C3SA FIELD GUIDE

CMMC & CPCSC READINESS GUIDE

A practical starting point for defence suppliers preparing for the U.S. Cybersecurity Maturity Model Certification (CMMC) and the Canadian Program for Cyber Security Certification (CPCSC). Requirements are applied through contracts and phased in over time, so confirm them against your current and anticipated contracts.

THE GUIDE

SIX STEPS TO DEFENSIBLE READINESS.

Readiness is easier when scope, ownership, evidence and dependencies are explicit before technology or compliance activity begins.

01

Identify regulated information and contracts

Readiness starts with knowing which contracts impose requirements and which information they cover, such as Federal Contract Information and Controlled Unclassified Information (CUI) for U.S. contracts, or sensitive unclassified information for Canadian defence contracts.

Questions to ask

  • Which current and upcoming contracts include cybersecurity clauses?
  • What controlled information do we receive, create or share?
  • Which certification level or requirements are likely to apply?
02

Define your enclave and boundary strategy

Requirements apply to every system, user and supplier that handles controlled information. A well-defined boundary, often a dedicated enclave, can reduce cost and simplify assessment.

Questions to ask

  • Where does controlled information enter, live and leave?
  • Could it be confined to a smaller environment?
  • Which cloud and managed service providers are inside the boundary?
03

Map CMMC and CPCSC requirements

Both programs draw on similar control sets derived from NIST SP 800-171. Mapping them together means one control and one piece of evidence can serve both where they overlap.

Questions to ask

  • Which requirements apply to our scoped environment?
  • Where do CMMC and CPCSC overlap, and where do they differ?
  • Which controls do we inherit from providers?
04

Validate identity, access and logging controls

Multi-factor authentication, least privilege, account management and audit logging are among the most commonly cited gaps and underpin many other controls.

Questions to ask

  • Is MFA enforced for all access to the scoped environment?
  • Are privileged accounts limited and reviewed?
  • Are logs collected, protected and reviewed?
05

Build evidence and POA&M discipline

Assessors look for evidence that controls operate, not just policies. A plan of action and milestones (POA&M) tracks gaps to closure; CMMC allows POA&Ms only for certain requirements and within a fixed closeout period, so check the current rule.

Questions to ask

  • Can we produce current evidence for every requirement?
  • Is our system security plan accurate?
  • Does every open gap have an owner and a date?
06

Exercise incident and reporting workflows

Defence contracts can include incident reporting obligations with short deadlines. Test that you could detect, assess and report an incident in time.

Questions to ask

  • What are our contractual incident reporting obligations and deadlines?
  • Who decides whether an incident is reportable?
  • Have we tested the reporting workflow?

Last reviewed September 24, 2026. This guide is general information, not legal advice. Print or save this page to use it as a workshop handout or pre-engagement checklist.

NEXT STEP

MOVE FROM CHECKLIST TO EVIDENCE.

C3SA can help validate the current state, identify material gaps, define the target state and support implementation, testing and readiness.

UNDER ATTACK? CYBERFIRE →