CPCSC is the Canadian Program for Cyber Security Certification—a mandatory compliance requirement for DND defence suppliers. Learn what it is, why it exists, and how to prepare.
No credit card required. 365-day evidence retention during 2026.
CPCSC stands for the Canadian Program for Cyber Security Certification. It is a three-tiered compliance certification framework designed by the Canadian Department of National Defence (DND) to protect "Controlled Information" within the Canadian defence supply chain. CPCSC is based on ITSP.10.171, Canada's adaptation of the NIST SP 800-171 Rev 3 security controls.
In simple terms: CPCSC is how the Canadian government ensures that companies handling sensitive defence data meet minimum cyber security standards. If you are a defence supplier working with DND contracts, CPCSC is mandatory.
The Canadian defence supply chain includes hundreds of prime contractors and thousands of subcontractors. Many handle "Controlled Information"—defence technical data, procurement plans, contract terms, security postures, and other information critical to Canada's military capability. If this information is compromised, stolen, or altered, it puts Canada's defence at risk.
CPCSC was created to:
Without CPCSC, every defence prime would have to conduct its own security assessment of every supplier—a fragmented, expensive process with zero consistency. CPCSC centralises this compliance requirement.
CPCSC has three certification levels. Each level requires progressively more controls, more rigorous assessment, and higher security maturity.
13 core controls across 6 families. You assess yourself. Mandatory at contract award starting April 2026.
Cost: Free on Solymus
97 full ITSP.10.171 controls. Certified by Standards Council of Canada (SCC) assessors. Required April 2027.
Cost: C$10K–15K/year
97 controls + 6 maturity domains. For highest-security contracts. Includes continuous monitoring.
Cost: C$10K–30K/year
CPCSC is not a separate framework—it is a certification program built on top of ITSP.10.171.
Think of it this way:
Standard published. Level 1 guidance available. Suppliers begin planning.
Level 1 is now mandatory. All DND defence primes must verify that all contractors have a Level 1 self-assessment. Level 2 assessor training begins.
Level 2 third-party certification required. Level 3 in high-sensitivity contracts. Early assessments begin.
CPCSC applies to anyone in the Canadian defence supply chain:
If your company has a DND contract or is on a defence prime's supplier list, CPCSC applies to you.
DND defence primes cannot award contracts to suppliers without Level 1 CPCSC certification (as of April 2026). Without certification, you lose the contract. Without the contract, your business is at risk.
This creates a compliance cascade:
There is no way around CPCSC if you work in the Canadian defence supply chain.
Preparing for CPCSC involves three steps:
Solymus automates this entire process. You upload evidence, Solymus maps it to controls, generates cryptographic receipts, and exports a compliance package ready for assessors.
If you are a Canadian defence supplier, here is what you should do now:
Start free with Solymus Level 1 today. Build your evidence chain and prepare for certification.
Everything you need to know about CPCSC compliance