

Devon Smibert
CPCSC Level 1 Requirements: What Canadian Defence Suppliers Need to Know

If you bid on or work under Government of Canada defence contracts, the rules just changed. In April 2026, the federal government introduced Level 1 of the Canadian Program for Cyber Security Certification (CPCSC)—and beginning in summer 2026, it will be a condition of award on select defence contracts. This isn't another voluntary framework you can shelve. It's a gate. No certification, no contract.

The good news: Level 1 is the most accessible tier of the program, built to be reachable even by small and medium-sized suppliers. The catch: "accessible" still means proving—not claiming—that 13 specific controls are in place, every year, with evidence to back it up. Below is exactly what Level 1 requires, and how to get there without drowning your team in spreadsheets.

What is the CPCSC, and where does Level 1 fit?

The CPCSC is Canada's official cybersecurity certification program for defence suppliers, managed by Public Services and Procurement Canada (PSPC). It exists to protect Specified Information (SI)—sensitive, unclassified government information (contract details, controlled goods information, protected information) that lives on suppliers' systems—from the cyber threats increasingly aimed at Canada's defence supply chain.

The program has three certification levels, scaled to risk:

  • Level 1 — an annual cyber security self-assessment against 13 controls. (Available now.)
  • Level 2 — an external assessment led by an accredited certification body, plus an annual affirmation, against 98 controls.
  • Level 3 — assessments conducted by National Defence, plus an annual affirmation, against 200 controls.

The 13 Level 1 controls are drawn from the Canadian Centre for Cyber Security's standard, ITSP.10.171 (Protecting specified information in non-Government of Canada systems and organizations)—the Canadian adaptation of the U.S. NIST SP 800-171. That alignment is deliberate, and it matters (more on that below).

Who needs Level 1—and when?

If your organization handles Specified Information in support of a Government of Canada defence contract, Level 1 applies to you. During the initial phase, the self-assessment is required at contract award—not during bidding—but PSPC is explicit that suppliers should pursue it proactively rather than scramble after a win. Over time, defence and other sensitive contracts will be certified under the CPCSC standard based on their risk level.

You'll also need an active CanadaBuys account: once you complete the self-assessment, you must record your self-attestation result and its expiry date in your organizational supplier profile, and again when you submit a bid.

The 13 Level 1 controls

The 13 controls group into six cyber hygiene best practices. None of them are exotic—this is foundational security done consistently and provably.

# Control Best practice Control ID
1Account managementAccess control — manage who can access systems03.01.01
2Access enforcementAccess control — manage who can access systems03.01.02
3Use of external systemsAccess control — control how systems and data are used03.01.20
4Publicly accessible contentAccess control — control how systems and data are used03.01.22
5User identification and authenticationIdentification & authentication — verify users and devices03.05.01
6Device identification and authenticationIdentification & authentication — verify users and devices03.05.02
7Multifactor authenticationIdentification & authentication — verify users and devices03.05.03
8Media sanitizationMedia protection — protect data and equipment03.08.03
9Physical access authorizationsPhysical protection — protect data and equipment03.10.01
10Physical access controlPhysical protection — protect data and equipment03.10.07
11Boundary protectionSystem & communications protection — defend against threats03.13.01
12Flaw remediationSystem & information integrity — defend against threats03.14.01
13Malicious code protectionSystem & information integrity — defend against threats03.14.02

In plain terms, Level 1 asks you to: know who has accounts and limit them to least privilege; keep work off personal email, devices, and cloud; protect what's public-facing; verify users and devices and enforce MFA (especially on remote, cloud, and admin access); wipe media before disposal; control who can physically enter the spaces where SI lives; lock down your network boundary; patch known flaws; and run malware protection. The official guidance notes that, once you've reviewed your policies, the self-assessment itself can be completed in under an hour—if the controls are actually implemented.

Scoping is the part everyone underestimates

Before you can attest to a single control, you have to define your scope: every system, device, cloud service, person, and facility that stores, transmits, or processes Specified Information. Get this wrong and your assessment is either dangerously narrow or impossibly broad. PSPC's scoping guide is clear: if your boundary is so small you can't honestly test a requirement, it's too narrow. Mapping where SI is received, created, stored, emailed, backed up, and destroyed—and keeping that map current—is where most suppliers lose time.

Already pursuing CMMC? You may be ahead.

The CPCSC was intentionally harmonized with the U.S. Cybersecurity Maturity Model Certification (CMMC). Both use the same technical controls, so suppliers don't have to maintain two separate standards. The Government of Canada may accept a valid CMMC certification on a case-by-case basis, once it confirms the assessment covers the required scope. For suppliers selling on both sides of the border, that's a real efficiency—build the program once, satisfy two regimes.

Where RESTIV fits

Here's the trap with Level 1: it looks like a one-hour annual form, so suppliers treat it like one. Then award day arrives and they're reconstructing account inventories, hunting for an MFA policy nobody wrote down, and trying to remember when laptops were last patched. A self-assessment is only as honest as the evidence behind it—and that evidence has to hold up not just at attestation, but for the audits and higher tiers that follow.

That's the problem RESTIV's Compliance Copilot was built to solve. Instead of a once-a-year fire drill, we make the 13 controls continuous and provable:

  • Control mapping that does the translation for you. Compliance Copilot maps your existing security posture against ITSP.10.171, CMMC, NIST SP 800-171, ISO 27001, SOC 2, and more—so the work you do for CPCSC counts toward every other framework, automatically.
  • Continuous evidence, not a snapshot. We continuously collect and monitor proof of control effectiveness—account reviews, MFA enforcement, patch status, malware protection—so your self-attestation reflects reality, every day, not just the day you signed it.
  • Scoping and gap analysis up front. We help you draw the right boundary, inventory in-scope assets, and surface gaps before they become a failed control—or a lost contract.
  • Batteries included. Unlike self-serve tools that hand you a dashboard and expect you to bring your own security team and toolchain, RESTIV delivers compliance as a managed outcome—ideal whether you're a green-field startup building a program from scratch or an established supplier preparing for Level 2 and 3.

The payoff is speed without shortcuts. For most SMEs, our highly automated platform can take you through CPCSC Level 1 in a single afternoon—and you walk away with a full, auditor-ready package of evidence and attestations, not just a signed form. That's the difference between checking a box and being able to prove it the day a contracting authority asks.

Level 1 is the floor, not the ceiling. Suppliers who treat it as a continuous program—rather than an annual checkbox—are the ones who'll move smoothly into Level 2's external assessments and stay eligible as more contracts fall under the CPCSC. The deadline is real, and summer 2026 is closer than it looks.

Compliance shouldn't be a bottleneck between you and the contract—it should be the reason you win it. RESTIV delivers the rigor of a traditional audit with the speed and continuity of AI and automation.

Bidding on Canadian defence work? Talk to RESTIV about getting CPCSC Level 1–ready—and building a compliance program that scales with the program's higher tiers.

Sources