CPCSC Level 1 Doesn't Gate Your Bid. It Gates Your Award.
Public Services and Procurement Canada is explicit about when the Canadian Program for Cyber Security Certification binds: the "Level 1 self-assessment will be required at contract award, and not during the bidding process" (Public Services and Procurement Canada, 2026b).
Most suppliers read that sentence as breathing room. It is the opposite.
A requirement that applies at bid is one you can plan around — you see it in the solicitation, you price the work, you decide whether to compete. A requirement that applies at award lands after you have already won, already committed a delivery date, and already told your board the deal closed. The compliance work does not get easier because it arrived later. You just have less room to do it in.
Two things about CPCSC Level 1 that change how you sequence a defence bid. First, the clause binds at award, not at bid — so the work lands when you have the least time (Public Services and Procurement Canada, 2026b). Second, if you already hold a valid CMMC certification, Canada may accept it. PSPC's own guidance says suppliers may meet the requirement by "having an existing valid Cybersecurity Maturity Model (CMMC) certification," because "both countries use the same technical controls, so suppliers don't need to meet two separate standards" (Public Services and Procurement Canada, 2026b). Most Canadian coverage of this program still says the two regimes are unrelated. They are not.
What Level 1 Actually Is
CPCSC is a mandatory cyber-security certification regime for suppliers handling sensitive unclassified information on behalf of the Government of Canada, led by Public Services and Procurement Canada. It is tiered into three levels: Level 1 (annual self-assessment, 13 controls), Level 2 (external assessments led by an accredited certification body, plus an annual affirmation, 98 controls), and Level 3 (assessments conducted by National Defence, plus an annual affirmation, 200 controls). The Standards Council of Canada accredits the certification bodies that conduct the Level 2 assessments (Public Services and Procurement Canada, 2026a).
Level 1 became available in April 2026 (Public Services and Procurement Canada, 2026a, 2026c). The standard underneath it is ITSP.10.171, the Canadian Centre for Cyber Security's adaptation of the NIST SP 800-171 control family (Canadian Centre for Cyber Security, 2025).
The 13 controls sit in six groupings, and PSPC names them in plain language rather than control-family jargon: access control, identification and authentication, media protection, physical protection, systems and communications protection, and system and information integrity. In practice: manage user accounts; give people only the access they need; use only approved systems and devices; prevent sensitive information from being shared publicly; use individual accounts and strong passwords; approve devices before they connect; enable multifactor authentication; wipe or destroy old devices; keep a list of who can access secure areas; control physical entry; use basic network protections; apply security updates; use antivirus and anti-malware software (Public Services and Procurement Canada, 2026b).
There is no certificate and no third-party assessor at Level 1. Certification is a self-declaration: you complete the assessment, receive a results page with an expiry date, and "provide proof of self-attestation and expiry date to your CanadaBuys profile." PSPC notes that once you are familiar with the standards and have reviewed your policies, "the assessment can be completed in less than an hour" (Public Services and Procurement Canada, 2026b).
That is basic cyber hygiene with no assessor to book and no queue to wait in. Which is exactly why the timing trap catches people who assume the hard part is the controls.
The Award Window
Run the sequence. A solicitation carries a Level 1 clause. You bid without the attestation, because you are permitted to. You win. Now the clause applies, and between award and contract execution you must scope your systems, work through all 13 controls, gather the evidence, and record the attestation and its expiry date in CanadaBuys (Public Services and Procurement Canada, 2026b).
For a mature organization that is a short, focused piece of governance work. For an organization discovering the requirement at award, it is that work stacked on top of contract execution, resourcing, and a customer who now has a delivery expectation. And every one of those days is spent on something a competitor could have finished last quarter.
The fix is almost insultingly simple: attest before you need to, and keep the attestation current year-round. There is no assessor to engage and no external assessment to pay for. The only reason not to hold a current Level 1 attestation is not having thought about it.
There is a second-order effect worth naming. Because the honest answer at bid time can be "not yet," a supplier who can answer "Level 1, attested, current" is volunteering information the process does not force out of anyone. That is a differentiator precisely because the rules do not require it.
The CMMC Route Almost Nobody Is Using
Here is the part that contradicts most of what is written about this program in Canada.
PSPC's Level 1 page carries a section headed "Recognition of Cybersecurity Maturity Model certification." It states that CPCSC "aligns with United States (U.S.) Cybersecurity Maturity Model certification (CMMC) requirements, but does not duplicate the U.S. certification system. Both countries use the same technical controls, so suppliers don't need to meet two separate standards." The Government of Canada "may accept a contractor's valid CMMC certification on a case-by-case basis, after confirming that the assessment covers the required scope," and reserves the right to verify compliance with specific controls. Proof of CMMC certification is submitted to PSPC by email for verification and assessment (Public Services and Procurement Canada, 2026b).
