CPCSC
7 min readCPCSC vs CMMC: what a Canadian supplier to U.S. primes has to do twice
CPCSC and CMMC grow from the same NIST SP 800-171 root, but there is no published reciprocity, so a Canadian supplier selling into both defence markets needs both. Here is where they overlap, where they differ, and how to build once and attest twice.
There is no published reciprocity between CPCSC and CMMC. If you sell to the Department of National Defence and to U.S. Department of Defense primes, you need both. The good news is that both programs are built on NIST SP 800-171, so most of the technical work counts twice. The bad news is that the assessments, the assessors, the paperwork and the renewal cycles do not. This article lays out what transfers and what you have to do again.
What the two programs share
CMMC is the U.S. Department of Defense program that verifies contractors protect federal contract information and controlled unclassified information. CPCSC is Canada's program for protecting what Ottawa calls specified information in non-government systems. Both take NIST SP 800-171 as the technical baseline. Both use a tiered model: a self-assessed entry level for basic safeguarding, a third-party assessed middle level for sensitive information, and a government-led top level for the most critical work. Both require an annual affirmation at the assessed levels and re-assessment every three years.
In practice that means an access control policy, a multi-factor authentication rollout, a patching cadence, a boundary diagram and an incident response plan built properly for one program are most of the way to satisfying the other.
Where they differ
The differences are in the details, and the details are what assessors check.
- The control set. CMMC Level 2 assesses against NIST SP 800-171 Revision 2, which has 110 requirements. CPCSC Level 2 assesses against ITSP.10.171, Canada's adaptation of the newer Revision 3, with 98 controls. The numbering, grouping and some wording differ, so a crosswalk is essential.
- The entry level. CMMC Level 1 is a self-assessment against a short list of basic safeguarding requirements. CPCSC Level 1 is a self-assessment against 13 ITSP.10.171 requirements, recorded in CanadaBuys and checked at contract award.
- The assessors. CMMC Level 2 certificates come from a C3PAO accredited under the Cyber AB. CPCSC Level 2 assessments come from certification bodies accredited by the Standards Council of Canada. One does not stand in for the other.
- The timing. CMMC has been phasing into U.S. contracts since late 2025. CPCSC Level 1 arrived in select Canadian contracts in summer 2026, with Level 2 and Level 3 requirements being incorporated gradually from April 2027.
- The information in scope. CMMC scopes around FCI and CUI. CPCSC scopes around specified information. The concepts overlap heavily, but the boundary you draw for one contract does not automatically match the other.
What Canada has actually said about CMMC
Public Services and Procurement Canada's supplier guidance says that defence suppliers already certified under CMMC should review ITSP.10.171 and contact the CPCSC program. That is an invitation to a conversation, not a recognition pathway. Until an equivalence arrangement is published, plan as though a CMMC certificate earns you goodwill and a head start, and nothing more.
Build once, attest twice
The efficient approach is to treat the union of the two control sets as your target and run one program of work.
- Write one System Security Plan with a crosswalk column, so every control statement maps to both a NIST SP 800-171 Revision 2 practice and an ITSP.10.171 control.
- Keep one evidence library, organized by control family rather than by program. Assessors from either side pull from the same folder.
- Draw one boundary if you can. If the same team on the same systems handles both U.S. and Canadian information, a single enclave serves both scopes and halves the work.
- Sequence the assessments. Do whichever the nearer contract requires first, then reuse the assessor-ready package for the second within the same year while the evidence is fresh.
- Track two renewal calendars. The annual affirmations and the three-year re-assessments will not line up unless you make them.
How HuCortex handles the bridge
Our CMMC bridge advisory does exactly this: one gap assessment against both control sets, one remediation plan, one evidence package, and coordination with the accredited assessors on each side. If you already hold a CMMC certificate, we start from your existing SSP rather than from a blank page.
Ready to take the next step?
HuCortex works with Canadian businesses on CPCSC readiness, PIPEDA compliance, and managed security. Start with a free assessment.
