A Canadian supplier with US defense work will often have a CMMC Level 1 self-assessment on file and assume the Canadian equivalent is a formality. Both levels are annual self-assessments, and both are cheap compared with Level 2, so the assumption is understandable. It's also wrong, and the reason is a single requirement.
The gap is 03.05.03
CPCSC Level 1 assesses 13 requirements from ITSP.10.171. One of them is 03.05.03, multi-factor authentication. The American Level 1 has no MFA requirement at all. A shop that cleared CMMC Level 1 on the strength of passwords is not at CPCSC Level 1 yet, whatever its CMMC certificate says.
PSPC may accept a valid CMMC certification for Level 1 on a case-by-case basis. There is no automatic mutual recognition. And a CMMC Level 1 scope drawn around your American contract data may not cover the systems that hold the Canadian contract's Specified Information. CPCSC Level 1 is required at contract award, so this is a bid-season problem, not a someday problem.
What "MFA" has to cover
The standard's wording covers privileged and non-privileged accounts. PSPC's Level 1 guidance describes it as required for privileged accounts and for the systems that store Specified Information. If you meet the standard's wording, you have met both.
In practice that means a list, and the list is where shops get caught. When I look at a small supplier's first pass, the pattern is the same: MFA on the VPN, maybe. None on email. None on the domain. None on the admin plane of the cloud tenant. Each of those is a path to Specified Information, and the control has to hold on every one of them, not only the front door.
So write the list before you answer the self-assessment:
- Remote access (VPN, remote desktop gateway, any support tool)
- Email and file sharing for the accounts that touch contract data
- Windows sign-in on enclave workstations and servers
- Every privileged account, including the cloud tenant admin roles
MFA gaps on secondary access paths are also a standard first-cycle finding at Level 2, so the work carries forward.
Which factor
Hardware keys are the option I push. A YubiKey on Windows login, or a YubiKey paired with Duo, is a combination I have deployed more than once, and it is the strongest option on this list for the accounts that matter most.
Authenticator apps are fine. They are PSPC's stated preference among the app and SMS options in its Level 1 guidance, and they cost nothing but an enrolment afternoon.
SMS is where I part company with the guidance. PSPC's Level 1 material lists SMS codes as acceptable, so you can meet the letter of the self-assessment with them. I wouldn't. A code sent over the phone network is a weaker factor than one generated on the device. SMS beats nothing, but the choice most shops actually have is SMS or an authenticator app, and there you take the app.
Keep the evidence
Nobody reviews your Level 1 evidence by default, and PSPC reserves the right to look. The attestation is a signed representation in a federal procurement context. For 03.05.03, 1 artifact is enough: the MFA enrolment list for privileged and non-privileged accounts, dated, filed with the rest of the evidence folder and kept for the length of the attestation cycle, or at least a year.
If a gap can't close before the bid deadline, don't shade the answer optimistically. Level 1 controls are cheap to close. If it really can't be done in time, that is a conversation with the contracting authority about timing.
Top comments (0)