CPCSC requires security awareness training for all users and role-based training for security personnel, both initially and at defined frequencies.
Security awareness and training requirements are fundamental to CPCSC compliance, recognizing that human factors remain among the most exploited vulnerabilities in cybersecurity.
Even the most sophisticated technical controls can be undermined by employees who don't understand security requirements, fall for phishing attacks, or inadvertently mishandle sensitive information. Understanding training obligations helps executives build security-aware cultures that complement technical protections.
The Awareness and Training family in ITSP.10.171 includes two core requirements that organizations must satisfy.
Security and privacy literacy training must be provided to all system users as part of initial training for new users and at defined frequency thereafter.
Role-based training must be provided to personnel with security responsibilities.
These requirements ensure all personnel understand baseline security principles while those with security-sensitive roles receive specialized training appropriate to their responsibilities.
All employees should receive training covering several core topics.
Understanding specified information includes what specified information is, how to recognize it in their work environment, why it requires protection, and consequences of unauthorized disclosure.
Password security covers the following topics:
Phishing and social engineering teaches recognition of suspicious emails, phone calls, and messages, verification procedures before providing sensitive information, reporting suspected social engineering attempts, and consequences of falling for attacks.
Physical security addresses the following areas:
Acceptable use policies outline approved systems and services for handling specified information, prohibited activities like using personal email for work, consequences of policy violations, and procedures for requesting exceptions.
Incident recognition and reporting helps employees understand what constitutes security incidents, how and when to report suspected incidents, the importance of prompt reporting, and protection from retaliation for reporting in good faith.
Personnel in certain roles require specialized training beyond general awareness.
System administrators need training on:
Security personnel require advanced training on:
Developers need training on:
Executives and managers benefit from training on:
HR personnel should understand:
Each role's training should align with their specific security responsibilities and the risks they manage.
Organizations can deliver security training through various approaches, each with tradeoffs.
In-person training provides direct interaction, allows questions and discussion, enables hands-on exercises, and can be tailored to specific audience needs, but requires scheduling coordination, facilities, and instructor availability.
Computer-based training offers flexibility for employees to complete at their convenience, consistency in content delivery across all employees, easy tracking of completion, and relatively low cost per employee, but lacks personal interaction, may be less engaging, and can feel like checkbox compliance.
Blended approaches combine computer-based training for foundational content with in-person sessions for advanced topics, discussions, or hands-on exercises, balancing efficiency and effectiveness.
Phishing simulations provide realistic testing of phishing recognition skills, immediate feedback when employees click suspicious links, metrics on organizational vulnerability, and reinforcement of training concepts through experiential learning.
Security communications through email newsletters, posters, screen savers, and other channels provide ongoing reinforcement between formal training sessions.
The most effective programs use multiple delivery methods tailored to content, audience, and organizational culture.
ITSP.10.171 requires training "at defined frequency" leaving specific intervals to organizational determination.
Annual security awareness training for all employees represents industry standard and satisfies most compliance frameworks.
Role-based training annually or semi-annually depending on role criticality ensures personnel with security responsibilities maintain current knowledge.
New employee training during onboarding, ideally before granting access to specified information, establishes security expectations from day one.
Event-triggered training following significant security incidents, introduction of new technologies or services, major policy changes, or identification of specific vulnerabilities provides timely, relevant education.
Continuous micro-learning through brief, frequent security tips or reminders complements formal training programs.
Organizations should document their training frequency decisions and rationale, particularly for CPCSC Level 2 assessments where assessors will examine whether training frequency is appropriate for the organization's risk profile and contractual obligations.
Effective training programs require systematic tracking and documentation.
Training records should capture the following information:
Learning management systems (LMS) provide automated tracking, reminders, and reporting for computer-based training. Attendance sheets for in-person training create records of participation. Completion certificates provide evidence for both organizational records and individual employees.
Periodic reports showing training completion rates, overdue training, and gaps help ensure comprehensive coverage.
This documentation serves multiple purposes:
For CPCSC Level 2 assessments, assessors will expect to see comprehensive training records spanning multiple years demonstrating sustained training efforts, not one-time compliance gestures.
