CMMC vs CPCSC: Canadian Defence Contractor Compliance Guide

If you are a Canadian defence supplier searching for CMMC, you may be looking for the Canadian requirement instead. The U.S. program is CMMC. Canada's defence-supplier program is CPCSC, the Canadian Program for Cyber Security Certification.

The two programs are aligned at the control level, but the contract triggers, evidence path, attestation process, and acceptance rules are different. Treat CMMC as useful context. Treat CPCSC as the Canadian procurement requirement to confirm against your contract.

Quick Answer

What is the difference between CMMC and CPCSC?

CMMC applies to U.S. Department of Defense contracts. CPCSC applies to select Canadian defence contracts. Canada based CPCSC on ITSP.10.171, its adaptation of NIST SP 800-171, the same standard family that underpins CMMC, though the two programs draw on different revisions and there is no reciprocity agreement. Canada may accept a valid CMMC certification case by case after confirming the assessment covers the required scope, and reserves the right to verify specific controls. Canadian suppliers still need to confirm CPCSC applicability, prepare CanadaBuys attestation records, and retain evidence for the Canadian contract.

Who this applies to

Canadian defence suppliers, subcontractors, and cross-border teams working with DND, PSPC, U.S. DoD, or defence primes

Timeline

CPCSC Level 1: available April 2026 and introduced in select defence contracts beginning summer 2026

Investment

Budget depends on scope, current controls, evidence quality, and whether the supplier also needs CMMC

Guide

Get the CPCSC Level 1 planning guide.

Use the guide to anchor the Canadian side of the comparison before you map CMMC reuse, CanadaBuys proof, and contract-specific evidence.

If you already know both programs may apply, use the readiness call below.

By submitting, you agree to our Terms of Service and Privacy Policy.

Practical answer

The practical answer for Canadian suppliers.

A Canadian supplier should ask three questions before starting any CMMC or CPCSC work:

  1. Which contract is driving the requirement? Canadian defence contract language points you toward CPCSC. U.S. DoD contract language points you toward CMMC.
  2. What sensitive information is in scope? CPCSC centers on federal Specified Information. CMMC centers on FCI and CUI.
  3. Can one control program support both? Often, yes. Shared controls can reduce duplicate work, but the evidence package and submission path still need to match each program.

Side by side

CMMC and CPCSC compared.

Question CPCSC CMMC
Primary market Canadian defence procurement, especially selected DND and PSPC contracts. U.S. defence contracts and prime-contractor flowdowns that name a CMMC requirement.
Information protected Federal Specified Information handled on supplier systems, networks, and applications. Federal Contract Information and Controlled Unclassified Information tied to U.S. DoD work.
Level 1 Annual self-assessment against 13 controls. Available April 2026 and introduced in select defence contracts beginning summer 2026. Annual self-assessment for Level 1, with results and affirmation entered in SPRS. This remains an active Phase I path where the contract requires it.
Higher levels Levels 2 and 3 are under development. Level 2 is planned around 98 controls, an external assessment every three years by an accredited certification body, annual affirmation, and select defence contract use beginning spring 2027. Level 3 is planned around 200 controls and a National Defence assessment. CMMC is paused in Phase I. Phase II, which was scheduled to expand Level 2 C3PAO assessments on November 10, 2026, was suspended on July 13, 2026. Current Phase I contracts may require Level 2 self-assessment. The official program page says NIST SP 800-171 Revision 2 self-assessments and select government-led assessments continue during the review.
Where proof lives Proof of self-attestation, including expiry date, is lodged in CanadaBuys when Level 1 applies. Current Phase I Level 1 and Level 2 self-assessment results and affirmations are entered in SPRS. C3PAO and later-phase record paths are planning background while Phase II is suspended.
CMMC reuse for CPCSC Canada may accept valid CMMC status case by case after scope confirmation and may verify specific controls. A CPCSC status should not be assumed to satisfy a U.S. CMMC contract requirement.

Process

A clean readiness path.

1. Confirm the contract driver

Read the solicitation or flow-down language. A Canadian DND or PSPC clause should be evaluated for CPCSC. A U.S. DoD clause should be evaluated for CMMC.

