
Filter by Tag
CPCSC & CMMC Cost in 2026: The 4 Factors
There is no single price tag for CPCSC or CMMC compliance, and any consultancy that quotes one before scoping your environment is guessing. The real...
CMMC Compliance Consulting for Canadian Defence Contractors
Canadian companies selling into the U.S. defence supply chain face a compliance requirement that is no longer theoretical. The Cybersecurity Maturity...
Risk Assessment and Security Planning for ITSP.10.171
The majority of ITSP.10.171 control families deal with operational security: how you configure systems, manage access, protect data. The Risk...
SOC 2 to CPCSC: Extending Your Security Program
The question comes up consistently when companies with established security programs look at entering the Canadian defence supply chain: Do we need...
Physical Security and Personnel Controls Under CPCSC
Every other control family in ITSP.10.171 has a reasonable analogue in the commercial compliance world. Access control maps to SOC 2 CC6. Incident...
Protecting Controlled Information: Media and Communications Security (CPCSC)
In a compliance landscape that increasingly assumes cloud-first architecture, media protection controls tend to get deprioritized. The assumption is...
Incident Response and System Integrity Under CPCSC
An incident response plan that exists only in a shared drive is not evidence of preparedness. It is evidence of intent, and the Canadian Program for...
Security Awareness, Training, and Governance for CPCSC
The previous twelve posts in this series covered the technical and operational control families in ITSP.10.171: access control, incident response,...
Configuration Management and System Maintenance for Defence Contractors Under CPCSC
There is a specific phrase that comes up in nearly every environment that has never been through a formal configuration review: We know our systems....
Audit Logging, Monitoring, and Accountability for CPCSC
Most organizations produce logs. Application servers generate them, firewalls record them, identity providers track them. The volume is rarely the...
Supply Chain Risk Management Under CPCSC
For most of the history of Canadian defence procurement, cybersecurity obligations ended at the prime contractor's perimeter. A prime could hold a...
Access Control and Identity Management Under ITSP.10.171
Every security program has access controls of some kind. Password policies exist, MFA is probably enabled somewhere, and someone has a spreadsheet...
CPCSC vs CMMC: What Dual-Jurisdiction Contractors Need to Know
CPCSC (Canada) and CMMC (United States) both derive from NIST SP 800-171, so their control sets largely overlap. They differ in how each program...
CPCSC Level 1 Self-Assessment: A Practical Guide
CPCSC Level 1 is an annual self-assessment of your organization against the expected security requirements of the Canadian Program for Cyber Security...
CPCSC: What Defence Contractors Need Before April 2026
The Canadian Program for Cyber Security Certification (CPCSC) is Canada's mandatory cybersecurity certification for companies bidding on Department...
CMMC Level 1 Compliance: Requirements and Implementation Guide
As of November 2025, CMMC is no longer a concept the DoD is considering. It is a contract requirement. Contracting officers are now including CMMC...














