Skip to content
CyberTECTDigital operations control
CPCSC Level 1 authority guide

CPCSC Level 1 for Canadian defence suppliers: do you need it, what it requires and how to prove your controls

A practical Canadian guide to the annual Level 1 self-assessment, the 13 cybersecurity controls, assessment scope and the evidence a defence supplier should retain before attesting.

Last reviewed July 27, 2026 · Based on current Government of Canada guidance
The direct answer: CPCSC Level 1 is not a universal rule for every company that works near a military base or sells to the defence sector. It is a contract-driven requirement being introduced into selected Government of Canada defence contracts. During the initial rollout, official guidance places the self-assessment requirement at contract award rather than throughout the bidding process.

Do you need CPCSC Level 1?

Start with the procurement documents, security requirements, contract clauses and any direction from a prime contractor. The location of the business does not decide applicability. Handling specified Government of Canada information under an affected contract does.

1 · Contract

Is Level 1 identified?

Review the solicitation, resulting contract and security clauses. A general relationship with defence does not create the requirement by itself.

2 · Information

Will you handle specified information?

Identify the protected, unclassified Government of Canada information involved and how your organization will receive, use, store or transmit it.

3 · Supply chain

Are you a subcontractor?

Confirm whether the prime contractor is flowing the requirement down because your systems or people will handle the same specified information.

Preparing before a requirement appears can still be commercially sensible. It lets a supplier identify account, device, MFA, physical-security, patching and evidence gaps before a contract award depends on them. Preparation, however, should not be presented as certification or as proof that every future contract will require the same level.

What CPCSC Level 1 actually means

The Canadian Program for Cyber Security Certification is the federal certification programme for defence suppliers. Level 1 became available on April 1, 2026 and is being introduced into selected defence contracts beginning in summer 2026. It asks the supplier to assess the implementation status of 13 cybersecurity controls and attest to meeting the Level 1 criteria.

Level 1

Annual self-assessment

Thirteen controls intended to establish basic cyber hygiene for suppliers handling specified information.

Level 2

External assessment

Ninety-eight controls assessed by an accredited certification body, with an annual affirmation.

Level 3

Government assessment

Two hundred controls assessed by National Defence, with an annual affirmation, for higher-risk work.

An existing valid CMMC certification may satisfy Level 1 according to current federal guidance, but the supplier should confirm acceptance and scope for the specific procurement. A certification or assessment with a different system boundary cannot simply be assumed to cover the Canadian contract.

Scope comes before the checklist

Level 1 applies to the environment that stores, processes or transmits specified information. The scope may be the whole company or a bounded enclave. Either way, the supplier must understand the people, technology, facilities and providers inside the boundary and document why assets are included or excluded.

People and places

Who and where

Employees, administrators, contractors, remote workers, offices, home workspaces and physical storage or handling points.

Technology

What touches the information

Computers, phones, servers, cloud applications, email, printers, scanners, storage media, networks and security tools.

Providers

Who operates part of it

Cloud hosts, managed providers, backup services, identity platforms, remote support and subcontractors.

The official scoping guide expects documentation such as an inclusion and exclusion rationale, a simple network diagram, lists of in-scope and out-of-scope assets, facilities, employees with access, external systems and remote-access arrangements. The separate CPCSC Level 1 scoping guide walks through that work in detail.

CPCSC Level 1: 13 controls across six security families

This map follows the current Government of Canada Level 1 programme overview. It is a navigation aid, not a substitute for the official assessment criteria.

What each Level 1 control asks and what could support it

Open each control for a plain-language explanation, practical implementation examples, possible evidence and a common gap. The official Level 1 criteria remain the controlling source.

03.01.0101. Account management
What the control asks

Define which account types are allowed, who is authorized to use them, what privileges each account receives, and how accounts are created, changed, monitored, disabled and removed.

What a smaller supplier may do

Keep a current account inventory, assign named owners, document role and group membership, remove former users promptly, disable stale accounts and define when users must sign out.

Possible evidence

Account exports, approved-user lists, role or group reports, offboarding records, disabled-account reports, review notes and relevant sign-in or audit records.

Common gap

Assuming the directory is accurate without a dated review or leaving shared, dormant and former-user accounts unexplained.

03.01.0202. Access enforcement
What the control asks

Enforce approved logical access to specified information and the systems that hold it according to documented authorization and access-control rules.

What a smaller supplier may do

Match permissions to job duties, restrict sensitive folders and systems, separate ordinary and administrator access, and review exceptions instead of letting access accumulate forever.

Possible evidence

Permission reports, approved access requests, role assignments, shared-drive or application access exports, configuration settings and periodic access reviews.

Common gap

Having a policy that says “least privilege” while broad groups or inherited permissions still provide access to people who do not need it.

