Skip to content
Concentric rings diagram: designated operators at the centre of Bill C-8, vendors on the second ring

This article is a follow-up to our Bill C-8 overview post


The contract renewal arrives from a customer you’ve served for a decade: a telecom, a bank, a pipeline operator. Your product hasn’t changed. Your service hasn’t changed. But the paper has. It now carries security attestations, audit rights, a 24-hour incident-notification clause, and a new right to terminate for unremediated cyber risk. Nothing about your business triggered this. Your customer’s legal environment did.

Bill C-8, An Act Respecting Cyber Security, received Royal Assent on June 16, 2026. Its centrepiece, the Critical Cyber Systems Protection Act (CCSPA), names only “designated operators” in six vital services: telecommunications, interprovincial pipeline and power line systems, nuclear energy, federally regulated transportation, banking, and clearing and settlement. If your company isn’t on that list, the Act never mentions you.

It will still rewrite your contracts. We have a front-row seat to this shift: Telnet Networks has supplied network, security, and timing infrastructure to Canada’s critical sectors for over 25 years, and we serve both the operators C-8 designates and the vendors who sell to them. Here’s why the flow-down is coming, and what to do about it.

Why flow-down is structural, not optional

The CCSPA makes designated operators responsible for risk they don’t directly control. Operators must establish a cybersecurity program that identifies and manages risks “associated with the operator’s supply chain and its use of third-party products and services,” and they must mitigate those risks as soon as they’re identified. This is a continuing duty, not an annual checkbox. Operators must also keep records of every step taken to mitigate supply-chain risk, which means your security posture becomes part of their compliance file.

The enforcement stakes explain what happens next. Administrative monetary penalties run up to $15 million per day for organizations and $1 million per day for individuals, and directors and officers can be personally liable for their organization’s violations. When executives are personally exposed for supplier risk, vendor risk tolerance goes to zero.

Operators can’t outsource the legal obligation. So they’ll do the only thing they can: transfer it contractually. Due diligence questionnaires, security schedules in MSAs, and continuous monitoring of the vendor base aren’t a courtesy anymore. They’re how a regulated operator proves it met its statutory duty.

That’s the second ring of C-8: a much larger population of undesignated companies (technology vendors, MSPs, integrators, SaaS providers, contractors) regulated not by Parliament, but by procurement.

What “C-8 by proxy” looks like in practice

Expect these artifacts to show up in RFPs, renewals, and vendor portals over the next 12–24 months:

  • Security questionnaires with teeth. No longer check-the-box. Answers will be tied to renewal, payment terms, and award decisions, and they’ll be retained as evidence of the operator’s own compliance.
  • Incident-notification clauses that beat the regulator’s clock. Operators must report significant cyber incidents to the Canadian Centre for Cyber Security within a window capped at 72 hours (regulations may set it shorter). An operator can’t report what it doesn’t know, so vendor contracts will require notification of incidents affecting the customer faster than the operator’s own deadline: often 24 hours, sometimes less.
  • Audit and inspection rights. Evidence requests for SOC 2 or ISO 27001 reports, penetration test results, and patch cadence, plus the right to inspect and, in some drafts, the right to direct remediation.
  • Vulnerability disclosure and patching SLAs for products embedded in or connected to critical systems.
  • Termination for cyber cause. If a risk you represent is identified and you don’t mitigate it, the operator’s cleanest legal path is to end the relationship. Expect that right to be explicit.
  • Insurance flow-down. Cyber coverage minimums appearing in MSAs and renewal terms.
  • Supplier-origin scrutiny. The companion amendments to the Telecommunications Act give the government authority to compel action against threats in telecom networks, including restricting suppliers. Expect heightened questions about product provenance, subcontractors, and where data lives.

What “somewhat compliant” actually means for a vendor

You don’t need a full CCSPA cybersecurity program. You need to be answerable. A pragmatic maturity ladder:

Tier 1: Table Stakes. Documented security policy, MFA everywhere, patch management, asset inventory, a named security contact. Without these you’ll struggle to complete a questionnaire honestly.

Tier 2: Contract-Ready. An incident-response plan with defined customer-notification timelines you can actually meet; vendor risk management for your own suppliers; a pre-built evidence pack (certifications, pen-test summaries, standard questionnaire answers).

Tier 3: Differentiated. Alignment to a recognized framework such as the Cyber Centre’s baseline guidance, NIST CSF, or ISO 27001; continuous monitoring; and the ability to support a customer audit without disrupting your operations.

The fourth-party ripple

Your customer’s obligation flows to you; yours flows onward. Because operators must manage supply-chain risk wherever it originates, they’ll increasingly ask about your suppliers: subprocessors, hosting providers, offshore development. Vendors will need their own miniature supply-chain risk program, starting with a current subprocessor list and baseline security requirements flowed into their own vendor contracts. C-8’s reach is recursive.

Turning compliance into a moat

Here’s the reframe worth internalizing: every artifact above is also a sales asset.

The first vendors in a category who can hand procurement a complete evidence pack shorten the security-review cycle from months to days, and win deals against slower competitors. “C-8-ready” is a positioning claim you can substantiate: pre-answered questionnaires, a standard security rider you’ll sign without three rounds of legal, notification commitments you’ve rehearsed. And as designation orders land, expect procurement teams at operators to begin disqualifying vendors on security posture alone. Readiness isn’t just risk management; it’s revenue protection.

