CPCSC
7 min readHow to self-attest for CPCSC Level 1 in CanadaBuys: a step-by-step walkthrough
CPCSC Level 1 is a self-assessment against 13 controls, recorded with an expiry date in your CanadaBuys supplier profile and checked at contract award. Here is the exact sequence, what to keep as evidence, and the mistakes that stall suppliers.
CPCSC Level 1 is a self-assessment, not an audit. You confirm that your organization implements 13 security requirements from ITSP.10.171, record the result and its expiry date in your CanadaBuys supplier profile, and repeat it every year. Public Services and Procurement Canada checks it at contract award, not during bidding. That sounds simple, and the mechanics are, but most of the suppliers who stall do so because they skipped scoping or cannot produce evidence when a contracting authority asks. Here is the sequence that works.
Step 1: confirm that Level 1 applies to you
Read the solicitation. Since summer 2026, select Department of National Defence contracts state a CPCSC level as a requirement, and the requirement is enforced at award. If the solicitation names Level 1, you need a valid self-attestation on file before the contract can be signed. If it names Level 2 or Level 3, the self-assessment is still useful groundwork, but it is not enough on its own.
Make sure your organization has an active CanadaBuys account. The attestation lives in the organizational supplier profile questionnaire, so without an account there is nowhere to record it.
Step 2: draw the boundary before you assess anything
The 13 controls apply to every system, device, person and facility that can access specified information, which the scoping guide defines as any Government of Canada information that must be protected when a non-government organization handles, processes or stores it. You decide whether that boundary is your whole organization or a bounded enclave, such as one team with its own devices and file store. The guide is blunt about one thing: you cannot exclude a device because someone thinks it is not important. Include or exclude based on whether it can reach the information.
Cloud services and managed providers that touch the information are inside the boundary too, and you remain responsible for verifying that they meet the requirements. Write the boundary down. A one-page diagram plus an asset list is the evidence a contracting authority will ask for first.
Step 3: run the self-assessment against the 13 requirements
The Canadian Centre for Cyber Security publishes an online self-assessment tool for CPCSC. Using it is encouraged rather than mandatory, and it is worth using because it walks you through the intent of each requirement. The 13 requirements, by their ITSP.10.171 identifiers, are:
- 03.01.01 Account management
- 03.01.02 Access enforcement
- 03.01.20 Use of external systems
- 03.01.22 Publicly accessible content
- 03.05.01 User identification, authentication and re-authentication
- 03.05.02 Device identification and authentication
- 03.05.03 Multi-factor authentication
- 03.08.03 Media sanitization
- 03.10.01 Physical access authorizations
- 03.10.07 Physical access control
- 03.13.01 Boundary protection
- 03.14.01 Flaw remediation
- 03.14.02 Malicious code protection
Step 4: close the gaps honestly
Answer as you are, not as you plan to be. The usual gaps we see are multi-factor authentication that covers email but not the file server or VPN, no written list of who is allowed into the office areas where the information is handled, and no process for wiping drives before old laptops leave the building. Each of those is a few days of work, not a project. Fix them, then re-run the assessment.
Keep the artefacts as you go: the MFA policy export, the physical access list, the patching report, the disposal log. A self-attestation without evidence behind it is a liability the day someone asks to see it.
Step 5: record the attestation in CanadaBuys
In your CanadaBuys organizational supplier profile, record the self-assessment result and its expiry date. The guidance also asks for proof of self-attestation when you submit a bid, so keep the assessment output where your bid team can find it. Decide internally who signs. The federal pages do not prescribe a role, but you are making a formal representation to the Government of Canada, so treat it like any other contractual declaration and have an officer of the company own it.
Step 6: put the renewal in the calendar
The self-assessment is annual. Set a reminder 60 days before expiry, because a lapsed attestation at award time is the easiest way to lose a contract you have already won. Re-scope at renewal as well: a new office, a new cloud tool or a new subcontractor changes the boundary.
Where HuCortex fits
We run the scoping, the assessment and the gap fixes as one short engagement, and hand you the evidence package and the boundary document so the CanadaBuys entry is a formality. For suppliers who will need Level 2 later, we build the Level 1 work so nothing has to be redone.
Sources
- How to meet Level 1 cyber security certification requirements, Public Services and Procurement Canada
- CPCSC Level 1 criteria (the 13 requirements), Public Services and Procurement Canada
- Level 1 cyber certification scoping guide, Public Services and Procurement Canada
- Additional information and support for suppliers about cyber security, Public Services and Procurement Canada
Ready to take the next step?
HuCortex works with Canadian businesses on CPCSC readiness, PIPEDA compliance, and managed security. Start with a free assessment.
