Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver. Updated August 4, 2026.
Not to be confused with Bill C-9: Bill C-8 is Canada’s cybersecurity law, the Critical Cyber Systems Protection Act (CCSPA). Bill C-9 is the Combatting Hate Act, a Criminal Code amendment unrelated to cybersecurity. This guide covers Bill C-8 and what it means for Canadian businesses.
Key Takeaways
- Bill C-8 was assented to on June 15, 2026 and is now Statutes of Canada 2026, chapter 9. It enacts a new federal cyber security regime for regulated sectors.
- Part 1 rewrites the Telecommunications Act and took effect immediately. Part 2 duties phase in by order in council, with the details set by regulation.
- Direct scope: designated operators in telecom, banking, energy, nuclear, interprovincial transport, and clearing and settlement.
- Operators must run a documented cyber program (within 90 days of designation), report significant incidents to the Cyber Centre within a window of up to 72 hours, and manage supplier risk.
- Penalties reach $15 million CAD per day for organizations and $1 million CAD per day for individuals, with personal liability for officers and directors.
- Most SMBs are not designated, yet feel the law through vendor questionnaires, contract clauses, and insurer expectations.
Bill C-8 status tracker · updated August 4, 2026
- Royal Assent: granted June 15, 2026, eleven days after Senate third reading (LEGISinfo).
- In force now: Part 1, which rewrites the Telecommunications Act, took effect on Royal Assent.
- Not yet in force: Part 2, the CCSPA itself. Its duties start on dates fixed by the Governor in Council, and no date had been announced as of August 4, 2026.
- Nobody is designated yet: Schedule 2, the list of designated-operator classes, is still empty, so no Canadian business currently carries those duties.
- Where the next move appears: the Canada Gazette, Part II, which publishes every order and regulation before a regulator writes to anyone.
Bill C-8 is now Canadian law. Earlier this year it received Royal Assent, turning Canada’s long-running infrastructure cybersecurity reform into binding law. It codifies what regulators have asked telecoms, banks, and energy operators to do for years.
Most Canadian small businesses sit outside the scope of Bill C-8, yet many will feel it through procurement clauses, insurer questionnaires, and supplier baselines. This guide covers what the new cybersecurity law is, who it covers, what changed when it passed, and where the pressure lands for SMB suppliers.
Fusion Computing tracks Bill C-8 obligations for its Canadian SMB clients and maps each requirement onto the CISSP-led security programs it already runs.
What is Bill C-8?
Bill C-8, the successor to Bill C-26, is now law: according to Parliament of Canada LEGISinfo it became Statutes of Canada 2026, chapter 9 on June 15, 2026. It amends the Telecommunications Act (in force immediately) and enacts the Critical Cyber Systems Protection Act, phased in by order in council for federally regulated sectors. Most SMBs fall outside its reach and should still anchor on CyberSecure Canada and CIS Controls v8.1.
Score your readiness against the controls Canadian regulators and cyber insurers now expect. About 3 minutes.
Run the compliance readiness check →or book a free 30-min call →Free · no email until you see your score, or talk to a senior engineer.
Bill C-8 + Copilot: the Pre-Copilot SharePoint Audit closes the SharePoint exposure gap that Canadian incident-reporting timelines now reach into.
Bill C-8 is the federal statute titled “An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts.” It has two operative parts. Part 1 rewrites the Telecommunications Act and adds security as an explicit policy objective, giving Ottawa authority to compel action against threats to telecom networks.
Part 2 enacts the Critical Cyber Systems Protection Act (CCSPA), giving the government authority to set and enforce cybersecurity baselines across federally regulated industries. The full text is tracked on the Parliament of Canada site.
The law is the renamed successor to Bill C-26, which lapsed when Parliament was prorogued in January 2025. References in older articles should now read as C-8. Bill C-8 passed Third Reading in the House of Commons on March 26, 2026, cleared the Senate, and was assented to less than three months later.
What changed when Bill C-8 became law?
Bill C-8 is now law, and its two parts run on different clocks. Part 1 is in force now. The CCSPA duties on operators start on dates fixed by order in council, with reporting windows, designated-operator classes, and penalty schedules to follow by regulation. Three amendments shaped the final text: a bar on ordering the decoding of encrypted communications, a higher threshold for ministerial action, and a mandatory five-year review.
Bill C-26 was tabled in 2022, so this framework spent almost four years in motion. That phase is over. Here is what the final law actually does, and what is still pending.
Part 1 is live today
The Telecommunications Act amendments took effect the moment Bill C-8 was assented to. They let the Governor in Council and the Minister of Industry issue binding orders to telecom providers. Those orders can prohibit the use of a specified supplier’s products and force the removal of high-risk equipment from Canadian networks. If you run or depend on telecom infrastructure, these powers are real now.
Part 2 phases in
The CCSPA is law, and the obligations on designated operators come into force on dates the Governor in Council will fix. The operational detail arrives by regulation. Schedule 2, which names who is actually designated, is still being populated. The exact incident-reporting window, capped at 72 hours, will also be set in regulation. Designated operators have a runway rather than an overnight deadline.
