The Canadian Program for Cybersecurity Certification is now table stakes to bid on federal defence contracts. Kobalt help you get you Level 1 ready in weeks, and will help you get Level 2 audit-ready on time.
Canada has committed over half a trillion dollars to defence over the next decade. Every supplier in the chain, from primes to tier-three subcontractors, will need to demonstrate compliance against the 17 CPCSC control families. Kobalt's managed program runs the full path: gap assessment, enclave scoping, evidence automation, System Security Plan, and audit prep with an accredited third-party assessor (3PAO).
The single most-asked question on every CPCSC briefing. The short answer: if any part of your business touches the Canadian defence supply chain, directly or several tiers down, expect some level of CPCSC to apply. Here's how that plays out for the most common scenarios.
If you respond directly to a DND solicitation, expect CPCSC requirements written into the bid. Level 1 self-assessment is already optional on contracts today, mandatory on most by 2027. Level 2 third-party audit will be required for any contract handling Protected B information from April 2027 onward.
You may never see the DND directly. The prime contractor will flow CPCSC requirements down to its supply chain, same as SOC 2 or ISO 27001 vendor requirements work today. If a prime depends on you, your security posture becomes their compliance risk. They will require certification.
If your software stores, processes, or transmits Federal Contractual Information, Protected B data, controlled goods data, or anything that ends up in a defence build (BOMs, specs, resource plans), CPCSC applies. "We're just SaaS" is not an exemption, it's the trigger.
Training providers, professional services firms, and consultants typically hold defence employee names, contact details, and program enrolment data. In the defence context, that information is sensitive even when it isn't classified. Provincial or municipal compliance experience is a head start, not a substitute.
No reciprocity exists between CMMC and CPCSC. A CMMC certificate does not satisfy a Canadian procurement officer. The good news: the standards mirror each other, so you're 80% of the way there. The gap is the three new ITSP.10.171 control families: Planning, System & Services Acquisition, and Supply Chain Risk Management.
CPCSC is currently scoped to defence procurement. Other federal departments still rely on SOC 2, ISO 27001, and Protected B guidance for their security expectations. The Canadian government has historically extended successful frameworks across departments, so building toward CPCSC now is a hedge against broader rollout in 2027 and beyond.
Not sure where you land? The 30-minute scoping call gives you a clear answer: which level applies, what data triggers the requirement, and what the runway to certification looks like for your specific business.
Book a free scope callCPCSC is not a single bar. The level that applies to you depends on the data type and the contract you're chasing. Most Canadian SMBs land at Level 1 today and Level 2 by 2027. Level 3 is reserved for critical defence systems.
| Level 1 | Level 2 Most SMBs by 2027 | Level 3 | |
|---|---|---|---|
| Assessment type | Self-assessment with submitted Security Plan | Third-party audit by an accredited 3PAO | 3PAO audit plus DND-led government assessment |
| Data covered | Federal Contractual Information (FCI) | Protected B information, controlled goods | Critical defence systems: command, control, weapons, comms |
| Who needs this | Any supplier in the defence supply chain | Suppliers handling Protected B data, most tier-1 and tier-2 vendors | Major defence primes, critical infrastructure operators |
| Mandatory by | April 2026 (Phase 2 already in flight) | April 2027 for Protected B contracts | Post-April 2027, contract-specific |
| Typical timeline | 30 days with Kobalt | 12-month managed program | 18+ months, scoped per contract |
| Kobalt's take | Foundation. Required minimum. | Where most contract value lives | Specialist engagement, scoped per contract |
Most Canadian SMBs should start Level 1 immediately and plan the runway to Level 2. Even if your current contracts only ask for self-assessment, the 12-month build-out for Level 2, plus the audit window itself, means starting now is the difference between making April 2027 and missing it.
Public Services and Procurement Canada is rolling out CPCSC in staged phases. The standard is live today as a self-assessment option. Within 24 months, Level 2 audits become mandatory for any contract touching Protected B data.
Procurement teams can begin requiring Level 1 self-assessment in DND solicitations. Not every bid asks for it yet, but the ones that do filter out non-compliant suppliers immediately.
The optional flag flips to mandatory on a growing share of defence solicitations. Self-attestation without a documented assessment is no longer accepted.
By the end of 2026, expect Level 1 to be a baseline qualifier on almost every DND bid, directly and through prime contractors flowing the requirement down the supply chain.
Any contract handling Protected B information requires a passing audit from an accredited 3PAO. Programs that haven't started by Q3 2026 are unlikely to make this date.
Pick the path that matches where you are. Start with the Level 1 project to clear an active bid, or step into the Compliance Program for full Level 2 readiness, with the option to bundle a second framework like SOC 2 or ISO 27001.
