As cyber threats continue to evolve, defence contractors and suppliers have become frequent targets of cybercriminals, nation-state actors, and other sophisticated adversaries seeking to gain unauthorized access to Government of Canada information. To strengthen cybersecurity across Canada's defence supply chain, the Government of Canada introduced the Canadian Program for Cyber Security Certification (CPCSC) on March 12, 2025.
CPCSC establishes a cybersecurity certification framework for organizations that bid, participate, and fulfil defence contracts. Similar to defence cybersecurity certification programs in the United States – CMMC 2.0, CPCSC requires suppliers to implement cybersecurity controls based on the sensitivity of the information they handle. This program is being introduced in phases; currently, Level 1 has been applicable since April 2026.
Under CPCSC, Specified Information (SI) is defined as "Sensitive, non-classified, government information that must be protected when handled, processed, or stored by non-Government of Canada organizations." Protecting this information throughout its lifecycle includes securely sanitizing storage media before it is disposed of or released for reuse.
What is CPCSC?
The CPCSC is the Government of Canada's cybersecurity certification program for defence suppliers, contractors, and subcontractors. It is led by Public Services and Procurement Canada, with the Level 3 assessments conducted by the Canadian Department of National Defence. The Standards Council of Canada (SCC) accredits the third-party bodies that carry out Level 2 assessments. The underlying technical standard, ITSP.10.171 – Protecting Specified Information in Non-Government of Canada Systems and Organizations, was developed by the Canadian Centre for Cyber Security.
The certification level required for a supplier depends on the cybersecurity risk associated with a specific contract. These requirements are communicated during the procurement process through ‘Requests for Proposals’ and contract documentation.
What are the Levels of CPCSC?
The CPCSC framework consists of three certification levels:
- Level 1 requires an annual self-assessment;
- Level 2 requires assessment by an SCC-accredited certification body; and
- Level 3 requires assessment by the Government of Canada for contracts with the highest cybersecurity requirements.
| Level |
Purpose |
Controls |
Assessment |
Current Status |
| 1 |
Establishes baseline cybersecurity controls for defence suppliers.
|
13 |
Annual self-assessment
|
Available
|
| 2 |
Introduces enhanced cybersecurity controls, assessed by an SCC-accredited third-party body.
|
98 |
Triannual cybersecurity assessment (Accredited certification body)
Annual affirmation
|
Under development
|
| 3 |
Applies to contracts involving the highest cybersecurity requirements, assessed directly by DND.
|
200 |
Triannual cybersecurity assessment (Government of Canada)
Annual affirmation
|
Under development
|
What are the Media Sanitization Requirements in CPCSC?
CPCSC requires contractors and subcontractors to enforce Media Protection controls throughout the media lifecycle. The system media must be sanitized by an authorized user or destroyed before disposal or release. This requirement is defined under Media Protection 3.08.
Media Sanitization 03.08.03 requires organizations to “Sanitize system media containing specified information (SI) prior to disposal, release out of organizational control, or release for reuse.” The requirement applies to both digital and non-digital media, removable or fixed.
The objective of media sanitization is to remove information by using different techniques mentioned in ITSP.10.171, like Cryptographic Erase, Clear (overwriting), Purge, and Destroy, so that it cannot be retrieved or reconstructed. In case the media cannot be sanitized using a data wiping software, then it should be physically destroyed.
The CPCSC Level 1 Media Protection Requirements for Erasing and Destroying Decommissioned Computer Storage specify both the "What" and the "How" of media sanitization, including secure data erasure and physical destruction. These include:
- Using data wiping software that securely overwrites storage media using secure algorithms like US DoD 5220.22 and NIST 800-88, so that the data cannot be recovered.
- Physically destroying USB drives and other removable media using shredders or certified destruction services.
- Physically destroying low-value hard drives and mobile devices containing specified information instead of selling or donating them.
- Maintaining a log of decommissioned assets that records the media disposed of, the sanitization or destruction method used, the disposal destination, and the date of decommissioning.
These practices help demonstrate that SI is protected throughout the media lifecycle and cannot be disclosed after the media leaves organizational control.
How BitRaser Helps Meet CPCSC Media Sanitization Requirements?
BitRaser helps organizations comply with CPCSC media sanitization requirements by securely sanitizing hard drives, SSDs, NVMe drives, USB storage devices, and other storage media permanently. The software performs data wipe in accordance with recognized data sanitization algorithms, including ITSP.40.006, DoD 3 Pass, NIST SP 800-88, and many other standards. Further, the software generates tamper-proof erasure certificates and audit-ready reports that help organizations demonstrate compliance during cybersecurity assessments.