Baseline Controls News Resources Glossary About

Bill C-8 Is Law: Who Canada's New Cyber Security Act Covers and When It Applies

Bill C-8 Is Law: Who Canada's New Cyber Security Act Covers and When It Applies

Bill C-8, An Act respecting cyber security, received Royal Assent on June 15, 2026, according to Parliament's LEGISinfo record. It does two things: it amends the Telecommunications Act, which took effect immediately, and it enacts the Critical Cyber Systems Protection Act (CCSPA), which is not yet in force. Most Canadian small businesses will never be regulated by Bill C-8 directly. Many will still feel it, because the operators it does cover must manage the cyber risk their suppliers bring.

This explainer covers what is actually law today, who the CCSPA will apply to, what those organizations will have to do, and what a smaller supplier can do now. It is informational only and is not legal advice.

What Is Bill C-8?

Bill C-8 is Canada's federal cyber security law for critical infrastructure. It is the successor to Bill C-26, which Osler notes did not become law before Parliament was prorogued and was reintroduced in substantially similar form. Part 1 adds security as a policy objective of the Telecommunications Act and lets the government direct telecom providers. Part 2 creates the CCSPA for designated operators.

Public Safety Canada's announcement describes the CCSPA as a framework "requiring designated operators in the finance, telecommunications, energy, and transportation sectors to protect their critical cyber systems." If you read our earlier explainer on Bill C-26, the structure will look familiar.

Is Bill C-8 in Force Yet?

Partly. Public Safety Canada says the Telecommunications Act amendments "take immediate effect upon Royal Assent," while the CCSPA "will be implemented gradually" through a phased approach. As of October 8, 2026, the Justice Laws text of the Critical Cyber Systems Protection Act still marks it "not in force," and Osler reported in June 2026 that Schedule 2, the list of designated operator classes, was blank.

In practical terms, nobody is a designated operator yet. That changes when the government publishes an order adding a class of operators to Schedule 2 in the Canada Gazette. The 90-day clock for building a cyber security program starts from that point, not from Royal Assent.

Who Will the Critical Cyber Systems Protection Act Cover?

The CCSPA applies to federally regulated "designated operators" that own, control or operate a critical cyber system. Schedule 1 of the Act lists six vital services and systems, which Osler's summary reproduces:

  • Telecommunications services
  • Interprovincial or international pipeline and power line systems
  • Nuclear energy systems
  • Transportation systems within the legislative authority of Parliament
  • Banking systems
  • Clearing and settlement systems

Oversight is split among six regulators named in the Act: the Superintendent of Financial Institutions, the Bank of Canada, the Minister of Industry, the Minister of Transport, the Canadian Energy Regulator and the Canadian Nuclear Safety Commission. The government can add services to Schedule 1 by order, so the scope may grow over time.

What Will Designated Operators Have to Do?

Once designated, an operator has 90 days to establish a cyber security program and provide it to its regulator. The Justice Laws text sets out the core duties:

  1. Build a cyber security program (section 9) that identifies and manages cyber risks, including supply chain and third-party risks, protects critical cyber systems, detects incidents and minimizes their impact.
  2. Mitigate supply chain risks (section 15) as soon as they are identified.
  3. Report cyber security incidents (section 17) to the Communications Security Establishment within a period set by regulation that cannot exceed 72 hours, then notify the regulator and give it a copy (section 18).
  4. Review the program on each anniversary of its creation, unless regulations set other dates (section 13).
  5. Keep records in Canada (section 30) of program steps, reported incidents, supply chain mitigation and compliance with any cyber security direction.
  6. Follow cyber security directions issued by the Governor in Council (section 20).

The Act also states that the incident reporting sections do not affect PIPEDA. A designated operator that loses personal information still has its separate PIPEDA breach reporting duties to the Privacy Commissioner.

What Are the Penalties Under Bill C-8?