Every Kobalt CPCSC program, Level 1 or Level 2, covers the same six workstreams. No deliverables left to the client's interpretation.
A full review against the 17 CPCSC control families plus a defensible boundary around the systems, data, and people that touch Protected B information.
The hands-on work: MFA, encryption (FIPS-aligned where required), EDR, logging, segmentation, vulnerability management, mapped to each control family.
Audit-ready policies tailored to your stack, not templates. Each policy maps to the specific ITSP.10.171 controls a 3PAO will look for.
The two documents the auditor and the procurement officer will read. We write them, you review them.
A Governance, Risk & Compliance (GRC) platform configured for CPCSC, with continuous evidence collection. Funded in part by IRAP grants we secured to bring this capability to Canadian SMBs.
A pre-audit run-through against 3PAO criteria. Surface and remediate gaps before the real audit costs you a re-engagement. Then we run point with the auditor through certification.
CPCSC is built on ITSP.10.171, Canada's adaptation of the NIST SP 800-171 baseline. Three of the 17 families are new and focused on third-party and supply-chain risk. If you've never had to think about these before, you will now.
Compliance automation platforms are powerful, but they're just software. They don't write your custom policies, remediate your AWS misconfiguration, or defend your control design choices to a 3PAO. Every Kobalt CPCSC program ships with a four-person squad that runs the program end-to-end.
Sets the program strategy, owns the certification roadmap, and makes the judgment calls on enclave scoping, residual risk, and audit readiness. Accountable for the program end-to-end.
Writes the System Security Plan, runs the compliance automation platform, drives the technical control implementation, and curates evidence ahead of the third-party audit.
Runs your weekly working sessions, keeps the 12-month program on schedule, and coordinates between your team, the squad, and the 3PAO during audit week.
Owns the relationship with your auditor from selection through certification. Manages evidence requests, walkthroughs, and findings, so your team isn't pulled into auditor exchanges.
Compliance automation platforms (Vanta, Drata, Scrut, and others) collect evidence from your cloud infrastructure, SaaS tools, and endpoints, then map it to control frameworks. They are essential. As Kobalt's CEO put it on the RBC briefing: "do not undertake CPCSC without a compliance automation platform. There are 250+ controls and thousands of data points to track every year."
What software won't do: write your custom policies, remediate the AWS misconfiguration it flagged, or defend your control design to a 3PAO. We configure and operate whichever platform fits your stack and budget, and we secured IRAP funding specifically to make this affordable for Canadian SMBs.
CPCSC isn't SOC 2. The control burden, audit rigor, and pace of change make internal-only programs risky. Most teams that try the DIY path end up engaging a partner anyway, with less time on the clock.
CPCSC has 250 to 300 controls and thousands of evidence points to refresh every year. Without a dedicated team, the work crowds out your IT lead and pulls focus from the product.
3PAO auditors look for evidence depth, not just policy presence. Most internal-only programs end up doing the work twice: once for the checkbox, once to actually pass.
You sign off on policies, attend a weekly working session, and show up to the auditor kickoff. We own the program. Your team stays focused on product and growth.
If you already run SOC 2 or ISO 27001, you're well ahead of where most suppliers start. But none of the common standards is a substitute for CPCSC certification, and the gaps are bigger than they look.
| Standard | How it relates to CPCSC |
|---|---|
| CMMC (US) | The closest sibling. CPCSC closely mirrors CMMC, but there's no reciprocity: a CMMC certificate does not satisfy a Canadian procurement officer. CPCSC adds three control families (Planning, System & Services Acquisition, Supply Chain Risk Management) that CMMC's older NIST baseline doesn't include. |
| SOC 2 | About 50% control overlap. SOC 2 is lighter on Media Protection, Physical Protection, and Personnel Security. CPCSC documentation is also significantly more prescriptive: a SOC 2 control written in a paragraph may need three to four pages under CPCSC. |
| ISO 27001 | About 60% control overlap. Strong foundational match, but CPCSC requires more depth on third-party risk and more direct evidence of technical implementation. A clean gap analysis is the right starting point. |
| Protected B (CCCS / ITSP guidance) | Historically, suppliers handling Protected B met requirements via SOC 2 or ISO. CPCSC replaces that ambiguity with a specific, audited compliance regime. You can no longer hand over a SOC 2 report and expect it to qualify. |
If you already hold SOC 2 or ISO 27001, your CPCSC engagement is a focused gap remediation, typically 30–40% smaller than starting from scratch. We run that exact gap analysis as the first step of every program.
