Bill C-26 Is Dead: What Canada's Bill C-8 Requires
Bill C-26 died, but successor Bill C-8 received royal assent. Learn who Canada's critical cyber law covers, what it requires, and what is not yet in force.
Ernest Bursa
Bill C-26 is no longer Canada’s critical-infrastructure cybersecurity bill. It died when the 44th Parliament ended, and successor Bill C-8 received Royal Assent on June 15, 2026, creating the Critical Cyber Systems Protection Act. As of August 2026, however, the Act is not yet in force and its operator-designation schedule is empty, so its compliance duties are not yet in effect.
That is the status most summaries miss. The law is real, but the operational clock is not running yet. Security leaders should use this interval to prepare while distinguishing enacted requirements, regulations that still need to be written, and sensible controls that the Act does not mandate.
What happened to Bill C-26?
Bill C-26 did not become law. It reached the final stages of the 44th Parliament, then died on the Order Paper when Parliament was prorogued in January 2025. The government introduced the substantially similar Bill C-8 in the new Parliament on June 18, 2025.
Parliament’s record for Bill C-26 stops at consideration of Senate amendments. The federal government’s later committee briefing on Bill C-8 describes Bill C-8 as nearly identical to the former bill. Bill C-8 completed the new legislative process and received Royal Assent on June 15, 2026.
| Date | Event | Legal result |
|---|---|---|
| June 14, 2022 | Bill C-26 introduced | Proposed a telecommunications security framework and the CCSPA |
| January 2025 | Parliament prorogued | Bill C-26 died without becoming law |
| June 18, 2025 | Bill C-8 introduced | Reintroduced the cybersecurity package in the 45th Parliament |
| June 15, 2026 | Bill C-8 received Royal Assent | Telecommunications amendments took effect; the CCSPA was enacted but did not come into force |
The current legal name matters. Bill C-8 is now Statutes of Canada 2026, chapter 9, formally titled An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts. Its second part enacted the Critical Cyber Systems Protection Act, usually shortened to CCSPA.
Calling the regime “Bill C-26” is useful only when explaining the history or matching an older search. Compliance plans, board papers, and vendor questionnaires should refer to Bill C-8 or, better, the CCSPA.
Is Bill C-8 in force now?
Only part of the package is in force. Bill C-8’s amendments to the Telecommunications Act took effect at Royal Assent. The CCSPA, which contains the cyber-security program, incident-reporting, supply-chain, records, and enforcement framework, remains explicitly marked not in force in the current Justice Laws text.
Public Safety Canada’s Royal Assent announcement says implementation will proceed gradually, in phases. The statute allows the Governor in Council to bring different provisions into force on dates set by order.
Three further steps matter before an organization can determine a binding compliance deadline:
- Commencement orders must bring the relevant CCSPA provisions into force.
- Designation orders must add classes of operators and their regulators to Schedule 2.
- Regulations must fill in details such as reportable incident types, the exact reporting period, program requirements, record handling, and applicable administrative penalties.
As of August 28, 2026, Schedule 2 is empty. It contains no pairing of an operator class with a regulator. That means the statute names vital services but does not yet designate a class of companies subject to the operator duties.
This is not a reason to ignore the law. It is a reason to describe the current position accurately: enacted, not in force, no designated operator classes yet.
Who will the Critical Cyber Systems Protection Act cover?
The CCSPA is designed for designated operators of critical cyber systems in federally regulated vital services. It is not a blanket cybersecurity law for every Canadian business, or even every company that sells into a listed sector.
Schedule 1 currently lists six vital services and systems:
| Vital service or system | Practical sector label |
|---|---|
| Telecommunications services | Telecommunications |
| Interprovincial or international pipeline and power-line systems | Energy |
| Nuclear energy systems | Energy |
| Transportation systems within federal legislative authority | Transportation |
| Banking systems | Finance |
| Clearing and settlement systems | Finance |
The Act defines a critical cyber system as a cyber system whose compromised confidentiality, integrity, or availability could affect the continuity or security of a vital service or system. That is narrower than “important IT.” An email platform may be important, while a control, payment, routing, signalling, or network system may be critical because its loss can interrupt the underlying service.
The Governor in Council can add classes of operators and corresponding regulators to Schedule 2. Once a company belongs to a designated class and owns, controls, or operates a critical cyber system, the statutory duties attach to that system.
