Search
CPCSC Certification, Canada

CPCSC certification for Canadian defence supply-chain suppliers

The Canadian Program for Cybersecurity Certification is now table stakes to bid on federal defence contracts. Kobalt help you get you Level 1 ready in weeks, and will help you get Level 2 audit-ready on time.

Canada has committed over half a trillion dollars to defence over the next decade. Every supplier in the chain, from primes to tier-three subcontractors, will need to demonstrate compliance against the 17 CPCSC control families. Kobalt's managed program runs the full path: gap assessment, enclave scoping, evidence automation, System Security Plan, and audit prep with an accredited third-party assessor (3PAO).

Built for Canadian SMBs ITSP.10.171 aligned IRAP-funded automation Level 1 from $5,000
Who Is In Scope

Does CPCSC apply to your business?

The single most-asked question on every CPCSC briefing. The short answer: if any part of your business touches the Canadian defence supply chain, directly or several tiers down, expect some level of CPCSC to apply. Here's how that plays out for the most common scenarios.

Tier-1 supplier bidding directly to DND
Applies

If you respond directly to a DND solicitation, expect CPCSC requirements written into the bid. Level 1 self-assessment is already optional on contracts today, mandatory on most by 2027. Level 2 third-party audit will be required for any contract handling Protected B information from April 2027 onward.

Tier-2 or tier-3 supplier to a defence prime
Applies

You may never see the DND directly. The prime contractor will flow CPCSC requirements down to its supply chain, same as SOC 2 or ISO 27001 vendor requirements work today. If a prime depends on you, your security posture becomes their compliance risk. They will require certification.

SaaS / software vendor to a defence contractor
Applies

If your software stores, processes, or transmits Federal Contractual Information, Protected B data, controlled goods data, or anything that ends up in a defence build (BOMs, specs, resource plans), CPCSC applies. "We're just SaaS" is not an exemption, it's the trigger.

Training or services firm to DND staff
Applies

Training providers, professional services firms, and consultants typically hold defence employee names, contact details, and program enrolment data. In the defence context, that information is sensitive even when it isn't classified. Provincial or municipal compliance experience is a head start, not a substitute.

Holds CMMC for US DoD work
Partial, gap remains

No reciprocity exists between CMMC and CPCSC. A CMMC certificate does not satisfy a Canadian procurement officer. The good news: the standards mirror each other, so you're 80% of the way there. The gap is the three new ITSP.10.171 control families: Planning, System & Services Acquisition, and Supply Chain Risk Management.

Federal agency vendor outside DND
Not yet, but watch

CPCSC is currently scoped to defence procurement. Other federal departments still rely on SOC 2, ISO 27001, and Protected B guidance for their security expectations. The Canadian government has historically extended successful frameworks across departments, so building toward CPCSC now is a hedge against broader rollout in 2027 and beyond.

Not sure where you land? The 30-minute scoping call gives you a clear answer: which level applies, what data triggers the requirement, and what the runway to certification looks like for your specific business.

Book a free scope call
CPCSC Levels

Three levels. Right-sized for what you actually bid on.

CPCSC is not a single bar. The level that applies to you depends on the data type and the contract you're chasing. Most Canadian SMBs land at Level 1 today and Level 2 by 2027. Level 3 is reserved for critical defence systems.

Level 1 Level 2 Most SMBs by 2027 Level 3
Assessment type Self-assessment with submitted Security Plan Third-party audit by an accredited 3PAO 3PAO audit plus DND-led government assessment
Data covered Federal Contractual Information (FCI) Protected B information, controlled goods Critical defence systems: command, control, weapons, comms
Who needs this Any supplier in the defence supply chain Suppliers handling Protected B data, most tier-1 and tier-2 vendors Major defence primes, critical infrastructure operators
Mandatory by April 2026 (Phase 2 already in flight) April 2027 for Protected B contracts Post-April 2027, contract-specific
Typical timeline 30 days with Kobalt 12-month managed program 18+ months, scoped per contract
Kobalt's take Foundation. Required minimum. Where most contract value lives Specialist engagement, scoped per contract

Most Canadian SMBs should start Level 1 immediately and plan the runway to Level 2. Even if your current contracts only ask for self-assessment, the 12-month build-out for Level 2, plus the audit window itself, means starting now is the difference between making April 2027 and missing it.

Implementation Timeline

The CPCSC rollout is already in flight

Public Services and Procurement Canada is rolling out CPCSC in staged phases. The standard is live today as a self-assessment option. Within 24 months, Level 2 audits become mandatory for any contract touching Protected B data.

