Skip to content
CyberTECTDigital operations control
CPCSC Level 1 scoping guide

How to scope a CPCSC Level 1 self-assessment without including too much or too little

Identify the people, devices, systems, facilities, providers and information flows that belong inside the assessment boundary before reviewing the 13 controls.

Last reviewed July 27, 2026 · Specified information and assessment boundaries
Scoping is a business decision: identify every asset and environment that stores, processes or transmits specified information. The boundary may be enterprise-wide or a limited enclave, but the rationale must be documented and defensible.

Start with specified information

Specified information is Government of Canada information that must be protected when handled, processed or stored by a non-government organization. Start with the contract and map how that information is received, created, viewed, emailed, printed, copied, backed up, transferred, archived and destroyed.

A six-step scoping method

Step 1

Identify the information

Record what specified information is involved, who provides it and which contractual requirement protects it.

Step 2

Trace the workflow

Follow the information from receipt through use, sharing, storage, backup, printing and disposal.

Step 3

List people and places

Include employees, contractors, administrators, facilities, home workspaces and physical storage points.

Step 4

List technology

Include devices, email, cloud services, servers, networks, printers, scanners, removable media and security tools.

Step 5

Map providers and connections

Identify external service providers, remote support, subcontractors and every connection into or out of the environment.

Step 6

Document inclusions and exclusions

Record why each asset is in scope, out of scope or specialized, and maintain a simple network diagram.

Assets suppliers often overlook

Remote work

Home and personal devices

A personal computer or phone belongs in scope when it can access specified information, even when it is used only for email.

Paper and output

Printers, scanners and records

Paper is storage. Multifunction devices may scan, cache and transmit information and should be considered accordingly.

Cloud and support

External providers

Microsoft 365, backup providers, managed services, identity systems and remote-support tools can operate within the security scope.

Supply chain

Subcontractor systems

Subcontractors perform their own scoping when they handle the same specified information. Prime contractors should document certification and access decisions.

Network edges

Remote and external connections

VPNs, vendor connections, cloud integrations, email forwarding and unmanaged routes can expand the real boundary.

Specialized equipment

Shop-floor and embedded systems

Include or exclude equipment based on whether it can access specified information, not whether somebody considers it “just a machine.”

Documents the official guide expects

  • A scoping rationale explaining asset inclusion and exclusion.
  • A simple physical and logical network diagram.
  • Lists of in-scope, out-of-scope and specialized assets.
  • Facilities, storage and physical handling points.
  • Employees and roles with access to specified information.
  • External systems, providers, remote access and personal-device use.
  • Proof of security tasks, contracts, agreements and key configurations.

Enterprise scope or bounded enclave?

An enterprise-wide scope may be simpler when specified information already moves throughout the business. A bounded enclave can reduce the number of systems and people subject to the controls, but only when the supplier can reliably restrict information flow, access and connections. Creating an enclave on paper while employees continue emailing, downloading or printing elsewhere is not a defensible boundary.

Practical rule: include or exclude an asset based on whether it can access, store, process or transmit specified information. Importance, ownership and physical location are not substitutes for that test.

Scoping questions to resolve before assessment

Government of Canada guidance used and reviewed for this page

Source review completed July 27, 2026. Contract documents and current Government of Canada instructions control where they differ from general guidance.

Prepare the scope, controls and evidence before signing the attestation.

CyberTECT supports Canadian defence suppliers with CPCSC Level 1 readiness, evidence organization and practical implementation planning.