CMMC Becomes Law: What Canadian Defence Suppliers Need to Do First
CYBER DEFENCE

BY ARNOLD VILLENEUVE
On 10 November 2025, the U.S. Department of Defense made the Cybersecurity Maturity Model Certification (CMMC) a binding condition of award. For Canadian primes and sub-tier suppliers in the U.S. defence supply chain, the immediate priority is Phase One: self-assessment and reporting to SPRS.
CMMC 2.0 sets three levels of assurance. Level 1 covers basic safeguarding of Federal Contract Information. Level 2, the centre of gravity for most Canadian firms, applies whenever you handle Controlled Unclassified Information and maps to the 110 practices in NIST SP 800‑171. Level 3 adds selected NIST SP 800‑172 controls for the most sensitive programs.
READ: CPCSC Level 1: What suppliers actually need to secure – and how to prove it
The change is sweeping but straightforward: solicitations now embed the required level, contracting officers will check status before award, and requirements flow down to subcontractors. If your shop touches FCI or CUI for a U.S. program—whether you are machining parts in Quebec, building software in Ontario, or providing engineering support in Alberta—you need a live, defensible CMMC posture to compete.
“Without demonstrable cyber controls, you will not compete.”
PHASE ONE: SELF-ASSESSMENT AND SPRS REPORTING
Phase One is live. For Level 1 and, in many cases, Level 2, the DoD accepts a contractor self‑assessment recorded in the Supplier Performance Risk System (SPRS) and backed by an annual executive affirmation. Start by scoping: identify where FCI and CUI reside, who can access them, and which systems process them. Then compare your environment against the required controls, record objective evidence, and calculate your score.
For Level 1, confirm the fifteen basic requirements and submit your attestation in SPRS. For Level 2, measure every NIST 800‑171 requirement, produce a System Security Plan that defines your CUI boundary, and document any gaps in Plans of Action and Milestones. Some controls—such as multi‑factor authentication, encryption of data at rest and in transit, and robust logging—are considered non‑deferrable. Treat them as immediate work.
Make SPRS accuracy a leadership issue. Contracting teams will review the record before award, and primes may request proof during teaming. Keep artefacts current: policies, procedures, configuration baselines, training records, and screenshots or system outputs that substantiate each control. If your CUI is limited, consider a segmented enclave so you can harden a smaller footprint quickly.
“Treat SPRS as your passport to the U.S. defence market.”
CANADA’S PARALLEL TRACK
Ottawa is standing up the Canadian Program for Cyber Security Certification to protect sensitive unclassified information in domestic procurements. While there is no formal reciprocity yet, aligning to CMMC Level 1 or Level 2 now positions Canadian suppliers for CPCSC and keeps cross‑border opportunities open as enforcement tightens.
FIVE PHASES AT-A-GLANCE:
| Phase | Dates | DoD requires | What Canadian contractors should do |
| 1 | Nov 2025–Nov 2026 | Self‑assessment for Level 1 and many Level 2; SPRS score and executive affirmation | Scope CUI, complete assessment, file in SPRS, stand up a hardened enclave |
| 2 | Nov 2026–Nov 2027 | Third‑party certification expands for Level 2 | Book a C3PAO; close POA&Ms; build audit evidence |
| 3 | Nov 2027–Nov 2028 | Level 3 appears on select programmes; government‑led audits | Pursue only if required; strengthen monitoring and insider‑threat controls |
| 4 | From Nov 2028 | CMMC in nearly all new DoD contracts | Maintain compliance; verify subcontractor status and flow‑down clauses |
| 5 | Ongoing | — | Operate, measure, improve; prepare for re‑certification every three years |
The message for 2026 is pragmatic: Phase One tasks are manageable if you start now. Inventory systems that handle FCI and CUI, fix the non-deferrable controls, calculate and post your SPRS score, and assign a senior official to affirm compliance annually. Use any conditional Level 2 status wisely to compete while you finish remediation. When Phase Two lands, early movers will certify first—and win now.
REFERENCES
- Defense Federal Acquisition Regulation Supplement (DFARS) final rule implementing CMMC, 10 Nov 2025.
- DoD guidance on CMMC 2.0 levels and assessment approaches, 2025.
- DFARS 252.204‑7019, 252.204‑7020, and 252.204‑7021 clauses (NIST SP 800‑171 assessments and CMMC), 2025.
- Supplier Performance Risk System (SPRS) — assessment and affirmation requirements, 2025.
- Industry legal analyses summarizing CMMC rollout phases and contractor obligations, late 2025.
- Government of Canada announcements on the Canadian Program for Cyber Security Certification (CPCSC), 2025.
Arnold Villeneuve is Director of Achieva Tech Incorporated. For more information, visit, www.achievatech.com. The views expressed here are his own and do not necessarily represent a CDR editorial position.