The full 10-step roadmap to certification. The information hierarchy (FCI, Protected B, controlled goods). CMMC reciprocity for cross-border tech. The compliance-vs-security trap that derails most first-time programs. Written for Canadian tech founders, by Kobalt's certification team.
Read the Definitive GuideIf you supply, directly or indirectly, to the Canadian defence supply chain, expect that some level of CPCSC will apply. Even tier-three subcontractors get pulled in when the prime contractor flows down requirements. The trigger is whether you handle Federal Contractual Information, Protected B data, controlled goods, or sensitive materials that end up in a defence build (bills of materials, specifications, resource plans).
Kobalt's Level 1 program is a fixed $5,000 and includes guided self-assessment, gap report, and Security Plan submission. The Level 2 program runs $3,000 to $5,000 per month for 12 months depending on the size of your organization, and covers full controls remediation, governance, policies, and audit prep. Audit fees from a 3PAO are separate and depend on the auditor and engagement scope.
Level 1 self-assessment is already an option on DND solicitations and becomes mandatory across most defence contracts through 2026. Level 2 third-party audits become mandatory in April 2027 for any contract handling Protected B information. The 12-month build-out for Level 2 means programs that haven't started by mid-to-late 2026 are unlikely to make the deadline.
No. There is no reciprocity between CMMC and CPCSC today. The good news: the two standards mirror each other closely, so a CMMC-certified organization is well-positioned for CPCSC. You'll still need to go through a CPCSC-specific assessment (Level 1) or third-party (3PAO) audit (Level 2), and you'll have a small gap to close on the three new ITSP.10.171 control families: Planning, System & Services Acquisition, and Supply Chain Risk Management.
Generally yes for Protected B and controlled information. Canada places a heavier emphasis on data sovereignty than most defence regimes, and most contracts will require sensitive data to reside within Canadian boundaries. The major hyperscalers (AWS, Azure, Google Cloud) all operate Canadian regions, so this is more straightforward than it was a decade ago, but the configuration matters and we audit it as part of every program.
You can scope it down. The "enclave" model defines a clear boundary around the systems, data, and people that touch sensitive information, and the controls apply to that scope, not the whole organization. A 500-person company with a 50-person defence-facing team can certify just the 50, provided the boundary is genuinely tight (no cross-boundary user access, proper administrative controls). Scoping is one of the highest-leverage decisions in the program; we run it on day one.
Level 1 is a self-assessment: you document where you stand against the 17 control families, write a Security Plan that covers any gaps, and submit it. Level 2 is an audited certification: an accredited 3PAO inspects your controls, reviews evidence, and certifies that you actually meet the standard. Level 1 is reflective: what do I have today? Level 2 is prescriptive: you must demonstrate every control. Most suppliers will be required to hit both within 24 months.
Not yet, and that's a real risk. The Standards Council of Canada is still working through the accreditation process for third-party assessment organizations (3PAOs), and the audit-firm capacity needed to support April 2027 isn't fully online. We work closely with auditor partners and track accreditation status. The practical implication: the suppliers who start their Level 2 program first will be the suppliers who actually get audited on time. Capacity tightens as the deadline approaches.
Yes. Selecting the right third-party assessor (3PAO) is part of every Compliance Program engagement. We maintain working relationships with the audit firms moving through Standards Council of Canada accreditation, match you to one that fits your scope and timeline, and run point with them through certification. You don't need to chase auditors yourself.
A compliance automation platform (also called a Governance, Risk & Compliance, or GRC, platform) connects to your cloud, identity provider, HR system, and SaaS tools to continuously collect the evidence an auditor will ask for. CPCSC requires hundreds of controls and thousands of pieces of evidence refreshed on a schedule, manual tracking falls behind almost immediately and creates audit risk. Every Kobalt CPCSC program ships with a platform configured for CPCSC and continuous evidence collection in place from day one. Through IRAP grants we secured for Canadian SMBs, this capability is included in the program at no separate platform fee.
For data at rest and in transit, expect FIPS-validated cryptographic modules to come up, particularly for archival and storage of sensitive or controlled data. Bring-your-own-key and zero-trust encryption can sometimes substitute for strict data residency in adjacent regimes, but it hasn't been tested under CPCSC yet. The technical implementation is rarely the hard part; proving compliance with continuous evidence is. Compliance automation handles that.
Not today. The federal government has not signaled that CPCSC will apply to non-DND procurement (Finance, Health, Industry, etc.), which still leans on SOC 2, ISO 27001, and Protected B guidance. That said, the Canadian government tends to extend successful frameworks. If CPCSC works well in defence, expect it to migrate. Building toward CPCSC now is a hedge against that broader rollout.