Skip to content

On June 15, 2026, Bill C-8, An Act Respecting Cyber Security, received Royal Assent. After years of consultation, a false start as Bill C-26, and months of committee scrutiny, Canada now has its first mandatory, enforceable cybersecurity law for critical infrastructure.

If you operate in energy, telecom, transportation, or finance, this law will reshape your network operations. Even for smaller, leaner organizations—like a local utility or independent provider—the headlines about ‘$15 million penalties’ can be overwhelming. This post helps you cut through that noise

This post breaks down Bill C-8’s requirements and provides a practical framework to turn these new obligations into an actionable compliance plan.

What Bill C-8 Actually Is

Bill C-8 does two distinct things, and it helps to keep them separate.

Part 1 amends the Telecommunications Act. It makes security an explicit policy objective of Canadian telecom law and gives the federal government new powers to order telecommunications service providers to take specific security actions, up to and including banning equipment from specific suppliers. These amendments took effect immediately on Royal Assent. If you’re a telecom or ISP, the era of voluntary security guidance is over.

Part 2 enacts the Critical Cyber Systems Protection Act (CCSPA). This is the centerpiece, and it’s what most critical infrastructure operators need to focus on. The CCSPA creates a regulatory framework requiring “designated operators” to protect their “critical cyber systems,” with mandatory cybersecurity programs, supply-chain risk management, incident reporting, and record-keeping, all backed by audits and significant penalties.

Importantly, the CCSPA comes into force in phases, with the operational details: who exactly is designated, what the reporting windows are, and what programs must contain, set by regulations that are still to come. That phased rollout is your runway. More on that below.

Who Is Covered (and Why You Shouldn’t Tune Out If You’re Small)

The CCSPA applies to six categories of “vital services and vital systems”:

  • Telecommunications services
  • Interprovincial or international pipeline and power line systems
  • Nuclear energy systems
  • Federally regulated transportation systems
  • Banking systems
  • Clearing and settlement systems

Oversight is distributed across six sector regulators, including the Superintendent of Financial Institutions, the Bank of Canada, the Ministers of Industry and Transport, the Canadian Energy Regulator, and the Canadian Nuclear Safety Commission, each with inspection, audit, and compliance-order powers.

Three things smaller operators should understand:

Designation isn’t about size. The classes of designated operators will be set by regulation, and there’s no revenue or headcount floor in the Act. If you own or operate a system whose compromise “could affect the continuity or security of a vital service or vital system,” you can be designated — whether you have a 40-person SOC or a two-person IT team.

The list can grow. The federal government of Canada can add new vital services and new classes of operators over time. Legal observers, including Osler and BLG, expect coverage to expand as the regime matures.

Even the undesignated will feel it. Designated operators must mitigate supply-chain and third-party cyber risk as soon as it’s identified. In practice, that obligation flows downhill: if you sell to, connect with, or provide services to a designated operator, expect security requirements, audit rights, and incident-notification clauses to start showing up in your contracts. Provincially regulated utilities and municipal systems aren’t directly covered, but C-8 is the clear signal of where Canadian regulatory expectations are heading — and frameworks like NERC CIP already reach Canadian electric utilities through provincial regulators.

The Obligations, In Plain Language

Strip away the legal drafting, and the CCSPA asks five things of a designated operator:

1. Know your critical cyber systems and stand up a cybersecurity program fast. Within 90 days of your class being designated, you must establish a cybersecurity program that identifies and manages cyber risks (including supply-chain and third-party risks), protects your critical cyber systems, detects incidents, and minimizes their impact. You must file that program with your regulator, implement it, and review it at least annually.

2. Manage your supply chain. When you identify a supply-chain or third-party risk, you have a duty to mitigate it promptly, and in line with guidance from the Communications Security Establishment. For many operators this is the most demanding requirement, because it forces a level of vendor risk management that few have formalized.

3. Report incidents within 72 hours. Incidents affecting a critical cyber system must be reported to the CSE’s Canadian Centre for Cyber Security within a window to be set by regulation, capped at 72 hours, with your sector regulator notified immediately after. The threshold is deliberately broad: incidents that interfere or may interfere with a vital service qualify. You can’t report what you can’t see, and you can’t meet a 72-hour clock with a detection capability that takes weeks to notice an intrusion.

4. Comply with cybersecurity directions. The government can direct operators to take specific protective measures, and those directions may be confidential: you may be legally barred from disclosing they exist.

5. Keep records in Canada. You must maintain records documenting your program, incidents, supply-chain mitigations, and compliance with directions, and be prepared for regulator audits.

The enforcement stakes are real: administrative monetary penalties of up to $15 million per violation (up to $500,000 for individuals), with each day of a continuing violation counting separately, plus criminal offences for serious contraventions. Directors and officers can be personally liable. But here’s the detail that should shape your entire response: the Act provides a due diligence defence. Documented, board-visible, honestly implemented compliance efforts matter. Perfect security is not the standard; demonstrable diligence is.

From Legislation to Operations: A Practical Readiness Roadmap

The gap between “read the Act” and “pass an audit” is where most organizations, especially smaller ones, get stuck. Here’s a sequence we recommend, aligned with the Cyber Centre’s Cross-Sector Cyber Security Readiness Goals — 36 foundational, achievable goals designed precisely for organizations that don’t have enterprise-scale security teams.

