Bill C-8 is now law. Its centrepiece, the Critical Cyber Systems Protection Act (CCSPA), places mandatory security obligations on operators in six critical sectors, backed by penalties up to $15 million per violation and a 90-day deadline to build a program once an operator is designated.
Bill C-8 at a glance
- Royal Assent: June 16, 2026
- Who it reaches: operators in six Schedule 1 sectors (telecom, pipelines and power lines, nuclear, federal transportation, banking, clearing and settlement)
- Maximum penalty: $15 million per violation for organizations; each day a violation continues counts as a separate violation
- Compliance clock: 90 days from designation to a working cybersecurity program
- Status: Part 1 (telecom) is in force now; Part 2 (the CCSPA) is enacted but awaits a coming-into-force order
What is in force now, and what is still pending?
Part 1 (telecom) is live law today. Part 2 (the CCSPA) is enacted but not yet operative, so no operator owes CCSPA obligations until a designation order names its class.
Part 1 of Bill C-8 amends the Telecommunications Act and took effect at Royal Assent. It adds the security of the Canadian telecommunications system as a formal objective of telecom policy, and it gives the Governor in Council and the Minister of Industry the power to order a telecommunications service provider to do, or refrain from doing, anything necessary to secure the system. That includes prohibiting a provider from using the products or services of a specified supplier and directing the removal of a specified supplier's equipment from networks. Contraventions carry administrative monetary penalties of up to $10 million for a first contravention and $15 million for subsequent ones for organizations.
Part 2 enacts the CCSPA, and none of it is operative yet. Its provisions come into force on a day or days fixed by order of the Governor in Council. Until that order is made, operator classes are added to Schedule 2, and supporting regulations exist, no organization owes the program, reporting, record-keeping, or directions obligations described below. Telecom providers should treat Part 1 as live law today; everyone else in the six sectors is in a preparation window of unannounced length.

Who does the CCSPA apply to?
The CCSPA reaches operators in six services Parliament has declared vital to national security or public safety, listed in Schedule 1. Oversight routes through the existing federal regulator for each sector. Under the framework as introduced:
| Schedule 1 sector | Regulator (as introduced) |
| Telecommunications services | Minister of Industry |
| Interprovincial or international pipelines and power lines | Canadian Energy Regulator |
| Nuclear energy systems | Canadian Nuclear Safety Commission |
| Federally regulated transportation systems | Minister of Transport |
| Banking systems | Superintendent of Financial Institutions (OSFI) |
| Clearing and settlement systems | Bank of Canada |
Being in a Schedule 1 sector does not by itself create obligations. The duties attach to designated operators: organizations in classes the Governor in Council adds to Schedule 2 by order. An energy company or a bank is not bound until its class is designated; the designation order, not Royal Assent, starts its obligations.
The CCSPA's program requirements read as a codification of what mature critical infrastructure operators already do, now extended by force of law to everyone in the sector.
The list can also grow. The Governor in Council may add further federally regulated services and systems to Schedule 1, and operator classes to Schedule 2, without new legislation, whenever it is satisfied they are vital to national security or public safety. Water systems, ports, or federally regulated data infrastructure could be added by order rather than by a new bill.
What must designated operators do?
The CCSPA organizes operator obligations into four duty areas, with a record-keeping duty running across all four:
| Duty | What it requires | Timing |
| 1. Cybersecurity program | Reasonable steps to identify, protect, detect, and minimize impact | Establish within 90 days of designation; review annually |
| 2. Supply chain mitigation | Mitigate identified third-party and supply chain risks | Continuous, once a risk is identified |
| 3. Incident reporting | Report incidents to the Cyber Centre, then notify the regulator | Within a window capped at 72 hours |
| 4. Cyber security directions | Implement ordered measures and keep the direction confidential | As specified in the direction |
1. Establish a cybersecurity program within 90 days of designation
A designated operator must establish a cybersecurity program within 90 days of its class being designated, then notify its regulator and provide the program to it. The program must set out reasonable steps to identify and manage cybersecurity risks, including supply chain and third-party product risks; protect critical cyber systems from compromise; detect cybersecurity incidents; and minimize their impact, mirroring the NIST CSF functions of identify, protect, detect, respond, and recover. The operator must then review the program at least annually and notify the regulator of changes.
Ninety days is a documentation window, not a build window. The gap between what the deadline permits and what the obligation demands is the practical argument for gap-assessing before designation. Each required program element, and the controls that satisfy it, is detailed in the CCSPA cybersecurity program requirements guide. Organizations already running ISO 27001 or NIST CSF programs are closer than they may think; the CCSPA crosswalk to ISO 27001, NIST CSF, and CPCSC maps the overlap control by control.

2. Mitigate supply chain and third-party risk as a standing duty
Separate from the program requirement, the CCSPA imposes a continuing obligation: as soon as a designated operator identifies a cybersecurity risk associated with its supply chain or its use of third-party products and services, it must take reasonable steps to mitigate that risk. Regulations may prescribe what those steps must include. This duty has teeth in both enforcement tracks: failing to mitigate an identified supply chain risk is a violation subject to administrative penalties and can also be prosecuted as an offence.
