SECURITY · CANADA

Canadian Program for Cyber Security Certification (CPCSC)
Assessment & Implementation

The CPCSC is Canada's official cyber security certification program for defence and government suppliers, managed by Public Services and Procurement Canada (PSPC). It protects Government of Canada unclassified contractual information and Controlled Information (CI) held on suppliers' networks.

Who This Applies To

Canadian organizationsDefence and government suppliersMSPs and their clientsLean IT teams carrying an audit

What the Canadian Program for Cyber Security Certification (CPCSC) Covers

PSPC runs the CPCSC to protect Government of Canada unclassified contractual information and Controlled Information (CI) held on suppliers' networks.

The program is based on the ITSP.10.171 standard published by the Canadian Centre for Cyber Security, which adapts NIST SP 800-171 Rev 3 to the Canadian context. Three certification levels address increasing sensitivity: Level 1 (self-assessment for basic cyber hygiene), Level 2 (third-party assessment against ITSP.10.171), and Level 3 (Department of National Defence assessment for highest-sensitivity contracts).

The CPCSC aligns with international standards and seeks mutual recognition with the US CMMC program to support interoperability with Five Eyes allies.

Official source: https://www.canada.ca/en/public-services-procurement/services/industrial-security/security-requirements-contracting/cyber-security-certification-defence-suppliers-canada.html

ThreeShield's CISSP- and CISA-certified assessors run the Canadian Program for Cyber Security Certification (CPCSC) engagement, and Lavawall® collects the technical evidence continuously, so your posture is current the day an auditor, insurer, or client asks for it, not just at renewal.

Assessment Levels We Support

LevelWhat it coversBuilds on the level below
Level 1: Basic Cyber HygieneAnnual self-assessment covering basic cyber hygiene practices to protect federal contractual information held below the classified level. Applicable to all Government of Canada defence suppliers. Covers fundamental practices including access controls, MFA, security awareness, patching, and incident reporting. Based on FAR 52.204-21 equivalents plus Canadian-specific additions including mandatory MFA.—
Level 2: Enhanced Security (ITSP.10.171)Third-party assessment by an accredited certification body (3PAO) against the full ITSP.10.171 standard (Canadian adaptation of NIST SP 800-171 Rev 3). Required for contracts involving Controlled Information (CI). Covers 97 security requirements across 17 control families. Includes all Level 1 requirements plus controls for access management, audit logging, configuration management, incident response, media protection, and supply chain risk management.Yes
Level 3: Advanced Security (DND)Assessment conducted directly by the Department of National Defence (DND) for the highest-sensitivity defence contracts. Builds on Level 2 with enhanced security requirements derived from NIST SP 800-172. Addresses advanced persistent threats (APTs) and state-sponsored adversaries through enhanced controls for penetration-resistant architectures, advanced monitoring, cyber threat intelligence, and supply chain integrity.Yes

Where the Work Splits

Canadian Program for Cyber Security Certification (CPCSC) requirementLavawall® collectsThreeShield delivers
Multi-factor authentication status✓ Continuously—
Patch and vulnerability posture✓ Continuously—
Encryption at rest and in transit✓ Continuously—
Access and audit-log review✓ Continuously—
Risk assessment and scoping⚑ Platform dataCISSP/CISA-led
Policies, procedures, and evidence package—Written by ThreeShield

Frequently Asked Questions

It does if you are a Government of Canada defence or government supplier. Level 1 applies to all Government of Canada defence suppliers, and Level 2 is required for contracts involving Controlled Information (CI). We confirm scope in the first call, at no charge.

A gap assessment against the CPCSC usually takes a few weeks. Closing the gaps and standing up the evidence takes longer, and that is where most of the work sits, so the total depends on your starting point. Because Lavawall® is already collecting the technical evidence while we work, you do not restart from zero at reassessment.

Yes. Many clients begin self-serve on Lavawall®, then bring in ThreeShield for the assessment, the policies, and the sign-off once they know where the gaps are. The three engagement models below are meant to be moved between.

Three Ways to Engage, from DIY to Done-for-You

ThreeShield meets you at your current security maturity. Every level includes Lavawall®.

Self-Serve

DIY via Lavawall®

For lean IT teams and cost-conscious organizations with internal security capacity

  • Lavawall® GRC with Canadian Program for Cyber Security Certification (CPCSC) control mapping
  • Continuous automated evidence collection
  • Live compliance dashboard and score
  • Policy template library
  • AI-generated status reports
Start with Lavawall®
Recommended for MSPs & Lean IT

Supported

Expert guidance alongside your team, ideal for MSPs and organizations with some internal IT capacity

  • Everything in the DIY tier
  • CISSP/CISA gap assessment
  • Prioritized remediation roadmap
  • Policy and procedure development
  • Quarterly compliance review calls
  • MSP white-label available
Get Supported Engagement
Fully Managed

Done-for-You

Full compliance delivery, managed end to end by ThreeShield

  • Everything in the Supported tier
  • Full compliance program management
  • CISSP/CISA-executed formal assessment
  • Detailed findings methodology
  • Complete documentation package
  • Annual reassessment included
Book Done-for-You

Ready to Get Compliant with the Canadian Program for Cyber Security Certification (CPCSC)?

Choose your engagement model: DIY via Lavawall®, supported by ThreeShield's CISSP/CISA team, or fully done-for-you. Every model includes continuous monitoring, so you stay compliant between audits.

Book a Scoping Call

DIY · Supported · Done-for-You