SECURITY · CANADA

Canadian Program for Cyber Security Certification (CPCSC)
Assessment & Implementation

The CPCSC is Canada's official cyber security certification program for defence and government suppliers, managed by Public Services and Procurement Canada (PSPC). It protects Government of Canada unclassified contractual information and Controlled Information (CI) held on suppliers' networks.

Who This Applies To

Canada organizationsSecurity sectorMSPs and their clientsLean IT teams carrying an audit

What Canadian Program for Cyber Security Certification (CPCSC) Covers

The CPCSC is Canada's official cyber security certification program for defence and government suppliers, managed by Public Services and Procurement Canada (PSPC). It protects Government of Canada unclassified contractual information and Controlled Information (CI) held on suppliers' networks.

The program is based on the ITSP.10.171 standard published by the Canadian Centre for Cyber Security, which adapts NIST SP 800-171 Rev 3 to the Canadian context. Three certification levels address increasing sensitivity: Level 1 (self-assessment for basic cyber hygiene), Level 2 (third-party assessment against ITSP.10.171), and Level 3 (Department of National Defence assessment for highest-sensitivity contracts).

The CPCSC aligns with international standards and seeks mutual recognition with the US CMMC program, supporting interoperability with Five Eyes allies.

Official source: https://www.canada.ca/en/public-services-procurement/services/industrial-security/security-requirements-contracting/cyber-security-certification-defence-suppliers-canada.html

ThreeShield's CISSP- and CISA-certified assessors run the Canadian Program for Cyber Security Certification (CPCSC) engagement, and Lavawall® collects the technical evidence continuously, so your posture is current the day an auditor, insurer, or client asks for it, not just at renewal.

Assessment Levels We Support

LevelWhat it coversBuilds on the level below
Level 1 — Basic Cyber HygieneAnnual self-assessment covering basic cyber hygiene practices to protect federal contractual information held below the classified level. Applicable to all Government of Canada defence suppliers. Covers fundamental practices including access controls, MFA, security awareness, patching, and incident reporting. Based on FAR 52.204-21 equivalents plus Canadian-specific additions including mandatory MFA.
Level 2 — Enhanced Security (ITSP.10.171)Third-party assessment by an accredited certification body (3PAO) against the full ITSP.10.171 standard (Canadian adaptation of NIST SP 800-171 Rev 3). Required for contracts involving Controlled Information (CI). Covers 97 security requirements across 17 control families. Includes all Level 1 requirements plus comprehensive controls for access management, audit logging, configuration management, incident response, media protection, and supply chain risk management.Yes
Level 3 — Advanced Security (DND)Assessment conducted directly by the Department of National Defence (DND) for the highest-sensitivity defence contracts. Builds on Level 2 with enhanced security requirements derived from NIST SP 800-172. Addresses advanced persistent threats (APTs) and state-sponsored adversaries through enhanced controls for penetration-resistant architectures, advanced monitoring, cyber threat intelligence, and supply chain integrity.Yes

Where the Work Splits

Canadian Program for Cyber Security Certification (CPCSC) requirementLavawall® collectsThreeShield delivers
Multi-factor authentication status✓ Continuously
Patch and vulnerability posture✓ Continuously
Encryption at rest and in transit✓ Continuously
Access and audit-log review✓ Continuously
Risk assessment and scoping⚑ Platform dataCISSP/CISA-led
Policies, procedures, and evidence packageWritten by ThreeShield

Frequently Asked Questions

If your organization operates in scope for Canada or in the security sector, Canadian Program for Cyber Security Certification (CPCSC) likely applies. The CPCSC is Canada's official cyber security certification program for defence and government suppliers, managed by Public Services and Procurement Canada (PSPC). We confirm scope in the first call, at no charge.

It depends on your starting point. A gap assessment against Canadian Program for Cyber Security Certification (CPCSC) is usually a few weeks; closing the gaps and standing up the evidence takes longer and is where most of the work sits. Because Lavawall® is already collecting the technical evidence while we work, you do not restart from zero at reassessment.

Yes. Many clients begin self-serve on Lavawall®, then bring in ThreeShield for the assessment, the policies, and the sign-off once they know where the gaps are. The three engagement models below are meant to be moved between.

Three Ways to Engage, from DIY to Done-for-You

ThreeShield meets you at your current security maturity. Every level includes Lavawall®.

Self-Serve

DIY via Lavawall®

For lean IT teams and cost-conscious organizations with internal security capacity

  • Lavawall® GRC with Canadian Program for Cyber Security Certification (CPCSC) control mapping
  • Continuous automated evidence collection
  • Live compliance dashboard and score
  • Policy template library
  • AI-generated status reports
Start with Lavawall®
Recommended for MSPs & Lean IT

Supported

Expert guidance alongside your team, ideal for MSPs and organizations with some internal IT capacity

  • Everything in the DIY tier
  • CISSP/CISA gap assessment
  • Prioritized remediation roadmap
  • Policy and procedure development
  • Quarterly compliance review calls
  • MSP white-label available
Get Supported Engagement
Fully Managed

Done-for-You

Full compliance delivery, managed end to end by ThreeShield

  • Everything in the Supported tier
  • Full compliance program management
  • CISSP/CISA-executed formal assessment
  • Detailed findings methodology
  • Complete documentation package
  • Annual reassessment included
Book Done-for-You

Ready to Get Compliant with Canadian Program for Cyber Security Certification (CPCSC)?

Choose your engagement model: DIY via Lavawall®, supported by ThreeShield's CISSP/CISA team, or fully done-for-you. Every model includes continuous monitoring, so you stay compliant between audits.

Book a Scoping Call

DIY · Supported · Done-for-You