home / frameworks / csa-z246-1

// Canadian sector regulators

CSA Z246.1:21, Security management for petroleum and natural gas industry systems

CSA Group's standard for security management programs at Canadian oil and gas facilities, covering physical and cyber security. The current CSA Z246.1:21 edition was reaffirmed in 2026, and the Canada Energy Regulator requires federally regulated pipelines to follow it.

CanadaCSA Z246.1:21, fourth edition, reaffirmed in 2026

Overview

CSA Z246.1 sets criteria for a security management program for petroleum and natural gas industry systems. The goal is to identify and manage security threats and to prevent or limit incidents that could harm people, the environment, assets, or economic stability. The current fourth edition, CSA Z246.1:21, replaced the 2017, 2013, and 2009 editions. Its biggest change was expanded cybersecurity measures, which replaced the old clause 7 and now run through the whole standard. CSA Group lists it as reaffirmed in 2026. It's a National Standard of Canada.

The standard is performance-based and built on risk management. An operator sets up governance, plans the program, runs security operations including detection and mitigation, and improves the program through change management and audits. It's meant to sit beside other standards, including CSA Z662 for pipelines, CAN/CSA-ISO 31000 for risk management, and CSA Z1600 for emergency and continuity management. It is aligned with CSA Z246.2 on emergency preparedness and response. It applies to operators of every size.

The Canada Energy Regulator (CER) gives the standard legal force for federally regulated pipelines. Section 4 of the Onshore Pipeline Regulations requires a company to design, construct, operate, and abandon its pipelines in line with CSA Z246.1, as amended from time to time. Section 47.1 requires a security management program, and the program must be audited at least every 3 years. Provinces set their own rules. CSA Group makes the petroleum and natural gas standards free to download in Canada, thanks to Western Regulators Forum funding.

Who it applies to in Canada

Operators of petroleum and natural gas industry systems of any size, including pipelines and their stations and terminals, LNG facilities, underground storage, refineries and gas plants, oil sands facilities, and wells. Offshore activity, tankers, and transport by rail, road, or ship are out of scope.

The Canada Energy Regulator requires federally regulated pipeline companies to follow CSA Z246.1 and to keep a security management program that is audited every 3 years. CSA Group offers the petroleum and natural gas standards as free downloads to Canadian users with funding from the Western Regulators Forum.

Controls at a glance

CSA Z246.1 follows a management system cycle. These groups paraphrase its program elements from CSA Group's published preface and scope.

Scope and applicability

  • All petroleum and natural gas industry systems
  • Pipelines, stations, terminals, LNG, storage, refineries, and wells
  • Applies to operators of any size
  • Excludes offshore, tankers, and rail, road, or ship transport

Governance

  • Management commitment to a security program
  • Defined roles and responsibilities
  • Security policy and program documentation
  • Integration with safety and emergency programs

Planning and security risk assessment

  • Identify assets and their importance
  • Assess threats, vulnerabilities, and consequences
  • Set risk-based security measures
  • Cover physical and cyber threats together

Security operations

  • Implement physical and cyber security controls
  • Detect and monitor for security incidents
  • Mitigate and respond to incidents
  • Security training and awareness

Cybersecurity measures (expanded in 2021)

  • Cybersecurity built into every program element
  • Cyber controls scaled to asset risk
  • Address cyber risk in planning and operations

Change management, audit, and improvement

  • Manage changes that affect security risk
  • Audit the security management program
  • Correct deficiencies and improve continually
  • Align with CSA Z246.2 emergency preparedness

Certification and assessment

CER-regulated companies must audit their security management program at least every 3 years and keep audit records that list any deficiencies and the corrective actions taken or planned. The CER checks through inspections and audits. Compliance is shown through program audits and CER oversight rather than certification.

Dates to know

2017
Third edition, Z246.1-17, published (now withdrawn)
2021
Fourth edition, CSA Z246.1:21, published with expanded cybersecurity measures
2026
CSA Z246.1:21 reaffirmed

Resources

Official texts and free tools for CSA Z246.1. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. CSA Z246.1:21 (R2026), product page with preface and scope, CSA Group
  2. Z246.1-17 product page and edition history, CSA Group
  3. Onshore Pipeline Regulations (SOR/99-294), Justice Laws Website, Government of Canada
  4. Security, Canada Energy Regulator