CMMC 2.0

Achieving CMMC Level 1 Certification, A Stepping Stone for Canadian Defence Contractors

BY ARNOLD VILLENEUVE

Soldiers working on computer cybersecurity, Countdown to CMMC 2.0

As the global defence industry becomes increasingly interconnected, Canadian companies are seizing new opportunities to collaborate with U.S. Department of Defense (DoD) contractors. This cross-border cooperation opens doors to lucrative contracts and partnerships but also introduces stringent cybersecurity requirements designed to protect sensitive information. One such requirement is the Cybersecurity Maturity Model Certification (CMMC) Level 1, a foundational cybersecurity standard mandated by the U.S. DoD for all contractors and subcontractors handling Federal Contract Information (FCI).

For Canadian defence contractors, achieving CMMC Level 1 certification is not merely a bureaucratic hurdle but a strategic move that enhances their competitiveness in the defence sector. It not only enables participation in U.S. defence contracts but also serves as a crucial stepping stone toward complying with the forthcoming Canadian Program for Cyber Security Certification (CPCSC) Level 1. This alignment presents a unique opportunity for Canadian companies to streamline their cybersecurity efforts and position themselves advantageously in both markets.

CMMC LEVEL 1 OVERVIEW

The Cybersecurity Maturity Model Certification (CMMC) is a unified cybersecurity standard developed by the U.S. DoD to enhance the protection of sensitive information within the Defense Industrial Base (DIB). Recognizing the escalating cyber threats targeting defence contractors, the DoD introduced CMMC Version 2.0, which streamlines the model into three levels of cybersecurity maturity. Level 1 focuses on basic cybersecurity hygiene practices essential for protecting FCI.

FCI (Federal Contract Information) is defined as information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. The equivalent of FCI in Canada is detailed under the Canadian Procurement Guidelines and Standards. Effectively, it is government contract information which is not supposed to be shared with the public. 

CMMC Level 1 encompasses 17 foundational cybersecurity practices across six domains:

  1. Access Control (AC)
  2. Identification and Authentication (IA)
  3. Media Protection (MP)
  4. Physical Protection (PE)
  5. System and Communications Protection (SC)
  6. System and Information Integrity (SI)

The practices are designed to establish a baseline of cybersecurity measures that any organization handling FCI should implement. These controls must be met across any system, person, or process who handles FCI at all times, or what is referred to as being “within the assessment scope”.

The 17 basic safeguarding rules have been in place since at least May 2016 for all federal contracts as the FAR 52 (48 CFR § 52.204-21).  These are for all US Federal contracts and must flow down into any subcontracts (ie: Canadian DIBs), not just US DoD contracts.  Thanks to the Christian Doctrine, it must be followed in any contract or subcontract serving the US Federal government even if it’s not explicitly stated as a “deeply ingrained strand of public procurement”,

Unlike higher levels of CMMC, which require third-party assessments, Level 1 allows companies to conduct an annual self-assessment. A senior company official must affirm compliance with the required practices, making the certification process more accessible for small to medium-sized enterprises.

Graph, CMMC Model Structure

THE CANADIAN CONTEXT: CPCSC LEVEL 1

In parallel with the U.S. efforts, the Canadian government is developing the Canadian Program for Cyber Security Certification (CPCSC) to safeguard federal contractual information within Canada’s defence sector. The CPCSC aims to enhance the cybersecurity posture of Canadian defence contractors by establishing standards like those of the CMMC security framework.

While the CPCSC is still under development, it is anticipated to align closely with the CMMC standards, especially at Level 1. This alignment means that efforts invested in achieving CMMC Level 1 certification can directly benefit Canadian companies when the CPCSC requirements come into effect. By proactively addressing these cybersecurity standards, companies can ensure compliance with both U.S. and Canadian regulations, thereby expanding their market opportunities.

WHY PURSUE CMMC LEVEL 1?

Access to U.S. Defence Contracts: The primary motivation for Canadian defence contractors to pursue CMMC Level 1 certification lies in the access it provides to U.S. defence contracts involving FCI. The U.S. DoD mandates that all contractors and subcontractors handling FCI comply with CMMC Level 1 requirements. Without this certification, Canadian companies may find themselves excluded from valuable opportunities in the U.S. defence market.