Read the compliance route plainly: you may meet the Level 1 requirement either by completing the annual self-assessment or by holding an existing valid CMMC certification (Public Services and Procurement Canada, 2026b).
If you are a Canadian supplier who already went through CMMC to serve US defence customers, you may already be able to answer the Canadian question. That is a live commercial asset most vendors in this market are not claiming, because the prevailing narrative — including in a good deal of vendor commentary — is that the two programs are unrelated.
Two caveats keep this honest. Acceptance is case-by-case, not automatic, and it is conditional on the assessment covering the required scope. So the correct posture on a bid is we hold CMMC and have submitted it to PSPC for recognition — never we're CPCSC certified.
It also means the US program's turbulence is not irrelevant here. The United States suspended CMMC Phase 2 — its third-party assessment expansion — on 13 July 2026, pending review (WilmerHale, 2026). That does not change Canada's schedule, and it does not affect a certification you already hold. But a supplier planning to obtain CMMC as its route into CPCSC recognition now has a less predictable path than one that simply self-attests to the 13 controls.
It Attests to Your Company, Not Your Product
Here is the boundary error I see most often, and it is the one that turns a documentation exercise into a remediation project.
Level 1 covers the systems your organization uses to handle the specified information — your corporate IT estate — not the service boundary that a cloud authorization covers. A vendor carrying FedRAMP or a Protected B authorization has a strong prior that the 13 controls are implemented somewhere in the organization. It does not follow that they are implemented, documented and evidenced across the estate that will actually touch defence information. Verify against ITSP.10.171 and the free Government of Canada self-assessment tool rather than assuming your cloud authorization answers it (Canadian Centre for Cyber Security, 2025; Public Services and Procurement Canada, 2026b).
Keep the Evidence PSPC Actually Asks For
Level 1 submits nothing to government, but you must retain evidence "for the duration of your attestation cycle, or at least one year." PSPC's own examples: account lists; device lists; access review notes; copies of security policies; security, IT and information management training records; logs of updates, patching and sanitization; visitor logs; firewall settings or screenshots; MFA configuration screens. The bar is explicitly practical — "evidence of compliance does not need to be complex, it must exist and be consistent with your business practices" (Public Services and Procurement Canada, 2026b).
What the Market Expected This to Cost
PSPC ran a Request for Information on CPCSC readiness in May 2024, drawing completed responses from 91 organizations, and published the summary in November 2024 (Public Services and Procurement Canada, 2024).
Two figures, and the denominators matter. Among prime contractors, "29% of Primes expect to invest over $250,000" in CPCSC readiness. Across all respondents who answered the investment question (72 of the 91), the distribution runs the other way: 34.72% expected to spend under $25,000, and only 13.89% expected to spend $250,000 or more (Public Services and Procurement Canada, 2024).
That gap is not a statement about the program. It is a statement about starting posture — primes carry more scope and more subcontractor flow-down than a small supplier attesting to 13 controls on its own systems. If you are budgeting from the headline number rather than from your own control inventory, you are budgeting for someone else's company.
The market those numbers gate is substantial. Canada's defence industry generated CA$17.3 billion in revenues, contributed over CA$11.1 billion to GDP, and supported 81,800 jobs in 2024, with small and medium-sized businesses making up over 90% of firms (Innovation, Science and Economic Development Canada, 2026).
When the Assessor Disappears, Verification Moves Into the Contract
The instinct is to read a self-attested regime as a softer one. The procurement research points the other way.
A 2025 study on assessing supplier cybersecurity trustworthiness in digital supply chains applies the zero-trust principle — a party is treated as untrustworthy until proven trustworthy — and makes a point most suppliers miss: trustworthiness assessments cannot run on publicly available information alone, so the procurement contract itself must carry clauses that make verification possible: audit scope, access, methodology, reporting, remediation timelines, subcontractor flow-down and termination rights (Latsiou et al., 2025). The authors build their method on control families drawn from the CMMC architecture — the same lineage that produces ITSP.10.171.
Translate that into a Canadian defence contract. Removing the assessor does not remove the verification; it relocates it. The buyer stops asking "do you hold a certificate?" and starts asking "what will you let us audit, and what evidence can you produce on demand?"
That reframes what readiness is for. The attestation is the entry ticket. The evidence package behind it is what survives the contract clause, the flow-down request from a prime, and the day someone asks you to prove it.
