The "Canadian CMMC" for defence suppliers — official program,
ITSP reference and a three-level structuring framework.
CPCSC is the official cyber certification program from Public Services and Procurement Canada (PSPC) for Canadian defence suppliers. It relies on ITSP.10.171 from the Canadian Centre for Cyber Security. CPPPP is a three-level reading framework to map those requirements; the mandatory program remains CPCSC.
What is CPCSC, the official program?
CPCSC (Canadian Program for Cyber Security Certification)
is the cybersecurity certification program launched by
Public Services and Procurement Canada (PSPC) for suppliers
in the Canadian defence supply chain.
It replaces self-attestation with a verifiable model: self-assessment at the entry
level, accredited third-party audits at the intermediate level, and government assessment
for the most sensitive contracts. The accreditation ecosystem is overseen by the
Standards Council of Canada (SCC).
What technical reference does CPCSC rest on?
CPCSC relies on documents from the CSE (Communications Security
Establishment, now integrated into the CCCS) published under the ITSP series.
The central document is ITSP.10.171 —
Protecting Specified Information in Non-Government of Canada Systems and Organizations
— which reflects NIST SP 800-171 revision 3 for protecting
controlled information in nongovernment systems.
Unlike the U.S. CMMC (still anchored on NIST 800-171 Rev. 2), Canada
directly adopted revision 3, which expands the framework to 17 control families
(up from 14 previously), including supply-chain risk management
and system acquisition.
How does the CPPPP framework structure Canadian levels?
The table below structures the three protection levels according to
CPCSC / ITSP.10.171 logic, indicating for each tier the intended purpose and the corresponding
NIST or Canadian reference.
Program
Level
Primary purpose
NIST / Canadian reference
CPPPP framework
Level 1
Basic hygiene for suppliers handling controlled information
(CMMC L1 equivalent)
ITSP.10.171 (CSE) as the Canadian adaptation of
NIST SP 800-171 revision 3, minimum requirements for nongovernment systems.
CPPPP framework
Level 2
Full protection of controlled information, defence contractual requirements
ITSP.10.171 applied in full plus
NIST SP 800-171 revision 3 requirements across the controlled-information perimeter,
with assessment procedures inspired by NIST SP 800-171A.
CPPPP framework
Level 3
Enhanced level for sensitive / high-criticality programs
ITSP.10.171 (NIST SP 800-171r3) plus additional controls
derived from NIST SP 800-172 and
CPCSC-specific requirements for advanced threats.
How does CPPPP map to official CPCSC?
CPPPP (framework)
CPCSC (official)
Assessment mode
Level 1
CPCSC Level 1
Annual self-assessment (government tool)
Level 2
CPCSC Level 2
Accredited third-party audit (SCC), every three years + annual affirmation
Level 3
CPCSC Level 3
Department of National Defence (DND) assessment, every three years
What does each CPPPP / CPCSC level cover?
Level 1 — Basic hygiene
Functional equivalent of CMMC Level 1. The supplier demonstrates a minimum
posture to protect controlled information received under a contract.
Reference: a subset of ITSP.10.171 (about 13 controls in the CPCSC
rollout). No third-party audit — documented self-assessment.
Level 2 — Full protection
Full application of ITSP.10.171 on the perimeter where controlled information
flows. Assessment procedures follow NIST SP 800-171A logic
(assessment objectives, evidence, gap treatment plan). This is the level
expected for most contracts involving specified information (SI).
Level 3 — High criticality
Full ITSP.10.171 plus enhanced controls modeled on NIST SP 800-172,
to counter advanced persistent threats (APT). Reserved for sensitive
programs: weapons systems, critical infrastructure, Five Eyes sharing.
Government assessment, not delegated to a third party.
How do NIST and Canadian references chain together?
Understanding the lineage between U.S. and Canadian documents makes
mapping easier for organizations operating in both markets.
United StatesNIST SP 800-171CUI protection requirements
No. CPCSC is the official Government of Canada program to certify defence suppliers. CPPPP is a structuring reading framework — not published under that name by Ottawa — that organizes protection levels while keeping an explicit link to NIST and Canadian references (ITSP.10.171).
What is ITSP.10.171?
ITSP.10.171 is a publication from the Canadian Centre for Cyber Security (CCCS) that defines security requirements to protect specified information in non-Government of Canada systems. It is the Canadian adaptation of NIST SP 800-171 revision 3.
When does CPCSC become mandatory?
CPCSC Level 1 (self-assessment) is being rolled out progressively in selected defence contracts starting summer 2026. Levels 2 and 3 will follow in later phases (spring 2027 and beyond). Check each RFP's clauses.
Is an organization CMMC-compliant automatically CPCSC-compliant?
Not automatically. Requirements largely converge, but Canada relies on ITSP.10.171 (NIST 800-171 Rev. 3) while CMMC 2.0 still rests on Rev. 2. Targeted gap analysis and control mapping remain necessary.
Where should you start to prepare for CPCSC?
Start by identifying the required (or likely) level in your contracts, then assess gaps against ITSP.10.171. Level 1 relies on self-assessment; Levels 2 and 3 require a third-party audit or a government assessment. Mapping controls you already have speeds preparation before clauses become mandatory.
Defence supplier in Quebec?
Assess your maturity against ITSP.10.171 and prepare for CPCSC
before clauses become mandatory in your contracts.
We use essential cookies for site operation. With your consent, we measure traffic anonymously (pages viewed, device type) using a tool hosted by Certi360. Privacy policy
EssentialAlways on
Required for site operation and to remember your consent preferences.
Anonymous measurement of pages viewed to improve the site (Umami, hosted on our servers).