home / frameworks / ccspa

// Canadian privacy and cyber law

Critical Cyber Systems Protection Act (CCSPA)

The Critical Cyber Systems Protection Act became law on June 15, 2026 as Part 2 of Bill C-8 but is not yet in force. Once operators are designated, they will need cyber security programs, supply chain risk controls, and incident reports to CSE within 72 hours.

Canada (federal)

Overview

The CCSPA was first proposed in Bill C-26 in 2022. That bill passed the House of Commons and then the Senate with amendments, but it died before the House dealt with those amendments when the session ended on January 6, 2025. The government reintroduced the package as Bill C-8 on June 18, 2025, and it received royal assent on June 15, 2026 as Statutes of Canada 2026, chapter 9. Part 1 amends the Telecommunications Act to add security as a policy objective and to let the government order telecommunications service providers to act against threats. That part is in force.

Part 2 enacts the CCSPA, and it's a different story. Its provisions come into force only on a day or days fixed by order of the Governor in Council. The Justice Laws consolidation current to September 21, 2026 shows Part 2 as not in force, and the Schedule 2 table of operator classes and regulators is empty. Nor are any regulations. Until a coming-into-force order, a Schedule 2 order, and regulations are published, the Act creates no obligations for any organization.

Once it applies, a designated operator will have 90 days after joining a class to establish a cyber security program, notify its regulator, and provide the program. It will need to mitigate supply chain and third-party risks, report cyber security incidents to CSE within the period set by regulation, which can't exceed 72 hours, and comply with cyber security directions from the Governor in Council. Regulators will differ by sector. They include OSFI, the Minister of Industry, the Bank of Canada, the Canadian Nuclear Safety Commission, the Canadian Energy Regulator, and the Minister of Transport. Administrative monetary penalties can reach $500,000 for individuals and $15 million for others.

Who it applies to in Canada

Designated operators, meaning federally regulated organizations in classes the Governor in Council adds to Schedule 2, in respect of 6 vital services and systems: telecommunications, interprovincial or international pipelines and power lines, nuclear energy, federally regulated transportation, banking, and clearing and settlement.

The CCSPA will set federal cyber security duties across several critical infrastructure sectors, with mandatory programs and 72-hour incident reporting to the Communications Security Establishment, home of the Canadian Centre for Cyber Security. Suppliers to banks, telecom carriers, pipelines, and federal transportation operators should expect these duties to flow down through contracts.

Controls at a glance

The obligations below follow the Act's parts on designation, cyber security programs, supply chain risk, incident reporting, directions, records, and enforcement.

Designation

  • Governor in Council lists vital services in Schedule 1
  • Governor in Council adds operator classes to Schedule 2
  • Each class is paired with one regulator
  • Only federally regulated operators can be designated

Cyber security program

  • Establish a program within 90 days of designation
  • Identify and manage organizational cyber risks
  • Protect, detect, and minimize impact of incidents
  • Notify the regulator and provide the program
  • Implement and maintain the program

Program review and changes

  • Review the program annually or on prescribed dates
  • Complete each review within 60 days
  • Report changes to the regulator
  • Report material ownership or supply chain changes

Supply chain and third-party risk

  • Identify risks from suppliers and third-party services
  • Mitigate those risks once identified
  • Follow CSE guidelines where issued

Incident reporting

  • Report incidents to CSE within the prescribed period
  • Prescribed period can't exceed 72 hours
  • Notify the regulator immediately after reporting

Cyber security directions

  • Comply with Governor in Council directions
  • Disclose a direction only as needed to comply
  • Directions can't order decryption of private communications

Records

  • Keep records on program steps taken
  • Keep records of reported incidents
  • Keep records on supply chain mitigation and directions

Enforcement

  • Regulators can inspect, order internal audits, and order compliance
  • Penalties up to $500,000 for individuals
  • Penalties up to $15 million for organizations
  • Offences can bring fines and imprisonment

Certification and assessment

No organization is assessed yet because Part 2 isn't in force and no operator classes are designated. Once it applies, operators will file their programs with the appropriate regulator, which can audit, inspect, issue compliance orders, and impose administrative monetary penalties.

Dates to know

2022-06-14
Bill C-26 introduced, first proposing the CCSPA
2025-01-06
Bill C-26 dies when the parliamentary session ends
2025-06-18
Bill C-8 introduced in the House of Commons
2026-03-26
House of Commons passes Bill C-8
2026-06-04
Senate passes Bill C-8
2026-06-15
Royal assent; Telecommunications Act amendments in force, CCSPA awaiting a coming-into-force order

Resources

Official texts and free tools for CCSPA. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Bill C-8 as passed (royal assent text), Parliament of Canada
  2. An Act respecting cyber security (S.C. 2026, c. 9), Justice Laws Website
  3. Bill C-8 (45th Parliament, 1st Session), LEGISinfo, Parliament of Canada
  4. Bill C-26 (44th Parliament, 1st Session), LEGISinfo, Parliament of Canada
  5. Government of Canada strengthens cyber security and critical infrastructure with royal assent of Bill C-8, Public Safety Canada