Contact us today.Phone: +1 888 776-9234Email: sales@plurilock.com

How do I complete the CPCSC Level 1 self-assessment?

The Level 1 self-assessment process is designed to be accessible for organizations of all sizes, including small and medium businesses without large IT departments. Understanding the process, preparation steps, and expected timeline helps executives plan resources appropriately.

Answer

Complete the online self-assessment tool after gathering security documentation and establishing basic policies, then update your CanadaBuys profile.

Preparation Before Starting

Before beginning the self-assessment, gather comprehensive information about your security posture.

Create lists documenting the following:

  • Where Government of Canada information is stored in your systems
  • Which systems, devices, and people access it
  • Which cloud services and tools handle it
  • Your current security measures

While you don't need a formal, documented security program for Level 1, you should understand where Specified Information exists in your environment to apply controls effectively.

This preparation phase typically takes 2-4 weeks for a small to medium organization, depending on how well-documented your existing systems are.

Establish Internal Policies

Level 1 is deliberately flexible to accommodate different organizational sizes and structures, but you need some basic written policies.

These should be short, practical documents covering the following areas:

  • Password requirements
  • What systems and tools employees can use for work
  • How user access is granted and revoked
  • How employee devices are approved before connecting to networks
  • How old media and devices are securely destroyed

These policies should be a few pages long, not lengthy manuals, and stored where all employees can access them. A shared folder or corporate intranet alongside other important policy documents works well.

Policies should be communicated to all employees as part of core HR and IT onboarding materials.

Using the Online Self-Assessment Tool

The Government of Canada provides an online self-assessment tool accessible through the CPCSC program website.

If you've already completed your preparation and reviewed your business policies, the assessment itself can be completed in less than one hour.

The tool walks through the 13 controls, asking questions about your implementation of each. You indicate whether each control is fully implemented, partially implemented, or not implemented, and provide evidence or explanations as needed.

Saving and Resuming

If you discover during the assessment that you need to implement one or more controls before you can honestly attest to compliance, you can save your progress and return to it later.

This is common. Many organizations identify gaps during the assessment that require technical implementation, policy development, or procedural changes before they can complete the certification.

Don't rush to attest compliance if controls aren't truly in place. The risk of fraudulent attestation outweighs any short-term convenience.

Completing and Recording Results

Once you've confirmed implementation of all 13 controls, you complete the self-assessment and receive a results page.

This page shows your attestation status and an expiry date, since Level 1 requires annual renewal.

You must print or save this results page for your records. This documentation proves your certification status and will be needed when bidding on contracts.

Updating CanadaBuys Profile

Organizations seeking Level 1 certification must have an active CanadaBuys account if they intend to participate in procurements or hold contracts requiring CPCSC Level 1.

After completing your self-assessment, you must confirm the results and expiration date in your CanadaBuys organizational supplier profile questionnaire.

This creates an official record that procurement officials can verify when evaluating bids. The connection between your self-assessment attestation and CanadaBuys profile is a key control point preventing false claims of certification.

Evidence Requirements

For Level 1, you must keep evidence for the duration of your attestation cycle, or at least one year.

Examples of required evidence include:

  • Account lists
  • Device inventories
  • Access review notes
  • Copies of security policies
  • System update logs
  • Antivirus scan results
  • Visitor logs
  • Physical access tracking records
  • Media destruction documentation

This evidence demonstrates that your attestation is based on actual implementation, not just paperwork.

If questions arise about your certification or you're selected for verification, this evidence substantiates your claims.

Alternative to the Online Tool

Suppliers can attest that they meet the 13 controls without using the online self-assessment tool.

However, the tool's use is strongly encouraged for the following reasons:

  • It provides important guidance and information about implementing controls effectively
  • It helps ensure you haven't missed aspects of a requirement
  • It creates standardized documentation

Organizations choosing not to use the tool must still maintain the same evidence and make the same attestation in their CanadaBuys profile.

Annual Renewal

Level 1 certification is not permanent. It requires annual self-assessment.

Before your certification expires, you must repeat the process with the following steps:

  • Review whether all 13 controls remain properly implemented
  • Update your attestation in the self-assessment tool
  • Confirm the new expiration date in your CanadaBuys profile

The annual cycle recognizes that security is not a one-time achievement. It is an ongoing practice requiring continuous attention as your organization, technology, and threats evolve.

Common Pitfalls to Avoid

Organizations sometimes rush through self-assessment treating it as a checkbox exercise rather than a genuine security evaluation.

This creates risk if your attestation doesn't reflect reality and controls aren't truly in place. Take the time to honestly assess each control, implement any gaps before attesting compliance, and maintain ongoing practices that keep controls effective.

Another common mistake is completing the self-assessment but forgetting to update the CanadaBuys profile. This leads to confusion when procurement officials can't verify your certification status.

Learn More

Additional resources are available online:

Why Choose Plurilock for CPCSC Readiness?

Preparing for CPCSC (Canadian Program for Cyber Security Certification) demands deep knowledge of the certification framework, careful evidence preparation, and hands-on technical implementation. Plurilock delivers with compliance readiness specialists serving Canadian defense suppliers who bring proven experience guiding contractors through cybersecurity certification programs on both sides of the border.

As an established CMMC readiness provider for U.S. defense contractors, we were among the first to extend that expertise north—launching CPCSC readiness services early and serving Canadian defense suppliers from the program's earliest days. We don't conduct audits; we get you ready for them, then help you stay ready.

Why we're the superior choice:

  • First-mover CPCSC expertise: Plurilock was among the first firms to launch dedicated CPCSC readiness services—and among the first to serve clients in this practice—giving your organization a partner with real, accumulated experience preparing suppliers for certification.
  • Deep CMMC heritage: Our established U.S. defense contractor practice has guided organizations through CMMC readiness for years, and those underlying controls map closely to CPCSC—we bring battle-tested methodologies, not theory borrowed from adjacent frameworks.
  • Federal experience on both sides of the border: With extensive engagements across U.S. and Canadian federal government environments, we understand the contractual, technical, and procedural realities that shape defense supply chain compliance.
  • Readiness assessment and gap analysis: We evaluate your current posture against CPCSC requirements, identify control gaps with precision, and deliver clear, prioritized roadmaps that align remediation effort to certification level and contract obligations.
  • Strategy and execution, not just paperwork: Beyond identifying gaps, we help you execute—planning the remediation program, supporting policy and evidence development, and preparing your team and systems so that when the assessor arrives, you're ready.

CPCSC-ready—with proven defense contractor experience guiding every step.

Reach Out Now â†’

+1 (888) 776-9234 (Plurilock)
+1 (310) 530-8260 (Aurora)
+1 (613) 526-4945 (Integra)

sales@plurilock.com

Schedule a free consultation to plot a course toward CPCSC compliance.

loading...

Thank you.

A plurilock representative will contact you within one business day.

Contact Plurilock

+1 (888) 776-9234 (Plurilock)
+1 (310) 530-8260 (Aurora)
+1 (613) 526-4945 (Integra)

sales@plurilock.com

Your information is secure and will only be used to communicate about Plurilock and Plurilock services. We do not sell, rent, or share contact information with third parties. See our Privacy Policy for complete details.

More About Plurilockâ„¢ Services

Subscribe to the newsletter for Plurilock and cybersecurity news, articles, and updates.

You're on the list! Keep an eye out for news from Plurilock.