CPCSC Overview
BY ARNOLD VILLENEUVE

In an era where cyber threats are increasingly sophisticated and pervasive, safeguarding sensitive information within Canada’s defence sector has become paramount. Recognizing this imperative, the Government of Canada has initiated the Canadian Program for Cyber Security Certification (CPCSC), a strategic initiative aimed at bolstering the cyber resilience of defence suppliers. This column delves into the CPCSC, addressing the fundamental questions of who, what, where, when, and why, to provide a comprehensive overview for companies within the Canadian Defence Industrial Base engaged with the Department of National Defence (DND) and the Canadian Armed Forces (CAF).
WHO IS INVOLVED
The CPCSC is a collaborative effort spearheaded by Public Services and Procurement Canada (PSPC), in partnership with DND and the Standards Council of Canada. The program primarily targets suppliers and contractors within the Canadian defence sector who handle sensitive unclassified government information. These entities are integral to Canada’s defence supply chain and play a crucial role in maintaining national security. By participating in the CPCSC, these organizations commit to adhering to stringent cyber security standards, thereby enhancing the overall resilience of Canada’s defence infrastructure.
WHAT IS CPCSC
The CPCSC is a structured framework designed to establish and enforce cyber security standards among defence suppliers. Its primary objective is to protect federal contractual information held below the classified level on contractors’ systems, networks, and applications. The program introduces a tiered certification system comprising three levels: • Level 1: Requires an annual cyber security self-assessment by the supplier. • Level 2: Necessitates external cyber security assessments conducted by an accredited certification body. • Level 3: Involves comprehensive cyber security assessments conducted directly by National Defence.
This tiered approach allows organizations to progressively enhance their cyber security posture in alignment with the sensitivity of the information they handle and the complexity of their operations.
WHERE DOES IT APPLY
The CPCSC is applicable across Canada, encompassing all defence suppliers and contractors who engage with the Government of Canada on defence-related projects. It extends to any non-Government of Canada systems and organizations that process, store, or transmit controlled information. The program ensures that such information remains protected, regardless of its location, by mandating adherence to standardized security requirements.
WHEN WAS IT LAUNCHED
The CPCSC was officially launched on March 12, 2025, marking the commencement of its phased implementation: • Phase 1 (March 2025): Introduction of a new cyber security standard for Levels 1 and 2, availability of a Level 1 self-assessment tool, and initiation of the accreditation process for certification bodies. During this phase, certification is required at the time of contract award, not during the bidding process. • Phase 2 (Fall 2025): Implementation of Level 1 certification requirements through self-assessment for certain defence contracts, and pilot testing of Level 2 certification involving third-party assessments. • Phase 3 (Spring 2026): Mandatory Level 2 certification for select defence contracts, with Level 3 certification becoming accessible following the publication of additional controls. • Phase 4 (2027): Gradual incorporation of Level 3 certification requirements into a limited number of defence Requests for Proposals (RFPs), with assessments conducted by National Defence.
This structured rollout allows defence suppliers adequate time to understand, prepare for, and comply with the evolving cyber security standards.
WHY WAS CPCSC ESTABLISHED
The establishment of the CPCSC is driven by several critical factors: • Protection of Sensitive Information: With the defence industry facing regular cyberattacks targeting contractors and subcontractors, there is a pressing need to safeguard unclassified federal information from unauthorized access and potential breaches. • Alignment with International Standards: The program aims to harmonize Canada’s cyber security practices with international allies, facilitating mutual recognition and ensuring that Canadian suppliers remain eligible for global defence procurement opportunities. • Enhancement of National Security: By strengthening the cyber resilience of defence suppliers, the CPCSC contributes to the overall security and operational readiness of the CAF, ensuring that critical supply chains remain robust and reliable. • Economic Stability: Implementing robust cyber security measures is fundamental to Canada’s economic stability, as it protects businesses from the financial and reputational damages associated with cyber incidents.
The CPCSC represents a proactive and strategic initiative by the Government of Canada to fortify the nation’s defence supply chain against the ever-evolving landscape of cyber threats. For companies within the Canadian Defence Industrial Base, understanding and engaging with the CPCSC is not only a compliance requirement but also a commitment to upholding the highest standards of cyber security. As the program progresses through its phased implementation, defence suppliers are encouraged to stay informed, assess their current cyber security readiness, and take the necessary steps to achieve certification.
This collective effort will ensure that Canada’s defence sector remains secure, resilient, and prepared to face the challenges of the digital age.
Arnold Villeneuve is a CMMC Certified Professional, Registered Practitioner, Instructor, and Founder of AchievaTech. For more information, visit, www.achievatech.com. The views expressed here are his own and do not necessarily represent a CDR editorial position.

