You know ITSP.10.171 applies to your defence work and that it sits behind the Canadian Program for Cyber Security Certification (CPCSC). The open question is what meeting it actually involves: what you need to build or document, where suppliers most often fall short, and whether to handle the work in-house, with software, or with a managed model.
This post maps the ITSP.10.171 control families to the practical work behind them, explains the difference between CPCSC Level 1 and Level 2, and lays out the three ways suppliers are approaching the requirement so you can choose the one that fits your team.
If you are still confirming what ITSP.10.171 is and whether it applies to you, start with our plain-language guide to ITSP.10.171 and come back here.
The control set, grouped by the work behind it
ITSP.10.171 organizes its roughly 97 requirements into 17 control families. Rather than walk all 17 in order, it helps to group them by the kind of work each one demands. Most suppliers find the effort concentrates in four areas.
Knowing and controlling access to specified information
The access-related families of ITSP.10.171 (access control, identification and authentication, personnel security) govern who can reach specified information and how they prove who they are. In practice this means enforcing multi-factor authentication, removing access when someone changes roles or leaves, applying least-privilege permissions, and keeping a record of who has access to what.
Common gap: Shared logins, standing administrator rights that were never scoped down, and access that is granted quickly but revoked slowly.
Protecting the information itself
The families that protect the information itself (media protection, system and communications protection, system and information integrity) cover how specified information is kept safe as it is stored and moved. This includes encrypting specified information at rest and in transit, controlling removable media, patching known vulnerabilities on a defined schedule, and monitoring systems for signs of compromise.
Common gap: Specified information sitting unencrypted in shared drives or email, and patch cycles that slip because no one owns them.
See how continuous cloud monitoring supports this.
Proving the program runs
Audit and accountability, security assessment and monitoring, planning, and configuration management are the requirements that produce evidence. They ask you to log activity, review those logs, document a system security plan, baseline your configurations, and track your own assessment results over time.
Common gap: Controls that are in place but undocumented. Without dated evidence, an assessor cannot confirm a control is operating, and a self-assessment score cannot be defended.
Preparing for what goes wrong and who you rely on
Incident response, risk assessment, maintenance, physical protection, awareness and training, and supply chain risk management round out the set. These cover having a tested incident response plan, running risk assessments, securing your facilities, training staff on their responsibilities, and managing the security of your own suppliers who touch specified information.
Common gap: Incident response plans that exist on paper but have never been tested, and no documented view of which of your own vendors handle specified information.
CPCSC Level 1 and Level 2: what each one asks
ITSP.10.171 is the full control set. CPCSC decides how much of it applies to you and how it gets verified.
CPCSC Level 1 applies 13 controls drawn from ITSP.10.171, assessed against 71 determination statements. You confirm compliance through an annual self-assessment and a signed affirmation submitted with the Government of Canada’s online tool. No external assessor is involved. Level 1 became available to suppliers on April 1, 2026 and is being written into select defence contracts through the summer of 2026. The Government of Canada’s CPCSC program overview sets out the phased schedule.
CPCSC Level 2 applies the full ITSP.10.171 control set and is verified by an independent, certified assessor rather than by self-assessment. Level 2 is scheduled to become mandatory in select contracts beginning in spring 2027.
The jump from Level 1 to Level 2 is not a small step up. It moves you from 13 self-assessed controls to the complete requirement set, checked by someone whose job is to find the gaps. Our breakdown of the CPCSC Level 1 13-control checklist shows exactly where the Level 1 line sits, which tells you how much of the full set is still ahead of you.
If you also pursue CMMC, read this before you build
ITSP.10.171 follows NIST SP 800-171 Revision 3. The U.S. Cybersecurity Maturity Model Certification (CMMC) program currently runs on NIST SP 800-171 Revision 2. Revision 3 uses 17 control families; Revision 2 uses 14 families and 110 requirements.
For a supplier serving both Canada and the United States, this has a direct consequence. The two programs share most of their substance, so the majority of your evidence supports both. The structural differences between the revisions mean you still have to map the deltas rather than assume one certificate covers the other. The efficient path is to build your evidence once and map it to each program’s requirements, instead of running two separate compliance projects.
If this describes your situation, see our CMMC framework page and the CMMC Level 2 requirements checklist, then plan a single scoping conversation that covers both.
Build in-house, use software, or use a managed model?
Most defence suppliers are choosing between three approaches to ITSP.10.171 and CPCSC.
Build in-house. This works for suppliers with a dedicated security or compliance function, existing controls that already map to NIST SP 800-171, and the capacity to interpret the requirements and keep the program current as the program evolves. For a machine shop or a professional services firm where compliance lands on whoever is closest to IT, this is a heavy lift.
Use compliance software. Automation software speeds up evidence collection and the documentation that tracks your controls. What it does not do is tell you which controls apply to your contract or interpret an ambiguous requirement for your environment. It cannot prepare you to defend a self-assessment score. Software leaves every judgment call with you.
Use a managed model. A managed model pairs the automation software with a credentialed advisory team that does the interpretation and preparation work alongside you. Advisors scope which controls apply and close the gaps, then get your evidence ready for a self-assessment or an assessor. This is the fit for suppliers without a dedicated compliance function, and for those facing a first CPCSC requirement or working to close material gaps before a contract clause lands.
Carbide pairs an automation platform with a credentialed advisory team that handles CPCSC and ITSP.10.171 compliance work end to end. The platform is hosted on Canadian infrastructure, which satisfies the data residency the program expects, and the advisory team carries NIST SP 800-171 expertise, which is the source ITSP.10.171 is built on. You can see how both fit together on our defence supplier compliance page and our compliance advisory services page.
The obligation does not end at certification
CPCSC Level 1 is not a one-time exercise. It requires an annual self-assessment and a renewed affirmation. A certification that lapses, or an affirmation that goes stale while your systems change underneath it, puts your eligibility for the next contract award at risk.
Is your CPCSC affirmation current, or approaching its annual renewal? If your posture has changed since you last self-assessed, a re-scoping conversation can confirm your affirmation still holds before you sign it again. This is where a managed model earns its keep: the advisory relationship keeps the program current between contracts rather than leaving you to rebuild it each year.
Next steps
When you have a clear picture of your current state, the next step is a scoping conversation. Carbide’s advisors will map your existing controls against ITSP.10.171 and tell you where the gaps are.
We will map your current controls against the ITSP.10.171 requirements and show you exactly where the gaps are. Book a Current State Assessment
If you have already found specific gaps and need to close them before a contract clause requires certification, read the next post in this series, ITSP.10.171 gap assessment: how to close the gaps before your CPCSC assessment.
If you have not yet benchmarked your position, the CPCSC Readiness Checklist 2026 is a useful groundwork step before your scoping call.