Complete the online self-assessment tool after gathering security documentation and establishing basic policies, then update your CanadaBuys profile.
Before beginning the self-assessment, gather comprehensive information about your security posture.
Create lists documenting the following:
While you don't need a formal, documented security program for Level 1, you should understand where Specified Information exists in your environment to apply controls effectively.
This preparation phase typically takes 2-4 weeks for a small to medium organization, depending on how well-documented your existing systems are.
Level 1 is deliberately flexible to accommodate different organizational sizes and structures, but you need some basic written policies.
These should be short, practical documents covering the following areas:
These policies should be a few pages long, not lengthy manuals, and stored where all employees can access them. A shared folder or corporate intranet alongside other important policy documents works well.
Policies should be communicated to all employees as part of core HR and IT onboarding materials.
The Government of Canada provides an online self-assessment tool accessible through the CPCSC program website.
If you've already completed your preparation and reviewed your business policies, the assessment itself can be completed in less than one hour.
The tool walks through the 13 controls, asking questions about your implementation of each. You indicate whether each control is fully implemented, partially implemented, or not implemented, and provide evidence or explanations as needed.
If you discover during the assessment that you need to implement one or more controls before you can honestly attest to compliance, you can save your progress and return to it later.
This is common. Many organizations identify gaps during the assessment that require technical implementation, policy development, or procedural changes before they can complete the certification.
Don't rush to attest compliance if controls aren't truly in place. The risk of fraudulent attestation outweighs any short-term convenience.
Once you've confirmed implementation of all 13 controls, you complete the self-assessment and receive a results page.
This page shows your attestation status and an expiry date, since Level 1 requires annual renewal.
You must print or save this results page for your records. This documentation proves your certification status and will be needed when bidding on contracts.
Organizations seeking Level 1 certification must have an active CanadaBuys account if they intend to participate in procurements or hold contracts requiring CPCSC Level 1.
After completing your self-assessment, you must confirm the results and expiration date in your CanadaBuys organizational supplier profile questionnaire.
This creates an official record that procurement officials can verify when evaluating bids. The connection between your self-assessment attestation and CanadaBuys profile is a key control point preventing false claims of certification.
For Level 1, you must keep evidence for the duration of your attestation cycle, or at least one year.
Examples of required evidence include:
This evidence demonstrates that your attestation is based on actual implementation, not just paperwork.
If questions arise about your certification or you're selected for verification, this evidence substantiates your claims.
Suppliers can attest that they meet the 13 controls without using the online self-assessment tool.
However, the tool's use is strongly encouraged for the following reasons:
Organizations choosing not to use the tool must still maintain the same evidence and make the same attestation in their CanadaBuys profile.
Level 1 certification is not permanent. It requires annual self-assessment.
Before your certification expires, you must repeat the process with the following steps:
The annual cycle recognizes that security is not a one-time achievement. It is an ongoing practice requiring continuous attention as your organization, technology, and threats evolve.
Organizations sometimes rush through self-assessment treating it as a checkbox exercise rather than a genuine security evaluation.
This creates risk if your attestation doesn't reflect reality and controls aren't truly in place. Take the time to honestly assess each control, implement any gaps before attesting compliance, and maintain ongoing practices that keep controls effective.
Another common mistake is completing the self-assessment but forgetting to update the CanadaBuys profile. This leads to confusion when procurement officials can't verify your certification status.
Additional resources are available online:
Preparing for CPCSC (Canadian Program for Cyber Security Certification) demands deep knowledge of the certification framework, careful evidence preparation, and hands-on technical implementation. Plurilock delivers with compliance readiness specialists serving Canadian defense suppliers who bring proven experience guiding contractors through cybersecurity certification programs on both sides of the border.
As an established CMMC readiness provider for U.S. defense contractors, we were among the first to extend that expertise north—launching CPCSC readiness services early and serving Canadian defense suppliers from the program's earliest days. We don't conduct audits; we get you ready for them, then help you stay ready.
Why we're the superior choice:
CPCSC-ready—with proven defense contractor experience guiding every step.
A plurilock representative will contact you within one business day.
Contact Plurilock
+1 (888) 776-9234 (Plurilock)