Skip to content
CyberTECTDigital operations control
All resources

CPCSC Level 1 Evidence Readiness for Canadian Defence Contractors

CPCSC Level 1 is a self-assessment, but a supplier still needs to know what is in scope, who owns each control and where supporting evidence lives.

The short answer

CPCSC Level 1 is a self-assessment, but it is not a memory exercise. A defence supplier should be able to explain what information and systems are in scope, who owns each control, what has actually been implemented and where the evidence is kept.

For a small Canadian defence contractor, the difficult part is often turning scattered practices into a defensible record before a contract requirement, renewal, employee change or customer question makes the gap visible.

The Government of Canada says suppliers may need Level 1 certification for applicable defence contracts beginning in summer 2026. Level 1 confirms the implementation status of 13 security requirements and controls. Suppliers are responsible for retaining their assessment results and supporting evidence.

Evidence readiness has four parts

  • Requirement: what the applicable contract or CPCSC guidance asks the supplier to address.
  • Scope: which information, systems, devices, people, locations and providers are involved.
  • Owner: who is responsible for the control and can explain how it works.
  • Record: what shows the control is implemented, reviewed or being corrected.

A policy in a folder does not prove that accounts are reviewed, old access is removed or MFA recovery works. A screenshot without an owner or date may not show what was true during the assessment period. The objective is not paperwork for its own sake. It is accurate, repeatable and explainable answers.

Start with scope

The official Level 1 guidance tells suppliers to gather information about their assets, the information they hold, and the systems, devices, people and cloud services that can access it. For a smaller supplier, that may include Microsoft 365 or Google Workspace, laptops, engineering files, email, accounting, customer portals, removable media and outside providers.

Create a simple scope record covering:

  • the contract or opportunity creating the requirement;
  • the specified information involved;
  • where it is stored, processed or transmitted;
  • the users, devices, cloud services and vendors that can reach it;
  • boundaries, exclusions or planned corrections; and
  • the person who approved the scope.

The evidence groups to organize

Accounts and access

Keep a current list of user, administrator and service accounts. Record who uses them, what they can access and how access is granted, changed and removed. Include shared accounts, former employees, contractors and recovery paths.

Systems and devices

Identify the approved systems and devices permitted to handle information in scope. Record the owner, purpose, administrator, vendor and review date. Include laptops, phones, external drives, printers and removable media where relevant.

Authentication and safeguards

Document unique accounts, strong passwords, MFA for privileged accounts and systems holding specified information, device approval, network protection, updates and anti-malware. Record whether each safeguard is enabled and for whom.

People, facilities and media

Depending on the environment, evidence may include staff guidance, training records, physical-access lists, visitor records, secure storage and records showing old devices or media were wiped or destroyed.

Policies and corrective work

Keep current short rules for passwords, approved systems, access, employee devices and media disposal. Keep a dated gap record showing what is missing, who owns the fix, what will prove completion and when it will be reviewed.

A practical 30-day sequence

  1. Days 1-5: identify contract language, specified information, systems, people, devices and vendors.
  2. Days 6-10: build account, device, approved-system and supplier-access lists.
  3. Days 11-17: review MFA, permissions, updates, malware protection, physical access and media handling.
  4. Days 18-23: gather policies, training records, configuration evidence and dated review notes.
  5. Days 24-30: record gaps and owners, perform management review and store the assessment record.

This is a starting sequence, not a guaranteed timeline. Complex environments may need deeper technical, procurement, privacy or legal advice.

Where CyberTECT fits

CyberTECT can help a smaller defence supplier define scope, map systems and information, organize evidence, identify control gaps and build an implementation record. See the CPCSC Level 1 Scoping Guide, Evidence Guide and Level 1 Readiness Guide.

CyberTECT does not issue CPCSC certification, act as a Government of Canada assessor or guarantee contract eligibility.

Frequently asked questions

Is CPCSC Level 1 a full independent audit?

No. Level 1 is an annual self-assessment and certification path for applicable contract requirements. Suppliers remain responsible for accurate answers and retaining supporting evidence.

What evidence should a small defence supplier keep?

Keep records that support controls in scope, such as account and device lists, access reviews, policies, training records, MFA settings, update and sanitization records, relevant logs and corrective-action notes.

Can CyberTECT certify a defence contractor?

No. CyberTECT can support scope, evidence organization and implementation planning. The supplier remains responsible for its assessment and any government certification or contract decision.

Start with the evidence question

Use the CPCSC Level 1 Evidence Guide to see what should be organized, or book a consultation about scope and implementation priorities.

Authoritative sources

General readiness information only. This article does not provide procurement, legal, privacy, engineering or certification advice.

Using this guidance

CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.

Discover more from Cybertect

Subscribe now to keep reading and get access to the full archive.

Continue reading