main logo icon

Published on

September 13, 2026

|

18 min read

CMMC vs CPCSC for Canadian Defence Suppliers (2026): Requirements and Testing

A Canadian defence supplier can face two cyber certifications at once: CPCSC for Canadian contracts and CMMC through US prime flow-downs. Which applies, what each level requires, the Revision 2 versus Revision 3 gap, and where testing fits.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecurityWeb App Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

CPCSC, the Canadian Program for Cyber Security Certification, applies to Government of Canada defence contracts. Level 1 (13 requirements, annual self-assessment) has been available since 1 April 2026 and is being written into select contracts from summer 2026; Level 2 (98 requirements, third-party assessment every three years) is expected in select contracts from spring 2027; Level 3 is assessed by National Defence. CMMC applies to US Department of Defense contracts and reaches Canadian companies through DFARS flow-downs from US primes. Since 13 July 2026 DoD has suspended third-party (C3PAO) and DIBCAC-assessed levels; solicitations may carry only Level 1 (Self) or Level 2 (Self), and the 3 September 2026 class deviation makes that binding. The two programs share a NIST SP 800-171 root but not a revision: CMMC Level 2 is assessed against Revision 2 (110 requirements); CPCSC's standard, ITSP.10.171, is the Cyber Centre's Canadian version of Revision 3 with 98 requirements, including one Canadian addition on dedicated administration workstations. There is no mutual recognition. Canada's program pages tell CMMC-certified suppliers to contact CPCSC; a company selling to both governments plans for both. Neither program mandates a penetration test below its top level. Both mandate vulnerability scanning and periodic assessment of control effectiveness, and both assessment guides list penetration testing as a way to test controls. Under ITSP.10.171 the scanning requirement adds organisation-defined remediation response times. One test programme, scoped to the controlled-information boundary and the applications inside it, produces evidence for both regimes.

Canada's own cyber certification for defence suppliers is no longer a plan. Public Services and Procurement Canada's 14 April 2026 backgrounder confirms that Level 1 of the Canadian Program for Cyber Security Certification (CPCSC) became available to suppliers on 1 April 2026, will be introduced in select defence contracts from summer 2026, and requires "an annual cyber security self-assessment of 13 security requirements and controls." Level 2, with external assessments by certification bodies accredited through the Standards Council of Canada, is expected in select contracts from spring 2027. Three months later, on 13 July 2026, the US Department of War suspended the third-party phase of its own program, CMMC, leaving self-assessed levels in place.

A Canadian company that builds components for a Canadian prime and also sits two tiers below a US prime can therefore face both regimes in the same year, on two different revisions of the same NIST standard, with no reciprocity between them. This guide sets out which program applies to which contract, what each level requires, what the two standards actually share, and where vulnerability scanning and penetration testing produce evidence that satisfies both.

Quick answer: CPCSC applies when the buyer is the Government of Canada, through National Defence and PSPC contracts; the requirement level is set per contract by a cyber security risk assessment, and Level 1 is a 13-requirement annual self-assessment, Level 2 a 98-requirement third-party assessment every three years with an annual affirmation, and Level 3 a National Defence assessment. CMMC applies when the buyer is the US Department of Defense and reaches Canadian subcontractors through DFARS 252.204-7012 and 252.204-7021 flow-downs; during the 2026 suspension only Level 1 (Self) and Level 2 (Self) can be required. Neither program mandates a penetration test below its top level, but both mandate vulnerability scanning and periodic assessment of control effectiveness, and a scoped penetration test is the accepted way to evidence the latter. Where Stingrai fits: Stingrai is a CREST-accredited offensive security company headquartered in Toronto with a London office. Its penetration testers simulate real-world attacks across applications, cloud, networks and people, delivered one-time or continuously through its PTaaS platform, with published pricing from US$3,000 per assessment for one web application and its APIs (pricing) and every other scope quoted.

Which program applies to you

The buyer decides. Use the table, then read the two paragraphs below it, because the flow-down case is where Canadian suppliers get surprised.

