Designation starts a 90 day clock. Be ready before it does.
The Critical Cyber Systems Protection Act is law. When designation orders land, operators in finance, telecommunications, energy, and transportation will have 90 days to establish a cyber security program, with incident reporting, supply chain duties, and board accountability behind it. The preparation window is now.
The obligations are set. The names are pending.
Part 2 of Bill C-8, the Critical Cyber Systems Protection Act, creates binding obligations for designated operators. Designation happens by order in council, and the schedule of designated classes is still being populated. That puts the compliance clock in 2027 and the preparation market in 2026: a credible program takes longer than 90 days to build well.
What the Act requires of designated operators
Four duties, each producing artifacts a regulator, and your board, can examine.
Establish a cyber security program
Within 90 days of designation: a documented program covering the identification and protection of critical cyber systems. This is the anchor artifact, and the one worth building before the clock starts.
Mitigate supply chain and third party risks
Identify and reduce the risks your vendors and service providers introduce into critical cyber systems, with contractual and technical measures behind the paperwork.
Report significant cyber incidents
Inside a window regulations are expected to cap at 72 hours. That takes detection, a severity decision process, and a rehearsed reporting runbook, not just a policy.
Comply with cyber security directions
The government can issue binding directions to designated operators. Compliance capability, and records of it, need to exist before a direction arrives.
Five services, one practice
CCSPA sets the floor. The practice is governance your board can stand behind.
CCSPA readiness and gap assessment
Exposure determination, critical cyber system identification, and a gap register against the Act's obligations and Cyber Centre guidance.
Cyber security program design
The 90 day artifact, built before designation: scoped to your critical cyber systems, owned by named roles, and evidenced from day one.
Incident reporting readiness
Detection thresholds, a severity decision process, and a reporting runbook that fits a 72 hour window, exercised on a tabletop before it is needed.
Resilience planning
Per Cyber Centre guidance: operating isolated from third party dependencies, rebuilding while degraded, and proving both are more than slideware.
Third party and supply chain risk
Who you depend on, what flows down to them, and which of those dependencies can take your vital service down with them.
Nine steps, exposure to exercised
Time and materials, with checkpoints. Your team implements; we design, support, and verify. Every stage produces an artifact you keep.
- Exposure determination
Is your organization in a class likely to be designated, what obligations follow, and what the realistic clock looks like.
- Critical cyber system identification
Which systems, if compromised, affect the vital service you deliver. This inventory anchors everything after it.
- Baseline gap assessment
Against the Act's obligations and Cyber Centre guidance, producing a prioritized register.
- Program design
The cyber security program the Act requires, built to be operated rather than filed.
- Supply chain risk process
Dependency mapping, flow down requirements, and contractual teeth.
- Incident reporting readiness
Thresholds, decision process, runbook, and the reporting path.
- Resilience planning
Isolation and rebuild scenarios, planned and costed.
- Board governance layer
Reporting cadence, records, and the answers directors must give on the record.
- Exercise and maintain
Tabletop the program, track designation orders and directions as they land, and keep the evidence current.
Artifacts, not advice
- A critical cyber system inventory your board has seen
- A gap register against the Act's four duties
- A cyber security program ready for the 90 day clock
- An incident reporting runbook that fits 72 hours, tested on a tabletop
- A third party risk map with flow down requirements
- A board reporting pack with records behind every answer
Asked often
We have not been designated. Why act now?
Because the program obligation arrives with a 90 day clock, and a credible program takes longer than that to build well. The Act is in force, the designation schedule is being populated, and boards in the four sectors are already being asked what the plan is.
Does CCSPA apply to us?
Part 2 of Bill C-8 applies to designated operators of critical cyber systems in federally regulated finance, telecommunications, energy, and transportation. Designation happens by order in council. Determining your realistic exposure is the first step of the engagement, and it is quick.
What counts as a critical cyber system?
In practice: a system whose compromise would affect the continuity or security of the vital service you deliver. Producing that inventory, and being able to defend it, is the first artifact of the work.
We are ISO 27001 certified. Are we covered?
A certified ISMS is a strong scaffold and shortens the build considerably, but the Act's duties are specific: the 90 day program, incident reporting on the regulator's clock, supply chain duties, and binding directions. We map your ISMS onto the Act's obligations and close what remains.