2. Scope the data and systems

Map where contract information is stored, processed, and transmitted. Include Microsoft 365, Google Workspace, endpoints, cloud accounts, backups, tickets, and vendors.

3. Build evidence before attesting

Do not treat self-assessment as a checkbox exercise. Retain control statements, screenshots, configuration exports, access reviews, diagrams, and remediation notes.

Reuse

What changed in CMMC, and can existing work help with CPCSC?

On July 13, 2026, the CMMC program office suspended Phase II, which had been scheduled to begin on November 10, 2026. CMMC is paused in Phase I. Level 1 and Level 2 self-assessment requirements remain active where a contract requires them. The broader Level 2 C3PAO path is not an active Phase I assessment path. Existing CMMC work can still help, but only if the scope matches. Canada may accept an existing valid CMMC certification case by case after confirming that the assessment covers the required Canadian scope. Canada may also verify specific controls. Acceptance is not automatic. The official CMMC status source below was checked July 18, 2026.

That means a Canadian supplier with CMMC should prepare a mapping pack, not a shortcut claim. Show which systems were assessed, which contract information they cover, which controls are shared, and what remains Canadian-specific, including CanadaBuys proof of self-attestation when Level 1 applies.

CMMC can also flow down through U.S. prime and subcontractor chains when FCI or CUI is processed, stored, or transmitted. Subcontractors that only provide commercially available off-the-shelf items are treated differently under FAR flowdown language, so check the clause before assuming every supplier tier has the same obligation.

If you already hold CMMC status and want Canada to assess it for CPCSC, Canada says proof of CMMC certification can be sent to tpsgc.pacertcybersecur-apcybersecurcert.pwgsc@tpsgc-pwgsc.gc.ca for verification and assessment.

Frequently asked

Frequently asked questions

Is CPCSC the Canadian version of CMMC?

CPCSC is Canada's domestic cyber security certification program for defence suppliers. It uses technical controls closely aligned with CMMC, but Canada and the U.S. run separate programs with different contract, scope, evidence, and submission paths. A Canadian contract controls the CPCSC requirement. A U.S. defence contract or prime-contractor flowdown controls the CMMC requirement.

Can a CMMC certification satisfy CPCSC?

Not automatically. Canada may accept an existing valid CMMC certification case by case after confirming that the assessment covers the required scope, and it may verify specific controls. That is a review path, not reciprocity or guaranteed acceptance. Keep CPCSC scope records, Level 1 self-assessment results, CanadaBuys proof, and Canadian contract records ready.

Do Canadian suppliers need CMMC?

Canadian suppliers may need CMMC when a U.S. defence contract or prime-contractor flowdown requires it. CMMC is paused in Phase I after Phase II was suspended on July 13, 2026. Under current official guidance, Phase I may require Level 1 or Level 2 self-assessment where the contract names it. CPCSC applies through Canadian contract requirements, so cross-border suppliers may still need both programs for different work.

When does CPCSC Level 1 apply?

CPCSC Level 1 became available in April 2026 and is being introduced in select Canadian defence contracts beginning in summer 2026. During the initial phase, Level 1 certification is required at contract award rather than throughout the bidding process.

What should Canadian suppliers do first?

Start by identifying whether your near-term contract is Canadian, U.S., or both. Then define the information scope, map where sensitive contract data lives, compare your current controls against CPCSC Level 1 and applicable CMMC requirements, and retain evidence before you attest.

Need help deciding which path applies?

Pilotcore helps Canadian defence suppliers scope CPCSC and CMMC requirements, map shared controls, prepare evidence, and plan readiness work. CPCSC is still rolling out, so we provide readiness support only. We help you prepare for the current self-assessment path. If a future contract names an independent CMMC or CPCSC assessment, we can prepare the handoff. We do not issue official certifications or determine the assessor's result.

Contract and flow-down requirement review
Specified Information, FCI, and CUI scope mapping
CPCSC Level 1 evidence and attestation preparation
CMMC/CPCSC control mapping for cross-border suppliers

Short readiness discussion to identify your likely contract driver, scope, and next evidence step.

References

Official sources.