The encryption fight was settled in the text
Civil-liberties groups spent four years arguing that the Telecommunications Act powers could be used to weaken encryption. The final Act answers that directly. It prohibits the government from ordering a provider to intercept a private communication or to decode an encrypted private communication.
Two further amendments tightened the guardrails. The Minister now needs “reasonable grounds” and a “serious, systematic” threat before acting, and section 147 requires a review of the law within 5 years. Privacy advocates still flag the breadth of information sharing among federal agencies, so the core concern is answered in law even as those questions continue.
Bill C-8 next steps: the four orders and regulations still to come
According to Parliament of Canada (2026), Bill C-8 is Statutes of Canada 2026, chapter 9, and it received Royal Assent on June 15, 2026. Four government actions still stand between that assent and a real duty: a coming-into-force order, a Schedule 2 designation order, the program and reporting regulations, and sector-regulator guidance. None carried an announced date as of August 4, 2026.
Watch one publication and you will see each step land. Orders in council and regulations are published in the Canada Gazette, Part II, normally within two weeks of the decision. Nothing reaches an operator before it reaches the Gazette.

Step 1: the coming-into-force order
The CCSPA starts on a day fixed by order of the Governor in Council. Cabinet can make that order on any day of the year. The House of Commons resumes sitting on September 21, 2026, and that date does not gate the order, because cabinet does not need Parliament in session to act.
Step 2: the Schedule 2 designation order
Schedule 1 already names six classes of vital services and systems. Schedule 2, which names the operators that actually carry the duties, is blank. Public Safety Canada leads the consultation with sectors and regulators that has to run before cabinet fills it in. Until Schedule 2 has names in it, no organization is a designated operator.
Step 3: the program and reporting regulations
Three numbers stay abstract until regulations arrive: the exact reporting window inside the 72-hour ceiling, the required contents of a cyber security program, and the penalty amount attached to each class of violation. Section 9 already fixes the 90-day program deadline, and it runs from designation rather than from the coming-into-force date.
Step 4: sector-regulator guidance
OSFI, the CRTC, the Canadian Nuclear Safety Commission, Transport Canada, the Canada Energy Regulator, and the Bank of Canada each supervise their own class of operator. Expect each one to publish its own reading of the same statute, the way OSFI Guideline B-13 already sits on top of general Canadian privacy law.
Three things a Canadian supplier can usefully do while those steps run:
- Check the Canada Gazette, Part II, on the first business day of each month, or set a Google Alert on “Critical Cyber Systems Protection Act”.
- Ask your two largest federally regulated clients whether they expect to be designated, and file the answer with the account record.
- Write the incident-response plan now, because 72 hours is a poor moment to start drafting one.
Want that watch handled for you? Ask Fusion Computing to track Bill C-8 for your sector →
Who does Bill C-8 actually apply to?
Bill C-8’s direct duties attach only to designated operators in six federally regulated categories; everyone else’s exposure is contractual. Regulated customers inherit a statutory program-and-reporting clock and flow it down to suppliers through procurement. According to Statistics Canada’s survey of cyber security and cybercrime, SMBs already absorb a disproportionate share of incident impact while running the leanest security teams, which is why those flow-down clauses bite.
Bill C-8’s direct obligations land on designated operators inside federally regulated critical sectors. The law names six categories of vital services and systems in its schedule; specific organizations are added as designated operators by further schedule and regulation. Innovation, Science and Economic Development Canada and the relevant sector regulators set the operational rules, and the ISED Canada site hosts the policy guidance.
The six vital sectors are telecommunications, banking, interprovincial and international pipelines and power lines, the nuclear sector, federally regulated transportation, and clearing and settlement systems. A typical Canadian SMB is almost never directly designated. What changes for those businesses is what their regulated clients can require contractually.
| Sector | Regulator | What changes under C-8 |
|---|---|---|
| Telecommunications | CRTC + ISED | Mandatory baseline plus federal authority to compel vendor or equipment removal. |
| Banking | OSFI | Cyber program, incident reporting, and supply-chain risk management requirements. |
| Interprovincial transport | Transport Canada | Designated rail, air, and marine operators face incident-reporting obligations. |
| Nuclear | CNSC | Existing security regimes layered with C-8 program and reporting duties. |
| Energy (pipelines, power) | CER + provincial co-regulators | Critical operators must document programs and report incidents on schedule. |
| Clearing and settlement | Bank of Canada | Payment and settlement systems gain cyber-program and incident-reporting duties. |
If your business is not on a designated-operator list, Bill C-8 does not impose duties on your organization directly.
What does Bill C-8 require organizations to do?
The CCSPA sets four obligations for designated operators. According to the statute as enacted in 2026, an operator must run a documented cyber security program within 90 days of designation. It must also manage supply-chain and third-party cyber risk, report incidents on the regulated clock, and keep Canadian records available for inspection. The program duty anchors the other three.
The four CCSPA pillars
- Program: establish a documented cyber security program within 90 days of designation.
- Supply chain: identify and manage cyber risk from vendors and third parties under section 9.
