Canada now runs two federal cybersecurity mandates that reach companies through entirely different doors. Bill C-8's Critical Cyber Systems Protection Act (CCSPA) binds critical infrastructure operators the government designates; the Canadian Program for Cyber Security Certification (CPCSC) gates the bids of companies pursuing Department of National Defence contracts. One reaches you because you are designated, the other because you chose to bid.
Bill C-8 vs CPCSC at a glance
- Bill C-8 (CCSPA): a regulatory statute binding designated critical infrastructure operators; Royal Assent June 16, 2026
- CPCSC: a procurement condition on Department of National Defence contract bids
- How each reaches you: the CCSPA by government designation; CPCSC by choosing to bid
- Live deadline now: CPCSC Level 1 self-assessment mandatory for most DND bids since April 2026; Level 2 from April 2027
- Penalties: CCSPA administrative penalties up to $15 million per violation; CPCSC has no fines, its enforcement is bid ineligibility
- Status: the CCSPA is enacted but awaits a coming-into-force order and designations, so no operator owes obligations yet
How do Bill C-8 and CPCSC differ?
| Bill C-8 (CCSPA) | CPCSC | |
| Legal basis | Federal statute: the Critical Cyber Systems Protection Act, enacted as Part 2 of Bill C-8 (Royal Assent June 16, 2026) | Procurement program run by Public Services and Procurement Canada; requirements written into DND contracts and bid conditions |
| Who is covered | Designated operators of critical cyber systems in six Schedule 1 sectors: telecommunications, interprovincial or international pipelines and power lines, nuclear energy, federally regulated transportation, banking, and clearing and settlement systems | Companies bidding on in-scope Department of National Defence contracts, across the defence supply chain |
| How it reaches a company | Government designation: the Governor in Council adds classes of operators to Schedule 2 by order; no opting out while operating the vital service | Contract bidding: the requirement attaches when a company pursues a contract that carries it |
| What it requires | A cybersecurity program (identify and manage risk including supply chain, protect, detect, minimize impact) within 90 days of designation; a standing duty to mitigate supply chain risk; incident reporting to the Cyber Centre on a clock capped at 72 hours; compliance with cyber security directions; records kept in Canada | Level 1: annual self-assessment against 13 requirements (71 assessment objectives); Level 2: all 97 ITSP.10.171 controls across 17 families; Level 3: DND assessment with additional controls |
| Assessment model | Regulatory oversight, not certification: the program is filed with the sector regulator, which holds audit, inspection, and compliance-order powers | Attestation and certification: Level 1 attested through the contractor's Canada Buys profile; Level 2 certified by an SCC-accredited third-party body; Level 3 assessed by DND directly |
| Penalties for falling short | Administrative monetary penalties up to $15 million per violation for organizations ($500,000 for individuals), with each day of a continuing violation counting as a separate violation; criminal offences carrying up to five years imprisonment; personal director and officer liability | Ineligibility to bid; lost contracts and lost recompetes; no fines, because the enforcement mechanism is the procurement gate itself |
| Status as of July 2026 | Part 1 (telecom powers) in force; the CCSPA is enacted but awaits a coming-into-force order, Schedule 2 designations, and supporting regulations, so no operator owes obligations yet | Level 1 attestation mandatory for most DND bids since April 2026; Level 2 requirements appear in contracts from April 2027; full rollout phases run through 2028 |
As of July 2026, CPCSC is the mandate with live deadlines. The CCSPA's obligations are written and its penalties are defined, but none of it binds anyone until the Governor in Council brings it into force and designates operator classes.
Which clock is running
CPCSC's Level 1 gate has been operating since April 2026. A defence supplier's clock is already running; a critical infrastructure operator's clock has a visible fuse but no lit match.
How does each mandate reach a company?
The CCSPA works the way banking or nuclear regulation works. Parliament declared six services vital to national security or public safety, and the Governor in Council will name the classes of operators that owe obligations. A payments processor or a pipeline operator does not apply for CCSPA coverage and cannot decline it; the only way out is to stop operating the vital service.
Once designated, the operator deals with its existing sector regulator (under the framework as introduced, the Bank of Canada for clearing and settlement, OSFI for banking, the Canadian Nuclear Safety Commission for nuclear, and so on), which receives the cybersecurity program, holds inspection powers, and administers penalties. The full breakdown of the statute is in the Bill C-8 and CCSPA guide.
CPCSC works the way procurement works. No statute compels a machining shop or a software firm to implement ITSP.10.171 controls. But when a DND contract carries a CPCSC requirement, an uncertified company cannot bid, and an incumbent that lets its attestation lapse cannot recompete. There is no fine; the government declines to buy. The CPCSC certification guide covers the program's three levels, four governing bodies, and phased timeline in detail.
A designated operator that neglects the CCSPA faces escalating penalties while continuing to operate, with each day of a continuing violation counted as a separate violation and directors and officers personally exposed. A defence supplier that neglects CPCSC faces nothing on paper and everything in the pipeline: the cost shows up as revenue that fails to arrive, which is harder to see on a dashboard and easier for a leadership team to discount until a bid deadline makes it concrete.