Section 91 of the CCSPA caps administrative monetary penalties at $500,000 per violation for an individual and $15,000,000 per violation for any other person, and section 94 treats each day a violation continues as a separate violation. Osler adds that directors and officers who direct or take part in a violation can be held personally liable, and that a due diligence defence is available.

Actual penalty amounts will be set by regulation. The maximums signal that the government expects board-level attention, not a policy filed and forgotten.

Does Bill C-8 Apply to My Small Business?

For most Canadian small businesses, no, not directly. The CCSPA only reaches federally regulated operators in designated classes. A retailer, clinic, law office or contractor is not a designated operator because it uses a bank or a phone line.

The indirect effect is different. Section 15 requires designated operators to mitigate risks from their supply chain and third-party products and services. Osler expects third-party contracts to need "cybersecurity requirements, audit rights, incident-notification provisions and compliance representations." If your business provides IT services, software, engineering, logistics or other services to a bank, telecom, airline, railway, pipeline or utility, expect more detailed security questionnaires and contract clauses. Our guide to vendor and third-party risk covers that relationship from the customer's side.

How Can Canadian Suppliers Prepare Now?

Suppliers can prepare by being able to show basic, documented security before a customer asks. None of this is required by Bill C-8 for a non-designated business, but it maps to what a designated customer will likely want to see, and to the Canadian Centre for Cyber Security's 13 Baseline Controls:

  • Incident response: a written plan that names who calls the customer and how fast. A 72-hour reporting window at your customer leaves little room for a supplier that takes a week to notice. See the incident response control.
  • Authentication: multi-factor authentication on email, remote access and admin accounts.
  • Patching and backups: evidence that critical updates are applied quickly and that restores are tested.
  • Access control: a current list of who can reach customer systems or data, reviewed when people leave.
  • Records: dated evidence of the above, kept somewhere you can produce it within days.

One question to ask your IT lead or provider this month: "If a customer covered by Bill C-8 asked us for evidence of our security controls and our incident notification process, what could we hand them within a week?"

If the answer is unclear, our free cybersecurity assessment measures your business against all 13 Baseline Controls and shows where the gaps are.

Free Assessment

How prepared is your business?

Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.

Check Your Score

Frequently Asked Questions

Is Bill C-8 law in Canada?

Yes. Bill C-8, An Act respecting cyber security, received Royal Assent on June 15, 2026 and became Statutes of Canada 2026, chapter 9. Its amendments to the Telecommunications Act took effect on Royal Assent. The Critical Cyber Systems Protection Act it creates is enacted but not yet in force, and will be brought in through orders and regulations.

Who does the Critical Cyber Systems Protection Act apply to?

It applies to designated operators: federally regulated organizations in classes listed in Schedule 2 of the Act. Schedule 1 names six vital services and systems: telecommunications, interprovincial or international pipelines and power lines, nuclear energy, federally regulated transportation, banking, and clearing and settlement systems. Most small businesses are not designated operators.

How quickly must designated operators report a cyber incident under Bill C-8?

Section 17 of the Critical Cyber Systems Protection Act requires a designated operator to report a cyber security incident affecting a critical cyber system to the Communications Security Establishment within a period set by regulation, which cannot exceed 72 hours. The operator must then notify its regulator and give it a copy of the report.

Does Bill C-8 affect small businesses that supply banks, telecoms or transport companies?

Possibly, indirectly. Designated operators must identify and mitigate cyber risks in their supply chains and their use of third-party products and services. Law firm Osler expects that to drive new contract terms such as cyber security requirements, audit rights and incident notification clauses for suppliers. The Act itself places obligations only on designated operators.

Cite This Page

Suggested citation:

Cybersecurity Canada (2026). Bill C-8 Is Law: Who Canada's New Cyber Security Act Covers and When It Applies. Retrieved from https://cybersecuritycanada.ca/news/posts/bill-c-8-law-who-canadas-cyber-security-act-covers/

Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.

Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.

How does your organization measure up?

Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.

Take the Free Assessment