Tracking completion rates demonstrates that training occurred, but doesn't confirm employees actually learned and apply concepts.
More sophisticated programs measure effectiveness through:
These effectiveness measures enable continuous improvement, identifying content that isn't working or topics requiring additional coverage.
Organizations that can demonstrate training effectiveness beyond just completion statistics show maturity in their security awareness programs.
The most effective security training transcends compliance to become embedded in organizational culture.
Leadership modeling where executives visibly follow security policies and discuss security importance sets tone from the top. Regular communications keep security top-of-mind through multiple channels beyond formal training.
Recognition programs acknowledge employees who demonstrate good security practices or identify security issues. Positive framing presents security as protecting the organization and its people rather than restrictive policies.
Integration with business processes embeds security considerations in everyday workflows rather than treating it as separate IT concern.
Open communication encourages reporting security concerns without fear of blame or retaliation.
Organizations that build this cultural foundation see better security outcomes than those that rely solely on compliance-driven checkbox training.
Defence contractors increasingly employ remote workers or distributed teams, creating training delivery challenges.
Online training platforms become more important when in-person delivery is impractical. Virtual instructor-led training using video conferencing can provide some interaction benefits of in-person training with geographic flexibility.
Training content must address remote work security topics:
Communication strategies ensure remote workers don't feel disconnected from organizational security culture.
Tracking and accountability may need additional attention to ensure remote workers complete training despite lacking direct supervision. Technology accessibility should be verified to ensure remote workers can access training platforms and materials from their work environments.
Security training supports multiple CPCSC requirements beyond just the Awareness and Training family.
Training users to recognize and prevent public disclosure of specified information supports Access Control requirement AC-22 on publicly accessible content.
Training on incident recognition and reporting enables effective Incident Response capabilities. Training on proper handling and disposal of media supports Media Protection requirements.
Training on physical security procedures supports Physical Protection requirements. Training on acceptable use of systems supports multiple technical controls.
This interconnectedness means effective training programs aren't just satisfying isolated training requirements but enabling broader security control effectiveness.
Organizations need not develop all training content from scratch.
The Canadian Centre for Cyber Security provides free security awareness resources and guidance tailored to Canadian context.
Commercial security awareness platforms like KnowBe4, Proofpoint, SANS Security Awareness, or Cofense provide comprehensive libraries of training content, phishing simulations, and tracking capabilities for typically $10-$30 per user annually.
Industry associations may offer sector-specific security training. Professional training organizations provide specialized courses for technical personnel on specific security topics.
Consultancies can develop customized training programs tailored to organizational needs and culture.
The choice between developing internal training content, using commercial platforms, or engaging external providers depends on budget, internal expertise, organizational size, and desired customization level.
Many organizations use hybrid approaches, leveraging commercial platforms for broad awareness training while developing custom content for organization-specific policies and procedures.
Security training represents risk management investment, not just compliance cost.
Reduced incident frequency from better employee awareness lowers incident response costs, operational disruption, and potential data breach expenses.
Improved incident detection when employees recognize and report suspicious activity enables earlier intervention.
Reduced social engineering success rates when employees identify phishing and pretexting attempts blocks a major attack vector.
Better compliance with security policies when employees understand rationale and expectations reduces audit findings. Enhanced security culture produces long-term benefits beyond individual training events.
From this perspective, security training delivers measurable return on investment through risk reduction, making it a sound business investment beyond regulatory compliance.
For additional information, consult the following resources:
Preparing for CPCSC (Canadian Program for Cyber Security Certification) demands deep knowledge of the certification framework, careful evidence preparation, and hands-on technical implementation. Plurilock delivers with compliance readiness specialists serving Canadian defense suppliers who bring proven experience guiding contractors through cybersecurity certification programs on both sides of the border.
As an established CMMC readiness provider for U.S. defense contractors, we were among the first to extend that expertise north—launching CPCSC readiness services early and serving Canadian defense suppliers from the program's earliest days. We don't conduct audits; we get you ready for them, then help you stay ready.
Why we're the superior choice:
CPCSC-ready—with proven defense contractor experience guiding every step.
A plurilock representative will contact you within one business day.
Contact Plurilock
+1 (888) 776-9234 (Plurilock)