The short answer
CPCSC Level 1 is a self-assessment, but it is not a memory exercise. A defence supplier should be able to explain what information and systems are in scope, who owns each control, what has actually been implemented and where the evidence is kept.
For a small Canadian defence contractor, the difficult part is often turning scattered practices into a defensible record before a contract requirement, renewal, employee change or customer question makes the gap visible.
The Government of Canada says suppliers may need Level 1 certification for applicable defence contracts beginning in summer 2026. Level 1 confirms the implementation status of 13 security requirements and controls. Suppliers are responsible for retaining their assessment results and supporting evidence.
Evidence readiness has four parts
- Requirement: what the applicable contract or CPCSC guidance asks the supplier to address.
- Scope: which information, systems, devices, people, locations and providers are involved.
- Owner: who is responsible for the control and can explain how it works.
- Record: what shows the control is implemented, reviewed or being corrected.
A policy in a folder does not prove that accounts are reviewed, old access is removed or MFA recovery works. A screenshot without an owner or date may not show what was true during the assessment period. The objective is not paperwork for its own sake. It is accurate, repeatable and explainable answers.
Start with scope
The official Level 1 guidance tells suppliers to gather information about their assets, the information they hold, and the systems, devices, people and cloud services that can access it. For a smaller supplier, that may include Microsoft 365 or Google Workspace, laptops, engineering files, email, accounting, customer portals, removable media and outside providers.
Create a simple scope record covering:
- the contract or opportunity creating the requirement;
- the specified information involved;
- where it is stored, processed or transmitted;
- the users, devices, cloud services and vendors that can reach it;
- boundaries, exclusions or planned corrections; and
- the person who approved the scope.
The evidence groups to organize
Accounts and access
Keep a current list of user, administrator and service accounts. Record who uses them, what they can access and how access is granted, changed and removed. Include shared accounts, former employees, contractors and recovery paths.
Systems and devices
Identify the approved systems and devices permitted to handle information in scope. Record the owner, purpose, administrator, vendor and review date. Include laptops, phones, external drives, printers and removable media where relevant.
Authentication and safeguards
Document unique accounts, strong passwords, MFA for privileged accounts and systems holding specified information, device approval, network protection, updates and anti-malware. Record whether each safeguard is enabled and for whom.
People, facilities and media
Depending on the environment, evidence may include staff guidance, training records, physical-access lists, visitor records, secure storage and records showing old devices or media were wiped or destroyed.
Policies and corrective work
Keep current short rules for passwords, approved systems, access, employee devices and media disposal. Keep a dated gap record showing what is missing, who owns the fix, what will prove completion and when it will be reviewed.
A practical 30-day sequence
- Days 1-5: identify contract language, specified information, systems, people, devices and vendors.
- Days 6-10: build account, device, approved-system and supplier-access lists.
- Days 11-17: review MFA, permissions, updates, malware protection, physical access and media handling.
- Days 18-23: gather policies, training records, configuration evidence and dated review notes.
- Days 24-30: record gaps and owners, perform management review and store the assessment record.
This is a starting sequence, not a guaranteed timeline. Complex environments may need deeper technical, procurement, privacy or legal advice.
Where CyberTECT fits
CyberTECT can help a smaller defence supplier define scope, map systems and information, organize evidence, identify control gaps and build an implementation record. See the CPCSC Level 1 Scoping Guide, Evidence Guide and Level 1 Readiness Guide.
CyberTECT does not issue CPCSC certification, act as a Government of Canada assessor or guarantee contract eligibility.
Frequently asked questions
Is CPCSC Level 1 a full independent audit?
No. Level 1 is an annual self-assessment and certification path for applicable contract requirements. Suppliers remain responsible for accurate answers and retaining supporting evidence.
What evidence should a small defence supplier keep?
Keep records that support controls in scope, such as account and device lists, access reviews, policies, training records, MFA settings, update and sanitization records, relevant logs and corrective-action notes.
Can CyberTECT certify a defence contractor?
No. CyberTECT can support scope, evidence organization and implementation planning. The supplier remains responsible for its assessment and any government certification or contract decision.
Start with the evidence question
Use the CPCSC Level 1 Evidence Guide to see what should be organized, or book a consultation about scope and implementation priorities.
Authoritative sources
- Government of Canada – How to meet Level 1 cyber security certification requirements
- Government of Canada – CPCSC Level 1 criteria
- Canadian Centre for Cyber Security – Protecting specified information in non-Government of Canada systems and organizations
General readiness information only. This article does not provide procurement, legal, privacy, engineering or certification advice.
CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.