Level 1 — Foundational
Intended for subcontractors that handle FCI only. Fifteen basic practices (passwords, anti-malware, physical access control) from FAR clause 52.204-21. Annual self-attestation assessment.
The U.S. cyber certification model for defence, and a structuring read of the Canadian equivalent — for Quebec subcontractors navigating both markets.
CMMC is the U.S. cyber certification program for Department of Defense (DoD) subcontractors, based on NIST SP 800-171. CPCSC is the official Canadian equivalent for defence suppliers, based on ITSP.10.171. On this page, CPPPP is a three-level structuring read — it is not a standard published under that name by the Government of Canada.
CMMC (Cybersecurity Maturity Model Certification) is the cybersecurity certification program of the U.S. Department of Defense (DoD). It aims to ensure that U.S. defence subcontractors and suppliers adequately protect federal information received under their contracts.
The current version, CMMC 2.0, simplifies the original model into three levels aligned with recognized NIST references. The program defines Level 1 (Self), Level 2 (Self or C3PAO) and Level 3 (government assessment) evaluations. Since July 2026, Phase II has been suspended: contracts currently primarily require Level 1 (Self) or Level 2 (Self), while NIST SP 800-171 obligations remain in force.
The table below summarizes the three CMMC 2.0 levels, their primary purpose and the associated technical reference.
| Program | Level | Primary purpose | NIST reference / key standard |
|---|---|---|---|
| CMMC 2.0 | Level 1 Foundational | FCI protection, basic hygiene | FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems |
| CMMC 2.0 | Level 2 Advanced | CUI protection, advanced practices | NIST SP 800-171 (revision 2) and assessment guide NIST SP 800-171A — 110 controls |
| CMMC 2.0 | Level 3 Expert | Enhanced protection for high-criticality programs | Full NIST SP 800-171 plus a subset of NIST SP 800-172 (Enhanced Security Requirements) |
Intended for subcontractors that handle FCI only. Fifteen basic practices (passwords, anti-malware, physical access control) from FAR clause 52.204-21. Annual self-attestation assessment.
The most common level for contracts involving CUI. Aligned with the 110 requirements of NIST SP 800-171 Rev. 2. In practice (2026), the usual contractual requirement is a Level 2 (Self) self-assessment; C3PAO assessment remains defined in the program, but Phase II — which was to impose it broadly — was suspended in July 2026.
Reserved for very high-sensitivity programs. Combines the full NIST SP 800-171 with enhanced NIST SP 800-172 requirements to counter advanced persistent threats (APT). The government assessment (DIBCAC) planned with Phase II has also been suspended since July 2026; check each contract's clauses.
The Canadian equivalent of CMMC is CPCSC, based on ITSP.10.171 (CSE/CCCS) — an adaptation of NIST SP 800-171 revision 3. The CPPPP framework offers a three-level structuring read, with an explicit link to the NIST references.
Both frameworks pursue the same goal — protecting sensitive information at subcontractors — but differ on authority, terminology and the underlying NIST reference version.
| Element | CMMC 2.0 (United States) | CPPPP / CPCSC (Canada) |
|---|---|---|
| Authority | Department of Defense (DoD) | Public Services and Procurement Canada (PSPC) |
| Information in scope | FCI (level 1) / CUI (levels 2–3) | Specified information (SI) / Protected A and above |
| Technical reference | NIST SP 800-171 Rev. 2 | ITSP.10.171 (aligned with NIST 800-171 Rev. 3) |
| Accreditation body | Cyber AB (C3PAO) | Standards Council of Canada (SCC) |
| Level 1 | 15 FAR practices, self-attestation | 13 ITSP.10.171 controls, self-assessment |
| Level 2 | 110 controls; self-assessment (Self) in force — C3PAO suspended (Phase II, Jul. 2026) | 98 controls, accredited third-party audit (triennial) |
| Level 3 | 800-171 + 800-172; gov. assessment suspended (Phase II, Jul. 2026) | 200 enhanced controls, DND assessment |
For a Quebec SMB operating in both markets, the good news is that the technical requirements largely converge. A security program built on ITSP.10.171 (Rev. 3) positions the organization well for both frameworks, with targeted adjustments depending on the contract at hand.