April 2025, Phase 1

Level 1 self-assessment goes live as an optional requirement

Procurement teams can begin requiring Level 1 self-assessment in DND solicitations. Not every bid asks for it yet, but the ones that do filter out non-compliant suppliers immediately.

Spring 2026, Phase 2 We are here

Level 1 mandatory on select DND RFPs

The optional flag flips to mandatory on a growing share of defence solicitations. Self-attestation without a documented assessment is no longer accepted.

Late 2026, Phase 3

Level 1 becomes the gate for most National Defence contracts

By the end of 2026, expect Level 1 to be a baseline qualifier on almost every DND bid, directly and through prime contractors flowing the requirement down the supply chain.

April 2027, Phase 4

Level 2 third-party audit mandatory for Protected B

Any contract handling Protected B information requires a passing audit from an accredited 3PAO. Programs that haven't started by Q3 2026 are unlikely to make this date.

Service Options

Two ways to work with Kobalt on CPCSC

Pick the path that matches where you are. Start with the Level 1 project to clear an active bid, or step into the Compliance Program for full Level 2 readiness, with the option to bundle a second framework like SOC 2 or ISO 27001.

Project

CPCSC Level 1 Program

$5,000 USD
Fixed-fee, ~30-day engagement
For: Clearing an active bid that requires CPCSC Level 1 self-assessment now.
  • Guided self-assessment against all 17 control families
  • Gap analysis report flagging anything below standard
  • Written System Security Plan (SSP)
  • Plan of Action & Milestones (POA&M) for remediation
  • Submission-ready package for procurement
Discounted entry point that sets the foundation for Level 2
Get Level 1 scoped
What You Get

Six workstreams. One audit-ready program.

Every Kobalt CPCSC program, Level 1 or Level 2, covers the same six workstreams. No deliverables left to the client's interpretation.

Gap Assessment & Enclave Scoping

A full review against the 17 CPCSC control families plus a defensible boundary around the systems, data, and people that touch Protected B information.

  • Prioritized remediation roadmap
  • Enclave boundary diagram and access controls
  • Effort and cost breakdown per finding

Technical Controls Deployment

The hands-on work: MFA, encryption (FIPS-aligned where required), EDR, logging, segmentation, vulnerability management, mapped to each control family.

  • MFA, encryption, EDR, logging, monitoring
  • Cloud config hardening and data residency review
  • Access reviews and personnel screening processes

Policy Suite & Governance

Audit-ready policies tailored to your stack, not templates. Each policy maps to the specific ITSP.10.171 controls a 3PAO will look for.

  • Information Security & Acceptable Use
  • Incident Response & Breach Notification
  • Supply Chain Risk Management (new family)
  • Data classification, retention, and disposal

System Security Plan & POA&M

The two documents the auditor and the procurement officer will read. We write them, you review them.

  • System Security Plan (SSP) covering all 17 families
  • Plan of Action & Milestones (POA&M) for residual gaps
  • Sign-off package ready for submission

Compliance Automation Platform

A Governance, Risk & Compliance (GRC) platform configured for CPCSC, with continuous evidence collection. Funded in part by IRAP grants we secured to bring this capability to Canadian SMBs.

  • Platform configured and mapped to CPCSC controls
  • Evidence collected continuously, not at audit time
  • Audit-ready reporting dashboard

Mock Audit & 3PAO Liaison

A pre-audit run-through against 3PAO criteria. Surface and remediate gaps before the real audit costs you a re-engagement. Then we run point with the auditor through certification.

  • Internal mock audit by Kobalt's CPCSC team
  • 3PAO selection from our auditor partners
  • Audit liaison and evidence-package ownership
CPCSC Scope

The 17 control families you'll be assessed against

CPCSC is built on ITSP.10.171, Canada's adaptation of the NIST SP 800-171 baseline. Three of the 17 families are new and focused on third-party and supply-chain risk. If you've never had to think about these before, you will now.

1
Access Control
2
Awareness and Training
3
Audit and Accountability
4
Configuration Management
5
Identification and Authentication
6
Incident Response
7
Maintenance
8
Media Protection
9
Personnel Security
10
Physical Protection
11
Risk Assessment
12
Security Assessment
13
System & Communications Protection
14
System & Information Integrity
15
Planning
New
16
System & Services Acquisition
New
17
Supply Chain Risk Management
New
The Kobalt CPCSC Squad

This isn't software. It's a managed program run by people who do this every day.

