DEFENCE · NATIONAL SECURITY

SECURE THE MISSION. PROTECT THE SUPPLY CHAIN.

Cybersecurity, compliance readiness, digital sovereignty and technology integration for defence, aerospace and national-security organizations, and for the suppliers that support them.

Defence supplier?Use the readiness navigator to identify likely evidence and scoping priorities.
Check Defence Readiness
IN PRACTICE

WHAT C3SA DELIVERS FOR EACH.

Requirements differ by program and contract, and several are being phased in. Confirm applicability against the clauses in your current and anticipated contracts.

UNITED STATES

CMMC

The U.S. Department of Defense's Cybersecurity Maturity Model Certification (CMMC) program sets cybersecurity requirements for contractors that handle Federal Contract Information or Controlled Unclassified Information. Requirements are applied through contract clauses, so the first question is which level your contracts require.

What you get

  • An applicability and level determination
  • A scoped assessment boundary and gap register
  • A remediation and evidence plan
Talk to C3SA about CMMC
CANADA

CPCSC

The Canadian Program for Cyber Security Certification (CPCSC) sets cybersecurity requirements for suppliers to Canada's defence procurement that handle sensitive unclassified information. C3SA helps Canadian suppliers determine likely requirements and prepare evidence, including suppliers who also face CMMC.

What you get

  • A readiness assessment against the applicable standard
  • A shared CMMC and CPCSC control and evidence plan
  • An implementation roadmap
Talk to C3SA about CPCSC
EXPORT CONTROL

ITAR & Controlled Goods

Access control, secure handling and system architecture for technical data subject to U.S. ITAR and Canada's Controlled Goods Program, so only authorized persons can reach it. Export-control legal determinations remain with your counsel and compliance officer.

What you get

  • A map of where controlled data lives and who can access it
  • Architecture and access-control recommendations
  • Handling procedures
Talk to C3SA about ITAR & Controlled Goods
GOVERNMENT OF CANADA

ITSG-33

Security control selection, implementation and assessment support based on the Canadian Centre for Cyber Security's ITSG-33 risk-management guidance for Government of Canada systems. C3SA supports readiness; authorization decisions rest with the responsible government authority.

What you get

  • A tailored security control profile
  • Implementation evidence
  • Assessment readiness
Talk to C3SA about ITSG-33
U.S. FEDERAL CLOUD

FedRAMP

Readiness and control alignment for cloud service providers pursuing U.S. federal authorization, including authorization-boundary definition, gap assessment and documentation support.

What you get

  • A defined authorization boundary
  • A gap assessment
  • A documentation and remediation plan
Talk to C3SA about FedRAMP
SUPPLY CHAIN

Defence Supply Chain

Third-party cyber risk, sovereignty and resilience across primes and their suppliers, answering one question for each critical component: who owns, operates, accesses, supports and can replace it?

What you get

  • Supplier risk tiering
  • A map of flow-down requirements
  • A supplier assurance approach
Talk to C3SA about Defence Supply Chain
CYBERSECURITY IS PART OF MISSION ASSURANCE.
WHERE C3SA ADDS VALUE

MISSION ASSURANCE ACROSS THE SUPPLY CHAIN.

Defence and national-security programs combine sensitive supply chains, mission-critical systems and contract-driven security requirements. C3SA brings security engineering, compliance readiness, exercises and sovereignty analysis together around the systems and suppliers the mission depends on.

For suppliers, that means one readiness program that addresses CMMC and CPCSC together where both apply, instead of two parallel compliance projects. For programs and primes, it means a defensible architecture, readiness evidence and exercised response plans.

COMMON QUESTIONS
Do we need CMMC, CPCSC or both?

It depends on your contracts. Suppliers to the U.S. Department of Defense may face CMMC requirements, and suppliers to Canada's defence procurement may face CPCSC requirements. Many Canadian suppliers face both. Requirements are phased in over time, so check the clauses in your current and anticipated contracts.

Can C3SA certify us?

C3SA's role is readiness: scoping, gap assessment, remediation and evidence preparation. Certification decisions rest with the authorized assessors or government authority for each program.

Where should a supplier start?

With the CMMC & CPCSC Readiness Navigator for an initial view of scope and evidence priorities, then a scoped readiness assessment.

THE C3SA DIFFERENCE

ADVICE. IMPLEMENTATION. PROOF.

THE NEED

Defence and national-security buyers face sensitive supply chains, mission demands and procurement-driven security requirements.

WHAT C3SA DOES

C3SA brings security engineering, assurance, exercises and sovereignty analysis together around mission-critical systems and suppliers.

WHAT YOU GET

A mission-focused risk picture, defensible architecture, readiness evidence and exercised response plans.

FREE C3SA FIELD GUIDE

CMMC & CPCSC Readiness Guide

Prepare Canadian defence suppliers for CMMC, CPCSC, controlled information and defence supply-chain security obligations.

UNDER ATTACK? CYBERFIRE →