1. Home
  2. |Insights
  3. |Canadian CMMC? Canada Proposes Cyber Compliance Regime for Canadian Defense Suppliers

Canadian CMMC? Canada Proposes Cyber Compliance Regime for Canadian Defense Suppliers

Client Alert | 2 min read | 03.31.25

On March 12, 2025, the Government of Canada announced plans to launch the Canadian Program for Cyber Security Certification (CPCSC). CPCSC is a cybersecurity compliance verification program that aims to protect sensitive unclassified government information handled by Canadian government contractors and subcontractors within Canada’s defense sector. Canada will roll out CPCSC to contractors in four phases, with the first phase launching this month.

CPCSC’s structure appears closely aligned with the U.S. Department of Defense (DoD) Cyber Maturity Model Certification (CMMC) program. Like CMMC, CPCSC is broken out into 3 compliance levels, will verify compliance via self, third-party, and government-conducted assessments, and will be included in Canadian government defense solicitations and other procurement opportunities.

However, CPCSC and CMMC have one key difference: as currently structured, they will evaluate contractors against fundamentally different security standards. CMMC assessments are primarily based on security controls from the U.S. National Institute of Standards and Technology Special Publication (NIST SP) 800-171, Revision 2. CPCSC, in contrast, will evaluate Canadian defense contractors against Canadian industrial security standard (ITSP 10.171), a Canadian government standard that mirrors NIST SP 800-171, Revision 3.

While this distinction may appear minor, there are significant differences between the security controls found in Revision 2 and Revision 3 of NIST SP 800-171. DoD has stated that CMMC will eventually adopt Revision 3, but to date all CMMC rulemaking and guidance materials have been tailored to Revision 2. Accordingly, reciprocity or mutual recognition for CMMC and CPCSC assessment and certifications does not appear feasible, at least for now. Simultaneously, however, DoD has begun socializing the possibility of contractors’ voluntary adoption of Revision 3, an approach that now merits more consideration for contractors supporting both countries’ defense supply chains.

Given the historically close ties between the U.S. and Canadian defense sectors, contractors on both sides of the border should watch closely for further updates from Canada on its phased rollout of CPCSC, updates from DoD regarding CMMC’s adoption of NIST SP 800-171, Revision 3, and any discussions of mutual recognition between the respective programs.

Contacts

Insights

Client Alert | 3 min read | 08.03.26

New Jersey Takes Aim at Algorithmic and Surveillance Pricing: What Landlords and Retailers Need to Know About the FAIR Act and the Fair Price Protection Act

On July 20, 2026, New Jersey Governor Mikie Sherrill signed the Forbidding the Algorithmic Inflation of Rent (FAIR) Act into law, making New Jersey the fourth state to regulate algorithmic rent-setting practices. Three days later, on July 23, 2026, Governor Sherrill signed the Fair Price Protection Act, which targets “surveillance pricing”—the practice of using or collecting personal data about a user and using an algorithm or artificial intelligence to charge different consumers different prices for the same products. Together, these laws represent a significant expansion of New Jersey's consumer protection framework in the algorithmic pricing context....