Compliance automation platforms are powerful, but they're just software. They don't write your custom policies, remediate your AWS misconfiguration, or defend your control design choices to a 3PAO. Every Kobalt CPCSC program ships with a four-person squad that runs the program end-to-end.

vCISO

Strategic Leadership

Sets the program strategy, owns the certification roadmap, and makes the judgment calls on enclave scoping, residual risk, and audit readiness. Accountable for the program end-to-end.

Compliance Lead

Policies, Controls & Evidence

Writes the System Security Plan, runs the compliance automation platform, drives the technical control implementation, and curates evidence ahead of the third-party audit.

Project Manager

Delivery & Coordination

Runs your weekly working sessions, keeps the 12-month program on schedule, and coordinates between your team, the squad, and the 3PAO during audit week.

3PAO Liaison

Auditor Interface

Owns the relationship with your auditor from selection through certification. Manages evidence requests, walkthroughs, and findings, so your team isn't pulled into auditor exchanges.

We work with the GRC platform you already use. Or help you choose one.

Compliance automation platforms (Vanta, Drata, Scrut, and others) collect evidence from your cloud infrastructure, SaaS tools, and endpoints, then map it to control frameworks. They are essential. As Kobalt's CEO put it on the RBC briefing: "do not undertake CPCSC without a compliance automation platform. There are 250+ controls and thousands of data points to track every year."

What software won't do: write your custom policies, remediate the AWS misconfiguration it flagged, or defend your control design to a 3PAO. We configure and operate whichever platform fits your stack and budget, and we secured IRAP funding specifically to make this affordable for Canadian SMBs.

Why partner with Kobalt

Three things internal-only CPCSC programs underestimate

CPCSC isn't SOC 2. The control burden, audit rigor, and pace of change make internal-only programs risky. Most teams that try the DIY path end up engaging a partner anyway, with less time on the clock.

250+

Controls to manage continuously

CPCSC has 250 to 300 controls and thousands of evidence points to refresh every year. Without a dedicated team, the work crowds out your IT lead and pulls focus from the product.

2x

Audit rigor vs. typical SOC 2

3PAO auditors look for evidence depth, not just policy presence. Most internal-only programs end up doing the work twice: once for the checkbox, once to actually pass.

5 hrs / wk

Your team's involvement with Kobalt

You sign off on policies, attend a weekly working session, and show up to the auditor kickoff. We own the program. Your team stays focused on product and growth.

CPCSC vs. other standards

How CPCSC differs from what you may already hold

If you already run SOC 2 or ISO 27001, you're well ahead of where most suppliers start. But none of the common standards is a substitute for CPCSC certification, and the gaps are bigger than they look.

Standard How it relates to CPCSC
CMMC (US) The closest sibling. CPCSC closely mirrors CMMC, but there's no reciprocity: a CMMC certificate does not satisfy a Canadian procurement officer. CPCSC adds three control families (Planning, System & Services Acquisition, Supply Chain Risk Management) that CMMC's older NIST baseline doesn't include.
SOC 2 About 50% control overlap. SOC 2 is lighter on Media Protection, Physical Protection, and Personnel Security. CPCSC documentation is also significantly more prescriptive: a SOC 2 control written in a paragraph may need three to four pages under CPCSC.
ISO 27001 About 60% control overlap. Strong foundational match, but CPCSC requires more depth on third-party risk and more direct evidence of technical implementation. A clean gap analysis is the right starting point.
Protected B (CCCS / ITSP guidance) Historically, suppliers handling Protected B met requirements via SOC 2 or ISO. CPCSC replaces that ambiguity with a specific, audited compliance regime. You can no longer hand over a SOC 2 report and expect it to qualify.

If you already hold SOC 2 or ISO 27001, your CPCSC engagement is a focused gap remediation, typically 30–40% smaller than starting from scratch. We run that exact gap analysis as the first step of every program.

Free resource

The Definitive Guide to CPCSC

The full 10-step roadmap to certification. The information hierarchy (FCI, Protected B, controlled goods). CMMC reciprocity for cross-border tech. The compliance-vs-security trap that derails most first-time programs. Written for Canadian tech founders, by Kobalt's certification team.

Read the Definitive Guide

Speak now with our CPCSC experts

Common Questions

Frequently asked questions about CPCSC

Does CPCSC actually apply to my business?+

If you supply, directly or indirectly, to the Canadian defence supply chain, expect that some level of CPCSC will apply. Even tier-three subcontractors get pulled in when the prime contractor flows down requirements. The trigger is whether you handle Federal Contractual Information, Protected B data, controlled goods, or sensitive materials that end up in a defence build (bills of materials, specifications, resource plans).

