Skip to content
CyberTECTDigital operations control
Canadian defence suppliers

Cybersecurity readiness for defence contractors facing new contract requirements.

CyberTECT helps Canadian defence suppliers prepare for CPCSC Level 1 by identifying control gaps, organizing evidence and turning self-attestation requirements into practical work the business can actually complete.

CPCSC Level 1 is a self-attestation, but it still requires defensible evidence.

Level 1 is being introduced into selected Canadian defence contracts. The supplier completes an annual self-assessment against 13 cybersecurity controls and must be able to support its answers. A policy copied from the internet is not the same as an implemented control. The organization needs to know what is in scope, who owns each requirement and what records demonstrate that the answer is accurate.

01

Scope & applicability

Clarify whether CPCSC language applies to the opportunity, contract or supplier relationship and identify the people, systems and information involved.

02

Control readiness

Review the 13 Level 1 controls, identify gaps and separate completed safeguards from work that is still only planned.

03

Evidence record

Organize policies, inventories, access records, training evidence, configurations and review records that support the annual self-attestation.

Practical CPCSC readiness and evidence guidance.

Start with the scope, controls and evidence questions that matter before an annual self-assessment or contract requirement.

A practical starting point for suppliers that need to prepare without overbuilding.

Exact scope depends on the organization, systems, evidence and question being answered.

  • CPCSC Level 1 readiness review
  • Self-assessment evidence checklist
  • Control ownership and gap record
  • Implementation priorities
  • Annual review and evidence maintenance planning
What this service covers: CyberTECT supports readiness, evidence organization and implementation planning. It does not issue CPCSC certification, act as a government assessor or guarantee contract eligibility.

Use trusted guidance to understand the issue and your next steps.

These official resources provide additional detail on the responsibilities, risks and practical safeguards discussed above. They are included so you can verify the guidance and explore the subject directly.

Resources reviewed July 2026. Requirements and programs can change, so confirm current details through the linked official source.

Start with the operating question, not a prebuilt package.

CyberTECT will confirm what needs to be reviewed, what evidence is required and whether a focused or broader engagement is appropriate.

Start with the authority guide, then work through evidence and scope.

Three connected guides explain applicability, all 13 controls, proof and assessment boundaries without pretending a readiness review is the government’s certification decision.