Ron Lloyd BETWEEN INTENT AND OUTCOMES

Home / Published Work / Canada's Cybersecurity Certification Program

POLICY PERSPECTIVECGAI, TRIPLE HELIXDECEMBER 2025

The Impact of Canada's Cybersecurity Certification Program on Defence and Canadian Security

Same standards as the American model, a markedly different application

Security & Assurance Digital Government & Procurement Defence & National Security

SYNOPSIS

Defence procurement in Canada is poised to encounter additional delays with the introduction of a new small p policy: the Canadian Program for Cyber Security Certification. Its technical underpinnings closely mirror the United States Department of Defense's Cybersecurity Maturity Model Certification, but the federal government is pursuing a distinctly Canadian implementation that reflects the overclassification and risk aversion embedded in the wider policy framework. This paper examines the genesis of the CPCSC, contrasts Canada's approach with the American model, and sets out how the differences could harm both Canadian Defence and Canada's defence industrial base. It concludes with four recommendations.

“Effective security does not need to come at the expense of industrial competitiveness.”

From the paper, page 3, on the risk-based models adopted by the United Kingdom and Australia

KEY FINDINGS

  1. 1

    The program is not arriving in isolation. It will sit alongside three existing frameworks that already impose significant compliance demands on industry: the Contract Security Program, the Controlled Goods Program and the Cyber Centre's Cloud Assessment Program. The paper argues that the Controlled Goods Program, like the CPCSC, was born out of a United States initiative and was then layered with additional Canadian requirements, contributing to procurement delays and disproportionate impacts on small and medium enterprises.

  2. 2

    The divergence is not technical. It is in governance and execution. Canada's technical standards, set out in ITSP.10.171, are for all intents and purposes aligned with NIST 800-171 revision 3. But oversight falls to Public Services and Procurement Canada rather than Defence, whose direct involvement is largely limited to Level 3. Canada also introduces a new term, Specified Information, in place of Controlled Unclassified Information, adding further confusion to a classification framework already out of step with allies.

  3. 3

    The application model is far more expansive than the American one. Based on the program design available in December 2025, the paper assessed the Canadian application as substantially broader. Level 1 is mandated for all procurements handling Protected A, and since almost every government contract involves Protected A, every Canadian supplier across all industries will eventually face it. At Level 2 self-assessment is off the table entirely, so the third-party assessment that applies in the United States to a subset of controlled technical data applies in Canada to nearly all federal procurements. The examples given for Level 3 are so expansive that most defence contracts would require it, far exceeding the one per cent threshold in the United States. Full rollout is planned for 2027, a year sooner than the American equivalent.

  4. 4

    Mutual recognition had not been secured. The paper notes that one of the original objectives was United States recognition of the CPCSC as equivalent to CMMC, letting Canadian companies sell seamlessly into the American market. As of publication that recognition had not been secured, and the paper assessed it as unlikely in the short term, which would leave Canadian industry adhering to two separate regimes at a competitive disadvantage.

  5. 5

    The burden lands on the firms least able to carry it. The paper argues that the burden would fall disproportionately on smaller suppliers. The United States is already short of qualified third-party assessor organizations. Eliminating self-assessment at Level 2 and applying Levels 2 and 3 broadly creates a bottleneck, first in certifying the assessors and then in certifying an artificially elevated number of suppliers. Large original equipment manufacturers may absorb the cost and delay. Smaller Canadian businesses will be disproportionately affected, which runs counter to the intent of Budget 2025 to strengthen exactly those firms.

RECOMMENDATIONS

The paper makes four recommendations, the last conditional on the program proceeding as designed.

1. Delay implementationRevisit the decision to adopt CMMC as the model. Conduct an options analysis against less prescriptive risk-based models, such as those of the United Kingdom and Australia, both updated in 2024, which are more in keeping with Canada's strategic priorities and realities.
2. Align the level of injuryBring the level of injury associated with personal information into line with allies and adopt a classification framework of Official (Sensitive), Secret and Top Secret. Refine the categories of official and official sensitive information so that another confusing term such as “specified information” is not required.
3. Recognize CMMC equivalencyIf a new risk-based model is adopted for the CPCSC, recognize CMMC accreditation for those Canadian companies that require it and have been granted it.
4. If CMMC remains the template Five adjustments would reduce the burden without weakening the outcome:
  • Follow rather than lead. There is little reason to move faster than Canada's largest ally. Phase the program in at least six months to a year after the United States and learn from that rollout.
  • Target Level 1 precisely. Limit it to companies handling Federal Contract Information, aligning with the American definition.
  • Reintroduce self-assessment at Level 2. Let companies judge whether self-assessment is more cost effective for lower-risk data, and require third-party audits only for the most sensitive information.
  • Restrict Level 3. Require it only on project manager recommendation, within the guardrails articulated in CMMC 2.0 and subject to independent departmental review. Use the one per cent benchmark to prevent scope creep, and report annually.
  • Assess and disclose the costs. Collect and publish compliance cost data with industry input, so that the real impact on small and medium enterprises is visible.

WHERE THIS FITS

Added September 2026

The earlier papers examined instruments that were already in place and had been for decades. This one caught a new instrument while it was still being designed, and showed the same pattern forming in real time: an allied model adopted for sound reasons, then widened in application because the underlying classification framework leaves no narrower category to apply it to. It is the clearest single illustration in the series of why the classification argument is not an abstraction.

SINCE PUBLICATION

What has changed, and where the argument went

UPDATE · SEPTEMBER 2026

WHAT HAS CHANGED

  • PSPC's evaluation of the program, approved in January 2026 and published in March, found that implementation had been slower than originally anticipated, linking this to the inability to secure reciprocity with the United States program and a redesign to a Canada-only model. Among the risks it identified were “SMEs struggling with the financial and technical demands.”
  • On 14 April 2026 the government introduced Level 1, an annual self-assessment against 13 controls, to appear in select defence contracts from summer 2026. Level 2, an external assessment against 98 controls, and Level 3, a National Defence assessment against 200 controls, were described as under development.
  • On 13 July 2026 the United States defense department suspended CMMC Phase II, due to begin on 10 November 2026, which would have extended third-party assessment across applicable contracts. Phase I self-assessments remained in effect and a 60-day review was launched. The reasons cited included prohibitive compliance costs and shortages in third-party assessment capacity, particularly for small businesses.

Sources: Public Services and Procurement Canada, Evaluation of the Canadian Program for Cyber Security Certification (March 2026), Level 1 announcement (14 April 2026) and Program Overview; U.S. Small Business Administration, 13 July 2026; Federal News Network, 13 July 2026.

HOW THE THINKING HAS DEVELOPED

This paper extended the earlier analysis from mature programs to policy design in real time. The central concern was no longer simply that an existing program had accumulated unintended consequences, but that the same institutional conditions, namely classification, risk allocation, distributed authorities and program specific accountability, could reproduce those consequences in a new program before implementation began.

Subsequent developments reinforced the importance of distinguishing the security objective from the mechanism chosen to achieve it. The question is not whether defence supply chains require strong cyber security; it is how requirements should be calibrated to risk, applied across different categories of information and suppliers, and adjusted as evidence about cost, capacity and allied implementation emerges.

ABOUT THE AUTHOR

Vice-Admiral (Ret'd) Ron Lloyd was the 35th Commander of the Royal Canadian Navy and is a Fellow of the Canadian Global Affairs Institute. Transparency →