Early Bird 2026

Level 1 is free for a limited time. Lock in Level 2/3 at C$5,000/mo before December 31, 2026. Days left: calculating...

Patent-Pending Technology

The Only Hardware-Safe
Compliance Infrastructure
for CPCSC & CMMC

Legacy compliance platforms cause FIPS 140-3 hardware rate-limit exhaustion under multi-framework load. Our patent-pending O(1) compression technology reduces N×M signing operations to exactly one—securing your defence supply chain without server paralysis.

FIPS 140-3 HSM Native Zero-Trust Verification CPCSC Level 1 Free
Request Enterprise Access For Prime Contractors — Merkle root normalization across your supply chain
Start Compliance Free For Suppliers — 1-click cryptographic receipts. Level 1 free for a limited time.
Patent-Pending O(1) compression
ITSP.10.171 + NIST 800-171 native
Data sovereignty in Canada
FIPS 140-3 hardware-rooted signing
Automated Cryptographic Reconstruction Trigger

Live Verification Demo

See how any third party can independently verify a compliance artifact without login, without trust, and without network access to our platform.

Simulates ACRT verification of a CPCSC compliance artifact

Zero Trust. No Login Required. Mathematics is the only auditor.

Product Tour

See Solymus in 3 Minutes

From sign-up to cryptographic evidence exports — everything you need to know about the CPCSC Readiness Platform.

3:16 · Covers sign-up, evidence upload, verification, CPCSC assessment, exports & plan tiers

CPCSC is mandatory for DND suppliers starting April 2026.
The question isn't if—it's are you ready?

Your CPCSC assessment is in 90 days.

The assessor needs evidence mapped to ITSP.10.171 controls. Your team is still collecting spreadsheets and screenshots from three departments.

With Solymus, you export a complete evidence package with per-artifact verification links—mapped to CPCSC controls.

DND asks for proof of Level 1 readiness.

Your contract renewal depends on demonstrating basic cyber hygiene. You need to show which controls are met and which have gaps—with evidence, not promises.

With Solymus, your readiness dashboard shows coverage by control family, and every artifact has a cryptographic receipt.

A prime contractor audits your compliance posture.

They need to verify your evidence is authentic and hasn't been modified since submission. Trust isn't enough—they need proof.

With Solymus, every piece of evidence is tamper-evident. Assessors verify independently, no login required.

Your compliance team shouldn't spend weeks assembling binders. Solymus replaces fragile paper trails with signed, verifiable evidence your CPCSC assessors can check themselves.

Four Steps to CPCSC Readiness

Solymus is a CPCSC Readiness Platform built on cryptographic receipts. Organize evidence, track gaps, prove integrity, and be assessment-ready.

Step 1

Organize Your Evidence

Upload policies, configurations, audit logs, and screenshots. Solymus maps each artifact to CPCSC controls based on ITSP.10.171, organized by control family.

Evidence mapped to controls automatically.

Step 2

Track Your Readiness

Real-time dashboard shows which controls are met, which have gaps, and what remediation is needed. Filter by control family to prioritize your work.

Gaps identified, remediation tracked.

Step 3

Prove It's Trustworthy

Every artifact gets a SHA-256 hash signed with AWS KMS (ECDSA P-256). Records link into a daily Merkle chain. Tamper-evident by design—retroactive changes break the chain.

Cryptographic proof, not screenshots.

Step 4

Be Assessment-Ready

Export evidence packages with a verification URL for every artifact. Assessors verify independently—no login, no trust in Solymus required.

Assessors click, verify, done.

How CPCSC Readiness Works

From evidence upload to assessment-ready export. Here's the step-by-step workflow for Canadian defence suppliers.

CPCSC Evidence & Readiness Tracking

For Canadian defence suppliers, subcontractors, consultants, and MSPs
  1. Upload artifacts via dashboard or API Drag-drop policies, screenshots, audit logs, and scan reports. Or use presigned S3 URLs for programmatic upload.
  2. Artifacts auto-map to CPCSC controls (ITSP.10.171) A policy document maps to AC-1, SC-1, PL-1. An audit log maps to AU-2, AU-3, AU-6. You can override with manual tags for exact mapping.
  3. Each artifact gets hashed and KMS-signed SHA-256 hash of the file content, signed with AWS KMS (ECDSA P-256). The key never leaves the HSM. Record links into the daily shard chain.
  4. Track readiness across CPCSC controls Dashboard shows which controls are met, partial, or missing evidence. Filter by control family (AC, AU, IA, SC) to find gaps and prioritize remediation.
  5. Export assessment-ready packages with verification URLs Generate an Evidence Index or CPCSC Readiness report. Every artifact entry includes a public verification link your assessor can click.
Your assessor clicks the verification URL from the export, sees "Signature Valid, Merkle Linked"—no login, no trust in Solymus required.
Upload Hash Sign Chain Verify

Set Up in 15 Minutes. Export Auditor-Ready Packages.

1

Create Account

Sign up and create a workspace. Choose your CPCSC level (Level 1 or Level 2).

2

Upload Evidence

Upload policies, configurations, audit logs, and scan reports. Drag-drop or use the API.

3

Map to CPCSC Controls

Artifacts auto-map to ITSP.10.171 controls. Override with manual tags for exact mapping.

4

Every Record Gets Signed

SHA-256 hash signed with AWS KMS (ECDSA P-256). Keys never leave the HSM. Evidence linked to daily Merkle chain.