Competitive Advantage: Beyond regulatory compliance, achieving CMMC Level 1 certification demonstrates a company’s commitment to cybersecurity, enhancing its reputation among partners and clients. It signals to prime contractors and government agencies that the company takes the protection of sensitive information seriously, which can be a differentiating factor in competitive bidding processes.

Foundation for CPCSC Compliance: By aligning with CMMC Level 1 now, Canadian companies position themselves favorably for swift compliance with CPCSC Level 1 once it is fully implemented. This proactive approach allows companies to spread out the effort and investment required for compliance, avoiding a last-minute scramble when CPCSC becomes mandatory.

CHALLENGES FOR CDN COMPANIES

Implementing CMMC Level 1 practices presents several challenges for Canadian companies, particularly given the diversity in company sizes and existing cybersecurity postures. The Canadian Defence Industrial Base comprises approximately 900 contractor companies, ranging from small enterprises with just a few employees to large corporations with thousands of employees located in different locations.

Resource Constraints: For smaller companies, resource constraints may make it difficult to allocate personnel and budget toward cybersecurity initiatives. They may lack dedicated IT staff or have minimal cybersecurity measures in place.

Complexity of Implementation: Larger companies, while potentially having more resources, may face complexity due to the scale of their operations and the need to coordinate efforts across multiple departments and locations.

Regulatory Alignment: Navigating the regulatory landscape of both the U.S. and Canada requires companies to ensure that their cybersecurity practices meet the requirements of CMMC while also aligning with Canadian laws and regulations. This dual compliance necessitates a thorough understanding of both sets of standards and careful planning to avoid conflicts or gaps.

PREPARING FOR CMMC

Achieving CMMC Level 1 certification within a three-month timeframe is an ambitious but attainable goal. It requires a structured approach that addresses each of the 17 security control practices in depth, ensuring that all assessment objectives are met and documented.

Month 1: Initiation and Assessment

The journey begins with establishing a CMMC compliance team composed of key stakeholders from various departments, including IT, human resources, legal, and senior management. This team is responsible for driving the certification process, assigning tasks, and ensuring that all requirements are addressed.

Conducting a Gap Analysis

Conducting a comprehensive gap analysis is the next critical step. This involves reviewing current cybersecurity practices against the CMMC Level 1 requirements to identify areas of compliance and those needing improvement. The gap analysis provides a roadmap for the implementation phase, highlighting where efforts should be concentrated.

Developing a Project Plan

Developing a detailed project plan is essential for keeping the certification process on track. The plan should outline specific tasks, deadlines, responsible parties, and resource allocations. Establishing clear communication channels and reporting mechanisms ensures that everyone involved stays informed and accountable.

Month 2: Implementation

Policy and Procedure Development

With the groundwork laid, the second month focuses on implementing the necessary policies, procedures, and technical controls. Developing a System Security Plan (SSP) is a foundational task, documenting the organization’s IT environment, security controls, and how they address the CMMC requirements.

Policies and procedures need to be crafted or updated to reflect the new cybersecurity practices. This includes policies for access control, physical security, media protection, and more. These documents serve as the official guidelines for how the organization manages and protects FCI.

Technical Controls Implementation

Implementing technical controls involves configuring systems and networks to enforce the established policies. For example, access controls must be set to ensure that only authorized users can access certain systems or data. This can be accomplished with firewalls and intrusion detection systems to monitor and protect communication at external and key internal boundaries and with appropriate access control for authorized users, processes, devices, transactions and functions.

Month 3: Validation and Certification

Employee Training and Awareness

In the final month, the focus shifts to validating the implemented controls and preparing for certification. Employee training and awareness programs are conducted to ensure that all staff members understand their roles and responsibilities in maintaining cybersecurity.

Self-Assessment

A thorough self-assessment is performed, reviewing each security control practice against the assessment objectives outlined in NIST SP 800-171A. This step is crucial for identifying any remaining gaps or weaknesses that need to be addressed before certification.

