Skip to main content

Sagentix Cyber & AI

“Are you compliant?”
Compliant with which one?

A federal buyer or a prime asking that question is pointing at one of several programmes — run by different authorities, resting on different law, answering different questions. They are complementary, not interchangeable.

Establishing which one they mean, before anyone puts an answer in writing, is the work. Getting it wrong costs a programme built against an obligation that does not bind you — and misses the one that does.

Four programmes, four questions

Status stated as at August 2026. In this area a summary without a date is worse than no summary — the rules have all moved in the last eighteen months.

CGP

Controlled Goods Program

Who may access defence-controlled goods and their technical data, and how are they safeguarded?

Run by
Public Services and Procurement Canada — Controlled Goods Directorate
Rests on
Defence Production Act, Part 2, and the Controlled Goods Regulations
What it is
Personnel screening plus physical and data safeguarding. Not a cybersecurity programme.
How you comply
Register, appoint a Designated Official, run security assessments of the people who will have access, and maintain an approved security plan.

CPCSC

Canadian Program for Cyber Security Certification

How cyber-mature are the supplier’s own systems that handle federal Specified Information?

Run by
PSPC, with National Defence, the Cyber Centre and the Standards Council of Canada
Rests on
ITSP.10.171 — the Canadian adaptation of the NIST SP 800-171 family
What it is
A three-level certification programme. ITSP.10.171 is the control standard; CPCSC is the certifying programme — a distinction routinely collapsed.
How you comply
Level 1 is a self-assessment of 13 controls in six groupings, attested annually in the CanadaBuys supplier profile. Levels 2 and 3 are assessed by others.

PBMM

CCCS Cloud Medium

Is the cloud service itself trustworthy enough to hold Government of Canada data at Protected B?

Run by
The Canadian Centre for Cyber Security
Rests on
ITSG-33 and the Canadian adaptation of NIST SP 800-53
What it is
A cloud security assessment producing a reusable risk authorization a department draws on.
How you comply
Independent third-party assessment, then Cyber Centre review. Covered in depth on its own page.

CMMC

CMMC (United States)

Does a supplier to the US defence department meet NIST SP 800-171?

Run by
The United States Department of Defense
Rests on
NIST SP 800-171 Revision 2 — not Revision 3, whose rule is unpublished
What it is
A separate US programme. Relevant in Canada mainly because CPCSC Level 1 can recognise a valid CMMC certification.
How you comply
The third-party assessment gate is currently suspended; the underlying obligation and self-attestation are not.

Four things you have probably been told that are no longer true

Each of these is widely published, widely repeated, and wrong as at August 2026. If an adviser quotes any of them at you, they are reading last year's summary.

“CPCSC Level 2 arrives in spring 2027.”

Withdrawn. PSPC now states that Levels 2 and 3 are currently under development, with no date attached. The spring-2027 figure — and the “summer 2026 solicitations” figure alongside it — trace to vendor commentary rather than to any Government of Canada page. Plan Level 2 as a capability to build, never as a date to hit.

“CMMC Level 2 assessments are rolling out, so we need a C3PAO.”

The third-party assessment gate has been suspended since July 2026 pending a reform review; only self-assessment tiers may be required at present. What did not pause is the obligation itself — the DFARS clause and all 110 NIST SP 800-171 requirements still apply, self-attested, with False Claims Act exposure behind the attestation. Note also that a score posted in SPRS is a Basic Assessment score, not a certification, and describing it as one is where the real risk sits.

“We store controlled goods data in the cloud, so our provider must be CGP-registered.”

The rule moved. Current guidance says cloud providers typically do not examine, possess or control customer content — but that services requiring them to examine or possess controlled data do require registration. The trigger is examination, not storage. The older bright-line language is still widely quoted; it now describes a rule that has been revised.

“We hold CMMC, so CPCSC Level 1 is covered.”