5

Export for Assessment

Evidence index grouped by CPCSC control, with a verification URL for every artifact. Assessors verify from the export—no login required.

Why Canadian Defence Suppliers Choose Solymus

Built for defence suppliers, subcontractors, compliance consultants, and MSPs preparing for CPCSC assessment.

Cryptographic Proof, Not Screenshots

Every artifact gets a KMS-signed receipt with SHA-256 hash. Evidence integrity is mathematical, not organizational.

Assessors Verify Independently

Public verification API lets CPCSC assessors, primes, and auditors check any receipt themselves. No login required—verification is cryptographic, not trust-based.

Tamper-Evident by Design

Daily Merkle chain linking means retroactive changes break the chain. Gaps and modifications are automatically detectable.

Self-Contained Export Bundles

Evidence packages include the receipt, signature, Merkle proof, daily root, and public key needed for offline verification. Bundles remain verifiable independently.

CPCSC-Focused, CMMC on Roadmap

Primary focus on CPCSC and ITSP.10.171. CMMC support is on our roadmap for Canadian suppliers with cross-border U.S. defence contracts.

Built for Your Team

Whether you're a defence supplier, subcontractor, compliance consultant, or MSP—Solymus organizes evidence the way assessors expect to see it.

Verify Without Trusting Us

Your assessors, primes, and auditors can check any receipt independently. No login required.

Verify a Receipt

Enter an event ID from any export or verification link.

What Gets Signed

SHA-256 hash + AWS KMS ECDSA P-256. Keys never leave HSM.

Who Can Verify

Third parties verify receipts via export links. Evidence bundles work offline.

What You Export

Evidence packages grouped by control, with verification URLs.

CPCSC Readiness Plans

Aligned to your CPCSC certification level. Level 1 is free for a limited time. All prices in CAD.

Early bird pricing (Level 2 & Level 3 at C$5,000/mo) expires December 31, 2026. After that, standard pricing applies to all new contracts.
Early Bird — Ends Dec 31
CPCSC Level 2
Early Bird C$5,000 Standard C$10,000/mo Save C$5,000/mo — 50% off
per month · annual contract
97 controls · Level 2 + CMMC Cross-Walk
  • Everything in Level 1
  • 100,000 events/month · 365-day retention
  • Full export suite (SSP + POA&M + Assessor Package)
  • Supply chain compliance reports
  • CMMC 2.0 cross-walk · Supply chain verification
  • 10 seats · 3 workspaces · Certificates of Truth
  • Connectors: M365, AWS (Beta)
  • Roadmap (included): ISO 42001 · CGP · Law 25 · ISO 27001 · SOC 2
Lock In Early Bird →
Early Bird — Same as Level 2
CPCSC Level 3
Early Bird C$5,000 Standard C$30,000/mo Save C$25,000/mo — 83% off
per month · 24-month contract
High-security contractors · full enforcement
  • Everything in Level 2
  • 1,000,000+ events/month · Unlimited retention
  • Level 3 advanced controls
  • Third-party assessor portal
  • Continuous monitoring dashboard + board reports
  • Unlimited seats + workspaces · CloudTrail Receipts
  • CMMC 2.0 cross-mapping · DFARS · SSO/SAML
  • Roadmap: GovCloud · GCC High · FedRAMP · NATO STANAG 4774
Contact Sales →

An event is a single evidence record (one artifact upload or API ingest call). Level 1 retention is 365 days during 2026 (reverts to 7 days after promo). Early bird requires annual contract signed before December 31, 2026—billing may be deferred to January 2027. All prices in Canadian dollars (CAD). Early bird customers keep their rate for the contract term.

Frequently Asked Questions

CPCSC (Canadian Program for Cyber Security Certification) is Canada's mandatory cybersecurity certification for Department of National Defence (DND) suppliers, taking effect April 2026. It is based on ITSP.10.171, Canada's adaptation of NIST SP 800-171 Rev 3. Solymus helps you organize evidence and prove readiness before your assessment.

No. Solymus is a CPCSC-focused readiness platform that helps you organize, track, and export assessment-ready evidence. Certification is determined by your CPCSC assessor. We give you the evidence trail; you own the compliance outcome.

Yes. Export packages include the receipt, cryptographic signature, Merkle proof, daily root, and verification instructions. Your assessor verifies mathematically without calling any Solymus API. Bundles work offline.

CMMC support is on our roadmap for Canadian suppliers with cross-border U.S. defence contracts. Our primary focus is CPCSC and ITSP.10.171. Since CPCSC and CMMC share roots in NIST 800-171, evidence organized for CPCSC will also support future CMMC readiness.

Today you upload evidence manually, via API, or via the Python SDK. Connectors are in development:

  • LIVE REST API & Python SDK
  • PLANNED M365 GCC High connector
  • PLANNED AWS GovCloud connector
  • PLANNED Endpoint agent (Windows/Linux)

We'll announce connectors when they're production-ready.

Export bundles are self-contained. They include everything needed to verify the cryptographic signatures offline. No Solymus API, account, or infrastructure required.

Early Bird Window Closes December 31, 2026

Level 1 Is Free. Start Now. Lock In Level 2 Before the Price Changes.

April 2027 is when Level 2 becomes mandatory and standard pricing kicks in—C$10,000/mo. Companies already on Solymus with 12 months of evidence history will sail through their assessment. Companies starting fresh won't.

Solymus provides tamper-evident evidence infrastructure that supports your CPCSC readiness program. Certification outcomes depend on your assessor's evaluation. See our Terms of Service for details.