CPCSC Consulting Overview

The Canadian Program for Cyber Security Certification (CPCSC) is Canada's cybersecurity certification program designed to protect sensitive government and defence information shared with contractors and suppliers. It establishes a consistent set of cybersecurity requirements that organisations must implement to demonstrate their ability to safeguard controlled information and meet contractual obligations.

At Coral, we assist clients in implementing this standard using a structured approach of scoping, gap analysis, risk assessment, security policy documentation, implementation support and internal audit. What we do helps your organisation reduce cybersecurity risks and achieve CPCSC certification.

Interested? Please reach out to us, and we can get started.

Start Your CPCSC Journey Now!

Coral Implementation Phases

Phase I – Gap Analysis & Readiness Assessment

Every organisation has a unique business model, technology environment, and cybersecurity maturity. Our engagement begins by understanding your organisation's scope, identifying the applicable Canadian Program for Cyber Security Certification (CPCSC) level, and assessing your existing cybersecurity controls against the program requirements.

Activities include:

  • Defining the certification scope
  • Understanding business processes and technology environment
  • Identifying the applicable CPCSC certification level
  • Performing a comprehensive gap analysis
  • Assessing current cybersecurity maturity
  • Developing a prioritised implementation roadmap

Deliverable

A detailed Gap Analysis Report outlining compliance status, identified gaps, implementation priorities, risks, and recommended remediation activities.

Phase II – Implementation & Control Development

Based on the gap assessment, Coral works with your business and IT teams to implement the required governance, administrative, technical, and operational cybersecurity controls.

Typical activities include:

  • Cybersecurity risk assessment and treatment planning
  • Development of policies, standards, procedures, and supporting documentation
  • Implementation of applicable security controls
  • Asset inventory and information classification
  • Identity and access management improvements
  • Security awareness and role-based training
  • Incident response and business continuity planning
  • Supplier security and third-party risk management
  • Evidence collection for implemented controls

Deliverable

A fully implemented cybersecurity management program supported by documented processes, operational evidence, and clearly assigned responsibilities.

Phase III – Internal Audit & Certification Readiness

Once implementation is complete, we independently verify that the controls are operating effectively and that sufficient evidence exists to support certification.

Activities include:

  • Internal compliance assessment
  • Control effectiveness testing
  • Technical and procedural evidence review
  • Risk and remediation validation
  • Internal audit
  • Management review facilitation
  • Certification readiness assessment
  • Closure of outstanding observations

Deliverable

A Certification Readiness Report confirming that the organisation is prepared for the external certification assessment.

Phase IV - Certification Support & Operational Handover

Coral continues to support your organisation throughout the certification process and ensures that your internal teams are equipped to maintain compliance after certification.

Activities include:

  • Support during the certification assessment
  • Coordination with the certification body
  • Responding to assessor questions
  • Evidence management and submission support
  • Assistance with remediation of any observations
  • Operational handover to internal process owners
  • Compliance calendar and continual improvement planning

Deliverable

Successful certification supported by a structured operational handover, enabling your organisation to maintain compliance and continually improve its cybersecurity program.

Levels of cyber security certification
The program’s mandatory cyber security certification requirements is made up of three levels:
01

Level 1

Requiring an annual cyber security self-assessment.

02

Level 2

Requiring an external cyber security assessment every three years, led by an accredited certification body.

03

Level 3

Requiring a cyber security assessment every three years, conducted by National Defence.

Level Summary
Level 1 The CPCSC’s Level 1 introduces 13 cybersecurity requirements and controls that suppliers are expected to assess and document against their current practices. The requirements will become mandatory in phases, giving suppliers sufficient time to understand the expectations, address identified gaps, and demonstrate compliance with Level 1.
Level 2 Level 2 involves a more detailed assessment of an organization’s implementation of the required cybersecurity controls. These assessments will be performed by independent third-party assessment organizations accredited by the Standards Council of Canada (SCC).
Level 3 Level 3 applies to the most sensitive and high-risk defence activities. Unlike Level 2, these assessments will be performed directly by the Government of Canada rather than independent third-party assessors. This level is intended for contracts involving highly sensitive activities, such as weapon systems, access to critical infrastructure, or sensitive information shared with Five Eyes partners.
Call or write to us at :
for proposal / roadmap / information
Would You Like To Speak To Our CPCSC Implementation?
Contact Us Now !