CPCSC Readiness Starts Here

Solymus helps Canadian defence suppliers organize compliance evidence, map it to CPCSC controls, and prove it is tamper-evident and assessment-ready—before the deadline, not after.

Built for CPCSC  |  Based on ITSP.10.171

CPCSC is mandatory for DND suppliers starting April 2026. The question isn't if—it's are you ready?

Your CPCSC assessment is in 90 days.

The assessor needs evidence mapped to ITSP.10.171 controls. Your team is still collecting spreadsheets and screenshots from three departments.

With Solymus, you export a complete evidence package with per-artifact verification links—mapped to CPCSC controls.

DND asks for proof of Level 1 readiness.

Your contract renewal depends on demonstrating basic cyber hygiene. You need to show which controls are met and which have gaps—with evidence, not promises.

With Solymus, your readiness dashboard shows coverage by control family, and every artifact has a cryptographic receipt.

A prime contractor audits your compliance posture.

They need to verify your evidence is authentic and hasn't been modified since submission. Trust isn't enough—they need proof.

With Solymus, every piece of evidence is tamper-evident. Assessors verify independently, no login required.

Your compliance team shouldn't spend weeks assembling binders. Solymus replaces fragile paper trails with signed, verifiable evidence your CPCSC assessors can check themselves.

Four Steps to CPCSC Readiness

Solymus is a CPCSC Readiness Platform built on cryptographic receipts. Organize evidence, track gaps, prove integrity, and be assessment-ready.

Step 1

Organize Your Evidence

Upload policies, configurations, audit logs, and screenshots. Solymus maps each artifact to CPCSC controls based on ITSP.10.171, organized by control family.

Evidence mapped to controls automatically.

Step 2

Track Your Readiness

Real-time dashboard shows which controls are met, which have gaps, and what remediation is needed. Filter by control family to prioritize your work.

Gaps identified, remediation tracked.

Step 3

Prove It's Trustworthy

Every artifact gets a SHA-256 hash signed with AWS KMS (ECDSA P-256). Records link into a daily Merkle chain. Tamper-evident by design—retroactive changes break the chain.

Cryptographic proof, not screenshots.

Step 4

Be Assessment-Ready

Export evidence packages with a verification URL for every artifact. Assessors verify independently—no login, no trust in Solymus required.

Assessors click, verify, done.

Built on the same infrastructure used by defence contractors: SHA-256 hashing, AWS KMS ECDSA P-256 signing, daily Merkle chain linking, and tamper-evident exports.

How CPCSC Readiness Works

From evidence upload to assessment-ready export. Here's the step-by-step workflow for Canadian defence suppliers.

CPCSC Evidence & Readiness Tracking

For Canadian defence suppliers, subcontractors, consultants, and MSPs
  1. Upload artifacts via dashboard or API Drag-drop policies, screenshots, audit logs, and scan reports. Or use presigned S3 URLs for programmatic upload.
  2. Artifacts auto-map to CPCSC controls (ITSP.10.171) A policy document maps to AC-1, SC-1, PL-1. An audit log maps to AU-2, AU-3, AU-6. You can override with manual tags for exact mapping.
  3. Each artifact gets hashed and KMS-signed SHA-256 hash of the file content, signed with AWS KMS (ECDSA P-256). The key never leaves the HSM. Record links into the daily shard chain.
  4. Track readiness across CPCSC controls Dashboard shows which controls are met, partial, or missing evidence. Filter by control family (AC, AU, IA, SC) to find gaps and prioritize remediation.
  5. Export assessment-ready packages with verification URLs Generate an Evidence Index or CPCSC Readiness report. Every artifact entry includes a public verification link your assessor can click.
Your assessor clicks the verification URL from the export, sees "Signature Valid, Merkle Linked" — no login, no trust in Solymus required.

Set Up in 15 Minutes. Export Auditor-Ready Packages.

Upload Hash Sign Chain Verify
1

Create Account

Sign up and create a workspace. Choose your CPCSC level (Level 1 or Level 2).

2

Upload Evidence

Upload policies, configurations, audit logs, and scan reports. Drag-drop or use the API.

3

Map to CPCSC Controls

Artifacts auto-map to ITSP.10.171 controls. Override with manual tags for exact mapping.

4

Every Record Gets Signed

SHA-256 hash signed with AWS KMS (ECDSA P-256). Keys never leave the HSM. Evidence linked to daily Merkle chain.

5

Export for Assessment

Evidence index grouped by CPCSC control, with a verification URL for every artifact. Assessors verify from the export—no login required.

