The Canadian Program for Cyber Security Certification (CPCSC) is becoming a condition of contract award for Canadian defense suppliers, and most of what's written about it sits behind a form or a sales call. This repo puts it in one place: all 98 ITSP.10.171 controls explained in plain language, Windows audit scripts that write evidence you can file, templates, and a curated set of resources that link out to the primary sources. It's built for the network admin at a 30-person shop who just got handed compliance.
It's the working companion to The Study Guide to CPCSC Readiness, a free book, and it's open: add a resource if you've found something that belongs here.
Not affiliated with Public Services and Procurement Canada (PSPC), the Canadian Centre for Cyber Security, NIST, or the CMMC program. Nothing here is an attestation, a certification, or legal advice. CPCSC is still being developed, so check the updates log and the contract in front of you.
| Folder | What's in it |
|---|---|
controls/ |
All 98 requirements by family: a plain-language reading, the evidence to keep, the values you set, and links to the standard. Plus the Level 1 checklist and crosswalk. |
scripts/ |
Read-only PowerShell that audits a Windows machine for the technical requirements and writes HTML, JSON, and CSV reports, plus a script that merges many machines into a fleet summary |
resources/ |
Government sources, standards, CMMC, hans.study material, tools and baselines, and a glossary |
templates/ |
A gap register with a row per requirement |
data/ |
The requirements and the Level 1 crosswalk as JSON and CSV |
Each page below is the reader-friendly version of what's in this repo, with a last-verified date.
| Page | What it answers |
|---|---|
| Does it apply to you? | Whether your contracts and data bring you into the program |
| Level 1 and Level 2 | What each level asks, who assesses it, and when |
| The 98 requirements | Every ITSP.10.171 requirement by family, with a plain reading |
| CPCSC vs CMMC | How the two programs differ and where they overlap |
| For MSPs and integrators | Responsibility, evidence, and remote access when a third party runs the systems |
| Glossary and FAQ | Terms and common questions |
Last verified October 5, 2026, against PSPC's program overview (revised September 29, 2026), its Level 1 guidance, and the Cyber Centre's ITSP.10.171.
| Level | Status | What it is |
|---|---|---|
| 1 | Live | Annual self-assessment against 13 requirements through PSPC's online tool, with the result and expiry date confirmed in your CanadaBuys profile. Open since April 1, 2026 and in select defense contracts since summer 2026. |
| 2 | Planned for spring 2027 | Third-party assessment of all 98 requirements by Standards Council of Canada accredited certification bodies, every 3 years with an annual affirmation. A completed Level 1 self-assessment is a prerequisite. |
| 3 | In development | Assessed by National Defence against 130-plus controls: the 98 plus enhancements adapted from NIST SP 800-172. Restated from 200 on September 29, 2026. |
Recognition between programs is limited. PSPC may accept a valid CMMC certification case by case at Level 1, after confirming its scope covers the Canadian contract data. Nothing is announced for Levels 2 and 3.
Not yet published: the Level 2 assessment methodology, the list of accredited certification bodies, fee structures, rules for open items at assessment, Level 3 criteria, and any CMMC recognition beyond Level 1. PSPC revises its pages without press releases, so the dated updates log tracks changes as they happen.
CPCSC is run by PSPC. It sets cyber security requirements for suppliers on Government of Canada defense contracts and verifies them through 3 certification levels. The level a supplier needs is named in the solicitation and the contract, one contract at a time. Enforcement runs through procurement: a supplier who can't show the named level isn't eligible for that award, and Level 1 is required at contract award, with proof included in the bid.
The program protects Specified Information, sensitive but unclassified government information that a contract identifies as needing safeguarding on supplier systems. Drawings, statements of work, schedules, pricing, and Controlled Goods data are typical. It reaches any supplier whose systems store, process, or transmit it under a defense contract, at any tier. The test is the data, not company size, and a prime's certification doesn't cover its subcontractors.
Answer them against the systems inside your boundary only, after you've mapped where Specified Information lives. Each one links to its entry in controls/.
| ITSP.10.171 | Requirement |
|---|---|
03.01.01 |
Account management |
03.01.02 |
Access enforcement |
03.01.20 |
Use of external systems |
03.01.22 |
Publicly accessible content |
03.05.01 |
User identification, authentication, and re-authentication |
03.05.02 |
Device identification and authentication |
03.05.03 |
Multi-factor authentication |
03.08.03 |
Media sanitization |
03.10.01 |
Physical access authorizations |
03.10.07 |
Physical access control |
03.13.01 |
Boundary protection |
03.14.01 |
Flaw remediation |
03.14.02 |
Malicious code protection |
The technical bar is modest, and the weight sits in the signature: the attestation is a representation made in a federal contract context, renewed every year. The one that catches people is 03.05.03. It requires multi-factor authentication for privileged and non-privileged accounts, and CMMC Level 1 has no such requirement, so a shop that cleared CMMC Level 1 on passwords isn't at CPCSC Level 1 yet. The Level 1 checklist adds the evidence to keep and the filing steps.
