Contact us today.Phone: +1 888 776-9234Email: sales@plurilock.com

What training must I provide to employees under CPCSC?

Security awareness and training requirements are fundamental to CPCSC compliance, recognizing that human factors remain among the most exploited vulnerabilities in cybersecurity. Even the most sophisticated technical controls can be undermined by employees who don't understand security requirements, fall for phishing attacks, or inadvertently mishandle sensitive information. Understanding training obligations helps executives build security-aware cultures that complement technical protections.

Answer

CPCSC requires security awareness training for all users and role-based training for security personnel, both initially and at defined frequencies.

Security awareness and training requirements are fundamental to CPCSC compliance, recognizing that human factors remain among the most exploited vulnerabilities in cybersecurity.

Even the most sophisticated technical controls can be undermined by employees who don't understand security requirements, fall for phishing attacks, or inadvertently mishandle sensitive information. Understanding training obligations helps executives build security-aware cultures that complement technical protections.

ITSP.10.171 Training Requirements

The Awareness and Training family in ITSP.10.171 includes two core requirements that organizations must satisfy.

Security and privacy literacy training must be provided to all system users as part of initial training for new users and at defined frequency thereafter.

  • Typically provided annually
  • When required by system changes or following defined events like security incidents
  • Covering recognizing and reporting indicators of insider threats, social engineering, and social mining

Role-based training must be provided to personnel with security responsibilities.

  • Before authorizing access to systems or specified information
  • Before performing assigned security duties
  • At defined frequency thereafter, typically annually
  • With content updated at defined frequency and following defined events

These requirements ensure all personnel understand baseline security principles while those with security-sensitive roles receive specialized training appropriate to their responsibilities.

General Security Awareness Training Content

All employees should receive training covering several core topics.

Understanding specified information includes what specified information is, how to recognize it in their work environment, why it requires protection, and consequences of unauthorized disclosure.

Password security covers the following topics:

  • Creating strong passwords or passphrases
  • Never sharing passwords
  • Using password managers
  • Recognizing password reset scams
  • Enabling multifactor authentication

Phishing and social engineering teaches recognition of suspicious emails, phone calls, and messages, verification procedures before providing sensitive information, reporting suspected social engineering attempts, and consequences of falling for attacks.

Physical security addresses the following areas:

  • Badge and access control procedures
  • Visitor escort requirements
  • Securing devices and documents
  • Clean desk policies
  • Reporting physical security concerns

Acceptable use policies outline approved systems and services for handling specified information, prohibited activities like using personal email for work, consequences of policy violations, and procedures for requesting exceptions.

Incident recognition and reporting helps employees understand what constitutes security incidents, how and when to report suspected incidents, the importance of prompt reporting, and protection from retaliation for reporting in good faith.

Role-Based Training for Specific Positions

Personnel in certain roles require specialized training beyond general awareness.

System administrators need training on:

  • Secure configuration management
  • Privileged access management
  • Security logging and monitoring
  • Backup and recovery procedures
  • Incident detection and response

Security personnel require advanced training on:

  • Threat landscape and attack techniques
  • Security tool operation and monitoring
  • Incident investigation and forensics
  • Security assessment methodologies
  • Relevant security standards including ITSP.10.171

Developers need training on:

  • Secure coding practices
  • Input validation and output encoding
  • Authentication and session management
  • Cryptographic implementation
  • Secure development lifecycle integration

Executives and managers benefit from training on:

  • Security governance and risk management
  • Incident decision-making and business continuity
  • Legal and regulatory obligations
  • Security investment justification
  • Organizational security culture

HR personnel should understand:

  • Personnel security requirements
  • Background check procedures
  • Security awareness in hiring and onboarding
  • Handling security incidents involving personnel

Each role's training should align with their specific security responsibilities and the risks they manage.

Training Delivery Methods

Organizations can deliver security training through various approaches, each with tradeoffs.

In-person training provides direct interaction, allows questions and discussion, enables hands-on exercises, and can be tailored to specific audience needs, but requires scheduling coordination, facilities, and instructor availability.

Computer-based training offers flexibility for employees to complete at their convenience, consistency in content delivery across all employees, easy tracking of completion, and relatively low cost per employee, but lacks personal interaction, may be less engaging, and can feel like checkbox compliance.

Blended approaches combine computer-based training for foundational content with in-person sessions for advanced topics, discussions, or hands-on exercises, balancing efficiency and effectiveness.

