The Canadian Program for Cyber Security Certification (CPCSC) is Canada's cybersecurity certification program designed to protect sensitive government and defence information shared with contractors and suppliers. It establishes a consistent set of cybersecurity requirements that organisations must implement to demonstrate their ability to safeguard controlled information and meet contractual obligations.
At Coral, we assist clients in implementing this standard using a structured approach of scoping, gap analysis, risk assessment, security policy documentation, implementation support and internal audit. What we do helps your organisation reduce cybersecurity risks and achieve CPCSC certification.
Interested? Please reach out to us, and we can get started.
Every organisation has a unique business model, technology environment, and cybersecurity maturity. Our engagement begins by understanding your organisation's scope, identifying the applicable Canadian Program for Cyber Security Certification (CPCSC) level, and assessing your existing cybersecurity controls against the program requirements.
Activities include:
Deliverable
A detailed Gap Analysis Report outlining compliance status, identified gaps, implementation priorities, risks, and recommended remediation activities.
Based on the gap assessment, Coral works with your business and IT teams to implement the required governance, administrative, technical, and operational cybersecurity controls.
Typical activities include:
Deliverable
A fully implemented cybersecurity management program supported by documented processes, operational evidence, and clearly assigned responsibilities.
Once implementation is complete, we independently verify that the controls are operating effectively and that sufficient evidence exists to support certification.
Activities include:
Deliverable
A Certification Readiness Report confirming that the organisation is prepared for the external certification assessment.
Coral continues to support your organisation throughout the certification process and ensures that your internal teams are equipped to maintain compliance after certification.
Activities include:
Deliverable
Successful certification supported by a structured operational handover, enabling your organisation to maintain compliance and continually improve its cybersecurity program.
Requiring an annual cyber security self-assessment.
Requiring an external cyber security assessment every three years, led by an accredited certification body.
Requiring a cyber security assessment every three years, conducted by National Defence.
| Level | Summary |
|---|---|
| Level 1 | The CPCSC’s Level 1 introduces 13 cybersecurity requirements and controls that suppliers are expected to assess and document against their current practices. The requirements will become mandatory in phases, giving suppliers sufficient time to understand the expectations, address identified gaps, and demonstrate compliance with Level 1. |
| Level 2 | Level 2 involves a more detailed assessment of an organization’s implementation of the required cybersecurity controls. These assessments will be performed by independent third-party assessment organizations accredited by the Standards Council of Canada (SCC). |
| Level 3 | Level 3 applies to the most sensitive and high-risk defence activities. Unlike Level 2, these assessments will be performed directly by the Government of Canada rather than independent third-party assessors. This level is intended for contracts involving highly sensitive activities, such as weapon systems, access to critical infrastructure, or sensitive information shared with Five Eyes partners. |
© 2026 www.coralesecure.com. All rights reserved | Privacy Policy