Until that order exists, avoid two common shortcuts:
- A bank, telecom provider, railway, airline, pipeline operator, or nuclear operator is not automatically a designated operator today. The sector list and the operator designation are separate legal steps.
- A cloud or SaaS supplier is not automatically regulated because a future designated operator uses it. Suppliers may face contractual pressure through their customers’ supply-chain duties, but that is different from a direct statutory designation.
What will designated operators have to do?
Once the CCSPA is in force and an operator is designated, it must maintain a cyber-security program, not merely produce a one-time policy document. The Act brings governance, technical protection, incident response, third-party risk, regulatory communication, and evidence together in one operating cycle.
Establish and maintain a cyber-security program
Sections 9 and 10 give a newly designated operator 90 days after it becomes a member of a designated class to establish a cyber-security program and provide it, or make it available, to the appropriate regulator. The regulator can extend that period on written request.
The program must include steps to:
- identify and manage organizational cyber-security risks, including supply-chain and third-party risks;
- protect critical cyber systems from compromise;
- detect incidents that affect or may affect those systems; and
- minimize the impact of incidents.
The operator must implement and maintain the program. It must review the program on dates set by regulation or, by default, on every anniversary of establishment. The current statutory default gives 60 days to complete that review and 30 days after completion to tell the regulator whether the program changed.
Treat supply-chain changes as security events
Section 15 says a designated operator must mitigate a supply-chain or third-party risk as soon as it is identified. Section 14 also requires notice of material changes in ownership, control, the supply chain, or the use of third-party products and services, within periods that regulations will prescribe.
This makes vendor management part of the ongoing security program. A designated operator cannot file a supplier questionnaire once a year and call the risk closed. It needs an inventory, named owners, material-change triggers, and a process for turning a finding involving a vendor into an updated risk decision.
Keep the evidence in Canada
Section 30 requires records covering program implementation, reported incidents, supply-chain mitigation, and measures taken under cyber-security directions. Those records must be kept in Canada at a prescribed place or, if none is prescribed, at the operator’s place of business. The regulator or future regulations determine the manner and retention period.
The point is not merely the storage location. The records must show what the organization did. A policy without version history, incident chronology, decision log, or remediation evidence will be difficult to defend during an inspection or ordered internal audit.
Is the CCSPA incident deadline exactly 72 hours?
Not yet. The Act sets a maximum reporting window, not the final universal deadline. Section 17 requires a designated operator to report a cyber-security incident to the Communications Security Establishment within a period prescribed by regulations, and that period cannot exceed 72 hours.
The regulations still need to define the types of incidents that must be reported, the exact deadline, the form, and the reporting method. It is therefore inaccurate to say that every cyber event must be reported within exactly 72 hours.
The statutory sequence is clear even though the details are pending:
- A designated operator identifies a reportable incident affecting one of its critical cyber systems.
- It reports the incident to the Communications Security Establishment within the prescribed period, capped at 72 hours.
- Immediately after that report, it notifies the appropriate regulator and gives the regulator a copy.
The statutory incident definition is broad. It includes an act, omission, or circumstance that interferes or may interfere with the continuity or security of a vital service, or with the confidentiality, integrity, or availability of a critical cyber system. Regulations still decide which incidents within that broad definition trigger reporting.
CCSPA reporting will not displace other duties. Section 18.1 expressly preserves the Personal Information Protection and Electronic Documents Act. A single incident may therefore create separate cyber-security, privacy, contractual, and sector-regulatory workstreams.
A sound readiness target is not “submit at hour 71.” It is a process that can classify an event, bring in counsel, preserve evidence, brief leadership, and prepare the CSE and regulator notifications well before the legal maximum.
What does Bill C-8 mean for suppliers and SaaS vendors?
Most suppliers will encounter Bill C-8 through customer requirements before any direct designation. This is an inference from the Act’s supply-chain duties, not a separate statutory rule for every vendor.
Designated operators will need to identify and mitigate risks from third-party products and services, then notify regulators of material changes. That makes several procurement questions predictable:
- Which customer systems and vital services depend on the supplier?
- Where are data, logs, backups, and incident records stored?
- How quickly must the supplier notify the operator of a suspected incident?
- Which subcontractors can access the service?
- Can the operator obtain evidence, audit results, and remediation status?
- What counts as a material change to the product, hosting model, ownership, or supply chain?
