Compliance glossary
What is CPCSC?
CPCSC (Canadian Program for Cyber Security Certification) is the Canadian federal government's emerging contractor cybersecurity certification program, designed in alignment with US CMMC 2.0.
In one line: CPCSC is Canada's answer to CMMC 2.0, a graduated certification program that verifies a supplier's cybersecurity before it can win Government of Canada contracts involving sensitive but unclassified information.
Definition
CPCSC was developed jointly by Public Services and Procurement Canada (PSPC) and the Communications Security Establishment (CSE), aligned with US CMMC 2.0 standards. It establishes graduated cybersecurity certification levels for Canadian Defence Industrial Base contractors and broader Government-of-Canada suppliers that handle sensitive but unclassified information.
The control framework mirrors NIST SP 800-171, so organisations pursuing both CPCSC and CMMC 2.0 can largely reuse a single evidence base. Implementation happens progressively, starting with Department of National Defence contracts. Organisations that fail to achieve the required certification level become ineligible for the affected procurement.
Core components
- Alignment with CMMC 2.0. Both frameworks use NIST SP 800-171 as the foundational control set to support Canadian-US interoperability.
- Graduated certification levels. Multiple certification tiers correspond to information sensitivity, mirroring the structure of CMMC 2.0.
- NIST SP 800-171 control set. 110 controls covering access control, training, audit functions, configuration management, authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system protection, and information integrity.
- Third-party assessment. Higher levels require independent assessment, comparable to the C3PAO model in CMMC 2.0.
- Procurement integration. Government of Canada solicitations incorporate CPCSC requirements and disqualify non-compliant contractors.
Why it matters
Canadian defence contractors face procurement gatekeeping requirements similar to the US CMMC 2.0 obligations. Where they previously relied on self-attestation, contractors increasingly need formal certification that matches the contract specification.
MSPs serving Government of Canada contractors must ensure their own security posture aligns with client requirements, because they form part of the client's system boundary.
Cross-border organisations benefit the most. A single evidence base built around NIST SP 800-171 controls supports both certifications, which reduces duplicate compliance overhead.
How Lavawall® helps with CPCSC
Lavawall® includes CPCSC as a first-class compliance target alongside CMMC 2.0 and a dozen more frameworks. Continuous evidence collection supports both certifications at once without duplication.
The platform was developed in Calgary by ThreeShield Information Security Corporation, so it reflects Canadian regulatory contexts. From a unified console it supports a 15+ framework set including CPCSC, CMMC 2.0, NIST CSF, NIST SP 800-171, CIS Controls, SOC 2, ISO 27001, HIPAA, PCI DSS, provincial health frameworks, NERC CIP, IIROC, and the Australian Essential Eight.
Frequently asked
- Is CPCSC the same as CMMC 2.0?
- They are aligned but separate. CPCSC is administered by the Canadian government and applies to Government of Canada procurement. CMMC 2.0 is administered by the US Department of Defense. Both draw on NIST SP 800-171, which lets organisations reuse evidence across the two programs.
- Do I need CPCSC if I already have CMMC 2.0?
- They are separate certifications from different governments. An organisation supplying both governments may need both. The underlying NIST SP 800-171 control evidence is largely identical, but the certification artifacts differ.
- When is CPCSC enforceable?
- CPCSC rolls out progressively into Canadian government procurement. Treat CPCSC requirements as enforceable as soon as they appear in a solicitation, and expect them to appear in a growing share of Department of National Defence and broader Government-of-Canada contracts during the rollout.
- How does CPCSC interact with PIPEDA, BC PIPA, Alberta PIPA, and Quebec Law 25?
- CPCSC governs cybersecurity controls for protecting government information, while the Canadian privacy frameworks govern personal information handling. They overlap in places such as access control and breach notification, but they are separate compliance regimes.