CMMC 2.0 and CPPPP framework

The U.S. cyber certification model for defence, and a structuring read of the Canadian equivalent — for Quebec subcontractors navigating both markets.

CMMC is the U.S. cyber certification program for Department of Defense (DoD) subcontractors, based on NIST SP 800-171. CPCSC is the official Canadian equivalent for defence suppliers, based on ITSP.10.171. On this page, CPPPP is a three-level structuring read — it is not a standard published under that name by the Government of Canada.

What is CMMC?

CMMC (Cybersecurity Maturity Model Certification) is the cybersecurity certification program of the U.S. Department of Defense (DoD). It aims to ensure that U.S. defence subcontractors and suppliers adequately protect federal information received under their contracts.

The current version, CMMC 2.0, simplifies the original model into three levels aligned with recognized NIST references. The program defines Level 1 (Self), Level 2 (Self or C3PAO) and Level 3 (government assessment) evaluations. Since July 2026, Phase II has been suspended: contracts currently primarily require Level 1 (Self) or Level 2 (Self), while NIST SP 800-171 obligations remain in force.

Which key CMMC concepts should you know?

  • FCI (Federal Contract Information) — information generated or provided under a federal contract, not intended for public release.
  • CUI (Controlled Unclassified Information) — unclassified information subject to dissemination or handling controls.
  • NIST SP 800-171 — a set of 110 security requirements to protect the confidentiality of CUI in nonfederal systems.

What are the CMMC 2.0 levels?

The table below summarizes the three CMMC 2.0 levels, their primary purpose and the associated technical reference.

Program Level Primary purpose NIST reference / key standard
CMMC 2.0 Level 1 Foundational FCI protection, basic hygiene FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
CMMC 2.0 Level 2 Advanced CUI protection, advanced practices NIST SP 800-171 (revision 2) and assessment guide NIST SP 800-171A — 110 controls
CMMC 2.0 Level 3 Expert Enhanced protection for high-criticality programs Full NIST SP 800-171 plus a subset of NIST SP 800-172 (Enhanced Security Requirements)

How should you read the CMMC 2.0 levels?

Level 1 — Foundational

Intended for subcontractors that handle FCI only. Fifteen basic practices (passwords, anti-malware, physical access control) from FAR clause 52.204-21. Annual self-attestation assessment.

Level 2 — Advanced

The most common level for contracts involving CUI. Aligned with the 110 requirements of NIST SP 800-171 Rev. 2. In practice (2026), the usual contractual requirement is a Level 2 (Self) self-assessment; C3PAO assessment remains defined in the program, but Phase II — which was to impose it broadly — was suspended in July 2026.

Level 3 — Expert

Reserved for very high-sensitivity programs. Combines the full NIST SP 800-171 with enhanced NIST SP 800-172 requirements to counter advanced persistent threats (APT). The government assessment (DIBCAC) planned with Phase II has also been suspended since July 2026; check each contract's clauses.

What is the Canadian CPCSC and CPPPP framework?

The Canadian equivalent of CMMC is CPCSC, based on ITSP.10.171 (CSE/CCCS) — an adaptation of NIST SP 800-171 revision 3. The CPPPP framework offers a three-level structuring read, with an explicit link to the NIST references.

See the CPPPP, CPCSC and references page →

How do CMMC and CPPPP compare?

Both frameworks pursue the same goal — protecting sensitive information at subcontractors — but differ on authority, terminology and the underlying NIST reference version.

Element CMMC 2.0 (United States) CPPPP / CPCSC (Canada)
Authority Department of Defense (DoD) Public Services and Procurement Canada (PSPC)
Information in scope FCI (level 1) / CUI (levels 2–3) Specified information (SI) / Protected A and above
Technical reference NIST SP 800-171 Rev. 2 ITSP.10.171 (aligned with NIST 800-171 Rev. 3)
Accreditation body Cyber AB (C3PAO) Standards Council of Canada (SCC)
Level 1 15 FAR practices, self-attestation 13 ITSP.10.171 controls, self-assessment
Level 2 110 controls; self-assessment (Self) in force — C3PAO suspended (Phase II, Jul. 2026) 98 controls, accredited third-party audit (triennial)
Level 3 800-171 + 800-172; gov. assessment suspended (Phase II, Jul. 2026) 200 enhanced controls, DND assessment

For a Quebec SMB operating in both markets, the good news is that the technical requirements largely converge. A security program built on ITSP.10.171 (Rev. 3) positions the organization well for both frameworks, with targeted adjustments depending on the contract at hand.

Where can you find official resources?

Frequently asked questions

What is the difference between CMMC and CPCSC?
CMMC is the U.S. cyber certification program for Department of Defense (DoD) subcontractors, based on NIST SP 800-171. CPCSC is the official Canadian equivalent for defence suppliers, based on ITSP.10.171 from the Canadian Centre for Cyber Security. Both aim to protect controlled unclassified information at subcontractors.
Is CPPPP an official Government of Canada standard?
No. CPPPP is a structuring proposal on this page to illustrate, by analogy with CMMC, how a Canadian framework could be read from CPCSC logic and ITSP.10.171. The official Canadian program is CPCSC.
Must a Quebec subcontractor comply with CMMC?
If your U.S. DoD contract requires a specific CMMC level, yes — regardless of your location in Quebec or Canada. Requirements are contractual. A gap assessment against NIST SP 800-171 is the usual starting point.
Which CMMC level most often applies to a Quebec subcontractor SMB?
For contracts involving CUI, the most common level is Level 2 (Advanced), aligned with the 110 requirements of NIST SP 800-171 Rev. 2. As of 2026, contracts primarily require a Level 2 (Self) self-assessment — C3PAO third-party assessments planned for Phase II were suspended in July 2026. Level 1 mainly covers FCI; Level 3 is reserved for very high-criticality programs.
Can Certi360 assess an organization's CMMC or CPCSC maturity?
Yes. Certi360's certified auditors can assess maturity against the applicable references (NIST SP 800-171 / ITSP.10.171), prioritize gaps, and prepare the organization for U.S., Canadian, or dual contractual requirements.

Defence subcontractor in Quebec?

Whether your contract requires U.S. CMMC, Canadian CPCSC or both, our certified auditors can assess your maturity and prioritize gaps.

Talk to an expert