Cyber Defence – CPCSC Level 1
BY ARNOLD VILLENEUVE

The launch of the Canadian Program for Cyber Security Certification (CPCSC) marks a major shift in how Canada intends to secure its defence industrial base. While much of the public discussion has focused on the strategic importance of the program, the real question for defence suppliers is far more practical: How does it work?
Level 1 is the entry point to the CPCSC framework. It is designed to establish a baseline of cybersecurity hygiene across Canada’s defence supply chain through a structured annual self-assessment process conducted by the supplier organization.
Understanding the assessment methodology behind Level 1 is critical because this process will soon become a requirement for many companies seeking to participate in Canadian defence procurement.
THE PURPOSE OF LEVEL 1 ASSESSMENT
The CPCSC Level 1 assessment is not intended to be a complex certification exercise. Instead, it focuses on confirming that an organization has implemented the fundamental cybersecurity practices necessary to protect sensitive government information.
The assessment is specifically designed to verify that an organization’s security controls and procedures are functioning effectively and that known cyber risks are being actively managed.
READ: CMMC Becomes Law: What Canadian Defence Suppliers Need to Do First
During the assessment process, organizations are expected to identify and evaluate several key elements of their cybersecurity posture, including: • gaps in existing security controls; • weaknesses in systems or infrastructure; • areas where cybersecurity risks need to be prioritized; • whether known vulnerabilities have been addressed.
In other words, Level 1 functions primarily as a structured risk-identification exercise combined with a formal declaration that the organization’s cybersecurity practices meet the government’s baseline expectations.
SELF-ASSESSMENT MODEL
Unlike the higher CPCSC certification levels, Level 1 does not require an external auditor. Instead, organizations perform the assessment internally and submit a formal self-attestation confirming that they meet the Level 1 cybersecurity requirements.
This self-assessment model serves several important purposes: • Lower barrier to entry for small and medium-sized suppliers; • Rapid scalability across Canada’s large defence supply chain; and • Early identification of cyber weaknesses before they become contractual risks.
Organizations will typically conduct this assessment annually as part of their ongoing cybersecurity governance program.
SECURITY CONTROL ASSESSMENT METHODS
Although Level 1 is a self-assessment, it still relies on a structured evaluation methodology. The Level 1 criteria are derived from the Canadian adaptation of NIST SP 800-171A Rev. 3, which defines standardized methods for assessing security requirements that protect sensitive government information.
These assessment methods generally follow three core evaluation techniques commonly used in security control assessments – Examine, Interview and Test.
Examine: The assessor reviews documentation and artifacts to determine whether required security practices exist. Examples include: • security policies; • system configuration standards; • incident response procedures; • access control documentation. This step determines whether the organization has formally defined the security practices required to protect sensitive information.
Interview: The assessment process may also involve discussions with personnel responsible for implementing or operating cybersecurity controls. Typical interview targets include: • system administrators; • security officers; • IT managers; • operational staff responsible for system security. The objective is to confirm that documented policies are actually understood and followed within the organization.
Test: Where appropriate, the assessment may involve technical verification of security controls. Examples may include: • verifying access restrictions on systems; • confirming that vulnerability management processes are functioning; • validating system configuration settings. Testing helps confirm that security controls are not only documented but also operationally effective.
RISK-BASED ASSESSMENT EFFORT
Another important element of the Level 1 methodology is that the depth of the assessment effort is determined by the security risk profile of the system being evaluated. The Government of Canada uses a security assurance model that classifies systems according to a Security Assurance Level (SAL) ranging from SAL-1 to SAL-5.
The higher the assurance level, the greater the level of scrutiny required during the assessment process. This risk-based approach ensures that assessment effort remains proportionate to the sensitivity of the information and systems involved.
SUBMITTING THE CERTIFICATION ATTESTATION
Once the organization completes the Level 1 assessment, the final step is formal self-attestation. The company must confirm that the required cybersecurity practices have been assessed and implemented and submit this declaration through its CanadaBuys supplier profile.
Under the current CPCSC rollout schedule, this self-attestation will typically be required at the time a defence contract is awarded, rather than during the initial bidding process.
WHY ASSESSMENT MATTERS
From a strategic perspective, the Level 1 assessment process is designed to accomplish two things simultaneously. First, it raises the baseline cybersecurity posture of Canada’s defence supply chain. Second, it introduces a standardized assessment methodology that can scale into more rigorous certification models at higher CPCSC levels.
For many Canadian defence suppliers, the Level 1 assessment will be the first time cybersecurity practices are formally documented, reviewed and validated against a government standard. That process alone will significantly improve visibility into cyber risk across the defence industrial ecosystem.
For more information on CPCSC visit: https://tinyurl.com/CDR-CPCSC
Arnold Villeneuve is Director of Achieva Tech Incorporated. For more information, visit, www.achievatech.com. The views expressed here are his own and do not necessarily reflect a CDR editorial position.

