Bill C-8 received Royal Assent on 15 June 2026. It is now Statutes of Canada 2026, chapter 9.

If you have been tracking this as Bill C-26, that bill died at the 2025 prorogation and came back under a new number. Same architecture, new label.

Most of the coverage since June has been written for boardrooms. This is the version for the people who actually install and maintain the systems, because the supply chain clauses reach further down than the headlines suggest.

Two parts, and only one of them is live

The single most useful thing to understand about C-8 is that it did two different things on two different timelines.

Part 1 amends the Telecommunications Act. It is in force now. It added security as an explicit policy objective and gave the government authority to compel action against threats in the telecom sector. That happened on Royal Assent. No further step was required.

Part 2 is the Critical Cyber Systems Protection Act. It is not in force. The CCSPA comes into effect by order in council, phased, and as of late August 2026 no date has been announced.

Both facts are true at once, which is why you will see confident articles claiming C-8 is either fully in effect or entirely theoretical. Neither is right.

Schedule 2 is empty, and that is the number to watch

Here is the detail that decides whether any of this applies to you today.

CCSPA obligations do not attach to sectors in the abstract. They attach to classes of operators listed in Schedule 2 of the Act. Schedule 2 is currently empty.

No organization in Canada carries a CCSPA obligation right now. Not one.

So if a vendor is selling you a CCSPA readiness package against a deadline, ask them which order in council created it. There isn’t one yet. That is a reason to prepare on your own schedule, and a reason to be sceptical of anybody manufacturing urgency.

The sectors expected to be designated are the ones you would guess: telecommunications, banking, energy including pipelines and power lines, nuclear, interprovincial and international transport, and clearing and settlement. If you work in any of those, the order is coming. You just do not have a date.

Ninety days is the part that should worry operators

When a class does get designated, the operators in it have ninety days to have a cyber security programme in place.

Ninety days is nothing. It is not enough time to inventory an OT estate, let alone build a programme around it, get it approved, and stand up the evidence to show it is operating. Any operator who waits for the order in council before starting will spend those ninety days discovering what they own.

The programme itself has to do more than tick an IT box. It has to identify and manage cyber security risks including supply chain and third-party product risk, protect critical cyber systems from compromise, detect incidents, and minimise their impact. If that shape looks familiar, it is the NIST identify, protect, detect, respond, recover cycle wearing Canadian clothes.

On top of the programme there is an annual review, an obligation to notify the regulator of changes, incident reporting to the Communications Security Establishment, and compliance with confidential cyber security directions that the operator may not be permitted to discuss.

One requirement that gets less attention than it deserves: cyber security records have to be kept in Canada. If your client’s logging, monitoring, or documentation lives in a cloud region outside the country, that is a design problem with a delivery date attached.

Penalties run to fifteen million dollars for operators and one million for directors. I do not think the number is the interesting part. What is interesting is what a penalty of that size does to how seriously an operator treats the questionnaire it sends its vendors.

Why this lands on integrators

You will not be designated. You will be asked.

A designated operator cannot satisfy the supply chain and third-party risk obligation without reaching into the people who install, configure, patch, and remotely access its critical systems. That is the integrator, the maintenance contractor, and the vendor with a support tunnel into the plant.

So the mechanism is commercial rather than regulatory. Nobody from the government audits your shop. Your client audits your shop, because their programme requires it, and the questions arrive as a condition of the next contract.

Based on what CPCSC did to defence suppliers, expect the questions to look roughly like this. Who has remote access to the client’s systems and how is it brokered. What happens to credentials when your technician leaves. How you patch, and how you handle equipment you cannot patch. Where your records live. Whether you have ever had an incident, and what you did about it.

None of those are hard questions if you have already answered them. All of them are hard if the first time you see them is in a procurement portal with a deadline.

What I would actually do now

Not much, and deliberately so. There is no deadline, and building a compliance programme against an order in council that does not exist is how budgets get wasted.

What is worth doing is cheap.

Find out whether your clients sit in a sector that is likely to be designated. If they do, they will be asking you questions inside the next couple of years, and knowing that changes how you scope work today.

Write down your own answers to the questions above. Not a policy document. A page. Who has access, how it is controlled, what you do when something goes wrong. That page is most of what a vendor questionnaire asks for, and writing it once beats improvising it five times.

Fix the things you already know are wrong. The forgotten cellular modem on a panel. The shared vendor account with a password from 2019. The flat network where the historian and the safety system share a broadcast domain. Those are findings today, regardless of what any Act says, and they are covered in more depth in OT network security controls and who owns the network.

Watch for the order in council rather than the news cycle. The Canada Gazette is where the designation will actually appear.

The honest summary

C-8 is law. The CCSPA is not yet operative. Schedule 2 is empty, no organization is currently obligated, and no compliance deadline exists.

And the work still arrives before the deadline does, because it arrives through your clients rather than through the regulator. Ninety days after designation is far too late to start, so the operators who handle this well will start early, and they will start by asking their vendors questions.

Have answers ready.

If you supply or maintain systems for an organization in one of the designated sectors and you want the vendor-side answers written down before somebody asks for them, that is the kind of engagement I take.

References

  1. Government of Canada Strengthens Cyber Security and Critical Infrastructure with Royal Assent of Bill C-815 June 2026
    Public Safety Canadacanada.ca
  2. Bill C-8 (45-1), An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other ActsRoyal Assent
    Parliament of Canadaparl.ca
  3. Q&A, Critical Cyber Systems Protection Act
    Public Safety Canadapublicsafety.gc.ca
  4. Canadian Program for Cyber Security Certification, program overview
    Public Services and Procurement Canadacanada.ca

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.