Your position

Program that applies

What sets the level

Direct supplier to National Defence or another Government of Canada defence buyer

CPCSC

A cyber security risk assessment of the contract, run by the buyer, identifies Level 1, 2 or 3 in the solicitation

Subcontractor to a Canadian prime on a Canadian defence contract

CPCSC, as flowed down by the prime

The level the prime must hold, or the level the prime assigns to your work

Prime or subcontractor on a US Department of Defense contract

CMMC

The CMMC level the DoD program office specifies; during the suspension, Level 1 (Self) or Level 2 (Self) only

Subcontractor to a US prime, at any tier, handling Federal Contract Information or Controlled Unclassified Information

CMMC, through the DFARS 252.204-7021 flow-down; NIST SP 800-171 through the DFARS 252.204-7012 flow-down

The level the prime's contract requires for the information you handle

Selling to both governments

Both, separately

No mutual recognition exists as of September 2026

Canadian suppliers inside US supply chains are covered by CMMC today. DFARS 252.204-7021 requires the prime to "insert the substance of this clause" in subcontracts where the subcontractor's information systems will process, store or transmit FCI or CUI. DFARS 252.204-7012 has carried NIST SP 800-171 down the supply chain since 2017. Neither clause has a nationality test. A Canadian machine shop receiving CUI drawings from a US prime has the same obligation as an American one.

No reciprocity, and Canada says so. PSPC's supplier support page tells suppliers to "review the CPCSC ITSP.10.171 standard and contact the CPCSC if they are certified under the U.S. Cybersecurity Maturity Model Certification." That is an invitation to a conversation, not a recognition agreement. Plan for two certifications with one control set underneath them.

CPCSC: the three levels, the standard and the dates

The program overview describes CPCSC as a joint initiative of PSPC, National Defence, the Canadian Centre for Cyber Security and the Standards Council of Canada, funded with C$25 million over three years from Budget 2023. Its levels are:

CPCSC level

Requirements

How it is assessed

Cadence

Status (September 2026)

Level 1

13

Self-assessment in the Cyber Centre's online tool; results and expiry confirmed in the CanadaBuys supplier profile

Annual

Available since 1 April 2026; in select contracts from summer 2026

Level 2

98

External assessment by a certification body accredited by the Standards Council of Canada, plus an annual affirmation

Every three years

Under development; expected in select contracts from spring 2027

Level 3

200

Assessment conducted by National Defence, plus an annual affirmation

Every three years

Under development; reserved for the highest-risk scenarios such as weapon systems, critical infrastructure and Five Eyes information

The 13 Level 1 requirements, listed on PSPC's Level 1 page, are basic hygiene: managed user accounts, least privilege, approved systems and devices, control over public release of sensitive information, individual accounts with strong passwords, device approval before connection, multifactor authentication for privileged accounts and systems holding sensitive information, secure wiping of retired devices, a list of who may enter secure areas, physical entry controls, basic network protections, security updates, and antivirus. Compare CMMC Level 1, which is the 15 FAR basic safeguarding requirements at 48 CFR 52.204-21.

The rollout, as published in April 2026. From April 2026 to March 2027 the government introduces the Level 1 tool and support materials, assesses National Defence contracts through a new cyber security risk assessment, and builds the Level 2 certification system; "Level 1 to 3 certification requirements may be identified in select defence contracts as early as summer 2026." From April 2027 to March 2028, "the requirement to have Level 2 or 3 certification will be gradually incorporated into select defence contracts." That schedule replaces the four-phase plan announced in March 2025, which had projected Level 2 in some contracts by spring 2026.

The standard. CPCSC assesses against ITSP.10.171, Protecting specified information in non-Government of Canada systems and organizations, published by the Canadian Centre for Cyber Security on 2 April 2025 with a second release on 28 October 2025. The Cyber Centre describes it as "a Canadian version of NIST SP 800-171" Revision 3, with "no substantial technical changes" and modifications arising only from differences in Canadian law and policy. "Specified information" is the Canadian term for what the US calls CUI: unclassified information that a Government of Canada authority identifies in a contract as requiring safeguarding. Its assessment companion, ITSP.10.171-01, published 20 April 2026, adapts NIST SP 800-171A Revision 3.

Who assesses Level 2. The Standards Council of Canada accredits the certification bodies that will conduct Level 2 assessments; a body must also hold ISO/IEC 17020 accreditation as a prerequisite. Level 3 stays with National Defence.