They differ, too, in what counts as proof. CPCSC is prescriptive and checkable: 13 requirements at Level 1, 97 controls at Level 2, each with defined assessment objectives a third-party assessor will verify. The CCSPA is outcome-based: it names four functions the program must perform (identify and manage risk including supply chain, protect, detect, minimize impact) and leaves the control detail to regulations and to the operator's judgment, backed by a due diligence defence that only helps those who can document their diligence. One regime hands you the checklist; the other hands you the burden of proof.
Where do Bill C-8 and CPCSC overlap?
Both regimes demand the same underlying capabilities in three areas: supply chain risk management, incident readiness, and program formality.
Supply chain risk management. The CCSPA imposes a standing duty: as soon as a designated operator identifies a cybersecurity risk in its supply chain or its use of third-party products, it must take reasonable steps to mitigate it, and failing to do so is both a penalty violation and a prosecutable offence. ITSP.10.171 dedicates an entire control family to the same territory, covering supplier assessment and acquisition safeguards, detailed in the CPCSC supply chain risk management post. Both governments reached the same conclusion: an organization's security boundary includes its vendors.
Incident readiness. A designated operator under the CCSPA must report incidents, including potential interference, to the Cyber Centre within a window that regulations will set at no more than 72 hours. ITSP.10.171's incident response family requires handling, monitoring, reporting, and testing capabilities. In both cases the requirement is only nominally about reporting; meeting either one demands detection that works, a classification process that can decide severity fast, and rehearsed response.
Program formality and evidence. The CCSPA requires the program to be written, filed with a regulator, reviewed annually, and backed by records kept in Canada covering implementation, incidents, supply chain mitigation, and any directions. CPCSC requires attestation against defined assessment objectives at Level 1 and third-party verification at Level 2. Neither regime accepts security that exists only in the practices of a capable team. Both demand a program that can be shown to someone whose job is to doubt it.
Because both regimes reward the same implemented controls, a single control can satisfy several masters at once. The CCSPA to ISO 27001, NIST CSF, and CPCSC crosswalk maps those overlaps control by control.
What do Bill C-8 and CPCSC mean for Canadian market access?
Within two years, Canada made a documented, verifiable security program the condition of bidding on defence work (April 2026) and the future condition of operating critical infrastructure (Royal Assent, June 2026). The mechanisms differ, designation on one side and procurement on the other, but the underlying transaction is identical: demonstrate a working security program or lose access to a market.
Companies at the checklist stage, where security is a folder of policies refreshed before each audit, will find CPCSC Level 2's 97 verified controls and the CCSPA's continuous duties equally uncomfortable, because both regimes test operation rather than intent.
Companies further up the curve, running a program with an owned control inventory, routine evidence collection, and rehearsed incident response, will experience either mandate as a mapping exercise. The gap between those two positions is measured in months of work, which is why the arrival of a designation order or an RFP is a poor moment to discover which one you occupy.
There is also a second-order effect that reaches companies neither mandate names. Designated operators must mitigate supply chain risk under penalty and prove it with records, so they will push requirements into vendor contracts: security clauses, questionnaires, audit rights, incident notification terms. The Bill C-8 vendor security requirements post covers that flow-down. A software company that sells to a bank or a telecom will feel the CCSPA through procurement paperwork long before it ever reads the statute, which means the practical experience of the regulatory mandate ends up looking a lot like the procurement one.
This dynamic is familiar from critical-infrastructure procurement: vendors who could demonstrate their security moved through onboarding, while those who could only describe it stalled. Both of these mandates take that dynamic and give it legal and contractual force across the economy.
Which mandate applies to my company?
Coverage resolves into four situations.
Federally regulated critical infrastructure operators: the CCSPA, on designation. Telecoms, banks, payment clearing systems, federally regulated carriers, pipeline and power line operators, and nuclear operators should assume their class will appear in a Schedule 2 order and prepare against the four program functions now, because the 90-day window after designation will not accommodate a build from scratch. The obligations are itemized in the CCSPA cybersecurity program requirements guide.
Defence suppliers: CPCSC, already. Any company bidding on DND contracts needed Level 1 attestation as of April 2026, and companies handling Controlled Information should be preparing for Level 2 certification ahead of the April 2027 contract requirements, with assessor capacity still limited. The Level 1 self-assessment guide is the starting point; suppliers also selling to the U.S. Department of Defense should note there is no mutual recognition between the programs, a gap examined in CPCSC vs CMMC.
The 90-day window is not a build window
A designated operator has 90 days to have a cybersecurity program in place, not 90 days to build one from scratch. Operators whose sector sits in Schedule 1 should be preparing against the four program functions now, before any designation order lands.
Companies exposed to both. A telecom or transportation firm with defence contracts, or a defence prime that operates designated infrastructure, will answer to both regimes: CPCSC on its bids today and the CCSPA on its operations once designated. For these companies the one-program argument below stops being an efficiency preference and becomes the only workable design.