Phishing simulations provide realistic testing of phishing recognition skills, immediate feedback when employees click suspicious links, metrics on organizational vulnerability, and reinforcement of training concepts through experiential learning.

Security communications through email newsletters, posters, screen savers, and other channels provide ongoing reinforcement between formal training sessions.

The most effective programs use multiple delivery methods tailored to content, audience, and organizational culture.

Training Frequency and Triggers

ITSP.10.171 requires training "at defined frequency" leaving specific intervals to organizational determination.

Annual security awareness training for all employees represents industry standard and satisfies most compliance frameworks.

Role-based training annually or semi-annually depending on role criticality ensures personnel with security responsibilities maintain current knowledge.

New employee training during onboarding, ideally before granting access to specified information, establishes security expectations from day one.

Event-triggered training following significant security incidents, introduction of new technologies or services, major policy changes, or identification of specific vulnerabilities provides timely, relevant education.

Continuous micro-learning through brief, frequent security tips or reminders complements formal training programs.

Organizations should document their training frequency decisions and rationale, particularly for CPCSC Level 2 assessments where assessors will examine whether training frequency is appropriate for the organization's risk profile and contractual obligations.

Tracking and Documenting Training

Effective training programs require systematic tracking and documentation.

Training records should capture the following information:

  • Who received training
  • When training occurred
  • What content was covered
  • Whether the individual completed or passed any assessments
  • Next scheduled training date

Learning management systems (LMS) provide automated tracking, reminders, and reporting for computer-based training. Attendance sheets for in-person training create records of participation. Completion certificates provide evidence for both organizational records and individual employees.

Periodic reports showing training completion rates, overdue training, and gaps help ensure comprehensive coverage.

This documentation serves multiple purposes:

  • Demonstrating compliance during CPCSC assessments
  • Identifying employees needing training or refresher
  • Supporting performance management by verifying employees met training obligations
  • Providing evidence of due diligence if security incidents occur

For CPCSC Level 2 assessments, assessors will expect to see comprehensive training records spanning multiple years demonstrating sustained training efforts, not one-time compliance gestures.

Measuring Training Effectiveness

Tracking completion rates demonstrates that training occurred, but doesn't confirm employees actually learned and apply concepts.

More sophisticated programs measure effectiveness through:

  • Knowledge assessments testing understanding of training content immediately after training
  • Phishing simulation results measuring actual susceptibility to phishing attacks over time
  • Incident rates tracking whether security incidents decrease after training initiatives
  • Behavioral observation noting whether employees demonstrate security-conscious behaviors in daily work
  • Employee surveys assessing perceived value of training and areas needing additional emphasis

These effectiveness measures enable continuous improvement, identifying content that isn't working or topics requiring additional coverage.

Organizations that can demonstrate training effectiveness beyond just completion statistics show maturity in their security awareness programs.

Cultural Integration

The most effective security training transcends compliance to become embedded in organizational culture.

Leadership modeling where executives visibly follow security policies and discuss security importance sets tone from the top. Regular communications keep security top-of-mind through multiple channels beyond formal training.

Recognition programs acknowledge employees who demonstrate good security practices or identify security issues. Positive framing presents security as protecting the organization and its people rather than restrictive policies.

Integration with business processes embeds security considerations in everyday workflows rather than treating it as separate IT concern.

Open communication encourages reporting security concerns without fear of blame or retaliation.

Organizations that build this cultural foundation see better security outcomes than those that rely solely on compliance-driven checkbox training.

Special Considerations for Remote and Distributed Workforces

Defence contractors increasingly employ remote workers or distributed teams, creating training delivery challenges.

Online training platforms become more important when in-person delivery is impractical. Virtual instructor-led training using video conferencing can provide some interaction benefits of in-person training with geographic flexibility.

Training content must address remote work security topics:

  • Home network security
  • Use of public WiFi
  • Physical security in home offices
  • Separating personal and work activities

Communication strategies ensure remote workers don't feel disconnected from organizational security culture.

Tracking and accountability may need additional attention to ensure remote workers complete training despite lacking direct supervision. Technology accessibility should be verified to ensure remote workers can access training platforms and materials from their work environments.

Compliance with Related Requirements

Security training supports multiple CPCSC requirements beyond just the Awareness and Training family.

Training users to recognize and prevent public disclosure of specified information supports Access Control requirement AC-22 on publicly accessible content.

