CPCSC readiness for Canadian suppliers
CPCSC is the certification regime Canada is building for suppliers to federal and defence contracts. It is not finished, and the honest preparation advice looks different from the advice for a framework that already exists.
The Canadian Programme for Cyber Security Certification, usually shortened to CPCSC, is a federal supply-chain security regime that will require companies bidding on certain Government of Canada contracts to demonstrate a defined level of cyber security, in some cases through an independent assessment rather than their own word. If you sell to a federal department, or to a defence prime that sells to one, it is the framework most likely to appear in your next solicitation. If you sell only to commercial buyers, it is not yours and you can stop here.
The programme is still being stood up. That matters more than it usually would, because most of what is written about CPCSC online either treats it as already in force or copies American CMMC guidance with the nouns changed. This page describes the mechanism, and says plainly where the detail is not yet fixed. It deliberately names no implementation dates, because the ones in circulation have not held.
What CPCSC actually is
CPCSC is led by Public Services and Procurement Canada, the department that runs federal contracting, working with the Department of National Defence and the Communications Security Establishment's Canadian Centre for Cyber Security. The problem it exists to solve is specific: unclassified but sensitive federal information sits on the systems of thousands of suppliers and subcontractors, and until now the government's assurance that those systems were protected came mostly from the supplier signing a clause promising it was.
The mechanism is procurement, not regulation. CPCSC is not a law and no regulator enforces it. It becomes binding on you the moment a solicitation includes a clause requiring a certification level, and it binds nobody else. A company with no federal contracts has no CPCSC obligation, and a company with one federal contract may find the requirement attaches to that contract and not to the rest of its business. This is the single most useful thing to understand about it, because it tells you where to look for your actual requirement: in the bid documents, not in a standard.
The control content is Canadian. The programme is being built on Canadian standards work rather than adopting an American control catalogue wholesale, with the Digital Governance Standards Institute publishing the underlying standards. Higher levels are expected to reach the sort of control depth that NIST SP 800-171 represents in the American programme, because the information being protected is comparable and the primes are frequently the same companies. Treat the exact control list at each level as the part still moving.
Where to check
Public Services and Procurement Canada publishes the current programme material, and it supersedes anything on this page or any other. Before you budget against a level, a date or a control count, read the current federal material and, if you have one, ask the contracting authority on your file directly. They will usually tell you.
Who needs to care
Four groups, in descending order of urgency.
Defence primes and their subcontractors. If your revenue comes through a prime contractor on a defence programme, the requirement will reach you through your contract with the prime rather than directly from the government. Primes tend to flow requirements down early and conservatively, which means you may be asked to meet a level before the federal timetable formally requires it. In practice the prime's procurement team is the deadline that binds you.
Companies already registered under the Controlled Goods Program. Controlled Goods registration and CPCSC are separate regimes with different scopes, but they land on largely the same population of Canadian firms and both turn on protecting information the government cares about. If you already hold a Controlled Goods registration, assume CPCSC is coming to your contracts and that some of your existing security screening and physical control work will be reusable evidence.
Ottawa-area technology suppliers selling into federal departments. Federal supply is a large share of that market, and security schedules in federal solicitations have been getting longer for years regardless of CPCSC. Our Ottawa compliance page covers what federal supply brings with it beyond commercial frameworks.
Companies that hold federal data but sell commercially. A software vendor whose product happens to store departmental information is closer to scope than it feels. Ask whether the data you hold on behalf of a federal client is unclassified but protected. If it is, expect the question.
How the levels work
CPCSC is tiered, and the tiering follows a logic worth learning even before the final details are published, because it is the same logic CMMC uses and the same logic any workable supply-chain regime has to use. The level required is set by the sensitivity of the information involved in that particular contract, and the assurance method escalates with it.
| Tier | How it is proven | What it costs you |
|---|---|---|
| Lowest tier, basic protection of federal contract information | Self-assessment against a defined baseline, attested by the company | Internal effort and honest record keeping. No assessor fee. |
| Middle tier, sensitive unclassified information | Assessment by an independent accredited body, with a certificate | Assessor fees, remediation, and evidence that survives an outsider reading it. |
| Highest tier, the most sensitive unclassified work | Government-led or government-supervised assessment | The above, plus scheduling around the assessing body's availability. |
Two consequences fall out of that structure immediately. The first is that self-attestation is not the soft option it looks like: attesting falsely to the federal government about your security posture is a materially different act from overstating your posture to a commercial buyer, and the American programme has already produced enforcement actions on exactly that point. The second is that the middle tier is where the money is. Independent assessment means an assessor who did not help you build the program has to be able to follow your evidence, which is the same discipline a SOC 2 audit imposes.