Why Canadian Defence Suppliers Choose Solymus

Built for defence suppliers, subcontractors, compliance consultants, and MSPs preparing for CPCSC assessment.

Cryptographic Proof, Not Screenshots

Every artifact gets a KMS-signed receipt with SHA-256 hash. Evidence integrity is mathematical, not organizational.

Assessors Verify Independently

Public verification API lets CPCSC assessors, primes, and auditors check any receipt themselves. No login required—verification is cryptographic, not trust-based.

Tamper-Evident by Design

Daily Merkle chain linking means retroactive changes break the chain. Gaps and modifications are automatically detectable.

Self-Contained Export Bundles

Evidence packages include the receipt, signature, Merkle proof, daily root, and public key needed for offline verification. Bundles remain verifiable independently.

CPCSC-Focused, CMMC on Roadmap

Primary focus on CPCSC and ITSP.10.171. CMMC support is on our roadmap for Canadian suppliers with cross-border U.S. defence contracts.

Built for Your Team

Whether you're a defence supplier, subcontractor, compliance consultant, or MSP—Solymus organizes evidence the way assessors expect to see it.

Verify Without Trusting Us

Your assessors, primes, and auditors can check any receipt independently. No login required.

Verify a Receipt

Enter an event ID from any export or verification link.

What Gets Signed

SHA-256 hash + AWS KMS ECDSA P-256. Keys never leave HSM.

Who Can Verify

Third parties verify receipts via export links. Evidence bundles work offline.

What You Export

Evidence packages grouped by control, with verification URLs.

CPCSC Readiness Plans

Choose the plan that matches your CPCSC certification level. All prices in CAD.

Starter
C$1,500
per month
CPCSC Level 1 readiness
  • 1,000 events/month
  • 7-day active access
  • Up to 3 seats
  • KMS receipts + Merkle chain
  • Evidence Index + CPCSC Readiness export
  • Public verification API
Get Started
Guided
C$10,000
per month
CPCSC Level 2 + AI Governance
  • Full export suite (SSP + POA&M + assessor package)
  • 100,000 events/month
  • 365-day active access
  • Up to 3 workspaces, 10 seats
  • Connectors (Beta)
  • Certificates of Truth
  • Roadmap: ISO 42001 · CGP · Law 25 · ISO 27001 · SOC 2
Get Started
Enterprise
Custom
pricing
For primes, MSPs, multi-entity
  • 1M events/month (negotiable)
  • Unlimited active access
  • Unlimited workspaces & seats
  • GovCloud + GCC High (Roadmap)
  • SSO/SAML (Roadmap), custom roles, certificates
  • Dedicated support + SLA
Contact Sales

An event is a single evidence record (one artifact upload or API ingest call). Active access is the period you can query evidence via API and dashboard; after that, records are archived per our retention policy. All prices in Canadian dollars (CAD).

Frequently Asked Questions

CPCSC (Canadian Program for Cyber Security Certification) is Canada's mandatory cybersecurity certification for Department of National Defence (DND) suppliers, taking effect April 2026. It is based on ITSP.10.171, Canada's adaptation of NIST SP 800-171 Rev 3. Solymus helps you organize evidence and prove readiness before your assessment.

No. Solymus is a CPCSC-focused readiness platform that helps you organize, track, and export assessment-ready evidence. Certification is determined by your CPCSC assessor. We give you the evidence trail; you own the compliance outcome.

Yes. Export packages include the receipt, cryptographic signature, Merkle proof, daily root, and verification instructions. Your assessor verifies mathematically without calling any Solymus API. Bundles work offline.

CMMC support is on our roadmap for Canadian suppliers with cross-border U.S. defence contracts. Our primary focus is CPCSC and ITSP.10.171. Since CPCSC and CMMC share roots in NIST 800-171, evidence organized for CPCSC will also support future CMMC readiness.

Today you upload evidence manually, via API, or via the Python SDK. Connectors are in development:

  • LIVE REST API & Python SDK
  • PLANNED M365 GCC High connector
  • PLANNED AWS GovCloud connector
  • PLANNED Endpoint agent (Windows/Linux)

We'll announce connectors when they're production-ready.

Export bundles are self-contained. They include everything needed to verify the cryptographic signatures offline. No Solymus API, account, or infrastructure required.

Be Assessment-Ready Before the Deadline

CPCSC is mandatory for DND suppliers starting April 2026. Start organizing your evidence and tracking your readiness today.

Solymus provides tamper-evident evidence infrastructure that supports your CPCSC readiness program. Certification outcomes depend on your assessor's evaluation. See our Terms of Service for details.