CMMC: the three levels and the 2026 suspension

CMMC is created by 32 CFR part 170 and put into contracts by DFARS 252.204-7021. Its levels, in the regulation as written:

CMMC level

Requirements

How it is assessed

Cadence

Status (September 2026)

Level 1

15 FAR basic safeguarding requirements (FCI)

Self-assessment, annual affirmation in SPRS

Annual

In force; "Level 1 (Self)" may be required in solicitations

Level 2

110, identical to NIST SP 800-171 Revision 2 (CUI)

Self-assessment every three years, or a C3PAO certification assessment every three years; annual affirmation

Three years

Self-assessment in force; C3PAO assessments suspended since 13 July 2026

Level 3

Level 2 plus 24 selected NIST SP 800-172 requirements

DCMA DIBCAC assessment every three years

Three years

Suspended; may not be designated in solicitations

On 13 July 2026 the Department of War CIO's memorandum 26-P-1023 suspended the November 2026 transition to Phase 2 and instructed that program managers "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period." The same memorandum states that DoD "will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments," and that DFARS 252.204-7012 requirements "remain in effect." On 3 September 2026, Class Deviation 2026-O0025, Revision 3 directed contracting officers to remove or revise CMMC requirements accordingly, while keeping the prescription that puts the CMMC clause in every FCI and CUI contract on or after 10 November 2028.

For a Canadian subcontractor the practical reading is: the NIST SP 800-171 obligation flowed down through your prime has not changed; the prime's ability to demand a C3PAO certificate from you has been paused; and the self-assessed SPRS score the prime may ask you to hold is a representation that the US government can check.

CMMC and CPCSC milestones from 2025 to 2028

The same standard, two revisions: what actually differs

Both programs descend from NIST SP 800-171, which is why a control set built for one gets you most of the way to the other. The revisions differ in ways that matter for scoping and evidence.

Aspect

CMMC Level 2

CPCSC Level 2

Baseline

NIST SP 800-171 Revision 2 (February 2020), incorporated by 32 CFR 170.2

ITSP.10.171, the Canadian version of NIST SP 800-171 Revision 3

Requirement count

110

98: the Revision 3 set plus one Canadian addition, 03.14.09 on dedicated administration workstations; withdrawn Revision 2 items are kept in the numbering as "not allocated"

Structure

Basic and derived requirements, no organisation-defined parameters

Revision 3 structure with organisation-defined parameters (ODPs) for frequencies and response times

Assessment procedures

NIST SP 800-171A (June 2018)

ITSP.10.171-01 (April 2026), adapted from NIST SP 800-171A Revision 3

Scoring

DoD Assessment Methodology: 110 points, 5/3/1 deductions, negative scores possible

Not published as a point system as of September 2026

Assessor

Self, or C3PAO (suspended)

Certification body accredited by SCC

Affirmation

Annual, by an Affirming Official, in SPRS

Annual affirmation (Level 2 and 3)

Two Revision 3 features change how a Canadian supplier documents scanning and assessment.

ODPs turn "periodically" into numbers you must choose. ITSP.10.171-01 decomposes requirement 03.11.02, vulnerability monitoring and scanning, into objectives that include: the system is monitored for vulnerabilities at a defined frequency; scanned at a defined frequency; monitored and scanned "when new vulnerabilities that affect the system are identified"; "system vulnerabilities are remediated within" defined response times; and the list of vulnerabilities to be scanned is updated at a defined frequency and when new vulnerabilities are identified. Revision 2's 3.11.2 has no remediation response time; Revision 3 does, and an assessor will ask what yours is.

Assessment is of "security and privacy requirements." Requirement 03.12.01 reads: "Assess the security and privacy requirements for the system and its environment of operation [Assignment: organization-defined frequency] to determine if the requirements have been satisfied." The assessment objects are the familiar ones: the security assessment plan, the assessment report, the system security plan, and a test of "mechanisms for supporting security assessments." The Cyber Centre's supporting references for this requirement include NIST SP 800-115, the technical guide to security testing and assessment.

Where scanning and penetration testing fit in each program

Neither program writes "penetration test" into a Level 2 requirement. Both write in the activities a penetration test is used to evidence, and both assessment guides name it as a test technique.

