How to coordinate cybersecurity investments across U.S. and Canadian requirements without confusing technical alignment with regulatory recognition.
For small and medium-sized enterprises in the defence industrial base, contractual cybersecurity is progressively becoming a condition of market access. Suppliers must be able to demonstrate, through verifiable evidence, how they protect sensitive information entrusted to them under their contracts.
Two programs are particularly important for Canadian suppliers operating in North American supply chains: CMMC 2.0 in the United States and the Canadian Program for Cyber Security Certification (CPCSC) in Canada. They pursue comparable objectives but remain distinct programs, with their own reference standards, assessment methods, and contractual requirements.
Program update — July 2026
Phase 1 of the CMMC rollout, launched on November 10, 2025, remains in effect and focuses on self-assessments. On July 13, 2026, the U.S. defence authority suspended the transition to Phase 2 and later milestones while the program is under review. Existing contractual obligations to protect FCI and CUI, including those based on NIST SP 800-171 Rev. 2, remain applicable.
1. Understanding the two programs
- CMMC 2.0 — United States: a program designed to verify the implementation of requirements for protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) in defence contractor and subcontractor systems.
- CPCSC — Canada: a program applicable to certain defence contracts when a supplier handles Specified Information (SI) in non-Government of Canada systems. The required level depends on the sensitivity of the information and the contractual risk.
- Specified Information: unclassified information that a Government of Canada authority identifies in a contract as requiring protection. It may include protected information, technical data related to controlled goods, and non-public contractual information.
Summary comparison
Element
CMMC 2.0
CPCSC
Protected information
FCI and CUI associated with U.S. defence contracts.
Specified Information (SI) in certain Canadian defence contracts.
Technical basis
Level 1: 15 requirements from FAR 52.204-21.
Level 2: 110 requirements from NIST SP 800-171 Rev. 2.
Level 3: Level 2 requirements, including requirements derived from NIST SP 800-172.
Level 1: 13 controls.
Level 2: 98 controls from ITSP.10.171, aligned with NIST SP 800-171 Rev. 3.
Level 3: 200 controls according to the current official overview.
Assessment
Level 1: annual self-assessment.
Level 2: self-assessment or certification assessment, depending on the contractual requirement.
Level 3: DIBCAC assessment.
Level 1: annual self-assessment.
Level 2: triennial external assessment by an accredited certification body, with annual affirmation.
Level 3: triennial assessment by DND, with annual affirmation.
Current implementation
Phase 1 is active.
The transition to Phase 2 and later milestones has been suspended since July 13, 2026, pending the program review.
Level 1 has been available since April 2026 and is expected in certain contracts beginning in summer 2026.
Levels 2 and 3 will be introduced progressively.
Recognition
Distinct U.S. program status.
No automatic reciprocity.
A valid CMMC status may be considered on a case-by-case basis, after scope confirmation and, where necessary, verification of controls.
Important: the exact requirements are determined by the clauses of each solicitation or contract. An organization should not assume that a level, scope, or form of evidence accepted under one program will automatically be accepted under the other.
2. Real but limited technical alignment
The principal area of convergence is the security controls. CMMC Level 2 remains based on NIST SP 800-171 Rev. 2, while CPCSC relies on ITSP.10.171, the Canadian standard aligned with NIST SP 800-171 Rev. 3.
Both standards address areas such as access management, authentication, configuration, communications protection, incident response, risk management, and monitoring. However, differences in version, structure, organization-defined parameters, assessment methods, and contractual context require separate analysis.
- What can be reused: security architecture, identity management, logging, segmentation, vulnerability management, policies, processes, and some operational evidence.
- What must remain distinct: the declared scope, assessment results, affirmations, evidence records, and requirements specific to each contract or program.
CPCSC and the Controlled Goods Program: two distinct obligations
CPCSC does not replace the Controlled Goods Program. An individual or organization that examines, possesses, or transfers controlled goods or related technology in Canada generally must register in the program, unless an applicable exclusion or exemption applies. The same contract may therefore trigger both CPCSC obligations and Controlled Goods Program obligations.
3. What this means for defence SMEs
- Scope becomes a business decision: an unnecessarily broad scope increases costs, while an imprecise scope weakens affirmations and assessment results.
- Evidence matters as much as implementation: policies, procedures, inventories, configurations, logs, reviews, and results must demonstrate that controls operate effectively in practice.
- Requirements follow the information: subcontractors must meet the level applicable to the information and services entrusted to them; they do not automatically inherit the prime contractor’s level.
- Regulatory monitoring remains necessary: the CMMC rollout is currently under review, while CPCSC continues its phased implementation. Investment decisions should remain grounded in current contractual obligations.
4. Where to start
1
Confirm contractual triggers
Identify the clauses, expected level, type of information handled, and the date by which compliance must be demonstrated.
Define the scope and information flows
Locate FCI, CUI, and Specified Information (SI); identify the systems, users, processes, sites, service providers, and subcontractors involved.
3
Establish a common control baseline
Build an architecture and governance model capable of supporting U.S. and Canadian requirements, then document differences arising from the standards and programs.
4
Perform an evidence-based gap assessment
Evaluate the actual implementation and effectiveness of controls, as well as the quality of available evidence, rather than relying solely on a compliance checklist.
5
Prioritize and track remediation
Address critical risks and dependencies, assign responsibilities, establish realistic timelines, and verify that gaps are properly closed.
6
Maintain separate compliance records
Retain the applicable scope, affirmations, results, evidence, action plans, and governance decisions for each program and contract.
5. Key message for executives
The most effective approach is to adopt the following principle: a common cybersecurity foundation, supported by separate compliance records.
This approach allows technical and organizational investments to be reused where requirements overlap, while avoiding the assumption that the programs are automatically equivalent. It also helps management prioritize spending based on the actual scope, contractual risk, and business timelines.
Conclusion
CMMC 2.0 and CPCSC both aim to strengthen trust in defence supply chains. Their technical alignment creates an opportunity to streamline efforts, but it does not eliminate differences in standards, assessment methods, or contract-specific requirements.
As of July 2026, the appropriate strategy is neither to wait nor to assume that the programs are interchangeable. It is to maintain existing contractual obligations, prepare for CPCSC according to its phased rollout, and build a demonstrable, adaptable, and sustainable cybersecurity capability.
Notice: this article provides a general overview. Applicable requirements are determined by procurement documents, contractual clauses, and current official guidance.