03.01.2003. Use of external systems
What the control asks

Prohibit external systems unless specifically authorized, define the security conditions they must meet, verify those conditions and retain appropriate connection or processing agreements.

What a smaller supplier may do

Decide whether personal devices, home computers, cloud applications, partner systems and portable storage may handle specified information, then enforce the decision.

Possible evidence

Approved-system lists, BYOD or remote-work rules, provider agreements, security requirements, device-compliance reports, remote-access settings and portable-media restrictions.

Common gap

Treating Microsoft 365, a subcontractor portal or an employee’s personal device as “outside the scope” even though it stores, processes or transmits specified information.

03.01.2204. Publicly accessible content
What the control asks

Train authorized publishers, review public content for specified information and remove protected information when it is discovered on a public system.

What a smaller supplier may do

Control who can publish to websites and social accounts, use a review step before posting, and document how accidental disclosure is removed and escalated.

Possible evidence

Publisher lists, approval records, training records, website-content reviews, public-system audit logs and records showing removal or response to exposed information.

Common gap

Checking the public website once while ignoring shared links, document portals, social media, job postings and cloud files made public by link.

03.05.0105. User identification, authentication and re-authentication
What the control asks

Uniquely identify and authenticate users and processes acting for users, and define circumstances that require users to authenticate again.

What a smaller supplier may do

Use individual accounts, eliminate avoidable shared identities, connect automated processes to accountable owners, and require re-authentication for sensitive or higher-risk actions.

Possible evidence

User directories, identity settings, authentication policies, account lists, re-authentication settings, application configuration and sign-in records.

Common gap

Relying on a shared shop-floor or office account that makes it impossible to determine who accessed or changed protected information.

03.05.0206. Device identification and authentication
What the control asks

Define which devices must be uniquely identified and authenticated before they establish a connection to the protected environment.

What a smaller supplier may do

Maintain a device inventory and use enrolment, certificates, managed-device rules or equivalent controls so unknown equipment cannot quietly join the environment.

Possible evidence

Device inventories, management-platform exports, enrolment records, certificates, connection reports, conditional-access settings and approved-device lists.

Common gap

Knowing which laptops were purchased but not knowing which computers and phones can currently connect to the systems in scope.

03.05.0307. Multi-factor authentication
What the control asks

Implement strong multi-factor authentication for both privileged and non-privileged account access.

What a smaller supplier may do

Cover administrators and ordinary users, including remote and cloud access, and identify legacy paths or service accounts that bypass the normal sign-in policy.

Possible evidence

MFA policy and configuration exports, conditional-access rules, authentication-method reports, administrator settings, sign-in reports and documented exceptions.

Common gap

Showing that some employees enrolled in MFA while break-glass accounts, administrators, legacy protocols or another application remain outside the policy.

03.08.0308. Media sanitization
What the control asks

Sanitize media containing specified information before disposal, release outside organizational control or release for reuse.

What a smaller supplier may do

Define approved wiping or destruction methods for computers, drives, phones, removable media, printers and other devices that can retain information.

Possible evidence

Sanitization procedures, wipe logs, disposal or destruction certificates, asset-return records, chain-of-custody records and disposition approvals.

Common gap

Deleting files, resetting a device or trusting a recycler without retaining evidence that the media was sanitized appropriately.

03.10.0109. Physical access authorizations
What the control asks

Develop, approve and maintain a list of people authorized to enter facilities where in-scope systems reside, issue credentials, review the list and remove access when no longer required.

What a smaller supplier may do

Identify protected rooms and workspaces, define who may enter them, review keys or badges on a schedule and promptly remove departed staff and expired access.

Possible evidence

Authorized-person lists, approval records, badge or key assignments, periodic review records, access-removal records and facility procedures.

Common gap

Assuming a locked exterior door proves authorization when keys, codes and badge lists have not been reviewed or tied to named people.

03.10.0710. Physical access control
What the control asks

Verify and enforce physical access at entry and exit points, maintain access logs, control and escort visitors, secure keys and combinations, and protect output devices.

What a smaller supplier may do

Use locks, badges, controlled reception or equivalent safeguards; log visitors; protect printed output; and control server, network and document-storage areas.

Possible evidence

Visitor and entry logs, key or badge inventories, access-control configurations, escort procedures, lock-change records, photos or diagrams and review records.

Common gap

Protecting the server room while printers, paper files, loading areas or an unattended reception desk expose the same specified information.

03.13.0111. Boundary protection
What the control asks

Monitor and control communications at managed external and key internal interfaces, separate publicly accessible components, and route external connections through managed boundary protections.

What a smaller supplier may do

Know where internet, cloud, remote-access and internal trust boundaries exist; manage firewalls and gateways; and avoid unmanaged paths around the protected environment.

Possible evidence

Network diagrams, firewall or gateway configurations, remote-access rules, approved-connection lists, network logs, segmentation settings and security architecture notes.