Do not invent a statutory vendor deadline or a mandatory contract clause. The regulations are not final, and operators will differ. Map critical customer dependencies now so contract negotiations start with documented architecture and incident-response facts instead of a generic security attachment.
For vendors that also sell in Europe, compare the structure with the EU Cyber Resilience Act reporting guide. The regimes differ in scope and triggers, but both punish the same operational weakness: discovering during an incident that nobody owns intake, classification, notification, and the evidence trail.
How large are the CCSPA penalties?
The CCSPA sets high statutory ceilings, but the actual administrative penalty scheme still needs regulations. Section 91 caps a penalty fixed by regulation at CAD 500,000 for an individual and CAD 15 million in any other case.
Those numbers are not automatic fines for any incident. Regulations must first designate which contraventions are violations, classify them, and fix the applicable maximum for each. The Act says penalties are intended to promote compliance, and due diligence is available as a defence in an administrative proceeding.
The enforcement framework also has substantial reach:
- a continuing violation can count as a separate violation for each day;
- directors or officers who directed, authorized, assented to, acquiesced in, or participated can be personally liable;
- regulators can inspect, order internal audits, and issue compliance orders; and
- separate offence provisions allow courts to set fines and, for individuals in specified cases, impose imprisonment.
The useful lesson is not “every breach costs CAD 15 million.” It is that evidence of reasonable preparation, escalation, mitigation, and follow-through may matter. The program needs to be operational before a regulator asks for it.
What should security teams do before the regulations arrive?
Do the preparation least likely to be wasted while tracking the Canada Gazette for the legal details. Do not guess which company will be designated or freeze a reporting rule that has not been made.
- Map vital services to supporting systems. Start from the service customers rely on, then identify the systems whose loss of confidentiality, integrity, or availability could interrupt it.
- Name an executive owner and operational owner. The cyber-security program needs a decision-maker and a person who can coordinate the response across engineering, legal, communications, privacy, and regulatory reporting.
- Inventory supply-chain dependencies. Record critical vendors, subcontractors, hosting regions, data locations, incident contacts, and material-change triggers.
- Build an incident classification and notification runbook. Keep the precise CCSPA threshold configurable. Cover CSE and future-sector-regulator notifications, plus privacy, contractual, insurance, law-enforcement, and communications decisions.
- Run a timed exercise. Test whether the team can detect, classify, preserve evidence, approve a report, and brief leadership in less than 72 hours.
- Preserve a defensible chronology. Capture when the event occurred, when it was detected, who decided what, which containment steps were taken, and when third parties were notified.
- Watch primary sources. Monitor the Justice Laws CCSPA page and Canada Gazette for commencement orders, Schedule 2 designations, and implementing regulations.
External vulnerability intake belongs within that work. The CCSPA does not mandate a vulnerability disclosure program or security.txt, but an outside report may be the first signal of a weakness in a critical system. Our guide to setting up a vulnerability disclosure program covers the public contact, scope, safe harbor, and internal triage path.
How Kit supports a defensible incident workflow
Kit supports the intake, ownership, coordination, and evidence layer around vulnerability reports. It does not make an organization CCSPA-compliant. It does not monitor networks, inventory critical systems, manage supplier risk, or file reports with CSE or a regulator.
Kit’s security module gives external researchers a branded reporting portal and publishes an RFC 9116 security.txt, so a finding has a defined route into the company. Reports move through structured triage, CVSS assessment, assignment, status history, researcher communication, and SLA tracking. On-call rotations and PagerDuty integration help assign an owner to an urgent report.
Once a finding is validated, a handoff to Jira or Linear can move remediation into the engineering queue without copying sensitive exploit details by default. The report timeline, messages, postmortem, evidence, and dossier preserve what happened and why. See the detailed workflows for triaging vulnerability reports and postmortems and root-cause analysis.
Bill C-8 has settled the legislative direction, but the CCSPA’s operational scope is still taking shape. Bill C-26 is history. The current position is more precise: the Act is enacted, not in force; Schedule 2 is empty; and regulations will determine the exact reporting and penalty mechanics.
That makes this a preparation window, not a compliance deadline. Build the inventory, owners, notification path, supplier evidence, and incident chronology now. When the designations and regulations are issued, your team should be adjusting a working system, not opening a blank document.
Related articles
Ready to hire smarter?
Start free for 30 days. Cancel before it ends and you pay nothing. Set up your first hiring pipeline in minutes.
Start hiring free