Vendors to any of the above: neither mandate directly, both commercially. A SaaS company selling into banking or a components supplier selling to a defence prime is outside both regimes on paper and inside both procurement gates in practice, through CCSPA flow-down clauses and CPCSC requirements passed down prime-to-subcontractor. For this group the mandates arrive as questionnaires, contract terms, and certification asks, and the companies that answer them quickly win the deals that stall for everyone else.
Can one security program satisfy both mandates?
A company facing CPCSC, future CCSPA exposure, and the SOC 2 or ISO 27001 demands of commercial customers has two options. It can run three compliance projects, each producing its own documents, its own evidence scramble, and its own annual panic. Or it can build one security program and treat each framework as a reporting view of it.
The second option works because the frameworks demand overlapping substance. ITSP.10.171 shares its structure with NIST SP 800-171; the CCSPA's four functions track the NIST CSF; ISO 27001 and SOC 2 cover much of the same control territory with different assessment lenses. The SOC 2 to CPCSC mapping guide maps the commercial-to-defence overlap, and the CCSPA crosswalk linked above maps the regulatory overlap. An access review that happens monthly, generates its own evidence, and is recorded in a control inventory satisfies an SCC-accredited assessor, a sector regulator, and a SOC 2 auditor alike. Three binders of framework-specific policies satisfy no one for long, because paper diverges from practice the moment the project team disbands.
This is the working definition of GRC engineering: build the control once, into the systems and processes where the work happens, and let each framework's evidence fall out as a byproduct. It is also where the mandates' differences stop mattering. The designation order and the RFP are different doors into the same room, and the room contains one question: does a real program exist, and can you prove it?
The sequence for a company starting this quarter:
- Classify your exposure. Which of the four situations above describes you? That determines which clock you are on: CPCSC's live deadlines, the CCSPA's pre-designation window, or a customer's procurement cycle.
- Pick the anchor. Choose the most demanding framework you plausibly face (ITSP.10.171 for defence-heavy companies, ISO 27001 or NIST CSF for most others) and build the control inventory against it.
- Map once, then reuse. Cross-reference the inventory to each additional framework before building anything new; the crosswalks above show that the genuinely new work per added framework is usually a fraction of the whole.
- Engineer the evidence. For each control, decide where its operating evidence is generated and make that generation automatic. Assessment, whether by self-attestation, accredited assessor, or regulator, becomes retrieval rather than reconstruction.
A company can meet Canada's two mandates with a stack of parallel paper exercises, or with one program that happens to be attestable in every direction it faces. The second approach costs less, holds up under audits it was not designed for, and turns the next mandate, whenever it arrives, into a mapping exercise instead of a project.
One program, both mandates
Truvo helps Canadian companies build one effective security program that answers CPCSC, the CCSPA, and commercial audits alike.
Frequently Asked Questions
What is the difference between Bill C-8 and CPCSC?
Bill C-8 enacts the Critical Cyber Systems Protection Act, a regulatory statute that binds designated operators in six critical infrastructure sectors. CPCSC is a procurement program that gates bids on Department of National Defence contracts. One reaches you by government designation; the other reaches you when you choose to bid.
Which mandate applies to my company?
Federally regulated critical infrastructure operators in the six Schedule 1 sectors fall under the CCSPA once their class is designated in Schedule 2. Companies bidding on in-scope DND contracts fall under CPCSC. Firms doing both answer to both, and vendors to either group meet the requirements through procurement flow-down.
Which mandate has active deadlines right now?
CPCSC. Level 1 self-assessment attestation has been mandatory for most DND bids since April 2026, with Level 2 third-party certification arriving in contracts from April 2027. The CCSPA is enacted but binds no one until the Governor in Council issues a coming-into-force order and designates operator classes.
What are the penalties under each mandate?
The CCSPA carries administrative monetary penalties up to $15 million per violation for organizations and $500,000 for individuals, with each day of a continuing violation counted separately, plus criminal offences and personal director and officer liability. CPCSC has no fines; the enforcement mechanism is ineligibility to bid.
Can one security program satisfy both Bill C-8 and CPCSC?
Yes. Both regimes demand overlapping substance: supply chain risk management, incident readiness, and a written, evidenced program. Building one control inventory against the most demanding framework you face, then mapping it to each mandate, satisfies an accredited assessor, a sector regulator, and commercial auditors from the same operating evidence.
Do these mandates affect companies that only sell to covered organizations?
Yes, commercially. Designated operators must mitigate supply chain risk and prove it, so they push security requirements to vendors through contracts, questionnaires, and audit rights. CPCSC requirements pass down from primes to subcontractors. Suppliers face both as procurement conditions rather than direct legal obligations.
If you are working out which of these mandates reaches your company, and whether your current program would satisfy either, we run scoping calls for exactly that question. You leave with a coverage map: which regime applies to you, on what timeline, and a gap summary against the one you face first. Book a scoping call before one of the clocks starts running.
Ready to Start Your Compliance Journey?
Get a clear, actionable roadmap with our readiness assessment.
Contact Us
Free Report: The CPCSC Compliance Playbook
Join the waitlist for a free copy when it's released.
About the Author
Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure.