A clause requiring Canadian Program for Cyber Security Certification (CPCSC) can appear in your next defence solicitation, and the attestation is due at contract award with no grace period. If your systems do not yet meet the ITSP.10.171 controls behind that certification, the time to find and close the gaps is before a contract deadline forces the issue, not after.
This post covers what an ITSP.10.171 gap assessment involves, where suppliers consistently fall short, what it costs to be caught short at award, and how to close the distance between your current posture and a defensible certification.
If you need the groundwork first, see our plain-language guide to ITSP.10.171 and our walkthrough of the ITSP.10.171 requirements in practice.
Why the timeline is tighter than it looks
CPCSC does not run against a single national deadline. It arrives contract by contract. Level 1 self-assessment requirements began appearing in select defence contracts through the summer of 2026, and Level 2, the third-party assessed tier built on the full ITSP.10.171 control set, is scheduled to become mandatory in select contracts beginning in spring 2027.
Two mechanics compress that timeline further. The attestation is required at contract award, not during bidding, so there is no window to remediate after you learn you have won. And there is no grace period once a clause requires certification: a supplier that cannot demonstrate the required level at award is not eligible for it. The official CPCSC program overview sets out this structure.
The practical result is that your remediation window is defined by your prime’s next solicitation or your own next contract, whichever comes first. For many suppliers that is months, not years.
What an ITSP.10.171 gap assessment covers
A structured gap assessment maps your current controls against the ITSP.10.171 requirements and produces a prioritized plan to close what is missing. It is different from a documentation review. Documentation that describes a compliant practice is not the same as a control that produces compliant outcomes and evidence an assessor can verify.
A complete assessment works through the requirement set and answers, for each area:
Access and identity. Is multi-factor authentication enforced everywhere specified information is reachable? Is access granted on least privilege and revoked promptly when roles change? Can you produce a current record of who has access?
Protecting specified information. Is specified information encrypted at rest and in transit? Is removable media controlled? Are known vulnerabilities patched on a defined schedule with evidence of the cycle?
Evidence and documentation. Is there a system security plan that reflects how your systems actually work? Are controls logged and dated so an assessor can confirm they operate? Is your self-assessment score supported by evidence rather than optimism?
Response and supply chain. Has your incident response plan been tested? Do you know which of your own vendors touch specified information, and how their security is managed?
The Cyber Centre’s companion guidance, ITSP.10.171-01, defines how each requirement is assessed. A gap assessment worth the name maps to those same determination statements, so what you fix is what an assessor will actually check.
Where Canadian suppliers can fail
Across defence suppliers working toward CPCSC, the same gaps surface again and again.
Specified information has never been scoped. Suppliers often cannot say precisely where specified information lives on their systems. Until you know which systems store, process, transmit, or handle it, you cannot draw the boundary the controls apply to, and an over-broad boundary makes the whole program more expensive than it needs to be.
Evidence is scattered or undated. Controls may be in place, but if the proof is spread across spreadsheets, screenshots, shared drives, and email inboxes, it cannot be produced on demand and it cannot be trusted to be current. Assessors expect evidence that is organized and dated, not reconstructed the week before.
The system security plan does not match reality. A plan written to look complete, rather than to describe how your systems actually operate, falls apart under assessment. The gap between the document and the deployed environment is one of the first things a capable assessor finds.
The self-assessment score is not defensible. For CPCSC Level 1, you sign an affirmation. A score you cannot support with evidence is a liability, not a credential, and it is your signature on it. Overstating readiness is a worse position than an honest score with a documented plan to close the remainder.
Nobody owns the program. In smaller suppliers the work lands on whoever is closest to IT or contracts, alongside their real job. Controls slip not because the team lacks intent but because no one is accountable for keeping them current.
Not sure your systems would hold up against the ITSP.10.171 controls? Get a credentialed advisor to map your current state and tell you where the gaps are, before a contract clause makes it urgent. Book a Current State Assessment.
The cost of being caught short
A gap found by an advisor before a contract clause requires certification gives you time to remediate and document the fix, so you can present a defensible position at award. A gap found at contract award means you are not eligible for the award, and there is no grace period to fix it afterward. For a supplier whose pipeline depends on defence work, that is a lost contract, not a deferred one.
The remediation work is the same in both cases. What changes is whether you did it on your schedule or discovered you needed it on the buyer’s.
How Carbide closes ITSP.10.171 gaps
Carbide pairs an automation platform with a credentialed advisory team that manages ITSP.10.171 and CPCSC readiness end to end. Advisors scope where specified information lives, map your current controls against the requirement set, produce a prioritized remediation plan, and prepare your evidence for a self-assessment affirmation or an independent assessor. The platform keeps that evidence organized against each control and up to date, hosted on Canadian infrastructure to satisfy the data residency the program expects.
This is not a report that lands on your desk for your team to act on. The advisory team owns the program alongside you through to readiness. Advisors carry NIST SP 800-171 expertise, which is the source ITSP.10.171 is built on, so the interpretation work is done by people who know the control set. You can see the defence-specific setup on our CPCSC and CMMC compliance for defence contractors page, and how other Canadian suppliers have approached it on our customers page.
Get your ITSP.10.171 gap assessment done before your next contract clause requires certification.
If you have seen CPCSC language in a solicitation or received a security requirement from a prime, or you simply have not benchmarked your posture against the ITSP.10.171 controls, the time to act is now.
Is your CPCSC affirmation current? Level 1 requires an annual self-assessment and a renewed affirmation. If your posture has drifted since you last signed, a re-scoping conversation can confirm your affirmation still holds before you certify again. See Carbide’s ITSP.10.171 compliance advisory services.