Training on incident recognition and reporting enables effective Incident Response capabilities. Training on proper handling and disposal of media supports Media Protection requirements.

Training on physical security procedures supports Physical Protection requirements. Training on acceptable use of systems supports multiple technical controls.

This interconnectedness means effective training programs aren't just satisfying isolated training requirements but enabling broader security control effectiveness.

External Training Resources and Providers

Organizations need not develop all training content from scratch.

The Canadian Centre for Cyber Security provides free security awareness resources and guidance tailored to Canadian context.

Commercial security awareness platforms like KnowBe4, Proofpoint, SANS Security Awareness, or Cofense provide comprehensive libraries of training content, phishing simulations, and tracking capabilities for typically $10-$30 per user annually.

Industry associations may offer sector-specific security training. Professional training organizations provide specialized courses for technical personnel on specific security topics.

Consultancies can develop customized training programs tailored to organizational needs and culture.

The choice between developing internal training content, using commercial platforms, or engaging external providers depends on budget, internal expertise, organizational size, and desired customization level.

Many organizations use hybrid approaches, leveraging commercial platforms for broad awareness training while developing custom content for organization-specific policies and procedures.

Training as Risk Management Investment

Security training represents risk management investment, not just compliance cost.

Reduced incident frequency from better employee awareness lowers incident response costs, operational disruption, and potential data breach expenses.

Improved incident detection when employees recognize and report suspicious activity enables earlier intervention.

Reduced social engineering success rates when employees identify phishing and pretexting attempts blocks a major attack vector.

Better compliance with security policies when employees understand rationale and expectations reduces audit findings. Enhanced security culture produces long-term benefits beyond individual training events.

From this perspective, security training delivers measurable return on investment through risk reduction, making it a sound business investment beyond regulatory compliance.

Learn More

For additional information, consult the following resources:

Why Choose Plurilock for CPCSC Readiness?

Preparing for CPCSC (Canadian Program for Cyber Security Certification) demands deep knowledge of the certification framework, careful evidence preparation, and hands-on technical implementation. Plurilock delivers with compliance readiness specialists serving Canadian defense suppliers who bring proven experience guiding contractors through cybersecurity certification programs on both sides of the border.

As an established CMMC readiness provider for U.S. defense contractors, we were among the first to extend that expertise north—launching CPCSC readiness services early and serving Canadian defense suppliers from the program's earliest days. We don't conduct audits; we get you ready for them, then help you stay ready.

Why we're the superior choice:

  • First-mover CPCSC expertise: Plurilock was among the first firms to launch dedicated CPCSC readiness services—and among the first to serve clients in this practice—giving your organization a partner with real, accumulated experience preparing suppliers for certification.
  • Deep CMMC heritage: Our established U.S. defense contractor practice has guided organizations through CMMC readiness for years, and those underlying controls map closely to CPCSC—we bring battle-tested methodologies, not theory borrowed from adjacent frameworks.
  • Federal experience on both sides of the border: With extensive engagements across U.S. and Canadian federal government environments, we understand the contractual, technical, and procedural realities that shape defense supply chain compliance.
  • Readiness assessment and gap analysis: We evaluate your current posture against CPCSC requirements, identify control gaps with precision, and deliver clear, prioritized roadmaps that align remediation effort to certification level and contract obligations.
  • Strategy and execution, not just paperwork: Beyond identifying gaps, we help you execute—planning the remediation program, supporting policy and evidence development, and preparing your team and systems so that when the assessor arrives, you're ready.

CPCSC-ready—with proven defense contractor experience guiding every step.

Reach Out Now â†’

+1 (888) 776-9234 (Plurilock)
+1 (310) 530-8260 (Aurora)
+1 (613) 526-4945 (Integra)

sales@plurilock.com

Schedule a free consultation to plot a course toward CPCSC compliance.

loading...

Thank you.

A plurilock representative will contact you within one business day.

Contact Plurilock

+1 (888) 776-9234 (Plurilock)
+1 (310) 530-8260 (Aurora)
+1 (613) 526-4945 (Integra)

sales@plurilock.com

Your information is secure and will only be used to communicate about Plurilock and Plurilock services. We do not sell, rent, or share contact information with third parties. See our Privacy Policy for complete details.

More About Plurilockâ„¢ Services

Subscribe to the newsletter for Plurilock and cybersecurity news, articles, and updates.

You're on the list! Keep an eye out for news from Plurilock.