The Canadian Program for Cyber Security Certification: How It Relates to UK Defence Requirements

Gareth Shaw, CEO Pera Prometheus

Key Takeaways

  • The Canadian Program for Cyber Security Certification (CPCSC) is built on ITSP.10.171, which adapts NIST SP 800-171 and NIST SP 800-172.
  • The UK’s Defence Cyber Certification (DCC) is built on DEFSTAN 05-138 Issue 4, which draws from NIST but is not a NIST-based standard.
  • CPCSC Levels 1–3 and DCC Levels 0–3 share similar intent — but different foundations, assessment routes, and evidence expectations.
  • UK organisations with DCC, Cyber Essentials, or ISO 27001 already operate many of the required controls — but certification does not translate directly.
  • Understanding the relationship between CPCSC and UK Defence assurance is essential for organisations working across NATO supply chains.

Why This Matters Now

With the Manitoba–UK Defence Summit taking place this week, cross-border defence collaboration is accelerating. UK organisations increasingly engage with Canadian primes, SMEs, and government programmes — and cyber assurance is now a central part of that cooperation.

The question is no longer “What do organisations need to do to meet Canadian and UK cyber assurance requirements?” The real question — and the one Pera Prometheus is uniquely positioned to answer — is:

How do Canadian Defence cyber requirements relate to the UK Defence assurance landscape?

Understanding this relationship helps organisations plan strategically, avoid duplicated effort, and build a coherent assurance posture across both jurisdictions.

What CPCSC Actually Is — From a UK Perspective

The Canadian Program for Cyber Security Certification (CPCSC) is Canada’s official cyber security supply-chain certification for Defence suppliers. It is administered by Public Services and Procurement Canada, supported by:

  • Department of National Defence
  • Standards Council of Canada
  • Canadian Centre for Cyber Security

CPCSC applies to sensitive federal contract information below the classified threshold, similar to the UK’s Cyber Security Model (CSM) and DCC.

Where a UK MOD contract specifies a Cyber Risk Profile and DCC level, a Canadian Defence contract may specify a CPCSC level.

The Standard Beneath CPCSC: ITSP.10.171 and NIST

CPCSC is built on ITSP.10.171, Canada’s adaptation of:

  • NIST SP 800-171 — controls for protecting Controlled Unclassified Information (CUI)
  • NIST SP 800-172 — enhanced controls for higher-risk work

This is important for UK suppliers because:

  • NIST influences DEFSTAN 05-138, but DEFSTAN is not a NIST standard
  • NIST 800-171 also underpins the US CMMC programme

This is the first major divergence between UK and Canadian Defence cyber requirements.

CPCSC Levels vs UK DCC Levels

CPCSC has three levels:

  • Level 1 — 13 controls, self-assessment
  • Level 2 — 98 controls, external assessment
  • Level 3 — 200 controls, assessed by National Defence

Levels 2 and 3 are still under development.

DCC has four levels (Cyber Risk Profile Levels):

  • Level 0 — 3 controls, self-assessment validated by an external Assessor
  • Level 1 — 101 controls, full external assessment
  • Level 2 — 139 controls, enhanced external assessment
  • Level 3 – 144 Controls, advanced external assessment

The UK’s DCC has four levels (0–3), assessed by IASME Certification Bodies, built on DEFSTAN 05-138 Issue 4.

Both schemes aim to:

  • Protect sensitive defence contract information
  • Raise the security floor across the supply chain
  • Ensure suppliers meet a defined assurance standard before handling sensitive data

Evidence Expectations

NIST-based schemes require structured, control-by-control evidence. DEFSTAN-based schemes require assurance across organisational processes, systems, and governance.

How CPCSC Relates to UK Defence Requirements

  • CPCSC is not DCC.  A DCC certificate does not map across to a CPCSC level. A Cyber Essentials Plus certificate does not map onto a CPCSC level.  The underlying standards differ, and no reciprocity agreement exists.
  • The controls overlap — the standards do not.  If you already operate:
  • Cyber Essentials
  • Cyber Essentials Plus
  • DCC Level 0–3
  • ISO 27001
  • NIST-aligned controls

You already meet many of the technical requirements CPCSC expects.  But the assessment mechanism is different.

  • UK and Canadian Standards Alignment.  The UK DEFSTAN 05-138 was shaped with NIST in mind, UK suppliers often find that:
  • Access control
  • Configuration management
  • Logging
  • Incident response
  • Personnel security
  • System integrity

Align well with Canadian ITSP.10.171. standards. The discipline required to maintain DCC and Cyber Essentials gives UK suppliers a strong evidence base for CPCSC.

  • Gap Analysis.  The only reliable way to understand your position is to map your existing controls against CPCSC or DCC respectively.  Do it once, do it properly, and identify the real gap.  Once you have this information, you can identify a Remediation Plan and implement it.  This avoids guesswork and prevents duplicated effort. 

What This Means for Cross-Border Defence Collaboration

As UK and Canadian defence cooperation grows — particularly under NATO programmes — suppliers will increasingly need to demonstrate assurance across both jurisdictions.

The practical implications:

  • UK suppliers should treat CPCSC as a distinct scheme, not an extension of DCC.
  • Canadian suppliers working with UK primes should understand DEFSTAN 05-138 and DCC.
  • Organisations operating in both markets should build a single, coherent control set mapped to both standards.
  • Early adopters will gain competitive advantage as CPCSC Levels 2 and 3 mature.

Conclusion

CPCSC represents Canada’s own Defence cyber assurance baseline — built on NIST 800-171 and structurally similar to the UK’s DCC but fundamentally different in its foundations.

For Canadian and UK organisations wishing to collaborate within each others Defence environments the message is clear:

Similar intent. Different standard

Similar controls. Different evidence

Similar goals. Different pathways

At Pera Prometheus, we help defence suppliers map their existing UK assurance posture against Defence and commercial frameworks, identify gaps, and build a practical route to compliance — without duplicating effort or reinventing controls.

I will be attending the Manitoba–UK Defence Summit on 28–29 September 2026. If you are attending, it is an ideal moment to connect on cross-border assurance and the future of UK–Canada Defence collaboration.