CPPPP, CPCSC and Canadian references

The "Canadian CMMC" for defence suppliers — official program, ITSP reference and a three-level structuring framework.

CPCSC is the official cyber certification program from Public Services and Procurement Canada (PSPC) for Canadian defence suppliers. It relies on ITSP.10.171 from the Canadian Centre for Cyber Security. CPPPP is a three-level reading framework to map those requirements; the mandatory program remains CPCSC.

What is CPCSC, the official program?

CPCSC (Canadian Program for Cyber Security Certification) is the cybersecurity certification program launched by Public Services and Procurement Canada (PSPC) for suppliers in the Canadian defence supply chain.

It replaces self-attestation with a verifiable model: self-assessment at the entry level, accredited third-party audits at the intermediate level, and government assessment for the most sensitive contracts. The accreditation ecosystem is overseen by the Standards Council of Canada (SCC).

What technical reference does CPCSC rest on?

CPCSC relies on documents from the CSE (Communications Security Establishment, now integrated into the CCCS) published under the ITSP series. The central document is ITSP.10.171Protecting Specified Information in Non-Government of Canada Systems and Organizations — which reflects NIST SP 800-171 revision 3 for protecting controlled information in nongovernment systems.

Unlike the U.S. CMMC (still anchored on NIST 800-171 Rev. 2), Canada directly adopted revision 3, which expands the framework to 17 control families (up from 14 previously), including supply-chain risk management and system acquisition.

How does the CPPPP framework structure Canadian levels?

The table below structures the three protection levels according to CPCSC / ITSP.10.171 logic, indicating for each tier the intended purpose and the corresponding NIST or Canadian reference.

Program Level Primary purpose NIST / Canadian reference
CPPPP framework Level 1 Basic hygiene for suppliers handling controlled information (CMMC L1 equivalent) ITSP.10.171 (CSE) as the Canadian adaptation of NIST SP 800-171 revision 3, minimum requirements for nongovernment systems.
CPPPP framework Level 2 Full protection of controlled information, defence contractual requirements ITSP.10.171 applied in full plus NIST SP 800-171 revision 3 requirements across the controlled-information perimeter, with assessment procedures inspired by NIST SP 800-171A.
CPPPP framework Level 3 Enhanced level for sensitive / high-criticality programs ITSP.10.171 (NIST SP 800-171r3) plus additional controls derived from NIST SP 800-172 and CPCSC-specific requirements for advanced threats.

How does CPPPP map to official CPCSC?

CPPPP (framework) CPCSC (official) Assessment mode
Level 1 CPCSC Level 1 Annual self-assessment (government tool)
Level 2 CPCSC Level 2 Accredited third-party audit (SCC), every three years + annual affirmation
Level 3 CPCSC Level 3 Department of National Defence (DND) assessment, every three years

What does each CPPPP / CPCSC level cover?

Level 1 — Basic hygiene

Functional equivalent of CMMC Level 1. The supplier demonstrates a minimum posture to protect controlled information received under a contract. Reference: a subset of ITSP.10.171 (about 13 controls in the CPCSC rollout). No third-party audit — documented self-assessment.

Level 2 — Full protection

Full application of ITSP.10.171 on the perimeter where controlled information flows. Assessment procedures follow NIST SP 800-171A logic (assessment objectives, evidence, gap treatment plan). This is the level expected for most contracts involving specified information (SI).

Level 3 — High criticality

Full ITSP.10.171 plus enhanced controls modeled on NIST SP 800-172, to counter advanced persistent threats (APT). Reserved for sensitive programs: weapons systems, critical infrastructure, Five Eyes sharing. Government assessment, not delegated to a third party.

How do NIST and Canadian references chain together?

Understanding the lineage between U.S. and Canadian documents makes mapping easier for organizations operating in both markets.

United States NIST SP 800-171 CUI protection requirements
Canada (CSE/CCCS) ITSP.10.171 Canadian adaptation (Rev. 3)
United States NIST SP 800-171A Control assessment guide
CPCSC Level 2 Assessment procedures Inspired by 800-171A, conducted by an SCC body
United States NIST SP 800-172 Enhanced requirements (APT)
CPCSC Level 3 Additional requirements Enhanced controls specific to the Canadian program

What terminology applies to controlled information?

  • Controlled information — generic term for unclassified information subject to dissemination or handling restrictions.
  • Specified information (SI) — Canadian category defined in ITSP.10.171, analogous to U.S. CUI.
  • Protected A / B / C — Government of Canada classification levels; defence contracts specify the applicable level.

What is the CPCSC rollout timeline?

  • April 2026 — CPCSC Level 1 available; online self-assessment tool.
  • Summer 2026 — Level 1 clauses introduced in selected defence contracts.
  • Spring 2027 — progressive Level 2 rollout (third-party audit).
  • 2027–2028 — gradual integration of Levels 2 and 3 based on contract criticality.

For the equivalent U.S. framework, see our CMMC 2.0 and CMMC / CPPPP comparison page.

Where can you find official resources?

Frequently asked questions

Are CPPPP and CPCSC the same thing?
No. CPCSC is the official Government of Canada program to certify defence suppliers. CPPPP is a structuring reading framework — not published under that name by Ottawa — that organizes protection levels while keeping an explicit link to NIST and Canadian references (ITSP.10.171).
What is ITSP.10.171?
ITSP.10.171 is a publication from the Canadian Centre for Cyber Security (CCCS) that defines security requirements to protect specified information in non-Government of Canada systems. It is the Canadian adaptation of NIST SP 800-171 revision 3.
When does CPCSC become mandatory?
CPCSC Level 1 (self-assessment) is being rolled out progressively in selected defence contracts starting summer 2026. Levels 2 and 3 will follow in later phases (spring 2027 and beyond). Check each RFP's clauses.
Is an organization CMMC-compliant automatically CPCSC-compliant?
Not automatically. Requirements largely converge, but Canada relies on ITSP.10.171 (NIST 800-171 Rev. 3) while CMMC 2.0 still rests on Rev. 2. Targeted gap analysis and control mapping remain necessary.
Where should you start to prepare for CPCSC?
Start by identifying the required (or likely) level in your contracts, then assess gaps against ITSP.10.171. Level 1 relies on self-assessment; Levels 2 and 3 require a third-party audit or a government assessment. Mapping controls you already have speeds preparation before clauses become mandatory.

Defence supplier in Quebec?

Assess your maturity against ITSP.10.171 and prepare for CPCSC before clauses become mandatory in your contracts.

Talk to an expert