What Bill C-8 did
Bill C-8 received Royal Assent on June 15, 2026. Its amendments to the Telecommunications Act took effect immediately, giving the government order making powers over telecommunications security. Part 2 enacted the Critical Cyber Systems Protection Act (CCSPA), Canada's first binding, cross sector cyber security law for critical infrastructure.
The CCSPA applies to designated operators: organizations in federally regulated finance, telecommunications, energy, and transportation that operate critical cyber systems, systems whose compromise would affect the vital services Canadians depend on.
Who gets designated, and when
Designation happens by order in council: the government adds classes of operators to the Act's schedule, and organizations in a designated class become subject to the duties. As of late August 2026 the schedule is still being populated, which is why prudent operators treat this as a preparation window rather than a waiting room.
The sectors are fixed: finance, telecommunications, energy, and transportation. If you are a bank, a telecom carrier, a pipeline or grid operator, a federally regulated transportation company, or a major supplier whose systems sit inside those services, your exposure question is when and how, not whether.
The four duties
- Establish a cyber security program, within 90 days of designation. A documented program identifying critical cyber systems and the measures protecting them. Ninety days is enough time to finalize a program that exists; it is not enough time to build one well from zero.
- Mitigate supply chain and third party risks. Identify the risks vendors and service providers introduce into critical cyber systems and take reasonable steps to reduce them, with substance behind the paperwork.
- Report significant cyber incidents. To the Cyber Centre, inside a window that regulations are expected to cap at 72 hours. Meeting it requires detection, a rehearsed severity decision, and a runbook, not just an obligation register entry.
- Comply with cyber security directions. The government can issue binding directions to designated operators. The capability to receive, act on, and evidence compliance with a direction needs to exist in advance.
Penalties and accountability
The Act carries administrative monetary penalties reaching $15 million per day for organizations, with separate personal exposure for directors and officers. The practical consequence is board attention: cyber readiness in the four sectors is now a governance topic with statutory teeth, and directors are asking for answers on the record: what are our critical systems, what protects them, where are the gaps, and can we prove any of it.
The resilience expectation
Alongside the statute, the Cyber Centre launched a critical infrastructure resilience initiative in April 2026 telling operators to prepare for severe disruption: operating independently of third party dependencies for extended periods, and rebuilding systems while isolated. This is guidance rather than law, but it shapes what a defensible program looks like, and what a regulator, or a post incident review, will consider reasonable.
What to do before designation
- Determine exposure. Which of your entities and services sit in a designatable class, and what the realistic timeline looks like.
- Inventory critical cyber systems. The systems whose compromise affects your vital service. This inventory anchors the program, the reporting duty, and the board conversation.
- Run a gap assessment. Against the four duties and Cyber Centre guidance, producing a register your board can see.
- Build the program before the clock. Drafting the 90 day artifact now converts a statutory deadline into a review exercise.
- Rehearse the 72 hours. Tabletop a significant incident through detection, severity decision, and report.
- Put it on the board agenda. A standing item with records, so accountability is demonstrated rather than asserted.