Canada CPCSC Level 1 in 2026: What Defence Suppliers Need to Do
BidClarity Editorial Team · Reviewed against official sources on
Quick answer: Level 1 of the Canadian Program for Cyber Security Certification (CPCSC) launched in April 2026. From summer 2026, select defence contracts can require it. Level 1 is an annual self-assessment against 13 controls. Where a contract requires it, the self-assessment is required at contract award, not during the bidding process.
Key facts
- Launched: April 2026.
- Where it applies: select defence contracts, from summer 2026. The solicitation says whether it does.
- How it is met: an annual self-assessment.
- What is assessed: 13 controls, grouped into 6 general cyber hygiene practices.
- When it is required: at contract award, not during the bidding process.
In this guide
What is the CPCSC?
The Canadian Program for Cyber Security Certification is the Government of Canada's cyber security certification for defence suppliers. Public Services and Procurement Canada (PSPC) is the federal lead. The program protects federal contractual sensitive information below the classified level.
It has three levels. Each level is meant for higher-risk work than the one before it.
What does Level 1 require?
Level 1 is the entry level. You assess your own organization and record the implementation status of 13 security controls, grouped into 6 general cyber hygiene practices. You repeat the self-assessment every year.
Treat the self-assessment as evidence work, not a checkbox exercise. Keep the records that show each control is in place.
- Annual self-assessment
- 13 controls
- Evidence kept by the supplier
- The requirement is set out in the solicitation and contract clauses
Does every defence contract require Level 1?
No. PSPC introduces the requirement in select defence contracts. It gives commercial off-the-shelf contracts as an example of contracts that may not be subject to cyber security certification.
Read the solicitation and its contract clauses. Only they can tell you whether one procurement requires certification.
When do suppliers have to meet Level 1?
PSPC says the Level 1 self-assessment will be required at contract award, and not during the bidding process.
That does not mean you can leave it until award. If you sell into defence, work through the 13 controls before you bid. Fixing a gap can take longer than the time between the bid and the award.
How does CMMC fit?
PSPC says the Government of Canada may accept a contractor's valid U.S. Cybersecurity Maturity Model Certification (CMMC) on a case-by-case basis, after confirming that the assessment covers the required scope.
So a CMMC certification is not automatically a substitute. Check the solicitation's clause and PSPC's current guidance. If you sell into both Canadian and U.S. defence markets, map your controls once and note where the same evidence serves both.
What comes after Level 1?
Level 2 is an external assessment by an accredited certification body. Level 3 is an assessment conducted by National Defence, for the highest-risk work.
PSPC's Level 1 announcement said Level 2 would be added to select defence contracts beginning in spring 2027. Its program overview, updated 29 September 2026, lists Levels 2 and 3 as under development. Check the overview for the current timetable.
CPCSC is not the same as security screening. If a solicitation also requires organization or personnel screening, read our guide to the Canada Contract Security Program. Certification does not replace screening.
Practical checklist
- Read the solicitation's cyber security clauses.
- Confirm which CPCSC level, if any, is required.
- Review the 13 Level 1 controls.
- Record how each control is implemented today.
- Give each gap an owner and a date.
- Keep the evidence behind your self-assessment.
- If you hold CMMC, check whether this procurement accepts it.
- Check PSPC's guidance again before award.
Where BidClarity fits
BidClarity helps suppliers decide which public sector opportunities are worth pursuing. It does not certify your organization, and it does not replace PSPC's process or the solicitation's terms.
To see which procurement sources BidClarity reads, and the status of each, see Procurement Sources.
See which open opportunities fit your company, and why.
Common questions
Is CPCSC Level 1 required for every Canadian defence contract?
No. It is introduced in select defence contracts, and the solicitation says when it applies.
How many controls are in Level 1?
13, grouped into 6 general cyber hygiene practices.
Do I need Level 1 before I submit a bid?
PSPC says it is required at contract award, not during bidding. Prepare earlier, so a gap does not hold up the award.
Related guides
Official sources
- PSPC: How to meet Level 1 certification requirements
- PSPC: CPCSC program overview
- Government of Canada: Canadian Program for Cyber Security Certification, Level 1 (April 2026)
- Government of Canada: Level 1 introduced (14 April 2026)
This guide is general information, not legal or procurement advice. The solicitation and the official sources control. If something here no longer matches them, report a correction.