Management Attestation

Finally, a senior company official must affirm the organization’s compliance with the CMMC Level 1 practices. This attestation is a formal declaration that the organization meets the necessary requirements and is committed to maintaining them.

Summary Table of Security Control Practices

 

DomainPracticeDescription
Access Control (AC)AC.L1-3.1.1Limit system access to authorized users and devices.
AC.L1-3.1.2Limit system access to authorized transactions and functions.
 AC.L1-3.1.20Verify and control/limit connections to and use of external information systems.
 AC.L1-3.1.22Control information posted or processed on publicly accessible information systems
Identification and Authentication (IA)IA.L1-3.5.1Identify users and devices accessing the system.
IA.L1-3.5.2Authenticate identities before granting system access.
Media Protection (MP)MP.L1-3.8.3Sanitize or destroy media containing FCI before disposal or reuse.
Physical Protection (PE)PE.L1-3.10.1Limit physical access to systems and equipment to authorized individuals.
 PE.L1-3.10.3Escort visitors and monitor visitor activity.
 PE.L1-3.10.4Maintain audit logs of physical access.
 PE.L1-3.10.5Control and manage physical access devices.
System and Communications Protection (SC)SC.L1-3.13.1Monitor and protect communications at system boundaries.
 SC.L1-3.13.5Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
System and Information Integrity (SI)SI.L1-3.14.1Identify and correct system flaws in a timely manner.
SI.L1-3.14.1Provide protection from malicious code within information systems.
SI.L1-3.14.2Update malicious code protection mechanisms when new releases are available.
 SI.L1-3.14.5Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

Leveraging CMMC Level 1 for CPCSC Level 1 Compliance

Given the anticipated alignment between CMMC Level 1 and CPCSC Level 1, Canadian companies can leverage their efforts in achieving CMMC certification to streamline compliance with CPCSC. Both programs share the objective of protecting unclassified federal contractual information, and many of the security practices and assessment objectives overlap.

By documenting the implementation of CMMC Level 1 practices thoroughly, organizations can create a repository of evidence and procedures that can be adapted or directly applied to meet CPCSC requirements. This approach not only saves time and resources but also ensures a consistent cybersecurity posture across both U.S. and Canadian contracts.

CONCLUSION

Achieving CMMC Level 1 certification is a strategic imperative for Canadian defence contractors aiming to expand their participation in U.S. defence contracts and prepare for future CPCSC requirements. The process demands commitment and diligence but offers significant rewards in terms of market access, competitive advantage, and enhanced cybersecurity resilience.

By adopting a structured approach that addresses each security control practice in depth and utilizing visual aids such as tables and charts for clarity, organizations can navigate the complexities of the certification process effectively. The investment made in strengthening cybersecurity not only satisfies regulatory demands but also protects the organization from the growing threats in the digital landscape.

As the defence industry continues to evolve, companies that prioritize cybersecurity will be better positioned to seize opportunities and build trust with partners and clients. CMMC Level 1 certification is not just a compliance checkbox—it’s a foundational step toward a more secure and prosperous future in the defence sector.

READ MORE: Cybersecurity Report on Volume 30 Issue 5.

About the Author

Arnold Villeneuve portrait

Arnold Villeneuve is a cybersecurity expert with extensive experience in helping organizations achieve compliance with international cybersecurity standards. Specializing in defence sector requirements, he was the first Canadian to achieve US DoD CMMC certification as a Provisional Assessor and Instructor. Arnold has assisted numerous companies in navigating the complexities of CMMC and CPCSC certifications. Arnold is dedicated to empowering companies to strengthen their cybersecurity posture and succeed in the global defence marketplace.

About the Technical EditorKristina Nairn is an American working in cybersecurity for nearly 30 years.  She worked for the first commercial Internet Service Provider in the state of Minnesota.  Kristina has worked with US Government and private sector to improve the security posture of corporations and execute compliance assessments, and focuses on her children, her Great Danes and improving the ecosystem surrounding Internet security, in no order. 


READ: Cybersecurity Report: Where Canada’s Cyber Defences Stand Now