Solymus maps your evidence to ITSP.10.171 controls, tracks your readiness, and produces tamper-evident records that auditors can independently verify.
The Canadian Program for Cyber Security Certification is mandatory for all DND suppliers.
Key dates for Canadian defence suppliers.
CPCSC officially launched by the Government of Canada. Framework published, assessor accreditation process begins.
Level 1 certification (self-assessment) required in DND contracts. Suppliers must demonstrate basic cyber hygiene controls.
Third-party CPCSC assessments begin for contracts requiring Level 2 certification. Independent assessors evaluate ITSP.10.171 compliance.
Government-led assessments for highest-sensitivity defence contracts. Full ITSP.10.171 compliance with additional requirements.
From evidence collection to assessment-ready exports.
Map your evidence to ITSP.10.171 controls across all 17 families. Auto-mapping by evidence type with manual override.
Upload policy documents, configurations, screenshots, and audit logs. Evidence organized by control family for assessment readiness.
Real-time visibility into your CPCSC readiness posture. Track coverage across control families and identify gaps at a glance.
Identify missing evidence and track remediation progress. Prioritize gaps by control family and assessment impact.
Every artifact hashed (SHA-256), signed (AWS KMS ECDSA P-256), and linked to a daily Merkle chain. Tampering is mathematically detectable.
Export evidence packages with verification URLs per artifact. Assessors verify signatures independently using standard cryptographic libraries.
What Solymus is and isn't.
Three tiers. All prices in Canadian dollars (CAD).
Common questions from Canadian defence suppliers.
CPCSC Level 1 requirements take effect in DND contracts starting April 2026.