Canadian defense contractors face a new compliance requirement that will shape their eligibility for government contracts. Public Services and Procurement Canada (PSPC) has introduced the Canadian Program for Cyber Security Certification (CPCSC), with Level 1 becoming mandatory for select solicitations starting in the summer of 2026. As such, contractors need to act now to understand what’s required and how to prepare.
This is what CPCSC Level 1 demands, why existing certifications don’t transfer, and how to build a compliance program that positions your business for government contracts.
What CPCSC Requires and Who Is in Scope
CPCSC is PSPC’s certification program for contractors handling Specified Information under DND contracts, regardless of where the company is headquartered. Level 1 became available for annual self-assessment in April 2026 and requires a written affirmation against 13 controls derived from ITSP.10.171, Canada’s adaptation of the broader 97-requirement NIST SP 800-171 Rev. 3.
A critical requirement is data residency: Specified Information must be stored and processed in Canada for applicable contracts. This means some U.S.-hosted cloud environments may not qualify, depending on your solicitation.
Why CMMC Certification Doesn’t Transfer to CPCSC
CMMC is assessed against NIST SP 800-171 Rev. 2, while CPCSC requires compliance with Rev. 3, which expanded the standard to 17 control families and introduced distinct gaps. There is no mutual recognition between the programs, so contractors holding CMMC certification must still achieve CPCSC independently.
For foreign-owned Canadian subsidiaries, the picture is more complex. PSPC assesses subsidiaries as independent entities, meaning a parent company’s CMMC program does not extend to or satisfy the subsidiary’s CPCSC obligations. Each legal entity must achieve its own compliance independently.
What a CPCSC Compliance Engagement With Carbide Involves
Your compliance strategy should rest on two pillars: localized infrastructure and expert guidance. Carbide provides a natively compliant, Canadian-hosted platform that satisfies CPCSC data residency requirements, eliminating the need to build separate regional repositories. The platform centralizes evidence, monitoring, and workflow management so your team tracks progress in one place rather than juggling spreadsheets across departments.
Beyond infrastructure, Carbide’s credentialed advisory team guides you through the full journey, which includes:
- Identifying gaps against ITSP.10.171 and NIST SP 800-171 Rev. 3
- Designing controls that meet the standard and scale with your operations
- Preparing affirmations that withstand scrutiny
- Coordinating evidence for assessments and ongoing compliance
For organizations managing both CMMC and CPCSC obligations, Carbide’s platform and advisory team identify overlapping requirements so evidence and remediation efforts can be reused where appropriate.
Achieve Your CPCSC Level 1 Compliance With Carbide
With Level 1 becoming mandatory for select DND solicitations starting in the summer of 2026, contractors need to be ready to meet the requirements when they apply. Carbide acts as an extension of your compliance team, merging a Canadian-hosted platform with expert advisors who shoulder meaningful portions of the workload. This hybrid approach lets your team focus on operations while Carbide handles evidence management, control readiness, and program development.
Start with Carbide’s free Level 1 self-assessment tool to instantly evaluate your alignment with ITSP.10.171 requirements, then schedule a technical scoping call to start your journey toward certification.