Under CMMC Level 2. RA.L2-3.11.2 requires scanning of systems and applications at a defined frequency and when new vulnerabilities appear; CA.L2-3.12.1 requires periodic assessment of whether controls "are effective in their application." DoD's Level 2 Assessment Guide, version 2.13 states in its discussion of scanning that "vulnerability analysis of a custom-made solution may require a penetration tester to properly test and validate findings" because "automated vulnerability scanners may not be as thorough when scanning custom developed applications," and its assessment consideration for 3.12.1 asks whether controls are "assessed at least annually." Under the DoD Assessment Methodology both requirements are worth 5 points and cannot sit on a POA&M. Our companion guide, CMMC Level 2 self-assessment: scanning and pentest evidence that holds up, walks through the objectives one by one.

Under CMMC Level 3. CA.L3-3.12.1e at 32 CFR 170.14(c)(4)(xx) is the one explicit mandate in either program: "Conduct penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts." Level 3 is suspended for new designations, but the requirement is the reference point for what "expert-led" means in DoD's vocabulary.

Under CPCSC Level 2. ITSP.10.171 03.11.02 and 03.12.01, described above, carry the scanning and assessment obligations, with ODPs for frequency and remediation response times. ITSP.10.171-01 lists, among the test methods for requirement 03.01.06 on least privilege for privileged accounts, "penetration testing on the DAW," the dedicated administration workstation that the Canadian standard adds. The general TEST method, "exercising 1 or more assessment objects under specified conditions to compare actual state to desired state," is the same family of activity a penetration test performs.

Under CPCSC Level 3. PSPC describes Level 3 as an assessment conducted by National Defence for the highest-risk scenarios, with the program aligned to NIST SP 800-171 and SP 800-172, the source of the enhanced requirements CMMC uses at its own Level 3. Detailed Level 3 requirements had not been published as of September 2026.

Activity

CMMC Level 2 evidence

CPCSC Level 2 evidence

Authenticated vulnerability scans of every in-scope host and application, at the defined frequency and on new critical CVEs

RA.L2-3.11.2 [a] to [e]; feeds 3.11.3 and 3.14.1

03.11.02 objectives on monitoring, scanning and list updates

Documented remediation response times, honoured

SI.L2-3.14.1 time windows; RA.L2-3.11.3 risk-based remediation

03.11.02 remediation within defined response times; 03.14.01 flaw remediation

Independent penetration test of the controlled-information boundary and the applications inside it

CA.L2-3.12.1 [b] effectiveness; scoping validation under 32 CFR 170.19; custom-application analysis per the assessment guide

03.12.01 assessment of security requirements; test method evidence; privileged-access testing including the DAW

Retest and closure records

RA.L2-3.11.3, CA.L2-3.12.2 plan of action

03.12.02 plan of action and milestones updated from assessment findings

Continuous monitoring outputs reaching decision makers

CA.L2-3.12.3

03.12.03 continuous monitoring

One test programme for both regimes

The two control sets overlap enough that a supplier selling to both governments should build one evidence programme rather than two. The scoping rules below produce artefacts both assessors recognise.

  1. Draw one boundary around specified information and CUI. Under 32 CFR 170.19 the CMMC scope is the CUI assets, the Security Protection Assets that defend them, and the paths in from everything else; ITSP.10.171 requires the system boundary to be established before risk can be assessed. Keep both in one enclave where you can. Two enclaves means two boundaries to test and two sets of scope documents to defend.

  2. Scan everything inside the boundary, with credentials, on a written schedule. Include applications, not just hosts. Record the schedule as an ODP value for CPCSC and as the defined frequency for CMMC objective 3.11.2[a]. Write the remediation response time down once and honour it for both.

  3. Test the boundary and the custom applications independently, at least annually. Test from the corporate network, from a compromised standard workstation, and from a remote user's position into the enclave. Test the applications that process the controlled information with every role exercised against every other role. Include the administration path, because the Canadian standard singles out the dedicated administration workstation.

  4. Document the methodology in the report. Both assessment guides ask for an assessment plan and a report; the CMMC Level 3 requirement, the strictest statement of intent in either program, wants automated tooling and expert-led testing both identified. A report whose methodology section names the tools used and the manual testing performed satisfies every assessor reading it.

