Cluster Brief // NA-CPCSC-2026-09
CPCSC vs CMMC: the residency split
Desmond Otieno Odhiambo · Verified 7 September 2026
Canadian defence suppliers keep asking whether CMMC work can be reused for CPCSC. The honest answer is yes on controls and no on location.
PSPC introduced CPCSC on 12 March 2025. Level 1 became available on 1 April 2026 as an annual self-assessment. Level 2 and Level 3 enter select defence contracts between April 2027 and March 2028.
What is reusable
Reuse the system security plan structure, control owners, evidence folders, and assessor-ready narratives from NIST SP 800-171 / CMMC work. Do not reuse the assumption that a US region or multi-tenant commercial cloud is an acceptable home for Canadian specified information.
Where the programs diverge
- CMMC certifies the contractor environment. FedRAMP authorizes a cloud offering. CPCSC certifies Canadian defence suppliers handling specified information below classified.
- CMMC Level 2 uses C3PAOs. CPCSC Level 2 uses SCC-accredited bodies. Level 3 is described as a Canadian military assessment for the most sensitive work.
- CMMC does not impose a Canada-only storage rule. CPCSC scoping treats data location and foreign access as in-scope. Safeguarded contract data is expected to stay in Canada.
- A US parent or US-operated cloud can still face US legal process under the CLOUD Act even when the disk is in Canada.
Build order
- Inventory specified information and any US CUI in the same workbook, with separate residency columns.
- Split estates if a shared tenant cannot enforce Canada-only storage and Canada-only privileged access.
- Keep one evidence ledger. Emit CPCSC and CMMC packets from the same records.
- Put agents and automation in scope.
- Write the residual CLOUD Act risk in the contract file.
Parent brief · Dual-clock runbook · Assessment
Public program pages only. Not a certification claim.