# CPCSC Level 1: Build an Evidence File You Can Explain

> A practical way for Canadian defence suppliers to connect cyber-hygiene controls to current records, owners, and contract scope.

[Canonical HTML page](https://trustcyber.ca/insights/cpcsc-level-1-evidence-guide/)

- Author: [Junior Williams](https://trustcyber.ca/about/)
- Type: Insight brief
- Published: 2026-09-26
- Modified: 2026-09-26
- Topics: Cybersecurity, Canadian public sector, Compliance

A folder full of screenshots can still leave a supplier unable to explain how its security controls work. The missing detail is often ordinary: which system the image came from, who checked it, whether it covers the contract’s information, and what happened after the picture was taken.

For suppliers subject to Canadian Program for Cyber Security Certification requirements, Level 1 evidence should make those connections easy to follow. Public Services and Procurement Canada’s guidance describes a self-assessment against 13 cyber-hygiene controls and gives examples of records suppliers can keep.

## Draw the boundary before collecting records

Start with the solicitation and contract. Identify the specified information, then trace where it is received, stored, processed, and shared. Include the people, endpoints, cloud services, and physical locations that can reach it. A security setting on a system outside that boundary tells you little about the information the contract requires you to protect.

The official guidance ties applicability and timing to contracting activity. Confirm the requirement with the contracting authority rather than treating a general program announcement as the schedule for a particular bid. If relying on recognition of a U.S. CMMC certification, obtain confirmation for the relevant scope; recognition should not be assumed.

## What an explainable record looks like

**Examples of evidence, not a complete control mapping**

| Practice | Useful record | Context to retain |
| --- | --- | --- |
| Access management | Account list and access-review result | System, reviewer, removals and review date |
| Device management | Current device inventory | Scope, owner and update process |
| Security awareness | Training completion record | Audience, material and completion date |
| System protection | Firewall or MFA configuration | Relevant service, scope and capture date |
| Recurring maintenance | Update or sanitization log | What was done, by whom and when |

A record can be simple. An access review might identify the account population, the manager who examined it, the exceptions found, and the date those exceptions were resolved. That tells a more useful story than a screenshot of the user-administration screen alone.

Avoid copying sensitive operational records into an unnecessarily broad evidence folder. Keep the evidence accessible to the people responsible for the assessment while preserving the access restrictions appropriate to its contents. A reference to a controlled source can be easier to maintain than several copies.

> **For every item**: Record the control it supports, the system or location it covers, its owner, the capture date, and when it needs review. These are working practices for keeping evidence usable.

## The attestation begins a maintenance cycle

Save the completed assessment, result and expiry information. PSPC’s guidance says evidence should be retained for the duration of the attestation cycle or at least one year. Assign responsibility for maintaining it through personnel changes, device replacement, and changes to service providers.

Set review dates according to how quickly a record can become wrong. An account list may change much faster than an approved policy. When a control is incomplete, record the gap and resolve it through the applicable assessment process; an attractive evidence pack cannot substitute for implementation.

A useful final check is to ask someone who did not assemble the folder to follow one control. Can they identify the requirement, the systems covered, the evidence of operation, and the owner who can answer a question? If they can, the file is much more likely to remain useful after the assessment is submitted.

## Selected primary sources

- [Public Services and Procurement Canada: Level 1 requirements and evidence](https://www.canada.ca/en/public-services-procurement/services/industrial-security/security-requirements-contracting/cyber-security-certification-defence-suppliers-canada/meet-level1-certification-requirements.html)