A 90-day starter plan

  1. Map your exposure. Inventory which customers are, or will plausibly become, designated operators across the six vital services.
  2. Read your own paper. Review existing contracts for security and notification clauses already in force. Know your current commitments before new ones arrive.
  3. Build the evidence pack before you’re asked. Policies, certifications, test results, standard answers.
  4. Rehearse incident notification. Define who calls whom, and prove you can beat a 24-hour clock. That requires two things most vendors haven’t built: the visibility to detect an incident quickly, and trustworthy timestamps that let you reconstruct exactly when it started.
  5. Push requirements downstream. Identify your own critical suppliers and set baseline expectations now.
  6. Anchor to a framework. Run a gap assessment against the Cyber Centre’s guidance or NIST CSF and prioritize the gaps a customer would flag first.

Where Telnet Networks fits

Telnet Networks has spent over 25 years supplying mission-critical network, security, and precision-time solutions to Canadian enterprises, government, and the very sectors C-8 designates. That puts us on both sides of this story: we help operators meet their obligations, and we help their vendors become the low-risk suppliers those operators need. Four areas matter most for second-ring readiness.

Visibility you can act on. A 24-hour notification commitment is only as good as your ability to detect an incident in the first place. Network TAPs, packet brokers, and bypass switches give your security tools complete, reliable access to traffic, so detection isn’t dependent on luck or SPAN-port leftovers. The same architecture becomes evidence in an audit: it shows a customer exactly how you’d know something happened.

Detection you can demonstrate. Visibility feeds detection, and detection is what the questionnaires will probe. Through our new partnership with Stamus Networks, we deliver Clear NDR: Suricata-based network detection and response that produces transparent, explainable findings rather than black-box verdicts. When a designated operator asks “how would you know you’d been breached, and can you show us?”, an NDR deployment turns that answer from a paragraph of assurances into something you can put on the table.

Time you can prove. When a customer or regulator asks “when did you know?”, the answer lives in your logs, and logs are only as credible as the clocks behind them. Our GNSS and NTP/PTP precision timing platforms keep timestamps synchronized and defensible across your environment, turning an incident timeline from an estimate into a record.

Connections that can’t flow backward. If your service touches a customer’s critical or OT environment, you are the pathway an operator worries about. Data diode TAPs enforce one-way traffic flow in hardware, letting you deliver monitoring and support while physically removing the inbound threat path, which is often the single fastest way to shrink the risk you represent.

If C-8 clauses are starting to appear in your renewals, or you want to get ahead of them, talk to our team about a visibility and readiness assessment.

Sidebar: The C-8 timeline: why vendors feel it first

June 2022: Bill C-26 introduced, Canada’s first attempt at critical cyber systems legislation.

January 2025: C-26 dies on the Order Paper when Parliament is prorogued.

June 2025: Reintroduced as Bill C-8, substantially the same framework.

April 2026: Passes the House of Commons following substantive committee amendments.

June 16, 2026: Royal Assent. Telecommunications Act amendments take effect immediately.

Today: The CCSPA itself is not yet in force. Its obligations begin on dates set by the Governor in Council, and the schedule of designated-operator classes is still empty. Regulations defining incident-reporting thresholds and program details are still to come.

Designation + 90 days: Once designated, operators have 90 days to stand up their cybersecurity program.

Here’s the catch for vendors: procurement moves ahead of the law. Operators know designation is coming and are papering their supply chains now, because remediating hundreds of vendor relationships takes longer than 90 days. The contractual flow-down is arriving before the legal obligations that drive it, which means the vendor deadline is, effectively, already here.

This post discusses commercial and contractual trends, not legal obligations. The CCSPA imposes no direct duties on non-designated companies. It isn’t legal advice; talk to counsel about your specific contracts.

Related Posts

The Second Ring of C-8: What Selling to Critical Infrastructure Now Requires

The Second Ring of C-8: What Selling to Critical Infrastructure Now Requires

This article is a follow-up to our Bill C-8 overview post The contract renewal arrives from a customer you’ve served…
Keysight Network Visibility, Testing and Security: Where Each Piece Fits

Keysight Network Visibility, Testing and Security: Where Each Piece Fits

You can’t secure or troubleshoot traffic you can’t see. That’s an old line, but it has become a harder problem:…
Your GPUs Are Idle. It's Probably Not the GPUs' Fault.

Your GPUs Are Idle. It's Probably Not the GPUs' Fault.

Canada is building AI data centres at unprecedented scale. Here’s how to make sure the fabric underneath them actually performs…
Understanding & Operationalizing Bill C-8 as a Critical Infrastructure Operator

Understanding & Operationalizing Bill C-8 as a Critical Infrastructure Operator

On June 15, 2026, Bill C-8, An Act Respecting Cyber Security, received Royal Assent. After years of consultation, a false…
Data Diodes in ICS Environments: Why One-Way Visibility Is Becoming Non-Negotiable

Data Diodes in ICS Environments: Why One-Way Visibility Is Becoming Non-Negotiable

“You cannot secure what you cannot see.”  It’s a mantra we come back to often, because it’s true. Your security…