Managed Compliance

CCSPA and Bill C-8 compliance

Canada's Bill C-8 is now in force. Telecom, energy, transportation, banking, and nuclear operators have 90 days to provide a cyber security program once designated. Are you ready?

Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. CISSP, CCSP, more than twenty years in enterprise security. Leads every engagement.

Connect on LinkedIn

What the engagement covers

Build the cyber security program the CCSPA will ask your regulator, or your customer, to inspect.

icon-5

Exposure read

Designated operator, supplier to one, or neither. Decided from Schedule 1 and Schedule 2 as published, in writing, with your counsel where a reading is contested.

icon-9

Critical cyber system scoping

The system as the law defines it rather than the boundary the company chose, and the third-party dependencies inside it.

icon-6

Gap analysis against the four program elements

Your existing ISO 27001 or SOC 2 program measured against identify and manage, protect, detect, and respond and recover. Usually re-cutting scope and evidence, not rebuilding controls.

icon-4

Supply chain risk duty

Vendor inventory, assessments, contract clauses, and the record trail behind them.

icon-2

Incident reporting rehearsal

Tabletop against the statutory 72-hour ceiling and the CSE Cyber Centre reporting path, with the period set by regulation once published.

icon-8

Records-in-Canada review

Where compliance evidence physically resides, and what has to move.

Assess, Build, Operate, applied to a designated operator's program

The program is built once and kept operating, so designation becomes a notification exercise. A documented methodology, led by a senior architect with more than ten years of enterprise security experience and a CISSP.

01

Assess

Exposure read, critical cyber system scoping, and a gap analysis of what you already hold against the four program elements and the supply chain duty.

02

Build

Scope and evidence re-cut to the statutory boundary, supply chain records, the regulator notification workflow, and the incident reporting rehearsal.

03

Operate

Records kept current, vendors reassessed, the reporting path exercised, and the program provided to the regulator on designation.

Built inside two of the six sectors

Truvo's team built and operated security programs inside Canada's national payments infrastructure. Clearing and settlement systems and banking systems are two of the six Schedule 1 sectors the CCSPA names.

  • Exposure determination, in writing

  • Critical cyber system scope and dependency map

  • Gap analysis against the four program elements

  • Supply chain risk register and contract clause set

  • Incident reporting runbook and rehearsal record

  • Records-in-Canada review

  • Cyber security program document ready to provide

What changes

The period before designation is the part an operator controls.

Who this is for, and who it is not

Being in one of the six sectors does not by itself make you a designated operator. Selling into one is enough to be asked about it.

Frequently asked questions

Directly, only if the organization is a designated operator: a member of a class added to Schedule 2 that runs a critical cyber system supporting one of six Schedule 1 sectors, namely telecommunications, interprovincial and international pipelines and power lines, nuclear energy, federally regulated transportation, banking, and clearing and settlement. Being in one of those sectors is not enough on its own. Indirectly, it reaches every company selling into them, because a designated operator has a statutory duty to mitigate the cyber security risk its suppliers introduce and to keep records of what it did.

Part 2 of Bill C-8, the CCSPA itself, was enacted on June 16, 2026 and comes into force on a day fixed by order. Obligations then attach to a given organization only once its class is designated in Schedule 2, published in the Canada Gazette, Part II, and that publication starts a 90-day clock. Ninety days is enough time to document a program that already exists. It is not enough time to build one. The period before designation is the part an operator controls.

Substantially, on control substance. An ISO 27001 ISMS or a SOC 2 report covers the identify, protect, detect, and respond elements the Act names. What neither supplies automatically is the CCSPA's scoping to the critical cyber system as the law defines it rather than the boundary the company chose, the regulator notification workflow, and whatever the regulations prescribe. The work is usually re-cutting scope and evidence, not rebuilding controls.

They need evidence they can put in their own record: what risk they identified in the relationship, and what reasonable steps were taken to mitigate it. In practice that arrives as security clauses, audit rights, incident notification terms, a completed questionnaire, and something certified behind it. A supplier who answers with verifiable proof clears procurement while competitors sit in security review.

Administrative monetary penalties reach $15 million per violation for organizations and $500,000 for individuals, and each day a violation continues counts as a separate violation. Serious contraventions can be prosecuted as offences. A due diligence defence is available, which is the reason the documented, operating program is the defensible position.

Talk to the architect who would do the work

A 30-minute call. We look at your environment and say plainly whether we can help and what it would take.

From the blog: Bill C-8 and the CCSPA

vCISO Services for Mid-Market SaaS: How to Evaluate Fractional Security Leadership in 2026

vCISO services give a mid-market SaaS company senior security leadership on a fractional basis: someone who owns the security program, drives SOC 2 ...

Top 8 vCISO Services for Mid-Market SaaS in 2026

The right vCISO service for a mid-market SaaS company is the one that owns and runs the security program end to end, on a fractional basis, the way a ...

What a Security Architect Actually Does: Three Roles and Where Requirements Come From

A security architect does three jobs: sets security requirements for systems other people design, assesses and reviews those designs, and solutions ...