Practical preparation for defence suppliers handling Specified Information (SI)
Canada’s cyber certification program has moved from planning into implementation. Level 1 became available in April 2026 and may be required in select defence contracts beginning in summer 2026. Suppliers should prepare before a contract clause creates an immediate deadline.
Current position — July 30, 2026
Level 1 requires an annual self-assessment of 13 security requirements. Initially, certification will be required at contract award, not during bidding. Level 2 third-party certification will be phased in for select contracts starting in spring 2027. DND will conduct Level 3 assessments for the highest-risk work.
Start with specified information and scope
The CPCSC protects Specified Information (SI): sensitive, unclassified Government of Canada information that must be safeguarded when handled, processed or stored by a non-government organization. It may include non-public contract information, controlled goods information and protected information. The applicable contract authority identifies which information requires protection.
Once Specified Information (SI) is identified, define the assessment boundary. Include the people, facilities, systems, devices, applications, service providers and processes that handle the information or protect the systems that do. The boundary may cover the full enterprise or a properly separated enclave.
What suppliers should do now
1
Review current and upcoming work
Identify contracts, bids and subcontracting opportunities that may involve Specified Information (SI).
Map the information
Document where Specified Information (SI) is received, stored, processed, transmitted and destroyed, including external service providers and subcontractors.
3
Complete the Level 1 assessment
Evaluate the 13 requirements, record gaps and assign accountable owners and realistic completion dates.
4
Keep evidence
Maintain account and device lists, access reviews, policies, training records, patching records, visitor logs, firewall settings and MFA configuration evidence for at least the attestation cycle.
5
Build toward the full standard
Organizations likely to face Level 2 should use ITSP.10.171 and ITSP.10.171-01 to develop a system security plan, evidence model and prioritized remediation roadmap.
Coordinate CMMC and Controlled Goods obligations
CPCSC and CMMC use closely aligned technical controls, so a coordinated implementation plan can reduce duplicated work. They remain separate programs, however. Canadian guidance indicates that a valid CMMC certification may support Level 1 recognition or be reviewed against CPCSC requirements, but scope and evidence must still be confirmed.
The Controlled Goods Program is also a separate legal obligation. An organization that examines, possesses or transfers controlled goods in Canada may still need to register and comply with that program, even when it is also preparing for CPCSC certification.
The practical message
Do not wait for a procurement deadline to begin. Early scoping, a documented self-assessment and consistent evidence allow suppliers to address gaps in a controlled sequence and respond to contract requirements with greater confidence.