Scope & applicability
Clarify whether CPCSC language applies to the opportunity, contract or supplier relationship and identify the people, systems and information involved.
CyberTECT helps Canadian defence suppliers prepare for CPCSC Level 1 by identifying control gaps, organizing evidence and turning self-attestation requirements into practical work the business can actually complete.
Level 1 is being introduced into selected Canadian defence contracts. The supplier completes an annual self-assessment against 13 cybersecurity controls and must be able to support its answers. A policy copied from the internet is not the same as an implemented control. The organization needs to know what is in scope, who owns each requirement and what records demonstrate that the answer is accurate.
Clarify whether CPCSC language applies to the opportunity, contract or supplier relationship and identify the people, systems and information involved.
Review the 13 Level 1 controls, identify gaps and separate completed safeguards from work that is still only planned.
Organize policies, inventories, access records, training evidence, configurations and review records that support the annual self-attestation.
Start with the scope, controls and evidence questions that matter before an annual self-assessment or contract requirement.
Organize scope, ownership, control records and corrective work for a defensible self-assessment.
Clarify the information, systems and people that may need to be included.
Review the types of records that can support the 13 Level 1 controls.
Exact scope depends on the organization, systems, evidence and question being answered.
These official resources provide additional detail on the responsibilities, risks and practical safeguards discussed above. They are included so you can verify the guidance and explore the subject directly.
See the official program scope, certification levels and phased implementation.
Review the official annual self-assessment, evidence and certification steps.
Read the 13 Level 1 requirements used for supplier self-assessment.
Resources reviewed July 2026. Requirements and programs can change, so confirm current details through the linked official source.
CyberTECT will confirm what needs to be reviewed, what evidence is required and whether a focused or broader engagement is appropriate.
Three connected guides explain applicability, all 13 controls, proof and assessment boundaries without pretending a readiness review is the government’s certification decision.
The programme, annual self-assessment, 13 controls and evidence expectations.
Read the complete guide →Evidence guideA control-by-control evidence matrix and printable pre-attestation check.
Review evidence guidance →Scoping guideSpecified information, people, systems, facilities, providers and exclusions.
Define the boundary →