Status (October 2025): Bill C-8 has passed Second Reading in the House of Commons and now sits before committee. It combines two parts: amendments to the Telecommunications Act and a new law called the Critical Cyber Systems Protection Act (CCSPA). Together, they aim to bring Canada’s approach to critical-infrastructure cybersecurity in line with other advanced jurisdictions—turning “best practice” into binding legal obligation.


What This Bill Does

Bill C-8 creates a mandatory cybersecurity framework for operators that provide vital services under federal jurisdiction. Think of large-scale telecommunications networks, pipelines, power lines, nuclear facilities, transportation systems, and the banking and financial-clearing sector. The government will designate which classes of operators fall within scope, and each will have to comply once formally named.

The Core Obligations

  1. Cybersecurity program in 90 days – Once designated, operators must establish and implement a cybersecurity program within 90 days. The program must identify risks, protect systems, and address supply-chain and third-party vulnerabilities.
  2. Annual reviews – Each program must be reviewed every year, completed within 60 days, and updated as needed. The operator then has 30 days to notify its regulator whether changes were made.
  3. Incident reporting – Cyber incidents must be reported to the Communications Security Establishment (CSE) within a period that will not exceed 72 hours, followed by a notice and copy to the sector regulator.
  4. Ongoing mitigation – Whenever a supply-chain or third-party risk is identified, the operator must take immediate steps to mitigate it.
  5. Records kept in Canada – Required records must be maintained within the country or at a Canadian business location.
  6. Compliance with cyber directions – The federal government can issue confidential “cyber directions” requiring specific actions to protect systems. Operators must comply, although limited judicial review remains available.

Oversight and Enforcement

Each regulated sector will have its own “appropriate regulator”—for example, the Ministers of Industry or Transport, the Office of the Superintendent of Financial Institutions, the Bank of Canada, the Canadian Energy Regulator, or the Canadian Nuclear Safety Commission.

Non-compliance carries serious financial risk. Administrative monetary penalties can reach up to $1 million for individuals and $15 million for organizations. Certain violations—such as failing to report an incident, ignoring a cyber direction, or disclosing a classified direction—can also amount to offences that expose corporations and their officers to prosecution and even imprisonment.

Separately, new Telecommunications Act powers will allow government to issue binding orders to telecom operators to secure their networks and prohibit risky products or services.


Why It Matters

Bill C-8 marks a clear policy shift: cybersecurity is no longer a purely technical or voluntary exercise. It’s a governance and compliance duty that reaches the boardroom. Directors and officers can be personally liable if they direct, authorize, or participate in a violation. The bill also introduces strong confidentiality rules around government directions, reshaping how organizations share information internally and with regulators.


How to Prepare Now

Even before regulations take effect, critical-infrastructure operators can take practical steps:

  1. Map exposure – Identify which of your systems qualify as “critical” under the federal categories.
  2. Gap assessment – Compare your existing cybersecurity policies and incident response plans to the CCSPA’s requirements and deadlines (90/60/30/72-hour cycles).
  3. Incident response integration – Embed regulatory reporting triggers and evidence-retention procedures into your playbooks.
  4. Third-party oversight – Strengthen supplier due-diligence clauses, security certifications, and patch-management timelines.
  5. Record management – Ensure data-retention and storage policies allow quick production of records located in Canada.
  6. Board engagement – Establish clear accountability; brief leadership on potential personal exposure.
  7. Simulate compliance – Run tabletop exercises using the 72-hour reporting scenario to test readiness.
  8. Stay tuned – Monitor committee amendments, draft regulations, and guidance from regulators and CSE.

Challenges Ahead

  • Designation uncertainty: No one knows exactly when each class will be designated, but once it happens, the countdown begins.
  • Information-sharing tension: Confidentiality rules around government cyber directions will need careful internal handling to protect privilege.
  • Cost and complexity: Smaller or less-resourced operators may face steep compliance and documentation burdens.
  • Overlap with provincial regimes: Some sectors already follow provincial or regulatory cybersecurity frameworks, raising coordination questions.

The Takeaway

Bill C-8 and the CCSPA represent the most significant step yet toward a mandatory cybersecurity regime for Canada’s vital infrastructure. The obligations are specific, the timelines short, and the penalties real. Treat compliance as a business-governance function, not an IT checklist.

The smartest move right now is to prepare as if your organization is already designated—because when the order arrives, the 90-day clock will already be ticking.

Leave a Reply

I’m Amin

AMNLEGAL

I’m Amin, a lawyer based in Ontario who’s passionate about Commercial Law, Technology & Privacy. Through AMN Legal, I share insights on tech regulation, commercial law, and the practical challenges lawyers face in a digital world.

Disclaimer: The content of this blog is for general information only and does not constitute legal advice. 

Let’s connect

Discover more from AMNLegal

Subscribe now to keep reading and get access to the full archive.

Continue reading