ITSP.10.171 is the Cyber Centre's Canadian version of NIST SP 800-171 Revision 3: 98 requirements in 17 families, each with discussion text. Identifiers match NIST's, the ones NIST withdrew stay in the numbering as "not allocated," and Canada added one requirement of its own, 03.14.09, the dedicated administration workstation. The second release, the current one, is dated October 28, 2025.
| Code | Family | Requirements | At Level 1 |
|---|---|---|---|
| 01 | Access control | 16 | 4 |
| 02 | Awareness and training | 2 | |
| 03 | Audit and accountability | 8 | |
| 04 | Configuration management | 10 | |
| 05 | Identification and authentication | 8 | 3 |
| 06 | Incident response | 5 | |
| 07 | Maintenance | 3 | |
| 08 | Media protection | 7 | 1 |
| 09 | Personnel security | 2 | |
| 10 | Physical protection | 5 | 2 |
| 11 | Risk assessment | 3 | |
| 12 | Security assessment and monitoring | 4 | |
| 13 | System and communications protection | 10 | 1 |
| 14 | System and information integrity | 6 | 2 |
| 15 | Planning | 3 | |
| 16 | System and services acquisition | 3 | |
| 17 | Supply chain risk management | 3 |
Many requirements leave a value to you: the inactivity period before an account is disabled, failed logons before lockout, log retention, patch windows. Unless the contract names one, you choose it, record it in your system security plan, and defend it at assessment. Each control page marks where that applies.
The 2 programs share a technical spine and almost nothing else.
| CPCSC (Canada) | CMMC (United States) | |
|---|---|---|
| Owner | PSPC | Department of Defense |
| Standard | ITSP.10.171, from NIST SP 800-171 Rev 3 | NIST SP 800-171 Rev 2 |
| Level 1 | 13 requirements, MFA included | 15 requirements (FAR 52.204-21), no MFA |
| Level 2 | 98 requirements, third-party assessed | 110 requirements |
| Level 3 | 130-plus controls, assessed by National Defence | Level 2 plus 24 from NIST SP 800-172 |
| Results filed in | CanadaBuys | SPRS |
The full comparison is in CMMC and the US program.
| Date | What happened |
|---|---|
| Fall 2023 | Treasury Board approved CPCSC; Budget 2023 set aside $25 million for design and implementation through 2025 to 2026 |
| March 2025 | Phase 1 launched; the Standards Council of Canada began accepting certification body applications |
| April 2, 2025 | ITSP.10.171 first release took effect |
| October 28, 2025 | ITSP.10.171 second release, the current version |
| April 1, 2026 | Level 1 self-assessment opened through CanadaBuys |
| April 14, 2026 | PSPC formally announced Level 1 |
| Summer 2026 | Level 1 requirements began appearing in select defense contracts |
| September 29, 2026 | PSPC revised its program overview and restated Level 3 as 130-plus controls |
| Spring 2027 | Level 2 third-party assessments planned for select contracts |
- List the contracts carrying Specified Information clauses.
- Map where that data lives and draw the boundary around those systems.
- Answer the 13 Level 1 requirements against those systems only.
- Capture one dated evidence artifact per requirement.
- Fix gaps before attesting; Level 1 gaps are cheap.
- Record the result and expiry date in CanadaBuys.
- Re-run the assessment when the environment changes, and again before the expiry date.
If Level 2 is ahead of you, scoping comes before anything you buy, because where Specified Information lives decides what you pay. To check the technical side of a Windows machine, run the audit script. To apply Windows hardening baselines for CMMC and CPCSC readiness, use CMMC-CPCSC-ITSP10171.ps1 in the windows-hardening-scripts repo.
The Study Guide to CPCSC Readiness: A Field Reference for Canadian Defense Suppliers is Book 3 in The Study Guide series by Hans Study. First edition, revision 1.3.2, October 2026. 12 chapters, free to read online or download, DOI 10.5281/zenodo.23145960, CC BY-ND 4.0.
Site copy · Zenodo v1.3.2 · DOI 10.5281/zenodo.23145960 · Internet Archive · Wikidata Q141648473
Also: Download the PDF · Sampler PDF · Templates · Policy builder
| Source | Why it matters |
|---|---|
| PSPC program overview | The federal bodies, the outcomes, and the level definitions |
| How to meet Level 1 requirements | PSPC's Level 1 criteria and the scoping guide |
| CPCSC Level 1 self-assessment tool | Where the annual self-assessment is completed |
| ITSP.10.171 | The Cyber Centre standard, with discussion text for every requirement |
| NIST SP 800-171 Rev 3 | The US document ITSP.10.171 adapts |
| Standards Council of Canada, CPCSC | Accreditation of the Level 2 certification bodies |
| CanadaBuys | Where results are recorded in your supplier profile |
Everything else, with notes, is in resources/.
Found something that belongs here? Any of these works:
- Email contact@hans.study with the link and a line on why it's useful.
- Open an issue with the suggest a resource form.
- Fork the repo, add a row to the right page in
resources/, and open a pull request.
Keep it to primary sources, free tools, and material a small supplier can use. Details are in resources/README.md. Spotted a mistake in a control? Open an issue or a pull request with a link to the source. Security problems go privately to bugs@hans.study, as described in SECURITY.md.
Hans Study is an independent network and security consultant in Ontario, Canada. The practice reviews a supplier against the 13 Level 1 requirements and writes a plain-language gap list, and it supports CMMC and NIST SP 800-171 readiness on both the technical and documentation sides. Start at CMMC 2.0 and CPCSC compliance, or write to contact@hans.study.
Elsewhere: LinkedIn · YouTube · ORCID · Wikidata · Amazon author page · DEV Community
- Scripts in
scripts/are MIT. - Documentation, controls, resources, templates, and data are CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with every copy, including copies an MSP makes for a client.
- The book is CC BY-ND 4.0 and isn't part of this repo.
To cite this work, use the book's DOI or the metadata in CITATION.cff.
Maintained by Hans Study, independent network and security consultant, Ontario, Canada · hans.study