home / frameworks / ciro-cyber

// Canadian sector regulators

CIRO cybersecurity incident reporting and related dealer requirements

CIRO requires investment dealers to report cybersecurity incidents within 3 days of discovery and to file an investigation report within 30 days. Consolidated CIRO Rules now under consultation would extend the duty to mutual fund dealers.

Canada (national self-regulatory organization)

Overview

The Investment Industry Regulatory Organization of Canada (IIROC) made cybersecurity incident reporting mandatory for its dealer members on November 14, 2019, after Canadian securities regulators approved the amendments. Dealers must report a cybersecurity incident to the regulator within 3 days of discovering it. They must then file an incident investigation report within 30 days of discovery. The rule lists required content. IIROC chose a broad, flexible definition of cybersecurity incident to fit different business models. It shares what it learns with other dealers only on an anonymous, high-level basis.

IIROC and the Mutual Fund Dealers Association of Canada amalgamated on January 1, 2023 and took the name CIRO on June 1, 2023. The reporting duty now sits in section 3703 of CIRO's Investment Dealer and Partially Consolidated (IDPC) Rules. It applies to investment dealers only. CIRO's own Phase 5 consultation in March 2025 noted that the Mutual Fund Dealer Rules have no cybersecurity reporting rule. Mutual fund dealers still report privacy breaches under those rules and privacy law.

Change is coming, though not yet. In February 2026 CIRO republished its complete proposed CIRO Rules, which would replace both dealer rulebooks with one set. The proposal moves cyber reporting to a new section 3712 for all dealer members, asks for the initial report as soon as possible and no later than 3 calendar days, and carves cyber incidents out of the separate business disruption reporting rule. It also keeps a duty to report material breaches of client information that privacy law requires to be reported. Comments closed June 12, 2026, and CIRO proposed an 18-month implementation period after approval. Its own data breach, disclosed with CSA oversight, has kept attention on dealer cyber risk.

Who it applies to in Canada

Investment dealers that are CIRO Dealer Members, including firms registered as both investment dealers and mutual fund dealers. Mutual fund dealers that follow only the Mutual Fund Dealer Rules have no current cyber incident reporting rule.

CIRO is the national self-regulatory organization for investment and mutual fund dealers, recognized and overseen by the Canadian Securities Administrators. Dealers report cyber incidents to CIRO on top of privacy breach reporting under PIPEDA or provincial law, and their technology suppliers support those reports.

Controls at a glance

CIRO's cyber requirements are a reporting rule backed by supervisory expectations, with a consolidated rule proposed.

Initial incident report (IDPC section 3703)

  • Report cybersecurity incidents to CIRO within 3 days of discovery
  • Broad definition covering incidents affecting information systems
  • Include the information the rule lists
  • Early report may hold limited information

Investigation report (IDPC section 3703)

  • File an investigation report within 30 days of discovery
  • Cover the content items the rule lists
  • Add details not known at the 3-day report

Related dealer duties

  • MFD Rules require reporting material client information breaches
  • Keep records available to CIRO on request
  • Separate from PIPEDA and provincial privacy breach reporting

Proposed consolidated CIRO Rules (not in force)

  • One rulebook for investment and mutual fund dealers
  • Cyber reporting moves to proposed section 3712
  • Initial report as soon as possible, within 3 calendar days
  • Cyber incidents carved out of business disruption reporting
  • 18-month implementation period proposed after approval

Certification and assessment

Dealers show compliance by filing timely initial and investigation reports and by keeping records CIRO can review in compliance examinations. There's no certification. CIRO can take enforcement action against a dealer that fails to report an incident on time or files reports that leave out required information.

Dates to know

2018-04-05
IIROC proposes mandatory cybersecurity incident reporting
2019-11-14
Mandatory cybersecurity incident reporting takes effect for IIROC dealers
2023-06-01
New Self-Regulatory Organization of Canada becomes CIRO
2026-02-12
CIRO republishes complete proposed consolidated CIRO Rules for comment
2026-06-12
Comment period on proposed CIRO Rules closes

Resources

Official texts and free tools for CIRO cyber reporting. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. IIROC Notice 19-0194, Amendments respecting mandatory reporting of cybersecurity incidents, Investment Industry Regulatory Organization of Canada, via the Ontario Securities Commission
  2. Notice of Commission Approval, amendments respecting mandatory reporting of cybersecurity incidents, Ontario Securities Commission
  3. CIRO Bulletin 25-0080, Rule Consolidation Project Phase 5, Canadian Investment Regulatory Organization (CIRO), via the Ontario Securities Commission
  4. CIRO Bulletin 26-0039, proposed CIRO Rules, Canadian Investment Regulatory Organization (CIRO), via the Ontario Securities Commission
  5. Canadian Investment Regulatory Organization (CIRO), oversight page, Ontario Securities Commission