Governance, risk & compliance
Canadian Program for Cyber Security Certification (CPCSC) ITSP.10.171 Oct 2025; Level 1 Apr 2026
Canadian Program for Cyber Security Certification, run by Public Services and Procurement Canada for defence suppliers.
A defence contract names the level a supplier needs, and the certification has to be in place at contract award, not at bid. Level 1: an annual self-assessment of 13 controls with the Cyber Centre's online tool, with proof of self-attestation and its expiry date in the supplier's CanadaBuys profile; in select defence contracts from summer 2026.
Level 2: an external assessment every three years by a certification body accredited by the Standards Council of Canada, plus an annual affirmation, against the 98 allocated requirements of ITSP. 10.
171 (second release, October 2025); in select contracts from spring 2027. Level 3: assessed by National Defence against a larger control set that is still under development.
ITSP. 10.
171 is the Cyber Centre's adaptation of NIST SP 800-171 Rev 3: the same numbering, 'specified information' in place of CUI, withdrawn requirements kept as 'not allocated', and one addition, 03. 14.
09 dedicated administration workstation. Requirements map to the shared control library, so an answer that satisfies CPCSC also counts for SOC 2, NIST SP 800-171 and CMMC wherever they share the control.
Assessment tiers & levels Lavawall supports
Lavawall assesses Canadian Program for Cyber Security Certification (CPCSC) at every level below, so you can start where you are and step up as your program matures.
| Tier / level | What it covers | Builds on lower |
|---|---|---|
| Level 1 — Self-assessment | Annual self-assessment of the 13 Level 1 controls using the Cyber Centre's online tool (under an hour once the controls are in place). Proof of self-attestation and its expiry date go in the supplier's CanadaBuys profile; required at contract award on defence contracts that name Level 1, from summer 2026. Keep evidence for the attestation cycle, at least one year. PSPC describes the controls in plain language without requirement numbers; the ITSP.10.171 requirement each is drawn from is Lavawall's derivation. | — |
| Level 2 — External audit | External assessment against the 98 allocated requirements of ITSP.10.171 by a certification body accredited by the Standards Council of Canada, every three years, with an annual affirmation in between. In select defence contracts from spring 2027. The 98 include everything Level 1 covers, so Level 1 is not added on top. | — |
| Level 3 — DND assessment | Assessed by National Defence, with an annual affirmation, against a larger control set (200 controls, drawing on NIST SP 800-172 enhanced requirements). Still under development and not yet published, so Lavawall assesses the Level 1 and Level 2 requirements under this level; treat the additional Level 3 controls as not yet assessed. | Yes |
How Lavawall® helps you get to Canadian Program for Cyber Security Certification (CPCSC) compliance
Most of Canadian Program for Cyber Security Certification (CPCSC) comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to Canadian Program for Cyber Security Certification (CPCSC), and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against Canadian Program for Cyber Security Certification (CPCSC) in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Lavawall® supports Canadian Program for Cyber Security Certification (CPCSC) as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.
At a glance
- Framework
- Canadian Program for Cyber Security Certification (CPCSC) ITSP.10.171 Oct 2025; Level 1 Apr 2026
- Category
- Security
- Region
- Canada
- Levels
- 3 assessment tiers
Map this framework freeTalk to our team