Step 1: Establish scope — inventory before anything else. You can’t identify your “critical cyber systems” if you don’t have an accurate, current picture of what’s on your network. Automated network discovery and inventory, the kind provided by platforms like Infosim StableNet, gives you a live map of devices, configurations, and dependencies, and doubles as the documented evidence base your regulator will expect. Determine which systems, if compromised, could affect the continuity of the vital service you deliver. Not everything will be in scope; a defensible scoping exercise keeps your program focused and affordable.

Step 2: Gain visibility into the traffic that matters. As we often say: you cannot secure what you cannot see. Detection and 72-hour reporting both depend on knowing what’s actually happening on your network. Network TAPs and packet brokers from partners like Garland Technology, Cubro, and Profitap deliver a complete, reliable copy of network traffic to your monitoring and security tools. In OT environments — substations, pipelines, plant floors — hardware data diodes let you extract that visibility and feed it safely to detection tools while physically guaranteeing nothing can flow back into the control network. That’s protection and detection from a single architectural decision, and it gives auditors something unambiguous.

Step 3: Build detection and response you can actually run. A lean team doesn’t need a dozen consoles; it needs consolidated, high-signal tooling. This is where network detection and response (NDR) earns its place at the centre of a CCSPA program, and it’s why we’ve partnered with Stamus Networks, whose Clear NDR platform is built on Suricata, the world’s most widely deployed open-source network security engine. 

Fed by the TAP-and-diode visibility fabric from Step 2, Clear NDR combines intrusion detection, network security monitoring, and behavioural anomaly detection in a single system, and distills the noise into high-confidence Declarations of Compromise®: exactly the kind of clear, evidence-backed signal a small team needs when deciding, on a 72-hour clock, whether an event is reportable. Automated alert triage and guided threat hunting mean you don’t need a deep bench of analysts to operate it, and because it’s offered in both a free open-source Community edition and a commercial Enterprise edition, operators can start proving value now and scale as designation approaches. 

Alongside it, AI-driven network forensics from CySight and managed endpoint detection and response from Cybereason, including 24/7 MDR for organizations without an around-the-clock SOC, round out the “detect” and “minimize impact” pillars of the mandated program without requiring you to build a security operations centre from scratch.

Step 4: Make your evidence trustworthy with precision time. This one is easy to overlook and painful to retrofit. Incident reports, forensic timelines, and audit records are only as credible as their timestamps. If your logs come from systems whose clocks disagree, reconstructing a 72-hour reportable incident becomes guesswork. Resilient, GNSS-backed network time from partners like Safran ensures every log, packet capture, and alert across IT and OT shares one accurate, traceable clock, a foundational control we’ve written about before in the context of Zero Trust.

Step 5: Validate, document, repeat. Before major changes to critical systems, test and verify that security and performance hold up. Review the program annually as the Act requires, keep your records current, and brief your board regularly; remember, the due diligence defence rewards exactly this discipline. As regulations arrive and your designation is confirmed, you’ll be adjusting details, not starting over.

The Runway Won’t Last Forever

The phased coming-into-force of the CCSPA is a gift to operators who use it. The 90-day clock for filing a cybersecurity program starts when your class is designated; 90 days is not enough time to build a program from a standing start. The operators who fare best under this regime will be the ones who treated the period between Royal Assent and designation as their build phase, not their waiting phase.

The encouraging news: nothing in the CCSPA asks for exotic technology. Asset inventory, network visibility, detection, incident response, supply-chain hygiene, accurate records: these are fundamentals, well understood and readily deployable, even for organizations without deep in-house security expertise. What most operators lack isn’t capability; it’s a clear, sequenced plan.

That’s where we can help. Telnet Networks has spent more than 25 years helping Canadian utilities, transportation operators, telecoms, government agencies, and industrial companies build secure, visible, well-managed networks. Our engineering team can walk through your environment, map your current posture against the CCSPA’s program requirements, and design a practical, right-sized roadmap to compliance, from visibility architecture to detection tooling to precision time.

Ready to build your Bill C-8 action plan? Contact the Telnet Networks team for a no-obligation consultation.


Further reading: the full text and status of Bill C-8 on LEGISinfo; the Government of Canada’s Royal Assent announcement; legal analyses from Osler, BLG, and McCarthy Tétrault; and the Cyber Centre’s Cyber Security Readiness Goals.

Related Posts

Understanding & Operationalizing Bill C-8 as a Critical Infrastructure Operator

Understanding & Operationalizing Bill C-8 as a Critical Infrastructure Operator

On June 15, 2026, Bill C-8, An Act Respecting Cyber Security, received Royal Assent. After years of consultation, a false…
Data Diodes in ICS Environments: Why One-Way Visibility Is Becoming Non-Negotiable

Data Diodes in ICS Environments: Why One-Way Visibility Is Becoming Non-Negotiable

“You cannot secure what you cannot see.”  It’s a mantra we come back to often, because it’s true. Your security…
Vendor Spotlight: Unlocking Enterprise Infrastructure Visibility with Garland Technology

Vendor Spotlight: Unlocking Enterprise Infrastructure Visibility with Garland Technology

Achieving comprehensive visibility across complex physical, virtual, and cloud infrastructure remains a persistent challenge for modern IT teams. Security and…
Vendor Spotlight: Unlocking Network Visibility with Profitap

Vendor Spotlight: Unlocking Network Visibility with Profitap

If your security tools are only as good as the data they receive, then visibility isn’t a nice-to-have — it’s…
The Hidden Foundation of Network Security: Why Precision Time Matters in a Zero Trust World

The Hidden Foundation of Network Security: Why Precision Time Matters in a Zero Trust World

Zero Trust Architecture has fundamentally changed how organizations think about network security. Identity must be continuously verified. Every access request…