Common gap

Providing a firewall screenshot without showing that all relevant external connections pass through it or that public systems are separated from internal systems.

03.14.0112. Flaw remediation
What the control asks

Identify, report and correct system flaws and define how quickly security-relevant software and firmware updates must be installed.

What a smaller supplier may do

Assign ownership for updates, define target timelines, track exceptions, include network and firmware updates, and verify that failed or deferred updates are corrected.

Possible evidence

Patch reports, vulnerability records, update policies, remediation tickets, change records, firmware inventories, exception approvals and recent correction logs.

Common gap

Relying on automatic updates without reviewing failures, unsupported devices, firmware, third-party applications or systems that were offline.

03.14.0213. Malicious code protection
What the control asks

Deploy malicious-code protection at appropriate locations, keep it updated, scan systems and external files, and block, quarantine or otherwise respond to detections.

What a smaller supplier may do

Cover endpoints and relevant gateways, keep protection current, enable real-time scanning, review unhealthy devices and document the response to detections and false positives.

Possible evidence

Endpoint-protection status reports, configuration exports, update records, scan results, detection and quarantine logs, alert tickets and exception records.

Common gap

Paying for endpoint protection but leaving devices inactive, unmanaged, out of date or excluded without a documented reason and compensating safeguard.

A control must exist, operate and cover the scope

The Level 1 criteria look beyond whether a safeguard is mentioned in a policy. The assessment procedures use documents, mechanisms, interviews and tests to establish confidence that the control is implemented and operating as intended.

Statement

“We review user accounts.” A claim, but not yet proof.

Process

A named owner reviews active and privileged accounts on a defined schedule.

Evidence

A dated export, completed review record, approvals and correction notes show the work occurred.

Coverage matters as much as existence. MFA configured for most users does not fully answer the control when an administrator, legacy protocol or separate application remains outside the policy. The separate Level 1 evidence guide provides a control-by-control evidence matrix and a printable review checklist.

How a smaller supplier can prepare

Step 1

Confirm applicability

Read the actual procurement and contract requirements. Record who confirmed the requirement and when.

Step 2

Define the scope

Map specified information and the people, systems, facilities and providers that touch it.

Step 3

Assess all 13 controls

Separate implemented safeguards from planned work and unsupported assumptions.

Step 4

Build the evidence register

Connect each control to its owner, records, settings, review date and storage location.

Step 5

Correct material gaps

Prioritize missing coverage, risky exceptions and controls that cannot be demonstrated.

Step 6

Review before attesting

Confirm the answers still match the real environment and retain evidence for the full cycle.

CyberTECT’s boundary: CyberTECT can support applicability discussions, scope definition, readiness review, evidence organization and practical remediation planning. CyberTECT does not issue CPCSC certification, act as an accredited Level 2 certification body or guarantee eligibility for a contract.

CPCSC Level 1 questions suppliers are likely to ask first

Does every Canadian defence contractor need CPCSC Level 1?

No. CPCSC is contract-driven. Level 1 is being introduced into selected defence contracts, and the applicable solicitation, contract clauses or prime-contractor requirements determine whether it applies.

When is Level 1 required during the procurement process?

During the initial rollout, official guidance says the Level 1 self-assessment is required at contract award rather than throughout the bidding process. Suppliers can still prepare before bidding so award is not delayed by missing controls or evidence.

Is CPCSC Level 1 an external audit?

No. Level 1 is an annual supplier self-assessment against 13 controls. Level 2 uses an external assessment and a larger control set.

Do all 13 controls need to be met?

The Government of Canada states that suppliers seeking Level 1 certification must complete the self-assessment and attest to meeting all Level 1 criteria. Contract-specific instructions remain controlling.

How long should Level 1 evidence be kept?

Official guidance says evidence should be retained for the attestation cycle, or at least one year. Evidence should remain identifiable, dated and consistent with actual business practices.

Can an existing CMMC certification satisfy Level 1?

Official guidance says an existing valid CMMC certification may meet Level 1 requirements. The supplier should confirm acceptance and scope for the particular procurement or contract.

Does CyberTECT issue CPCSC certification?

No. CyberTECT supports readiness, scoping, control review, evidence organization and remediation planning. The supplier remains responsible for its self-assessment and attestation.

Government of Canada guidance used and reviewed for this page

Source review completed July 27, 2026. Contract documents and current Government of Canada instructions control where they differ from general guidance.

Prepare the scope, controls and evidence before signing the attestation.

CyberTECT supports Canadian defence suppliers with CPCSC Level 1 readiness, evidence organization and practical implementation planning.

The complete Level 1 control structure in one view.

This CyberTECT visual follows the current Government of Canada programme overview. The official assessment criteria remain the controlling source.

CPCSC Level 1 infographic showing 13 controls grouped into six security families
Open the visual at full size. Last reviewed July 27, 2026.