Is Level 1 identified?
Review the solicitation, resulting contract and security clauses. A general relationship with defence does not create the requirement by itself.
A practical Canadian guide to the annual Level 1 self-assessment, the 13 cybersecurity controls, assessment scope and the evidence a defence supplier should retain before attesting.
Start with the procurement documents, security requirements, contract clauses and any direction from a prime contractor. The location of the business does not decide applicability. Handling specified Government of Canada information under an affected contract does.
Review the solicitation, resulting contract and security clauses. A general relationship with defence does not create the requirement by itself.
Identify the protected, unclassified Government of Canada information involved and how your organization will receive, use, store or transmit it.
Confirm whether the prime contractor is flowing the requirement down because your systems or people will handle the same specified information.
Preparing before a requirement appears can still be commercially sensible. It lets a supplier identify account, device, MFA, physical-security, patching and evidence gaps before a contract award depends on them. Preparation, however, should not be presented as certification or as proof that every future contract will require the same level.
The Canadian Program for Cyber Security Certification is the federal certification programme for defence suppliers. Level 1 became available on April 1, 2026 and is being introduced into selected defence contracts beginning in summer 2026. It asks the supplier to assess the implementation status of 13 cybersecurity controls and attest to meeting the Level 1 criteria.
Thirteen controls intended to establish basic cyber hygiene for suppliers handling specified information.
Ninety-eight controls assessed by an accredited certification body, with an annual affirmation.
Two hundred controls assessed by National Defence, with an annual affirmation, for higher-risk work.
An existing valid CMMC certification may satisfy Level 1 according to current federal guidance, but the supplier should confirm acceptance and scope for the specific procurement. A certification or assessment with a different system boundary cannot simply be assumed to cover the Canadian contract.
Level 1 applies to the environment that stores, processes or transmits specified information. The scope may be the whole company or a bounded enclave. Either way, the supplier must understand the people, technology, facilities and providers inside the boundary and document why assets are included or excluded.
Employees, administrators, contractors, remote workers, offices, home workspaces and physical storage or handling points.
Computers, phones, servers, cloud applications, email, printers, scanners, storage media, networks and security tools.
Cloud hosts, managed providers, backup services, identity platforms, remote support and subcontractors.
The official scoping guide expects documentation such as an inclusion and exclusion rationale, a simple network diagram, lists of in-scope and out-of-scope assets, facilities, employees with access, external systems and remote-access arrangements. The separate CPCSC Level 1 scoping guide walks through that work in detail.
This map follows the current Government of Canada Level 1 programme overview. It is a navigation aid, not a substitute for the official assessment criteria.
Open each control for a plain-language explanation, practical implementation examples, possible evidence and a common gap. The official Level 1 criteria remain the controlling source.
Define which account types are allowed, who is authorized to use them, what privileges each account receives, and how accounts are created, changed, monitored, disabled and removed.
Keep a current account inventory, assign named owners, document role and group membership, remove former users promptly, disable stale accounts and define when users must sign out.
Account exports, approved-user lists, role or group reports, offboarding records, disabled-account reports, review notes and relevant sign-in or audit records.
Assuming the directory is accurate without a dated review or leaving shared, dormant and former-user accounts unexplained.
Enforce approved logical access to specified information and the systems that hold it according to documented authorization and access-control rules.
Match permissions to job duties, restrict sensitive folders and systems, separate ordinary and administrator access, and review exceptions instead of letting access accumulate forever.
Permission reports, approved access requests, role assignments, shared-drive or application access exports, configuration settings and periodic access reviews.
Having a policy that says “least privilege” while broad groups or inherited permissions still provide access to people who do not need it.
Prohibit external systems unless specifically authorized, define the security conditions they must meet, verify those conditions and retain appropriate connection or processing agreements.
Decide whether personal devices, home computers, cloud applications, partner systems and portable storage may handle specified information, then enforce the decision.
Approved-system lists, BYOD or remote-work rules, provider agreements, security requirements, device-compliance reports, remote-access settings and portable-media restrictions.
Treating Microsoft 365, a subcontractor portal or an employee’s personal device as “outside the scope” even though it stores, processes or transmits specified information.
Train authorized publishers, review public content for specified information and remove protected information when it is discovered on a public system.
Control who can publish to websites and social accounts, use a review step before posting, and document how accidental disclosure is removed and escalated.
Publisher lists, approval records, training records, website-content reviews, public-system audit logs and records showing removal or response to exposed information.
Checking the public website once while ignoring shared links, document portals, social media, job postings and cloud files made public by link.
Uniquely identify and authenticate users and processes acting for users, and define circumstances that require users to authenticate again.
Use individual accounts, eliminate avoidable shared identities, connect automated processes to accountable owners, and require re-authentication for sensitive or higher-risk actions.
User directories, identity settings, authentication policies, account lists, re-authentication settings, application configuration and sign-in records.
Relying on a shared shop-floor or office account that makes it impossible to determine who accessed or changed protected information.
Define which devices must be uniquely identified and authenticated before they establish a connection to the protected environment.
Maintain a device inventory and use enrolment, certificates, managed-device rules or equivalent controls so unknown equipment cannot quietly join the environment.
Device inventories, management-platform exports, enrolment records, certificates, connection reports, conditional-access settings and approved-device lists.
Knowing which laptops were purchased but not knowing which computers and phones can currently connect to the systems in scope.
