Overview
The CCSPA was first proposed in Bill C-26 in 2022. That bill passed the House of Commons and then the Senate with amendments, but it died before the House dealt with those amendments when the session ended on January 6, 2025. The government reintroduced the package as Bill C-8 on June 18, 2025, and it received royal assent on June 15, 2026 as Statutes of Canada 2026, chapter 9. Part 1 amends the Telecommunications Act to add security as a policy objective and to let the government order telecommunications service providers to act against threats. That part is in force.
Part 2 enacts the CCSPA, and it's a different story. Its provisions come into force only on a day or days fixed by order of the Governor in Council. The Justice Laws consolidation current to September 21, 2026 shows Part 2 as not in force, and the Schedule 2 table of operator classes and regulators is empty. Nor are any regulations. Until a coming-into-force order, a Schedule 2 order, and regulations are published, the Act creates no obligations for any organization.
Once it applies, a designated operator will have 90 days after joining a class to establish a cyber security program, notify its regulator, and provide the program. It will need to mitigate supply chain and third-party risks, report cyber security incidents to CSE within the period set by regulation, which can't exceed 72 hours, and comply with cyber security directions from the Governor in Council. Regulators will differ by sector. They include OSFI, the Minister of Industry, the Bank of Canada, the Canadian Nuclear Safety Commission, the Canadian Energy Regulator, and the Minister of Transport. Administrative monetary penalties can reach $500,000 for individuals and $15 million for others.
Who it applies to in Canada
Designated operators, meaning federally regulated organizations in classes the Governor in Council adds to Schedule 2, in respect of 6 vital services and systems: telecommunications, interprovincial or international pipelines and power lines, nuclear energy, federally regulated transportation, banking, and clearing and settlement.
The CCSPA will set federal cyber security duties across several critical infrastructure sectors, with mandatory programs and 72-hour incident reporting to the Communications Security Establishment, home of the Canadian Centre for Cyber Security. Suppliers to banks, telecom carriers, pipelines, and federal transportation operators should expect these duties to flow down through contracts.
Controls at a glance
The obligations below follow the Act's parts on designation, cyber security programs, supply chain risk, incident reporting, directions, records, and enforcement.
Designation
- Governor in Council lists vital services in Schedule 1
- Governor in Council adds operator classes to Schedule 2
- Each class is paired with one regulator
- Only federally regulated operators can be designated
Cyber security program
- Establish a program within 90 days of designation
- Identify and manage organizational cyber risks
- Protect, detect, and minimize impact of incidents
- Notify the regulator and provide the program
- Implement and maintain the program
Program review and changes
- Review the program annually or on prescribed dates
- Complete each review within 60 days
- Report changes to the regulator
- Report material ownership or supply chain changes
Supply chain and third-party risk
- Identify risks from suppliers and third-party services
- Mitigate those risks once identified
- Follow CSE guidelines where issued
Incident reporting
- Report incidents to CSE within the prescribed period
- Prescribed period can't exceed 72 hours
- Notify the regulator immediately after reporting
Cyber security directions
- Comply with Governor in Council directions
- Disclose a direction only as needed to comply
- Directions can't order decryption of private communications
Records
- Keep records on program steps taken
- Keep records of reported incidents
- Keep records on supply chain mitigation and directions
Enforcement
- Regulators can inspect, order internal audits, and order compliance
- Penalties up to $500,000 for individuals
- Penalties up to $15 million for organizations
- Offences can bring fines and imprisonment
Certification and assessment
No organization is assessed yet because Part 2 isn't in force and no operator classes are designated. Once it applies, operators will file their programs with the appropriate regulator, which can audit, inspect, issue compliance orders, and impose administrative monetary penalties.
Dates to know
- 2022-06-14
- Bill C-26 introduced, first proposing the CCSPA
- 2025-01-06
- Bill C-26 dies when the parliamentary session ends
- 2025-06-18
- Bill C-8 introduced in the House of Commons
- 2026-03-26
- House of Commons passes Bill C-8
- 2026-06-04
- Senate passes Bill C-8
- 2026-06-15
- Royal assent; Telecommunications Act amendments in force, CCSPA awaiting a coming-into-force order
Resources
Official texts and free tools for CCSPA. Links open the publisher’s site.
- An Act respecting cyber security (S.C. 2026, c. 9), Justice Laws Website
- Bill C-8 (45th Parliament, 1st Session), LEGISinfo, Parliament of Canada
- Bill C-8 as passed (royal assent text), Parliament of Canada
- Cyber security, Public Safety Canada
- Report a cyber incident, Canadian Centre for Cyber Securitytool
Need help? Browse the directory or read the guides.
References
- Bill C-8 as passed (royal assent text), Parliament of Canada
- An Act respecting cyber security (S.C. 2026, c. 9), Justice Laws Website
- Bill C-8 (45th Parliament, 1st Session), LEGISinfo, Parliament of Canada
- Bill C-26 (44th Parliament, 1st Session), LEGISinfo, Parliament of Canada
- Government of Canada strengthens cyber security and critical infrastructure with royal assent of Bill C-8, Public Safety Canada
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.