How much does CPCSC certification cost?+

Kobalt's Level 1 program is a fixed $5,000 and includes guided self-assessment, gap report, and Security Plan submission. The Level 2 program runs $3,000 to $5,000 per month for 12 months depending on the size of your organization, and covers full controls remediation, governance, policies, and audit prep. Audit fees from a 3PAO are separate and depend on the auditor and engagement scope.

When does CPCSC become mandatory?+

Level 1 self-assessment is already an option on DND solicitations and becomes mandatory across most defence contracts through 2026. Level 2 third-party audits become mandatory in April 2027 for any contract handling Protected B information. The 12-month build-out for Level 2 means programs that haven't started by mid-to-late 2026 are unlikely to make the deadline.

Can my CMMC certification satisfy CPCSC?+

No. There is no reciprocity between CMMC and CPCSC today. The good news: the two standards mirror each other closely, so a CMMC-certified organization is well-positioned for CPCSC. You'll still need to go through a CPCSC-specific assessment (Level 1) or third-party (3PAO) audit (Level 2), and you'll have a small gap to close on the three new ITSP.10.171 control families: Planning, System & Services Acquisition, and Supply Chain Risk Management.

Does CPCSC require my data to be hosted in Canada?+

Generally yes for Protected B and controlled information. Canada places a heavier emphasis on data sovereignty than most defence regimes, and most contracts will require sensitive data to reside within Canadian boundaries. The major hyperscalers (AWS, Azure, Google Cloud) all operate Canadian regions, so this is more straightforward than it was a decade ago, but the configuration matters and we audit it as part of every program.

Do I have to certify my whole company, or can I scope it down?+

You can scope it down. The "enclave" model defines a clear boundary around the systems, data, and people that touch sensitive information, and the controls apply to that scope, not the whole organization. A 500-person company with a 50-person defence-facing team can certify just the 50, provided the boundary is genuinely tight (no cross-boundary user access, proper administrative controls). Scoping is one of the highest-leverage decisions in the program; we run it on day one.

What's the difference between Level 1 and Level 2?+

Level 1 is a self-assessment: you document where you stand against the 17 control families, write a Security Plan that covers any gaps, and submit it. Level 2 is an audited certification: an accredited 3PAO inspects your controls, reviews evidence, and certifies that you actually meet the standard. Level 1 is reflective: what do I have today? Level 2 is prescriptive: you must demonstrate every control. Most suppliers will be required to hit both within 24 months.

Are there enough third-party assessors (3PAOs) accredited to audit CPCSC?+

Not yet, and that's a real risk. The Standards Council of Canada is still working through the accreditation process for third-party assessment organizations (3PAOs), and the audit-firm capacity needed to support April 2027 isn't fully online. We work closely with auditor partners and track accreditation status. The practical implication: the suppliers who start their Level 2 program first will be the suppliers who actually get audited on time. Capacity tightens as the deadline approaches.

Can Kobalt help me find a 3PAO?+

Yes. Selecting the right third-party assessor (3PAO) is part of every Compliance Program engagement. We maintain working relationships with the audit firms moving through Standards Council of Canada accreditation, match you to one that fits your scope and timeline, and run point with them through certification. You don't need to chase auditors yourself.

Why do I need a compliance automation platform?+

A compliance automation platform (also called a Governance, Risk & Compliance, or GRC, platform) connects to your cloud, identity provider, HR system, and SaaS tools to continuously collect the evidence an auditor will ask for. CPCSC requires hundreds of controls and thousands of pieces of evidence refreshed on a schedule, manual tracking falls behind almost immediately and creates audit risk. Every Kobalt CPCSC program ships with a platform configured for CPCSC and continuous evidence collection in place from day one. Through IRAP grants we secured for Canadian SMBs, this capability is included in the program at no separate platform fee.

What about the encryption and FIPS requirements?+

For data at rest and in transit, expect FIPS-validated cryptographic modules to come up, particularly for archival and storage of sensitive or controlled data. Bring-your-own-key and zero-trust encryption can sometimes substitute for strict data residency in adjacent regimes, but it hasn't been tested under CPCSC yet. The technical implementation is rarely the hard part; proving compliance with continuous evidence is. Compliance automation handles that.

Will CPCSC apply outside of defence procurement?+

Not today. The federal government has not signaled that CPCSC will apply to non-DND procurement (Finance, Health, Industry, etc.), which still leans on SOC 2, ISO 27001, and Protected B guidance. That said, the Canadian government tends to extend successful frameworks. If CPCSC works well in defence, expect it to migrate. Building toward CPCSC now is a hedge against that broader rollout.