  5. Retest and file the closure evidence with the POA&M. CMMC's Conditional status expires after 180 days if the POA&M is not closed; CPCSC's 03.12.02 requires the plan of action and milestones to be updated from assessment findings. A retest record is the cleanest closure artefact in both.

  6. Time the test before the affirmation. Both programs run on an annual affirmation. Run the test and the remediation cycle in the quarter before the affirmation date so the official signing it is signing on current evidence.

A 2026 to 2027 plan for a Canadian supplier

Quarter

CPCSC action

CMMC action

Testing action

Q4 2026

Complete the Level 1 self-assessment in the Cyber Centre tool if any Canadian defence contract is in the pipeline; confirm the result in the CanadaBuys profile

Confirm which flowed-down clauses you hold; post or refresh the Basic NIST SP 800-171 assessment in SPRS; identify the Affirming Official

Define the boundary; run the first authenticated scan cycle; commission a boundary and application penetration test

Q1 2027

Map the 98 ITSP.10.171 requirements to your existing 110-requirement SSP; set ODP values for 03.11.02 and 03.12.01

Re-score against NIST SP 800-171A; close any 5-point gaps before scoring

Remediate and retest; file the closure evidence with the POA&M

Q2 2027

Watch for Level 2 language in solicitations from spring 2027; engage an SCC-accredited certification body once the list is published

Annual affirmation if due; monitor the CMMC Reform Task Force outcome

Second scan cycle; assess whether new systems entered the boundary

Q3 to Q4 2027

Level 2 assessment readiness; assessments of Level 2 and 3 are expected to be "gradually incorporated" through March 2028

Prepare for the November 2028 clause prescription regardless of task force outcome

Annual penetration test, scoped to both boundaries' evidence needs

Two Canadian-specific points round this out. First, CPCSC is a cyber certification, distinct from registration in the Controlled Goods Program, which governs access to controlled goods and technology under the Defence Production Act; a supplier can need both. Second, both programs are built on the premise that specified information and CUI are identified in the contract. Ask the buyer or the prime to identify the information and its markings before you draw the boundary, because the boundary is what you will be scanning, testing and affirming.

How Stingrai supports Canadian defence suppliers

Stingrai is headquartered in Toronto, was founded in 2021, and is a CREST-accredited penetration testing service provider at firm level, one of four such providers listed in Canada on the CREST marketplace as of August 2026. Its penetration testers hold OSCE3, OSCP, OSWE, CREST CRT and CISSP certifications, have published 18 CVEs, and deliver human-led penetration testing for regulated industries. The firm holds 5.0 out of 5.0 across 19 Clutch reviews.

For a defence supplier facing CPCSC, CMMC or both, an engagement is scoped to the controlled-information boundary and the applications inside it: internal and external network testing, privileged-access and administration-path testing, application testing with full role coverage, and cloud configuration review where the enclave is hosted. Findings are published to the PTaaS portal as they are confirmed, with reproduction steps and remediation guidance, retesting is included, and the engagement closes with a report and a signed attestation letter that state scope, methodology and retest results, which is the artefact both assessment guides ask for. Stingrai delivers both one-time annual penetration tests and continuous testing programmes. Snipe, Stingrai's autonomous AI agent for web application penetration testing, works concurrently with the penetration testers on web application scopes only; network, cloud and infrastructure testing is human-led throughout.

Frequently Asked Questions

Does a Canadian company need CMMC or CPCSC?

It depends on the buyer. CPCSC applies to Government of Canada defence contracts, with the level set by a cyber security risk assessment of each contract. CMMC applies to US Department of Defense contracts and reaches Canadian subcontractors through the DFARS 252.204-7021 and 252.204-7012 flow-downs whenever they handle Federal Contract Information or Controlled Unclassified Information. A company selling into both supply chains needs both; there is no mutual recognition as of September 2026, and Canada's program pages ask CMMC-certified suppliers to contact CPCSC directly.

What is CPCSC Level 2 and when is it required?

CPCSC Level 2 is an external assessment of 98 security requirements under ITSP.10.171, conducted every three years by a certification body accredited by the Standards Council of Canada, with an annual affirmation in between. Public Services and Procurement Canada expects Level 2 to appear in select defence contracts from spring 2027, with Level 2 or 3 requirements "gradually incorporated" into select contracts between April 2027 and March 2028.

