Canada’s defence cyber certification is in contracts now. Here’s a plain-language manual for the shops it’s about to reach.
If you install cameras or card readers at a defence site, or you’re the person who keeps the network running at a parts shop with one DND job on the books, CPCSC is heading your way. Hans Study just put out a book about it, and the digital edition is free.
The Study Guide to CPCSC Readiness is written for the person who got handed compliance because nobody else put their hand up: the network admin, the office manager, the IT lead at a 30-person shop. It walks through the program in the order you’d actually do the work. Does it apply to you? What are the 13 Level 1 requirements, and what does each one look like at a small business? How do you fence off the contract data so you’re assessing 9 machines instead of 40? Then it goes through all 98 requirements in ITSP.10.171 family by family, with a plain read on what each one is really asking.
There’s more physical security in it than you’ll find in most CPCSC material. Access control and video systems count as part of the assessed environment when they protect, or sit on the same network as, the systems holding contract data. The book covers that end to end, from which credentials hold up after HID’s 2024 advisories to the door event reports an assessor will ask for.
“Most of these companies make fasteners or wiring harnesses or machined parts, and one defence job out of 400 customers just made them a defence contractor,” Study said. “The requirements aren’t the hard part. Translating them to a shop with one IT person and a deadline is the hard part.”
It’s current, too. Revision 1.3 picks up PSPC’s September 29 rewrite of the program overview (Level 3 went from 200 controls to 130-plus with no announcement) and covers 03.14.09, the dedicated admin workstation requirement Canada added on top of the NIST set. Since the program keeps moving, there’s a companion hub at hans.study/CPCSC with a dated updates log, plus the book’s policy templates and checklists, also free.
Where to get it
Download the free PDF at hans.study/CPCSC_BOOK. It’s also available on Amazon in print, or from your preferred ebook vendor.
CPCSC in 2 minutes
What is it? The Canadian Program for Cyber Security Certification. Public Services and Procurement Canada runs it, and it sets cyber security rules for suppliers on federal defence contracts. Each contract names the level you need.
What’s it protecting? Specified Information, the sensitive but unclassified stuff a contract says has to be protected on your systems: drawings, statements of work, schedules, pricing.
What’s the standard? ITSP.10.171, Canada’s version of NIST SP 800-171 Revision 3. 98 requirements across 17 families.
| Level | Requirements | Who checks | Where it’s at |
|---|---|---|---|
| 1 | 13 | You do, every year, with the result recorded in CanadaBuys | Live, in contracts since summer 2026 |
| 2 | 98 | An SCC-accredited certification body, every 3 years | Select contracts from spring 2027 |
| 3 | 130-plus | National Defence, every 3 years | Still in development |
Does it reach me? If contract data touches your systems, yes, at any tier. Your prime’s certification doesn’t cover you.
I’m an integrator. Am I in? Probably more than you think. Drawings and device schedules for a defence site can be Specified Information, so the commissioning laptop and the project share are in scope. If you remote into a client’s VMS or access control server, that connection is part of their assessment. Our guide to hardening the networks security systems run on is a practical starting point.
What don’t we know yet? How Level 2 assessments will actually run, who the accredited assessors are, what it’ll cost, whether you can pass with open items, and what Level 3 requires.
Disclosure: Hans Study is a contributor to securitystandards.ca.