Contact us today.Phone: +1 888 776-9234Email: sales@plurilock.com

What are third-party assessors and how do I find one for Level 2?

Third-party assessors are independent organizations accredited by the Standards Council of Canada to evaluate defence contractors' compliance with CPCSC Level 2 requirements. Understanding their role, how to find qualified assessors, and what to expect from the assessment process is critical for organizations planning to pursue Level 2 certification.

Answer

Third-party assessors are independent organizations accredited by the Standards Council of Canada to evaluate defence contractors' compliance with CPCSC Level 2 requirements.

The Role of Third-Party Assessors

Unlike Level 1's self-assessment model, Level 2 requires external verification by independent experts to ensure objectivity and rigor. Third-party assessors conduct comprehensive evaluations of your security implementation across all 98 required controls, examining documentation, interviewing personnel, testing technical implementations, and observing operational practices.

They function similarly to financial auditors or ISO certification bodies, bringing independent expertise, following standardized assessment methodologies, maintaining objectivity and impartiality, and issuing formal assessment reports documenting findings.

The "third party" designation emphasizes their independence: you (the contractor being assessed) are the first party, the government (whose requirements you're meeting) is the second party, and the assessor is an independent third party with no stake in the outcome beyond professional reputation for conducting credible assessments.

Assessment Scope and Methodology

Level 2 assessments follow rigorous procedures aligned with NIST SP 800-171A, the companion document to NIST SP 800-171 that defines assessment procedures for each security requirement.

Assessors examine the following areas during their evaluation:

  • Defined system boundaries including all systems, components, and connections that process, store, or transmit specified information
  • Interviews with personnel across your organization from executives and managers to system administrators and end users to understand how security requirements are implemented in practice
  • Documentation review covering policies, procedures, system security plans, configuration baselines, change management records, incident response plans, training records, and audit logs
  • Technical testing involving examining system configurations, testing access controls, reviewing network segmentation, evaluating cryptographic implementations, and verifying security tool functionality
  • Observation of operations including watching how personnel follow security procedures, how systems respond to events, and how your security culture manifests in daily activities

The assessment typically occurs over several days or weeks depending on organization size and complexity, with both on-site and remote activities.

Finding Accredited Assessors

Once the Level 2 accreditation ecosystem matures in 2027, the Standards Council of Canada will likely maintain a public registry or directory of accredited CPCSC Level 2 certification bodies. This will be your primary resource for identifying qualified assessors.

Several resources can help you find accredited assessors:

  • The CPCSC program website maintained by Public Services and Procurement Canada, which may link to the SCC directory or provide additional guidance
  • Industry associations representing defence contractors may compile lists of accredited assessors with comparative information about their services, specializations, and costs
  • Professional networks and peers who have undergone Level 2 assessment can provide recommendations based on their experiences

When the ecosystem is nascent in 2027, options may be limited, but as it matures, multiple accredited certification bodies should emerge providing contractors with choices.

Evaluating and Selecting an Assessor

Not all SCC-accredited certification bodies will be identical, even though they all meet accreditation standards.

Consider several factors when selecting an assessor:

  • Industry expertise matters—assessors with defence industry experience will understand your operational context better than those primarily serving other industries, potentially making assessments more efficient and recommendations more practical
  • Technical expertise should align with your technology environment; if you heavily use cloud services, an assessor with cloud security assessment experience is valuable
  • Assess their assessment methodology—while all must follow baseline procedures, some may use more sophisticated tools or approaches
  • Geographic presence can be important if on-site assessment is needed, though remote assessment is increasingly viable
  • Cost is obviously a consideration, with assessment fees varying significantly based on organization size, complexity, and assessor overhead, but the cheapest option isn't always the best value if it results in less thorough assessment or poor service
  • Scheduling availability matters if you're working toward a specific contract deadline
  • References from previous clients provide insight into the assessor's professionalism, thoroughness, communication, and overall quality

Conflict of Interest and Independence

A critical rule in the certification ecosystem is that the organization conducting your formal Level 2 assessment cannot be the same organization that provided consulting services to help you achieve compliance. This independence requirement prevents conflicts of interest where an assessor might be incentivized to overlook deficiencies in systems they helped design or implement.

If you engage a consultant to help prepare for Level 2, you must use a different organization for the actual certification assessment. Some organizations offer both consulting and assessment services but maintain separate business units with information barriers between them—verify with the SCC whether such arrangements satisfy independence requirements for your specific situation.

The Assessment Process Timeline

Typical Level 2 assessments follow a multi-phase process spanning several months.

The pre-assessment phase includes:

  • Initial contracting with the certification body
  • Scoping the assessment to define system boundaries and affected systems
  • Conducting optional readiness assessments or gap analyses to identify areas needing remediation before formal assessment (though formal assessment must be conducted by an independent body)

The formal assessment phase includes:

  • Document submission where you provide policies, procedures, system security plans, and evidence to the assessor in advance
  • On-site or remote assessment activities occurring over multiple days or weeks depending on scope
  • Interviews and technical testing as described earlier
  • Preliminary findings discussion where assessors share initial observations

The post-assessment phase involves:

  • The formal assessment report documenting findings, deficiencies, and recommendations
  • Remediation of identified deficiencies if any exist
  • Certification decision where the certification body determines whether to grant certification or require additional remediation

Finally, certification issuance provides official certification documentation upon successful completion, which you then record in your CanadaBuys profile.