An operator cannot mitigate risks it never looks for, and a regulator reviewing an incident will ask what the operator's third-party risk process was designed to find. This makes vendor risk management a regulated activity in the six sectors, the mechanism behind the commercial ripple covered later in this guide.
3. Report incidents to the Cyber Centre, on a clock capped at 72 hours
A designated operator must report a cybersecurity incident affecting a critical cyber system to the Communications Security Establishment's Canadian Centre for Cyber Security, and immediately afterward notify its regulator that a report was made. The trigger is broad: it captures incidents that interfere with, or could interfere with, the continuity or security of a vital service or the confidentiality, integrity, or availability of the critical cyber system. Potential interference is reportable, so the duty covers near misses, and the reporting decision cannot wait for confirmation of impact.
The deadline itself will be set by regulation, but the Act caps it: the prescribed period may not exceed 72 hours, a ceiling first added by committee amendment to Bill C-26 and carried into C-8 from introduction. Operators should plan against the cap. Meeting a 72-hour window requires detection that works, an incident classification process that can decide reportability fast, and someone with authority to file. Those are program capabilities, which is why the reporting duty and the program duty are the same project.
4. Comply with cyber security directions, and keep their existence confidential
The Governor in Council may issue a cyber security direction requiring a designated operator, or a class of them, to implement specified measures within a specified time. Non-compliance is both a violation and an offence. The directions regime comes with an unusual constraint: directions are confidential, and disclosing the existence or contents of one is itself an offence. Committee amendments added reasonableness and necessity conditions to these powers, but the core design stands: the federal government can order specific security measures at specific operators and require silence about having done so.
Underlying all four duties: record-keeping in Canada
Designated operators must keep records in Canada documenting the implementation of their program, every incident reported, the steps taken to mitigate supply chain risks, and the measures taken under any direction. The Act is explicit that doing the work is insufficient; the operator must be able to demonstrate it, in records held in this country.
How much are the penalties under Bill C-8?
Bill C-8 contains two separate penalty schemes:
| Scheme | Organizations | Individuals |
| Part 1, Telecommunications Act | Up to $10M (first contravention); $15M (subsequent) | Set by the scheme |
| Part 2, CCSPA | Up to $15M per violation (each day continuing = a separate violation) | Up to $500,000 per violation |
Committee amendments set the CCSPA individual maximum at $500,000 per violation, half the figure carried over from Bill C-26.
Under the CCSPA, a violation that continues for more than one day constitutes a separate violation for each day it continues, so up to $15 million per day is accurate shorthand for a continuing corporate violation. The penalty regime is designed to promote compliance rather than punish, and a due diligence defence is available.
Serious contraventions can be prosecuted as offences rather than penalized administratively. Failing to establish a cybersecurity program, failing to mitigate an identified supply chain risk, breaching a cyber security direction, or disclosing a direction's existence can bring imprisonment for individuals of up to five years on indictment, or two years less a day on summary conviction.
CCSPA liability is personal
Directors and officers who direct, authorize, assent to, acquiesce in, or participate in a violation or offence are parties to it, whether or not the organization itself is proceeded against. The liability reaches the people who govern the operator, and the due diligence defence is only available to those who can document their diligence.
What regulatory milestones are still coming?
The CCSPA moves from statute to operational obligation through a sequence of government actions, none of which had announced dates as of early July 2026:
- The coming-into-force order. The Governor in Council fixes the day the CCSPA's provisions take effect. When this order is made, the preparation window has a visible end.
- Schedule 2 designation orders. Published in the Canada Gazette, Part II, these name the classes of designated operators and their regulators. The 90-day program clock starts here.
- Draft regulations in the Canada Gazette, Part I. The regulations will set the incident-reporting window (within the 72-hour cap), the required particulars of reports, program content details, supply chain mitigation requirements, record-keeping specifics, and the penalty schedule. Pre-publication for comment is the standard federal process, and it is the industry's one structured chance to shape the requirements. Sector associations and larger operators should be drafting comments, not reading them.
- The statutory review. The Act requires a ministerial review of the C-8 provisions within five years of Royal Assent. Whatever compliance patterns establish themselves in the first implementation wave will set the baseline that review measures against.
For a comparison of how this staged federal rollout differs from the certification-driven CPCSC timeline in defence procurement, see Bill C-8 versus CPCSC.
How does Bill C-8 affect vendors and suppliers?
The CCSPA regulates only designated operators; it does not directly regulate anyone who sells to them. But the statute requires operators to identify supply chain risks, take reasonable steps to mitigate them, and keep records in Canada proving they did, all under penalty and offence exposure softened only by a due diligence defence. An operator in that position has one rational move: push the requirements downstream. Law firm analyses of the Act converge on the same expectation, and it matches the established pattern in other regulated sectors: security requirements written into vendor contracts, audit and assurance rights, incident-notification clauses, security questionnaires, and standing due-diligence assessments of third-party products.