What Sagentix Does — and Does Not Do
Scope: Sagentix prepares organizations for independent assessment; it is not a 3PAO and does not perform the independent assessment, issue certification, run penetration tests, or operate a security operations centre. Sagentix also does not perform CPCSC assessments or sign self-attestations on a client's behalf. What it does do is prepare organizations for assessment, and advise vendors on go-to-market strategy — positioning, pricing, sales process, buyer journey — so they can sell into markets where compliance is the buying trigger. The CISSP underwrites both. The control mapping, the sign-off and the CanadaBuys attestation belong to your governance team.
What This Looks Like in Practice
A Sagentix Phase 1 proof-of-concept for a vendor selling into Canadian defence-adjacent sectors produces Sagentix Phase 01 Market Intelligence, 2026:
- A competitive positioning matrix on compliance-outcome dimensions — attestation currency, evidence-package completeness, flow-down readiness — instead of feature parity
- A buyer journey map anchored on the actual procurement gates, including where the clause enters and which stakeholder raises it
- A bottom-up TAM/SAM/SOM filtered by NAICS codes for defence primes, sub-tier suppliers and adjacent regulated sectors
- A pricing benchmark against the buyer's internal compliance labour cost, so the platform reads as an ROI line item rather than a security expense
The deliverable is a 60–90+ page evidence-traced document carrying a median of 38 APA 7th edition citations, passed through an 18-check quality gate.
Three Paths From Here
You do not need Sagentix to act on any of this.
- Check whether you already qualify, then attest. If you hold a valid CMMC certification, send it to PSPC for case-by-case recognition. If you don't, scope your systems, work the 13 controls, get sign-off and record the attestation in CanadaBuys — no assessor, no queue, and it removes the award-window risk entirely.
- Build the evidence package, not just the declaration. Assemble the account lists, access review notes, patching logs, firewall settings and MFA screens into something you can hand over on request. That is what survives an audit clause and a prime's flow-down.
- Pressure-test how you say it. Bring in someone who can turn "Level 1, attested, current" into a positioning asset rather than a checkbox, and stress-test whether your narrative survives a compliance-led procurement evaluation. That is the Sagentix Phase 1 proof-of-concept — 1,412 curated artifacts and an 18-check quality gate, CA$4.5K–$45K end-to-end in 6–8 weeks, with Phase 1 under a money-back guarantee (subject to terms) Sagentix GTM Methodology, 2026.
If you want to test whether your current positioning survives a defence procurement review, book a free 30-minute Strategy Diagnostic or email stephane@sagentix.ca.
Yesterday's piece covered the other half of the question defence prospects actually ask — the Controlled Goods Program, which turns on what your platform does with data rather than on what a contract clause says. The two regimes are separate, and holding one says nothing about the other.
So here is my question for suppliers already in this market: if you won a clause-bearing contract this month, how many days would it take you to attest — and does anyone in your company know whether your existing certifications already count?
References
- Canadian Centre for Cyber Security. (2025, April 2; rev. October 28, 2025). Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171). Communications Security Establishment.
- Innovation, Science and Economic Development Canada. (2026). State of Canada's defence industry 2026. Government of Canada.
- Latsiou, A. C., Nygård, A. R., Katsikas, S., & Lambrinoudakis, C. (2025). Never trust – always verify: Assessing the cybersecurity trustworthiness of suppliers in the digital supply chain. Procedia Computer Science, 254, 98–107.
- Public Services and Procurement Canada. (2024, November 18). Canadian Program for Cyber Security Certification Request for Information: Summary report. CanadaBuys.
- Public Services and Procurement Canada. (2026a). Canadian Program for Cyber Security Certification: Program overview. Government of Canada.
- Public Services and Procurement Canada. (2026b). How to meet Level 1 cyber security certification requirements. Government of Canada.
- Public Services and Procurement Canada. (2026c, April 14). Government of Canada introduces Level 1 of the Canadian Program for Cyber Security Certification [News release]. Government of Canada.
- WilmerHale. (2026, July 20). Pentagon suspends CMMC Phase 2 requirements and launches review of cybersecurity certification program. Wilmer Cutler Pickering Hale and Dorr LLP.
Subscribe + get the workbook
The Bottom-Up TAM / SAM / SOM Workbook — free with your subscription
An 11-page tactical workbook with fillable worksheets — NAICS lookup, three-filter SAM test, Bull/Base/Bear SOM, and the diligence cross-checks. Not published anywhere else. Then get evidence-backed analysis every other Tuesday. No spam. Unsubscribe anytime. See past issues.

Stéphane Raby, CISSP, CMC, P.Eng., MBA
Founder & Principal — Sagentix Advisors
CMC | CISSP | P.Eng. | uOttawa Telfer Executive MBA — ranked #1 globally by CEO Magazine, 2023. 25+ years in technology strategy, cybersecurity, and management consulting.
Want This Evidence Applied to Your Market?
Phase 1 Market Intelligence starts at CA$4,500 with a money-back guarantee.