Cost Expectations

Level 2 assessment costs vary widely based on organizational factors. Small organizations with simple IT environments might pay in the range of $20,000-$50,000 for tri-annual assessment, while larger, more complex organizations with multiple locations, extensive IT infrastructure, and large user populations might pay $100,000 or more.

These costs cover the assessor's time for planning, conducting assessment activities, analyzing evidence, preparing reports, and managing the certification process. Travel costs may be additional if on-site assessment is required.

Organizations should obtain quotes from multiple accredited assessors and ensure quotes clearly define what's included, what's additional, and what triggers additional costs (like finding significant deficiencies requiring follow-up assessment).

Preparing for Assessment

To maximize value from your assessment investment and minimize the risk of deficiencies that delay certification, prepare thoroughly.

Follow these preparation steps:

  • Conduct self-assessment against all 98 controls using NIST SP 800-171A assessment procedures to identify and remediate gaps before engaging the formal assessor
  • Organize documentation systematically so you can efficiently provide evidence the assessor requests
  • Train personnel who will be interviewed so they understand security requirements and how your organization implements them
  • Test technical controls to ensure they're functioning as documented
  • Consider engaging a consultant (different from your certification body) for a readiness assessment that simulates the formal assessment and identifies remaining gaps

The better prepared you are, the more efficiently the assessment proceeds and the higher your likelihood of certification on the first attempt without requiring expensive remediation cycles.

Ongoing Relationship

After initial certification, you'll maintain an ongoing relationship with your certification body or potentially switch to a different accredited body for the next tri-annual assessment. Between full assessments, you must complete annual affirmations attesting that you've maintained compliance.

Some certification bodies offer surveillance or monitoring services between full assessments to help ensure continued compliance, though these are typically optional add-on services rather than mandatory requirements.

View your certification body as a partner in maintaining security posture, not just a one-time audit vendor, and leverage their expertise to continuously improve your security program.

Learn More

Additional resources are available to help you understand third-party assessments:

Why Choose Plurilock for CPCSC Readiness?

Preparing for CPCSC (Canadian Program for Cyber Security Certification) demands deep knowledge of the certification framework, careful evidence preparation, and hands-on technical implementation. Plurilock delivers with compliance readiness specialists serving Canadian defense suppliers who bring proven experience guiding contractors through cybersecurity certification programs on both sides of the border.

As an established CMMC readiness provider for U.S. defense contractors, we were among the first to extend that expertise north—launching CPCSC readiness services early and serving Canadian defense suppliers from the program's earliest days. We don't conduct audits; we get you ready for them, then help you stay ready.

Why we're the superior choice:

  • First-mover CPCSC expertise: Plurilock was among the first firms to launch dedicated CPCSC readiness services—and among the first to serve clients in this practice—giving your organization a partner with real, accumulated experience preparing suppliers for certification.
  • Deep CMMC heritage: Our established U.S. defense contractor practice has guided organizations through CMMC readiness for years, and those underlying controls map closely to CPCSC—we bring battle-tested methodologies, not theory borrowed from adjacent frameworks.
  • Federal experience on both sides of the border: With extensive engagements across U.S. and Canadian federal government environments, we understand the contractual, technical, and procedural realities that shape defense supply chain compliance.
  • Readiness assessment and gap analysis: We evaluate your current posture against CPCSC requirements, identify control gaps with precision, and deliver clear, prioritized roadmaps that align remediation effort to certification level and contract obligations.
  • Strategy and execution, not just paperwork: Beyond identifying gaps, we help you execute—planning the remediation program, supporting policy and evidence development, and preparing your team and systems so that when the assessor arrives, you're ready.

CPCSC-ready—with proven defense contractor experience guiding every step.

Reach Out Now â†’

+1 (888) 776-9234 (Plurilock)
+1 (310) 530-8260 (Aurora)
+1 (613) 526-4945 (Integra)

sales@plurilock.com

Schedule a free consultation to plot a course toward CPCSC compliance.

loading...

Thank you.

A plurilock representative will contact you within one business day.

Contact Plurilock

+1 (888) 776-9234 (Plurilock)
+1 (310) 530-8260 (Aurora)
+1 (613) 526-4945 (Integra)

sales@plurilock.com

Your information is secure and will only be used to communicate about Plurilock and Plurilock services. We do not sell, rent, or share contact information with third parties. See our Privacy Policy for complete details.

More About Plurilockâ„¢ Services

Subscribe to the newsletter for Plurilock and cybersecurity news, articles, and updates.

You're on the list! Keep an eye out for news from Plurilock.