For a company selling software or services into telecom, energy, banking, transportation, or payments, the question stops being does Bill C-8 apply to us and becomes can we pass the procurement gate our customer is now legally required to run. That gate decides revenue. A vendor that can produce a credible security program, evidence of its operation, and fast questionnaire answers moves through procurement while competitors stall in security review. The Bill C-8 vendor security requirements post covers what those flow-down requirements look like in practice.
Canada now runs two federal supply-chain security mandates on parallel tracks: the CCSPA for critical infrastructure and CPCSC for the defence supply chain, the latter built on the ITSP.10.171 control catalogue. The design philosophies differ, but the message to suppliers is identical: demonstrated security is becoming the price of admission to regulated Canadian revenue. Against a backdrop where Canadian breach costs rose 10.4% while the global average fell, that policy direction is unlikely to reverse.
What should you do before designation?
For organizations in the six sectors that are plausibly within a future designated class:
- Decide whether you are likely covered. Map your services against Schedule 1 and your regulator relationships against the sector list. If your service is federally regulated and vital, plan as if designation is coming.
- Gap-assess against the four program functions. Measure the current program against identify (including supply chain), protect, detect, and minimize impact. An honest assessment now converts the 90-day deadline from a build project into a documentation exercise.
- Pressure-test incident response against a 72-hour clock. Run a tabletop where the scenario includes deciding reportability and drafting a Cyber Centre report. The gaps that exercise reveals are the ones regulations will not wait for.
- Inventory third parties and their contract terms. The supply chain duty starts with knowing who the suppliers are and what security obligations their contracts already carry. The delta between current terms and CCSPA-grade terms is next year's renegotiation agenda.
For companies selling into the six sectors: build the security program and the evidence trail before the questionnaires arrive. Certifications and attestations your buyers already recognize, whether SOC 2, ISO 27001, or CPCSC where defence work overlaps, become the fast lane through the procurement gates the CCSPA is about to formalize.
Point-in-time attestations are not enough under the CCSPA: what counts is a program that runs, detects, responds, and can prove all of it on demand. Organizations that build to that standard will find the eventual regulations largely describe what they already do, and their compliance obligations arrive as a byproduct. Organizations that wait for the designation order will be building a security program with a 90-day fuse burning.
If your organization operates in one of the six Schedule 1 sectors, or sells to companies that do, we run CCSPA readiness scoping calls: a working session that maps your current security program against the Act's four duty areas and leaves you with a gap summary you can put in front of your board. Book a scoping call to see where you stand before the designation orders start the clock.
Know Where You Stand on Bill C-8
We map your program against the CCSPA's four duties and build an effective security program before the clock starts.
Frequently Asked Questions
When did Bill C-8 become law?
Bill C-8 received Royal Assent on June 16, 2026. Part 1, which amends the Telecommunications Act, took effect immediately. Part 2, which enacts the Critical Cyber Systems Protection Act, is law but not yet operative; it comes into force on a day fixed by the Governor in Council.
Who does the Critical Cyber Systems Protection Act apply to?
It applies to designated operators in six Schedule 1 sectors: telecommunications, interprovincial or international pipelines and power lines, nuclear energy, federally regulated transportation, banking, and clearing and settlement systems. Obligations attach only once the Governor in Council designates an operator's class in Schedule 2, not at Royal Assent.
What are designated operators required to do?
Four duties: establish a cybersecurity program within 90 days of designation, mitigate identified supply chain and third-party risks on a continuing basis, report cybersecurity incidents to the Cyber Centre within a window capped at 72 hours, and comply with any confidential cyber security direction. A record-keeping duty, with records held in Canada, underlies all four.
What are the penalties under Bill C-8?
The CCSPA allows administrative penalties up to $15 million per violation for organizations and $500,000 per violation for individuals, and a violation that continues counts as a separate violation for each day. The separate Part 1 telecom scheme allows up to $10 million for a first contravention and $15 million for subsequent ones. Serious contraventions can also be prosecuted as offences carrying imprisonment.
Does Bill C-8 affect companies that only sell to these sectors?
Yes, indirectly. The Act requires designated operators to identify and mitigate supply chain risk and prove they did, so operators are expected to push security requirements down to vendors through contracts, audit rights, incident-notification clauses, and security questionnaires. For suppliers, a demonstrable security program becomes the gate to regulated revenue.
When do the compliance deadlines start?
The 90-day clock for a cybersecurity program starts when an operator's class is designated in Schedule 2, published in the Canada Gazette, Part II. No dates had been announced as of early July 2026, which is why gap-assessing before designation converts the deadline from a build project into a documentation exercise.
Ready to Start Your Compliance Journey?
Get a clear, actionable roadmap with our readiness assessment.
Contact Us
Free Report: The CPCSC Compliance Playbook
Join the waitlist for a free copy when it's released.
About the Author
Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure.
