Practice 02 · Critical Infrastructure Cyber Governance

Designation starts a 90 day clock. Be ready before it does.

The Critical Cyber Systems Protection Act is law. When designation orders land, operators in finance, telecommunications, energy, and transportation will have 90 days to establish a cyber security program, with incident reporting, supply chain duties, and board accountability behind it. The preparation window is now.

Bill C-8 received Royal Assent June 15, 2026
Administrative monetary penalties reach $15 million per day
Why now

The obligations are set. The names are pending.

Part 2 of Bill C-8, the Critical Cyber Systems Protection Act, creates binding obligations for designated operators. Designation happens by order in council, and the schedule of designated classes is still being populated. That puts the compliance clock in 2027 and the preparation market in 2026: a credible program takes longer than 90 days to build well.

4
federally regulated sectors in scope: finance, telecommunications, energy, transportation
90 days
to establish a cyber security program after designation
72 hrs
incident reporting window regulations are expected to cap
The obligation

What the Act requires of designated operators

Four duties, each producing artifacts a regulator, and your board, can examine.

Duty 01

Establish a cyber security program

Within 90 days of designation: a documented program covering the identification and protection of critical cyber systems. This is the anchor artifact, and the one worth building before the clock starts.

Duty 02

Mitigate supply chain and third party risks

Identify and reduce the risks your vendors and service providers introduce into critical cyber systems, with contractual and technical measures behind the paperwork.

Duty 03

Report significant cyber incidents

Inside a window regulations are expected to cap at 72 hours. That takes detection, a severity decision process, and a rehearsed reporting runbook, not just a policy.

Duty 04

Comply with cyber security directions

The government can issue binding directions to designated operators. Compliance capability, and records of it, need to exist before a direction arrives.

Also in motion: the Cyber Centre's critical infrastructure resilience initiative, launched April 2026, tells operators to prepare for severe disruption: operating independently of third party dependencies for extended periods and rebuilding systems while isolated. Boards in these sectors now face questions they must answer on the record.
What we do

Five services, one practice

CCSPA sets the floor. The practice is governance your board can stand behind.

CCSPA readiness and gap assessment

Exposure determination, critical cyber system identification, and a gap register against the Act's obligations and Cyber Centre guidance.

Cyber security program design

The 90 day artifact, built before designation: scoped to your critical cyber systems, owned by named roles, and evidenced from day one.

Incident reporting readiness

Detection thresholds, a severity decision process, and a reporting runbook that fits a 72 hour window, exercised on a tabletop before it is needed.

Resilience planning

Per Cyber Centre guidance: operating isolated from third party dependencies, rebuilding while degraded, and proving both are more than slideware.

Third party and supply chain risk

Who you depend on, what flows down to them, and which of those dependencies can take your vital service down with them.

How the engagement runs

Nine steps, exposure to exercised

Time and materials, with checkpoints. Your team implements; we design, support, and verify. Every stage produces an artifact you keep.

  1. Exposure determination

    Is your organization in a class likely to be designated, what obligations follow, and what the realistic clock looks like.

  2. Critical cyber system identification

    Which systems, if compromised, affect the vital service you deliver. This inventory anchors everything after it.

  3. Baseline gap assessment

    Against the Act's obligations and Cyber Centre guidance, producing a prioritized register.

  4. Program design

    The cyber security program the Act requires, built to be operated rather than filed.

  5. Supply chain risk process

    Dependency mapping, flow down requirements, and contractual teeth.

  6. Incident reporting readiness

    Thresholds, decision process, runbook, and the reporting path.

  7. Resilience planning

    Isolation and rebuild scenarios, planned and costed.

  8. Board governance layer

    Reporting cadence, records, and the answers directors must give on the record.

  9. Exercise and maintain

    Tabletop the program, track designation orders and directions as they land, and keep the evidence current.

What you walk away with

Artifacts, not advice

  • A critical cyber system inventory your board has seen
  • A gap register against the Act's four duties
  • A cyber security program ready for the 90 day clock
  • An incident reporting runbook that fits 72 hours, tested on a tabletop
  • A third party risk map with flow down requirements
  • A board reporting pack with records behind every answer
Questions

Asked often

We have not been designated. Why act now?

Because the program obligation arrives with a 90 day clock, and a credible program takes longer than that to build well. The Act is in force, the designation schedule is being populated, and boards in the four sectors are already being asked what the plan is.

Does CCSPA apply to us?

Part 2 of Bill C-8 applies to designated operators of critical cyber systems in federally regulated finance, telecommunications, energy, and transportation. Designation happens by order in council. Determining your realistic exposure is the first step of the engagement, and it is quick.

What counts as a critical cyber system?

In practice: a system whose compromise would affect the continuity or security of the vital service you deliver. Producing that inventory, and being able to defend it, is the first artifact of the work.

We are ISO 27001 certified. Are we covered?

A certified ISMS is a strong scaffold and shortens the build considerably, but the Act's duties are specific: the 90 day program, incident reporting on the regulator's clock, supply chain duties, and binding directions. We map your ISMS onto the Act's obligations and close what remains.

Boards are asking the question already.

What are our critical systems, what controls do we have, where are the gaps, can we prove any of it. A gap assessment gives you the answers on the record.