// WHO IT’S FOR
It’s written for the person who found out on a Tuesday. The network admin keeping the business running who just got forwarded a solicitation with a certification clause in it. The office manager handed “compliance” because nobody else put their hand up. The IT lead at a 30-person shop expected to become a certification program on top of everything else. Plain language, sized for evenings and stolen Friday afternoons, built on scenarios inspired by ISO 27001, PCI-DSS, and CMMC readiness engagements with real suppliers.
// WHAT’S INSIDE
Twelve chapters in the order you’d actually work: what CPCSC is and why Ottawa built it, the 3 levels, whether the program applies to you, how it compares with CMMC and where the overlap saves you effort, the Level 1 controls and the attestation you’re signing, scoping an enclave that keeps assessment costs sane, running a gap assessment worth trusting, the technical work family by family, documentation that survives an assessor, Level 2 preparation, small shop realities including the MSP conversation, and staying certified after the first attestation. Study Notes from the field throughout, plus a Level 1 readiness checklist and a Canada-US terminology translation table in the appendices.
// FORMATS
Free digital PDF, ISBN 978-1-0680175-2-0, tagged and searchable, 61 pages: Download the PDF.
EPUB, ISBN 978-1-0680175-3-7, free on Apple Books, Kobo, and Google Play, and on Kindle.
Paperback, 8.5 × 11, 72 pages, ISBN 978-1-0680175-1-3, from Amazon.
First edition, revision 1.3, October 1, 2026, including the September 29, 2026 program changes. DOI 10.5281/zenodo.23145960.
Licensed CC BY-ND 4.0: share it freely with credit, unmodified.
// THE LIVING COMPANION
A printed book can’t chase a moving program, so this one doesn’t pretend to. The companion pages carry the current program state with a last-verified date: the CPCSC hub and CPCSC vs CMMC. The policy templates and checklists from the appendices are at CPCSC templates as editable downloads. The controls, Windows audit scripts, and data are open in the CPCSC repository on GitHub.
// CONTENTS
- 1 What CPCSC is and why Ottawa built it
- 2 The 3 levels, plainly
- 3 Does this apply to you
- 4 CPCSC, CMMC, and ITSP.10.171
- 5 Level 1: the 13 requirements and the attestation you’re signing
- 6 Scoping: where Specified Information lives
- 7 Running your own gap assessment
- 8 The technical work, control family by control family
- 9 Documentation that survives an assessor
- 10 Level 2 prep: what third-party assessment looks like
- 11 Small shop realities: MSPs, cloud, cost, and sequencing
- 12 Staying certified: life after the first attestation
- A to E Appendices: Level 1 checklist, Canada and US terminology table, sources, templates, and the full ITSP.10.171 requirement index