Do you need certification to sell to the federal government?
Short answer: increasingly, yes. Since April 2026 the Canadian Program for Cyber Security Certification has applied Level 1 to in-scope suppliers: an annual self-assessment documenting the implementation status of thirteen security requirements. Level 2 goes further, with an external assessment by an accredited certification body renewed every three years.
For a Canadian technology SMB, this is a commercial shift as much as a technical one. A federal tender can now require certification as an eligibility condition : not merely as a scoring criterion. Without it, the bid is not evaluated.
The good news: Level 1 is designed to be achievable by a small organization. The thirteen requirements map to baseline controls most companies already apply in part : the work is usually more about documenting and formalizing than about buying tools.
The thirteen requirements, grouped by theme
The Level 1 baseline covers the fundamental controls expected of any organization handling unclassified government information:
Governance : designate a security lead, maintain an asset inventory, apply a documented policy
Access protection : strong authentication, privileged account management, revocation on departure
System protection : patching, secure configuration, endpoint and server protection
Data protection : encryption, backups and verified restoration
Detection and response : logging, an incident response procedure and staff awareness training
Each requirement calls for a three-part answer: what you do, what you do it with, and how you prove it. That third part is what usually stalls organizations, because it assumes dated evidence rather than assertions.
CPCSC and CyberSecure Canada: what is the difference?
CyberSecure Canada is a voluntary certification program for small and medium organizations, with a baseline set of controls, a displayable certification mark and a recertification cycle. It targets general market confidence.
The Canadian Program for Cyber Security Certification is procurement-oriented: it conditions eligibility for certain public contracts and relies on accredited assessment bodies for its higher levels.
In practice the two reinforce each other. The compliance work (inventory, policies, evidence, incident procedure) is largely shared. An SMB targeting federal business is well advised to build one evidence file and then map it to whichever baseline is requested.
An eight-week preparation plan
Scoping (weeks 1-2): target scope, designate the lead, inventory assets and access, identify the government data you handle
Gap analysis (weeks 3-4): assess each requirement across four states (implemented, partial, planned, not applicable) and document the rationale
Quick wins (weeks 5-6): complete MFA, revoke dormant accounts, establish a patch cycle, encrypt endpoints, run a timed restoration test
Documentation (week 7): security policy, incident response procedure, third-party access register, dated evidence for each control
Self-assessment and review (week 8): complete the declaration, have it peer-reviewed, schedule the annual review
The most frequent mistake is over-declaring. A requirement marked "partial" with a dated plan is perfectly acceptable; a requirement declared compliant but not demonstrable becomes a contractual problem, and potentially an insurance problem when a loss occurs.
The ripple effect beyond federal procurement
This movement extends well past government contracting. Critical infrastructure operators covered by the new Critical Cyber Systems Protection Act will have to manage supply chain risk, and will push those requirements onto their suppliers. Large private buyers are moving the same way in their vendor questionnaires.
In other words, the evidence file you build for Level 1 will also answer client security assessments, your cyber insurance application and your Law 25 obligations. It is an investment with multiple uses.
Conclusion
Certification is no longer a differentiator: it is becoming an entry ticket. Organizations that start now move at the pace of their normal cycles; those that wait for the tender will discover you cannot retroactively manufacture twelve months of evidence. ITCS Group supports Canadian SMBs through gap analysis, technical remediation and evidence file preparation. Contact us for a diagnostic of your current level.
Sources
Canadian Program for Cyber Security Certification, Level 1 : Public Services and Procurement Canada, April 2026
CyberSecure Canada : Innovation, Science and Economic Development Canada
Standards Council of Canada : certification body accreditation