How it relates to CMMC
CMMC is the American Cybersecurity Maturity Model Certification programme, run by the United States defence department for its own supply chain. CPCSC is Canada's counterpart and was designed with an eye on it. The two share a structure: tiered levels, self-assessment at the bottom, third-party certification in the middle, and the requirement arriving through a contract clause rather than a statute.
What they do not yet share is a formal recognition arrangement. The obvious question from any Canadian company already carrying a CMMC obligation through an American prime is whether one certification will satisfy both governments. Alignment has been an explicit goal on the Canadian side, and cross-recognition is the natural end state given how integrated the two defence industrial bases are, but you should not plan a budget on the assumption that your CMMC work transfers automatically. Plan instead on the control work transferring, which it largely will, and on the certificates being separate until somebody tells you otherwise in writing.
What is not settled, and should not be guessed
Being specific about the gaps is more useful than filling them, so here are the things this page will not tell you, because nobody can tell you them reliably yet: the calendar date on which clauses start appearing in solicitations, the final control count at each level, the fee an accredited assessor will charge, the size of the assessor market when the programme opens, and how many of your existing certifications will be accepted as partial evidence. Any page giving you a confident number on those is either quoting material that has since changed or making it up.
What you can rely on is the direction. Federal buyers are going to ask for evidence rather than assurances, the evidence will be graded by sensitivity, and the middle tier will require somebody independent to look at it. None of that is in doubt, and all of it is enough to start on.
How to prepare without guessing
The work that pays off regardless of where the final details land is the work that any assessment regime requires, so do that and wait for the specifics.
- Find out what federal information you hold and where it lives. Not a policy, an inventory: which systems, which cloud regions, which subcontractors. Scope is what drives assessment cost, and most companies discover their scope is wider than assumed because someone attached a document to a shared drive three years ago.
- Narrow the scope deliberately. If federal contract information can be confined to a defined set of systems, confine it. This is the single largest lever on what an assessment costs, and it is far cheaper to pull before you have built controls across everything.
- Get the basic controls in place and evidenced. Access control with multi-factor authentication, asset inventory, patching with records, logging that is retained, backups that have been restored from, incident response with a named owner, and security awareness training people actually completed. These appear in every tier of every regime of this type.
- Write down what you cannot yet do, with a date. Gap registers with owners and target dates are treated as evidence of a working programme in most assessment regimes. Silence about a gap is treated as the opposite.
- Ask the prime. If you subcontract to a prime, ask their supply-chain security team what they expect to flow down and when. They have been planning for this longer than you have and they would rather tell you than lose you as a supplier.
- Do not buy a certificate that does not exist. There is no CPCSC certificate available to you before the programme opens, and anyone selling one is selling nothing.
If you already hold ISO 27001 or a SOC 2 report, much of the underlying control work is reusable, though the mapping is never one for one and the evidence formats differ. Companies deciding between frameworks for the first time should start with which framework applies to you, since CPCSC sits alongside the commercial ones rather than replacing them.
What to budget
No credible assessment fee exists yet, so the only honest budgeting advice is to price the preparation rather than the certificate. Readiness work of the type described above, done with outside help, generally falls in the same band as any first-time framework preparation in Canada: roughly $20,000 to $70,000 CAD depending on how many systems are in scope and how much documentation already exists, plus your own team's time, which is usually the larger number. Scope reduction work done early tends to pay for itself twice over.
Selling to a federal buyer or a prime
Tell us what the contract asks for and we will point you at Canadian firms that have done federal supply-chain security work.
Get matchedCommon questions
Is CPCSC mandatory yet?
It becomes mandatory for you when a contract or solicitation says so, not on a general commencement date. The programme is being phased in through procurement clauses, so the accurate answer for any given company is found in its bid documents and its prime contractor's flow-down terms rather than in a statute.
Will our CMMC certification be accepted in Canada?
Not automatically, and not on the strength of anything published so far. Alignment between the two programmes is a stated goal and the control work overlaps heavily, so the preparation transfers even if the certificate does not. Budget for the possibility of two separate assessments until a formal recognition arrangement is announced.
Does ISO 27001 or SOC 2 cover us for CPCSC?
No, but neither is wasted. An ISO 27001 information security management system or a SOC 2 report demonstrates the same underlying practices in access control, change management, logging and vendor oversight, which is most of the work. What they do not do is satisfy a federal contract clause that names CPCSC, because the clause names CPCSC.
We are a subcontractor two levels down. Does this reach us?
Frequently yes. Supply-chain regimes of this type work by flow-down, and the requirement follows the sensitive information rather than the contract tier. If federal contract information reaches your systems, expect the obligation to reach you with it, arriving as a clause from whoever you invoice.
What can we do right now that will definitely not be wasted?
Build the inventory of where federal information lives and reduce that footprint. Every version of every assessment regime prices you on scope, so the work of knowing and shrinking your scope pays back under any final ruleset, and it is the piece that takes the longest because it depends on people remembering what they built.