Implement strong multi-factor authentication for both privileged and non-privileged account access.
Cover administrators and ordinary users, including remote and cloud access, and identify legacy paths or service accounts that bypass the normal sign-in policy.
MFA policy and configuration exports, conditional-access rules, authentication-method reports, administrator settings, sign-in reports and documented exceptions.
Showing that some employees enrolled in MFA while break-glass accounts, administrators, legacy protocols or another application remain outside the policy.
Sanitize media containing specified information before disposal, release outside organizational control or release for reuse.
Define approved wiping or destruction methods for computers, drives, phones, removable media, printers and other devices that can retain information.
Sanitization procedures, wipe logs, disposal or destruction certificates, asset-return records, chain-of-custody records and disposition approvals.
Deleting files, resetting a device or trusting a recycler without retaining evidence that the media was sanitized appropriately.
Develop, approve and maintain a list of people authorized to enter facilities where in-scope systems reside, issue credentials, review the list and remove access when no longer required.
Identify protected rooms and workspaces, define who may enter them, review keys or badges on a schedule and promptly remove departed staff and expired access.
Authorized-person lists, approval records, badge or key assignments, periodic review records, access-removal records and facility procedures.
Assuming a locked exterior door proves authorization when keys, codes and badge lists have not been reviewed or tied to named people.
Verify and enforce physical access at entry and exit points, maintain access logs, control and escort visitors, secure keys and combinations, and protect output devices.
Use locks, badges, controlled reception or equivalent safeguards; log visitors; protect printed output; and control server, network and document-storage areas.
Visitor and entry logs, key or badge inventories, access-control configurations, escort procedures, lock-change records, photos or diagrams and review records.
Protecting the server room while printers, paper files, loading areas or an unattended reception desk expose the same specified information.
Monitor and control communications at managed external and key internal interfaces, separate publicly accessible components, and route external connections through managed boundary protections.
Know where internet, cloud, remote-access and internal trust boundaries exist; manage firewalls and gateways; and avoid unmanaged paths around the protected environment.
Network diagrams, firewall or gateway configurations, remote-access rules, approved-connection lists, network logs, segmentation settings and security architecture notes.
Providing a firewall screenshot without showing that all relevant external connections pass through it or that public systems are separated from internal systems.
Identify, report and correct system flaws and define how quickly security-relevant software and firmware updates must be installed.
Assign ownership for updates, define target timelines, track exceptions, include network and firmware updates, and verify that failed or deferred updates are corrected.
Patch reports, vulnerability records, update policies, remediation tickets, change records, firmware inventories, exception approvals and recent correction logs.
Relying on automatic updates without reviewing failures, unsupported devices, firmware, third-party applications or systems that were offline.
Deploy malicious-code protection at appropriate locations, keep it updated, scan systems and external files, and block, quarantine or otherwise respond to detections.
Cover endpoints and relevant gateways, keep protection current, enable real-time scanning, review unhealthy devices and document the response to detections and false positives.
Endpoint-protection status reports, configuration exports, update records, scan results, detection and quarantine logs, alert tickets and exception records.
Paying for endpoint protection but leaving devices inactive, unmanaged, out of date or excluded without a documented reason and compensating safeguard.
The Level 1 criteria look beyond whether a safeguard is mentioned in a policy. The assessment procedures use documents, mechanisms, interviews and tests to establish confidence that the control is implemented and operating as intended.
“We review user accounts.” A claim, but not yet proof.
A named owner reviews active and privileged accounts on a defined schedule.
A dated export, completed review record, approvals and correction notes show the work occurred.
Coverage matters as much as existence. MFA configured for most users does not fully answer the control when an administrator, legacy protocol or separate application remains outside the policy. The separate Level 1 evidence guide provides a control-by-control evidence matrix and a printable review checklist.
Read the actual procurement and contract requirements. Record who confirmed the requirement and when.
Map specified information and the people, systems, facilities and providers that touch it.
Separate implemented safeguards from planned work and unsupported assumptions.
Connect each control to its owner, records, settings, review date and storage location.
Prioritize missing coverage, risky exceptions and controls that cannot be demonstrated.
Confirm the answers still match the real environment and retain evidence for the full cycle.
No. CPCSC is contract-driven. Level 1 is being introduced into selected defence contracts, and the applicable solicitation, contract clauses or prime-contractor requirements determine whether it applies.
During the initial rollout, official guidance says the Level 1 self-assessment is required at contract award rather than throughout the bidding process. Suppliers can still prepare before bidding so award is not delayed by missing controls or evidence.
No. Level 1 is an annual supplier self-assessment against 13 controls. Level 2 uses an external assessment and a larger control set.
The Government of Canada states that suppliers seeking Level 1 certification must complete the self-assessment and attest to meeting all Level 1 criteria. Contract-specific instructions remain controlling.
Official guidance says evidence should be retained for the attestation cycle, or at least one year. Evidence should remain identifiable, dated and consistent with actual business practices.
Official guidance says an existing valid CMMC certification may meet Level 1 requirements. The supplier should confirm acceptance and scope for the particular procurement or contract.
No. CyberTECT supports readiness, scoping, control review, evidence organization and remediation planning. The supplier remains responsible for its self-assessment and attestation.
Source review completed July 27, 2026. Contract documents and current Government of Canada instructions control where they differ from general guidance.
CyberTECT supports Canadian defence suppliers with CPCSC Level 1 readiness, evidence organization and practical implementation planning.