Comparison

CPCSC vs CMMC: Differences for Cross-Border Defence Suppliers

Both frameworks protect defence supply chains, but they are different. Understand the key differences between Canadian CPCSC and US CMMC compliance.

CPCSC and CMMC: Two Different Frameworks

If you are a defence supplier working in both Canada and the US, you might wonder: "Are CPCSC and CMMC the same thing?" The answer is no. They are separate compliance frameworks with different requirements, different timelines, and different enforcement bodies.

The simple version:

Both protect defence data, both are mandatory, and both are structured in three certification levels. But they have different implementations, different timelines, and different terminology.

Comparison Table: CPCSC vs CMMC

Aspect CPCSC CMMC
Country Canada United States
Enforcer Department of National Defence (DND) US Department of Defense (DoD)
Based On ITSP.10.171 (Canadian Centre for Cyber Security) NIST SP 800-171 Rev 2
Controlled Data Term Controlled Information (CI) Controlled Unclassified Information (CUI)
Level 1 Timeline Mandatory April 2026 Mandatory April 2024 (already in effect)
Level 2 Timeline Mandatory April 2027 Mandatory May 2025 (phased)
Level 1 Controls 13 core controls 17 core practices
Full Framework 97 controls (17 families) 110 practices (17 domains + 5 processes)
Certification Model Level 1 = self-assessment, Level 2/3 = third-party All levels = third-party certified assessor
Assessor Authority Standards Council of Canada (SCC) accredited assessors CMMC-AB (CMMC Accreditation Body) certified assessors
Target Suppliers All DND defence suppliers (600 primes + thousands of subs) All DoD defence contractors (10,000+ companies)
Applies To Companies handling Canadian Controlled Information Companies handling US Controlled Unclassified Information
Cost (Level 2) C$10K–15K/year $3K–5K per assessment

Similarities: Both Frameworks Protect Defence Supply Chains

Based on NIST 800-171

  • Both use NIST SP 800-171 as a foundation
  • Core controls map to each other
  • Similar security families (access, audit, cryptography, etc.)

Three Certification Levels

  • Level 1 = baseline / foundational
  • Level 2 = intermediate / third-party
  • Level 3 = advanced / specialist

Mandatory Compliance

  • Both are mandatory to work with defence
  • Both have hard deadlines
  • Both create supply chain cascades

Evidence-Based Assessment

  • Both require cryptographic evidence
  • Both allow third-party audit trails
  • Both prioritize tamper-proof records

Tiered Maturity

  • Start small (basic) and scale up
  • Continuous monitoring at higher levels
  • Assessments at regular intervals

Supply Chain Cascade

  • Defence primes require supplier compliance
  • Compliance cascades down the supply chain
  • No contracts without certification

Key Differences

1. Timeline Difference

CMMC enforcement started in 2024 (Level 1 mandatory by April 2024). CPCSC starts in 2026 (Level 1 mandatory by April 2026).

Why the difference? The US defence department moved faster due to a series of high-profile breaches (SolarWinds, etc.). Canada took more time to adapt NIST 800-171 into ITSP.10.171 and plan the rollout. Both countries saw the urgency, but enforced different timelines.

2. Terminology Difference

CMMC uses "CUI" (Controlled Unclassified Information). This is US terminology. CUI includes defence technical data, procurement information, security assessments, and other unclassified but sensitive DoD data.

CPCSC uses "CI" (Controlled Information). This is Canadian terminology, adapted from ITSP.10.171. CI is conceptually similar to CUI but includes information protected under Canadian law (Access to Information Act, Privacy Act, trade secrets, etc.).

In practice: Both terms mean defence-sensitive data. If you handle either, you need compliance certification in that country.

3. Level 1 Certification Model Difference

CPCSC Level 1 is self-assessment. You assess your own controls. No external auditor is required. You upload evidence to Solymus, generate a readiness report, and share it with defence primes. This is fast and low-cost but relies on your honesty.

CMMC Level 1 is third-party assessment. You cannot self-assess. You must hire a CMMC-certified assessor to audit your controls. This is slower and more expensive but adds external credibility.

For cross-border suppliers: If you have CPCSC Level 1 self-assessment, you still need a CMMC Level 1 third-party assessment. The two do not overlap.

4. Control Count Difference

CPCSC Level 1: 13 controls across 6 families (AC, IA, MP, PE, SC, SI).

CMMC Level 1: 17 core practices across multiple domains.

CPCSC Full: 97 controls across 17 families.

CMMC Full: 110 practices across 17 domains + 5 processes.

The differences in control count reflect how each country adapted NIST 800-171. CPCSC is slightly more streamlined for the Canadian market. CMMC added additional practices to address US-specific threats and requirements.

5. Assessor Authority Difference

CPCSC: Assessors are accredited by the Standards Council of Canada (SCC). This is Canada's national standards body.

CMMC: Assessors are certified by the CMMC Accreditation Body (CMMC-AB), a non-profit created by the DoD to manage assessor training and certification.

Implication: The assessor pools are completely separate. A CMMC-certified assessor cannot audit CPCSC compliance, and vice versa. If you need both, you hire two different assessors.

Cross-Border Suppliers: You Need Both

If You Do Business in Both Canada and the US

You need both CPCSC and CMMC certification. They do not substitute for each other. Here is why:

Scenario: Your company is a Canadian defence technology vendor. You supply software to both Canadian DND and US DoD.

  • DND requires CPCSC Level 1 certification (starting April 2026)
  • DoD requires CMMC Level 1 certification (already mandatory since April 2024)
  • You cannot use CPCSC certification to satisfy DoD requirements
  • You cannot use CMMC certification to satisfy DND requirements

You must maintain both certifications simultaneously.

Good news: The core controls overlap significantly (both are based on NIST 800-171). If you implement controls for CMMC, many will also satisfy CPCSC. But you still need separate assessments and certifications for each.

Solymus can help: We support CPCSC now (Level 1 free, Level 2/3 paid). CMMC support is on our Level 3 roadmap. Using a single platform for both frameworks reduces duplicate evidence collection.

Which Should You Prioritize?

If you only work in Canada: Focus on CPCSC. Level 1 is mandatory by April 2026 (12 months from now). Start your gap assessment immediately.

If you only work in the US: CMMC Level 1 is already mandatory (since April 2024). If you haven't certified yet, you are late. Hire a CMMC-AB assessor immediately.

If you work in both countries: Prioritize whichever has the nearest deadline. If you are a Canadian company working with US DoD, you may already have CMMC Level 1 requirements. If you are also starting Canadian defence contracts, add CPCSC to your roadmap for 2026. Focus on implementing shared controls that satisfy both frameworks.

Next Steps

Regardless of which framework applies to you, start now:

  1. Identify which frameworks apply to your company — Do you have Canadian DND contracts? US DoD contracts? Both?
  2. Determine the mandatory timeline — When is Level 1 required for your jurisdiction?
  3. Assess your current state — Which controls do you already meet? Which need work?
  4. Create an implementation plan — Prioritize controls, assign owners, set timelines.
  5. Use Solymus to manage evidence — Collect evidence, generate compliance packages, prepare for assessments.

Ready to Prepare for CPCSC?

Start free with Solymus Level 1 today. Build your evidence chain and get audit-ready for Canadian defence contracts.