The CPCSC is Canada's official cyber security certification program for defence and government suppliers, managed by Public Services and Procurement Canada (PSPC). It protects Government of Canada unclassified contractual information and Controlled Information (CI) held on suppliers' networks.
The CPCSC is Canada's official cyber security certification program for defence and government suppliers, managed by Public Services and Procurement Canada (PSPC). It protects Government of Canada unclassified contractual information and Controlled Information (CI) held on suppliers' networks.
The program is based on the ITSP.10.171 standard published by the Canadian Centre for Cyber Security, which adapts NIST SP 800-171 Rev 3 to the Canadian context. Three certification levels address increasing sensitivity: Level 1 (self-assessment for basic cyber hygiene), Level 2 (third-party assessment against ITSP.10.171), and Level 3 (Department of National Defence assessment for highest-sensitivity contracts).
The CPCSC aligns with international standards and seeks mutual recognition with the US CMMC program, supporting interoperability with Five Eyes allies.
ThreeShield's CISSP- and CISA-certified assessors run the Canadian Program for Cyber Security Certification (CPCSC) engagement, and Lavawall® collects the technical evidence continuously, so your posture is current the day an auditor, insurer, or client asks for it, not just at renewal.
| Level | What it covers | Builds on the level below |
|---|---|---|
| Level 1 — Basic Cyber Hygiene | Annual self-assessment covering basic cyber hygiene practices to protect federal contractual information held below the classified level. Applicable to all Government of Canada defence suppliers. Covers fundamental practices including access controls, MFA, security awareness, patching, and incident reporting. Based on FAR 52.204-21 equivalents plus Canadian-specific additions including mandatory MFA. | — |
| Level 2 — Enhanced Security (ITSP.10.171) | Third-party assessment by an accredited certification body (3PAO) against the full ITSP.10.171 standard (Canadian adaptation of NIST SP 800-171 Rev 3). Required for contracts involving Controlled Information (CI). Covers 97 security requirements across 17 control families. Includes all Level 1 requirements plus comprehensive controls for access management, audit logging, configuration management, incident response, media protection, and supply chain risk management. | Yes |
| Level 3 — Advanced Security (DND) | Assessment conducted directly by the Department of National Defence (DND) for the highest-sensitivity defence contracts. Builds on Level 2 with enhanced security requirements derived from NIST SP 800-172. Addresses advanced persistent threats (APTs) and state-sponsored adversaries through enhanced controls for penetration-resistant architectures, advanced monitoring, cyber threat intelligence, and supply chain integrity. | Yes |
| Canadian Program for Cyber Security Certification (CPCSC) requirement | Lavawall® collects | ThreeShield delivers |
|---|---|---|
| Multi-factor authentication status | ✓ Continuously | — |
| Patch and vulnerability posture | ✓ Continuously | — |
| Encryption at rest and in transit | ✓ Continuously | — |
| Access and audit-log review | ✓ Continuously | — |
| Risk assessment and scoping | ⚑ Platform data | CISSP/CISA-led |
| Policies, procedures, and evidence package | — | Written by ThreeShield |
If your organization operates in scope for Canada or in the security sector, Canadian Program for Cyber Security Certification (CPCSC) likely applies. The CPCSC is Canada's official cyber security certification program for defence and government suppliers, managed by Public Services and Procurement Canada (PSPC). We confirm scope in the first call, at no charge.
It depends on your starting point. A gap assessment against Canadian Program for Cyber Security Certification (CPCSC) is usually a few weeks; closing the gaps and standing up the evidence takes longer and is where most of the work sits. Because Lavawall® is already collecting the technical evidence while we work, you do not restart from zero at reassessment.
Yes. Many clients begin self-serve on Lavawall®, then bring in ThreeShield for the assessment, the policies, and the sign-off once they know where the gaps are. The three engagement models below are meant to be moved between.
ThreeShield meets you at your current security maturity. Every level includes Lavawall®.
For lean IT teams and cost-conscious organizations with internal security capacity
Expert guidance alongside your team, ideal for MSPs and organizations with some internal IT capacity
Full compliance delivery, managed end to end by ThreeShield
Choose your engagement model: DIY via Lavawall®, supported by ThreeShield's CISSP/CISA team, or fully done-for-you. Every model includes continuous monitoring, so you stay compliant between audits.
Book a Scoping CallDIY · Supported · Done-for-You