Is ITSP.10.171 the same as NIST SP 800-171?

ITSP.10.171 is the Canadian Centre for Cyber Security's Canadian version of NIST SP 800-171 Revision 3, with no substantial technical changes. It contains 98 requirements: the Revision 3 set plus one Canadian addition on dedicated administration workstations, with withdrawn Revision 2 items kept in the numbering as "not allocated." CMMC Level 2 assesses against Revision 2, which has 110 requirements, so a control set built for one needs a mapping to the other rather than a rebuild.

Does CPCSC require a penetration test?

Not by name at Level 1 or Level 2. Level 2 requires vulnerability monitoring and scanning with defined frequencies and remediation response times (03.11.02) and periodic assessment of the security requirements (03.12.01). The assessment guide, ITSP.10.171-01, lists penetration testing as a test method for privileged access on the dedicated administration workstation and defines the general test method as exercising assessment objects to compare actual state to desired state. A penetration test is therefore the accepted way to evidence control effectiveness rather than a mandated control.

Does CMMC require a penetration test?

Only at Level 3, through CA.L3-3.12.1e, which requires penetration testing at least annually or on significant security changes, using both automated scanning tools and ad hoc tests by subject matter experts. Levels 1 and 2 impose no penetration testing obligation. Level 2 does require vulnerability scanning (RA.L2-3.11.2) and periodic assessment of control effectiveness (CA.L2-3.12.1), each worth 5 points and ineligible for a POA&M, and DoD's Level 2 Assessment Guide notes that custom software "may require a penetration tester."

What did the July 2026 CMMC suspension change for Canadian subcontractors?

It paused the ability of US program offices to require C3PAO-certified Level 2 or DIBCAC-assessed Level 3; only Level 1 (Self) and Level 2 (Self) may be designated during the suspension, and the 3 September 2026 class deviation directs contracting officers to remove third-party assessment requirements from solicitations and contracts. The NIST SP 800-171 Revision 2 obligation flowed down through DFARS 252.204-7012 is unchanged, SPRS posting and annual affirmations continue, and government-led DIBCAC assessments remain possible.

Can one penetration test serve both CMMC and CPCSC?

Yes, if it is scoped to the controlled-information boundary and the applications inside it, exercises every role including the administration path, documents both the tools used and the manual testing performed, and closes with a retest record. Those elements map to CMMC objectives 3.11.2 and 3.12.1 and to ITSP.10.171 requirements 03.11.02, 03.12.01 and 03.12.02, so a single annual test produces evidence both assessors recognise.

Where do I complete the CPCSC Level 1 self-assessment?

In the Canadian Centre for Cyber Security's online self-assessment tool, after which the result and its expiry date are confirmed in the organisation's CanadaBuys supplier profile questionnaire when bidding on or working under a qualifying defence contract. The self-assessment is annual and covers 13 requirements.

Talk to Stingrai

Scoping a penetration test to the boundary both programs care about takes one short conversation. Stingrai is a CREST-accredited offensive security company headquartered in Toronto with a London office. Its penetration testers simulate real-world attacks across applications, cloud, networks and people, delivered one-time or continuously through its PTaaS platform, with documented findings, remediation guidance and retesting included. Book a free scoping call, get a quote, or read the published pricing.

References

  1. Public Services and Procurement Canada. _Canadian Program for Cyber Security Certification: Level 1_ (backgrounder). 14 April 2026. https://www.canada.ca/en/public-services-procurement/news/2026/04/canadian-program-for-cyber-security-certification-level-1.html. Level 1 availability from 1 April 2026, the 13 requirements, and the expected timing of Levels 2 and 3.

  2. Public Services and Procurement Canada. _Cyber security certification for defence suppliers in Canada: Program overview_. Last modified 14 April 2026. https://www.canada.ca/en/public-services-procurement/services/industrial-security/security-requirements-contracting/cyber-security-certification-defence-suppliers-canada/program-overview.html. The three levels, requirement counts, assessment bodies and program partners.

