CPCSC

CPCSC Compliance Software with Expert Support

Canada’s defence supply chain has mandatory cybersecurity requirements. Carbide’s platform maps your controls to the ITSP.10.171 standard and puts credentialed advisors behind the implementation, so your program is ready before a contract is on the line.

STRONGER SECURITY LEADS TO FASTER COMPLIANCE

DRIVE security & privacy by design
Achieve compliance by default

Everything you need for CPCSC compliance

  • CPCSC Plan

    CPCSC Plan

    Step-by-step implementation plan outlining every ITSP.10.171 control and requirement your organization needs to satisfy

    Build Your CPCSC Compliance Program

  • Customized Policies

    Customized Policies

    Our automated platform ensures your policies are tailored to your environment and meet CPCSC requirements

  • Policy Management

    Policy Management

    Reduce admin time with automated employee reminders and tracking

  • Security Awareness Training

    Security Awareness Training

    In-platform Carbide Academy videos on security and privacy best practices with a template library for common requirements

  • Evidence Collection

    Evidence Collection

    100+ technical integrations connecting to your tech stack to automatically capture compliance evidence mapped to ITSP.10.171 controls

  • Audit Support

    Audit Support

    Save time by giving procurement officers and assessors a read-only view of your CPCSC reporting dashboard

  • Robust Ecosystem

    Robust Ecosystem

    Carbide’s security and privacy services and network of assessment partners help Canadian defence suppliers meet CPCSC requirements faster

     

  • Multi-Compliance by Design

    Multi-Compliance by Design

    Already pursuing CMMC? Carbide maps both frameworks and identifies exactly where ITSP.10.171’s additional requirements go beyond your existing Rev, 2 program

  • Cloud Monitoring

    Cloud Monitoring

    Easily collect data with automated security monitoring, security assessments, and remediation tools to maintain a defensible posture across your cloud environment

Frequently Asked Questions

What is CPCSC?

CPCSC stands for Cyber Protection and Cyber Security Conditions. It is Canada’s official cybersecurity certification program for organizations operating in the defence supply chain, administered by Public Services and Procurement Canada in collaboration with the Department of National Defence, and based on NIST 800-171 Rev. 3. See the CPCSC program overview for official Government of Canada guidance.

How is CPCSC different from CMMC?

Both frameworks draw from NIST 800-171, but CMMC applies to US defence contractors under the Department of Defense while CPCSC applies to Canadian defence suppliers through Canada’s federal defence procurement framework. Organizations working across both supply chains will find significant control overlap but will need to satisfy each framework’s specific documentation and assessment requirements separately.

Who does CPCSC apply to?

CPCSC applies to Canadian organizations that hold or are pursuing contracts with the Department of National Defence or within the broader Canadian defence supply chain. Compliance is a direct contract requirement, not a voluntary standard.

If you are unsure whether your current program meets Level 1 requirements, Carbide’s CPCSC Level 1 Readiness Assessment gives you a clear view of where you stand before your contract window opens.

Is CPCSC based on an existing framework?

Yes. CPCSC is built on NIST 800-171 Rev. 3 through the ITSP.10.171 standard, which contains 97 core security controls. Organizations that have already implemented NIST 800-171 for US federal contracts will have a head start, but CPCSC runs on a different revision and introduces Canadian-specific obligations that require separate attention.

Does CMMC certification satisfy CPCSC requirements?

Not currently. There is no formal mutual recognition between CMMC and CPCSC. CMMC uses NIST 800-171 Rev. 2, while CPCSC is based on ITSP.10.171 and NIST 800-171 Rev. 3. Canada may accept a valid CMMC certification on a case-by-case basis after confirming it covers the required scope, so organizations should not assume an existing CMMC certification automatically satisfies CPCSC requirements.

What are the CPCSC compliance levels?

CPCSC has three compliance levels. Level 1 requires an annual self-assessment against 13 security requirements. Level 2 involves 98 controls and requires an external cybersecurity assessment led by an accredited certification body, conducted every three years, plus an annual affirmation. Level 3 includes 200 controls and requires a cybersecurity assessment conducted by the Department of National Defence, also every three years, plus an annual affirmation.

What happens if my organization doesn't meet CPCSC requirements?

Organizations that cannot demonstrate a conformant security program under CPCSC risk losing eligibility for defence procurement contracts. As enforcement tightens, gaps identified after a contract is awarded carry significantly higher remediation costs than gaps addressed during implementation.

When does CPCSC become mandatory?

CPCSC Level 1 began appearing in select defence contracts in summer 2026, and Level 1 certification is required at contract award for affected solicitations.

How long does CPCSC compliance take?

Preparing for CPCSC Level 1 readiness can take three to six months for small and midsize suppliers, depending on the organization’s existing security program and the gaps that need to be addressed. Starting early gives your team time to implement controls, collect evidence, and complete the required self-assessment before CPCSC requirements apply to your contract.

See How Carbide Can Help You

Book a demo with one of our Security Solutions Advisors to learn how Carbide can fast-track your CPCSC compliance.

This field is for validation purposes and should be left unchanged.
By submitting this request you consent to receive emails from Carbide. You can opt-out from receiving emails at any time.