CPCSC requires retaining audit logs for at least 90 days online, with 1-2 years archival recommended for incident investigation.
The standard requires retaining audit records for time periods consistent with organizational records retention policies, without prescribing specific durations. This flexibility allows organizations to tailor retention based on their risk profile, contractual obligations, and operational needs.
However, the standard assumes retention periods will be formally defined through organization-defined parameters (ODPs), documented in security plans, and consistently enforced. While ITSP.10.171 doesn't mandate specific periods, it references Treasury Board directives and guidelines that inform retention policies.
Organizations must document their chosen retention periods and justify them based on risk assessments, legal requirements, and operational considerations. During Level 2 assessments, assessors will examine whether documented retention policies exist, whether they're reasonable given the organization's risk profile, and whether they're actually enforced through technical controls and operational procedures.
While organizations have flexibility, cybersecurity best practices and regulatory precedents suggest minimum retention periods:
Multiple legal frameworks influence retention requirements. The Treasury Board Directive on Security Management establishes baseline records management requirements for federal government operations that often flow to contractors through contract clauses.
Privacy legislation including federal privacy laws requires retaining personal information used for administrative decisions for at least two years following last administrative use, affecting personnel records, access logs containing user identities, and incident records involving individuals. Provincial privacy laws may impose additional retention requirements depending on jurisdictions where contractors operate.
Contract-specific requirements may specify longer retention periods than baseline standards—organizations must review each contract involving specified information for explicit retention obligations. Industry-specific regulations in sectors like healthcare, finance, or energy may mandate longer retention for certain record types.
Litigation hold requirements can suspend normal retention schedules when legal proceedings are anticipated or underway, requiring preservation of potentially relevant records. Organizations should engage legal counsel to identify all applicable retention obligations and ensure policies satisfy them.
Organizations must retain multiple categories of security-relevant records. Audit logs and security event data capture the following:
Security documentation includes the following records:
Incident response records document the following information:
Personnel security records include the following documentation:
Configuration management records document the following items:
Each category serves specific purposes for security operations, compliance demonstration, and incident investigation.
Retained records must be protected with security controls appropriate to their sensitivity. Audit logs containing specified information must receive the same confidentiality protections as the specified information itself, including encryption at rest and in transit, access controls limiting viewing to authorized security personnel, and protection from unauthorized modification or deletion.
Integrity protection through write-once storage, cryptographic signatures, or blockchain-style chaining ensures records remain tamper-proof and trustworthy as evidence. Availability and backup requires redundant storage protecting against hardware failures, geographic distribution protecting against site disasters, and regular backup verification ensuring recoverability.
Secure disposal when retention periods expire requires cryptographic erasure or physical destruction rather than simple deletion, and documentation proving disposal for compliance audits. Many organizations implement tiered storage strategies with recent logs in high-performance online storage for active monitoring, older logs in lower-cost archival storage for investigation needs, and eventual secure disposal when retention periods expire.
This balances security requirements, operational needs, and cost efficiency.
Organizations using cloud services for log storage must address additional considerations:
Organizations should formally evaluate cloud storage providers against CPCSC requirements before storing security records containing or related to specified information.
Organizations need formal policies governing records retention. The policy should include the following elements:
The policy should be formally approved by executive management, communicated to relevant personnel, and reviewed during internal audits and external assessments. During Level 2 CPCSC assessments, assessors will examine records retention policies as evidence of mature security program governance.
Organizations face several challenges implementing retention requirements. Storage costs for retaining large volumes of logs and records can be substantial, requiring budget planning and cost-optimization strategies like tiered storage, compression, and selective retention of high-value data.
Technical complexity in implementing automated retention enforcement, secure disposal, and integrity protection requires skilled personnel or external expertise. Legacy systems may lack modern logging capabilities or integration with centralized log management, creating gaps or requiring upgrades.
Balancing retention needs against privacy principles of data minimization can create tension—retaining logs longer improves security but increases privacy risk if logs contain personal information. Organizations should address these challenges through strategic planning, phased implementation starting with highest-risk systems, and investment in appropriate infrastructure and expertise.
The alternative—inadequate retention—creates severe risk by limiting incident investigation capabilities, making compliance demonstration difficult, and potentially violating legal obligations.
Additional resources on retention requirements include the following:
Preparing for CPCSC (Canadian Program for Cyber Security Certification) demands deep knowledge of the certification framework, careful evidence preparation, and hands-on technical implementation. Plurilock delivers with compliance readiness specialists serving Canadian defense suppliers who bring proven experience guiding contractors through cybersecurity certification programs on both sides of the border.
As an established CMMC readiness provider for U.S. defense contractors, we were among the first to extend that expertise north—launching CPCSC readiness services early and serving Canadian defense suppliers from the program's earliest days. We don't conduct audits; we get you ready for them, then help you stay ready.
Why we're the superior choice:
CPCSC-ready—with proven defense contractor experience guiding every step.
A plurilock representative will contact you within one business day.
Contact Plurilock
+1 (888) 776-9234 (Plurilock)