  3. Public Services and Procurement Canada. _Additional information and support for suppliers about cyber security_. Last modified 14 April 2026. https://www.canada.ca/en/public-services-procurement/services/industrial-security/security-requirements-contracting/cyber-security-certification-defence-suppliers-canada/additional-information-support.html. The April 2026 to March 2028 rollout and the note to CMMC-certified suppliers.

  4. Public Services and Procurement Canada. _How to meet Level 1 cyber security certification requirements_. Last modified 1 May 2026. https://www.canada.ca/en/public-services-procurement/services/industrial-security/security-requirements-contracting/cyber-security-certification-defence-suppliers-canada/meet-level1-certification-requirements.html. The 13 Level 1 requirements and the self-assessment tool.

  5. Public Services and Procurement Canada. _Government of Canada announces first phase of Canadian Program for Cyber Security Certification_. 12 March 2025. https://www.canada.ca/en/public-services-procurement/news/2025/03/government-of-canada-announces-first-phase-of-canadian-program-for-cyber-security-certification.html. The original four-phase plan.

  6. Canadian Centre for Cyber Security. _Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)_. First release 2 April 2025, second release 28 October 2025. https://www.cyber.gc.ca/en/guidance/protecting-specified-information-non-government-canada-systems-and-organizations-itsp10171. The CPCSC control standard.

  7. Canadian Centre for Cyber Security. _Assessing security requirements for specified information (ITSP.10.171-01)_. 20 April 2026. https://www.cyber.gc.ca/en/guidance/assessing-security-requirements-specified-information-itsp10171-01. The assessment procedures, including the objectives for 03.11.02 and 03.12.01.

  8. Standards Council of Canada. _Canadian Program for Cyber Security Certification_ (accreditation scheme). https://scc-ccn.ca/accreditation-scheme/inspection-bodies/canadian-program-cyber-security-certification. Accreditation of Level 2 certification bodies and the ISO/IEC 17020 prerequisite.

  9. Department of War Chief Information Officer. _Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements_, publication case 26-P-1023, with Attachment 1. 13 July 2026. https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf.

  10. Office of the Assistant Secretary of War for Acquisition and Sustainment. _Class Deviation 2026-O0025, Revision 3_. 3 September 2026. https://www.acq.osd.mil/dpap/dars/classdev/DFARS_RFO/Part-240/2026-O0025_Rev3_TAB_A_Deviation_Memo.pdf.

  11. Department of Defense. _32 CFR part 170, Cybersecurity Maturity Model Certification (CMMC) Program_. https://www.ecfr.gov/current/title-32/part-170.

  12. Department of Defense Chief Information Officer. _CMMC Assessment Guide, Level 2, Version 2.13_. September 2024. https://dodcio.defense.gov/Portals/0/Documents/CMMC/AssessmentGuideL2v2.pdf.

  13. Acquisition.gov. _DFARS 252.204-7012_, _252.204-7020_ and _252.204-7021_. https://www.acquisition.gov/dfars/252.204-7021-cybersecurity-maturity-model-certification-requirements. The flow-down paragraphs that reach Canadian subcontractors.

0 views

0

X

Related reading

CMMC Level 2 Self-Assessment in 2026: Scanning and Pentest Evidence That Holds Up
Network SecurityWeb App Security

CMMC Level 2 Self-Assessment in 2026: Scanning and Pentest Evidence That Holds Up

CMMC Level 2 self-assessment after the 2026 suspension: what RA.L2-3.11.2 and CA.L2-3.12.1 require, the 5-point POA&M trap, and the evidence DIBCAC accepts.

19 min read

Test d'intrusion pour la certification TGV (2026) : exigences, portée, délais et coût
Web App SecurityNetwork Security

Test d'intrusion pour la certification TGV (2026) : exigences, portée, délais et coût

Test d'intrusion TGV : boîte blanche, tous les rôles, rapport en français, correctifs en 15 jours, test annuel. Ce que Santé Québec exige en 2026.

17 min read

Automated Penetration Testing Platforms (2026): Coverage, Gaps and the Best Ranked
Web App SecurityNetwork Security

Automated Penetration Testing Platforms (2026): Coverage, Gaps and the Best Ranked

Automated penetration testing platforms in 2026: the four categories, what autonomy finds and misses, published prices, and 11 platforms ranked.

19 min read

Contents

X