Directionally right, conditionally true, and currently narrower than it looks. PSPC does recognise a valid CMMC certification in place of the Level 1 self-assessment, case by case. But a self-assessment with an SPRS score is not a certification — and with the US third-party path suspended, a firm that does not already hold one cannot currently obtain one. For most Canadian suppliers the Canadian self-assessment is the only open route.

The part most suppliers miss

Two of these programmes can reach the same data

CPCSC protects what the Government of Canada calls Specified Information — its own term, standing in for what the United States calls controlled unclassified information, and defined as information a federal authority identifies in a contract as requiring safeguarding. That definition expressly contemplates that Specified Information may include controlled goods information.

So a cyber-certification gap and a controlled-goods gap can bear on the same class of information in the same contract. Sequenced as one decision, most of the underlying work — the access control, the screening of who may see what, the physical and logical boundary — is shared. Run as two separate projects by two separate advisers, it is scoped, staffed and paid for twice.

What the engagement covers

Applicability and readiness. The certification, the registration decision and the legal interpretation all belong to someone else.

Which programme is actually being asked about

The first deliverable, and often the only one needed. A buyer question, a prime’s supplier questionnaire or a solicitation clause is mapped to the programme it actually invokes — before anyone drafts an answer.

Product-by-product applicability

Whether each programme reaches your service on the facts of your architecture: what data you hold, whether anyone examines it, where it sits, and who can see it in the clear.

CPCSC Level 1 readiness

The thirteen controls, the evidence set to retain against them, and the attestation itself — plus an honest read of whether a valid CMMC certification could be offered in its place.

Controlled Goods registration readiness

The Designated Official role, the security plan, the security-assessment process for people with access, and the least-privilege and residency positions the guidance expects.

Sequencing them as one decision

Specified Information may include controlled goods information, so a CPCSC gap and a CGP gap can bear on the same data. Sequenced together, much of the work is shared; run as separate projects, it is paid for twice.

Bid and questionnaire positions

The defensible written answer — and, just as often, the answer to hold back until a fact is confirmed. A compliance representation is easy to make and hard to withdraw.

Delivered

Produced for a global infrastructure and security provider on a live federal file — including the data-handling analysis that decides whether a service which never stores data at rest is in scope at all, and the written positions behind a defence supplier questionnaire. No client is named; engagements are described at method level, with named references available on request subject to client consent.

Where you will want someone else

  • Certify, assess or audit against any of these programmes
  • Act as an accredited certification body or third-party assessor
  • Provide legal advice, or an export-controls opinion
  • Make a compliance representation on your behalf
  • Interpret the Defence Production Act or export-control law — that is counsel’s work

One boundary matters more than the rest here. Before any written representation that you are compliant on the controlled-goods side, the specific data flow should be confirmed and Canadian export-controls counsel should sign it off. Storing controlled technical data outside Canada can raise a separate export question, and that is a legal determination — not an architecture one.

Bring us the question you were asked.

Thirty minutes. Send the clause, the questionnaire or the email, and we will establish which programme it actually invokes, whether it reaches your product on the facts, and what a defensible answer looks like — including the parts worth holding back until something is confirmed.

Sources

  • Public Services and Procurement Canada — Canadian Program for Cyber Security Certification: program overview, Level 1 criteria and How to meet Level 1. canada.ca.
  • Canadian Centre for Cyber Security — Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171). cyber.gc.ca.
  • Public Services and Procurement Canada — Controlled Goods Program guidance, including the cloud-services and data-residency guidance. canada.ca.
  • Government of Canada — Defence Production Act, Part 2, and the Controlled Goods Regulations. laws-lois.justice.gc.ca.
  • Global Affairs Canada — Notice to Exporters No. 1159 (5 November 2025), on foreign access to controlled technical data.
  • United States Department of Defense — 32 CFR Part 170 and DFARS 252.204-7012; the Phase II suspension announced 13 July 2026.

Status stated as at August 2026. Every programme on this page has changed within the last eighteen months and at least two are mid-development, so confirm the current position before contracting. This page is general information, not legal advice — and controlled-goods and export-control questions belong with qualified Canadian counsel.