- Reporting: report significant cyber incidents inside the regulated time limit.
- Records: keep records in Canada and available for inspection.
The program must identify and manage cyber risks, be implemented and maintained, and be reviewed at least annually. The Canadian Centre for Cyber Security publishes the technical baseline most Canadian businesses use as the floor.
Across Fusion Computing’s 2026 client-engagement data, the common gap among non-designated suppliers is not the program existing on paper. It is that the program lacks board sign-off, named owners, and a tested incident-response runbook. Those three artifacts are exactly what regulated clients ask for in vendor due-diligence packets.
Bill C-8 incident reporting timeline and process
Bill C-8 caps the incident-reporting window at 72 hours for designated operators, with the exact clock to be fixed by regulation. According to the Canadian Centre for Cyber Security (2025), ransomware remains the top cybercrime threat to Canadian critical infrastructure, and it is exactly the incident class this reporting duty was written for.
The CCSPA requires designated operators to report significant cyber incidents promptly after detection. The statute caps that period at 72 hours, and the exact timeline will be fixed by regulation. Practitioners should plan for a response measured in hours.
Who receives the report
Section 17 names the Communications Security Establishment as the recipient of the technical report. The Canadian Centre for Cyber Security is the public-facing arm of that agency, which is why most guidance points there. The operator then notifies its own sector regulator, so two filings leave the building for one incident.
Under section 17 the trigger is a cyber incident affecting a critical cyber system that interferes, or may interfere, with the operator’s ability to deliver the regulated service. That captures near-misses and active intrusions, not only completed breaches. Operators log the event, classify it, file the initial report, then update as the investigation matures.
For SMB suppliers the effect is contractual. If an incident in the supplier’s environment touches a regulated client, the supplier has to notify that client fast enough for the client to make its own 72-hour filing. A documented incident-response plan is the artifact that turns that clause from a problem into a paragraph.
What are the penalties under Bill C-8?
The penalties are real and now law. According to the Critical Cyber Systems Protection Act, administrative monetary penalties reach up to $15 million CAD for organizations and up to $1 million CAD for individuals. A violation continued on more than one day counts as a separate violation for each day. The specific amounts tied to particular violations will be set by regulation.
Part 1 and Part 2 carry separate penalty ceilings
Bill C-8 created two regimes on the same day, and they do not share a schedule. Confirm the live figures against the Parliament of Canada source as regulations are published.
| Regime | Individuals | Organizations | Repeat exposure |
|---|---|---|---|
| CCSPA (Part 2), not yet in force. | Up to $1 million CAD. | Up to $15 million CAD. | Each day of a continued violation counts separately. |
| Telecommunications Act (Part 1), in force. | Up to $25,000 CAD, then $50,000 CAD. | Up to $10 million CAD, then $15 million CAD. | A subsequent contravention carries the higher ceiling. |
“Boards ask me whether the $15 million CAD number applies to them. For most SMBs the honest answer is no, not directly. The exposure that actually lands on a 40-person supplier is contractual. Your regulated customer inherits a statutory clock. Their procurement team passes that pressure into your MSA at renewal.”
Not sure which side of that line your business sits on? Talk to Fusion about your actual Bill C-8 exposure → and we will map it against your customer list.
Three features that matter beyond the headline numbers
Under Bill C-8, penalties apply per violation, so failures across sections compound. Certain contraventions can also be prosecuted as criminal offences. Summary conviction carries imprisonment of up to 2 years less a day, and indictment carries up to 5 years.
Officers and directors who direct, authorize, or acquiesce in a violation carry personal exposure. That moves cyber accountability into the boardroom, and a due-diligence defence rewards documented, demonstrable compliance. For SMB suppliers the regime acts indirectly. Insurers and regulated buyers read the $15 million CAD ceiling, then raise their own minimum standards.
Field Note from Mike
A Hamilton engineering firm we onboarded in early 2026 thought Bill C-8 had nothing to do with them. Six weeks in, their largest client, a federally regulated transport operator, sent a 14-page vendor security questionnaire with a 30-day deadline. We had already mapped them to CIS Controls v8.1 and built an incident-response runbook. They returned it in nine days and kept the contract.
Bill C-8 vs PIPEDA vs PHIPA vs Quebec Law 25: how do they fit together?
Bill C-8 does not replace existing Canadian privacy or sector laws. Most Canadian SMBs already have obligations under PIPEDA federally, PHIPA in Ontario for health information, and Law 25 in Quebec. C-8 layers cyber-program duties on top of that privacy stack for designated operators only, and the statute expressly preserves PIPEDA, so cybersecurity reporting and privacy-breach notification run in parallel rather than one replacing the other.
| Law | Scope | Trigger | Notification | Penalty |
|---|---|---|---|---|
| Bill C-8 (CCSPA) | Designated operators in federally regulated critical sectors. | Significant cyber incident on a critical cyber system. | Federal government and sector regulator, within a window of up to 72 hours. | AMPs up to $15M CAD (organizations), plus offence provisions. |
| PIPEDA | All Canadian commercial activity touching personal information. | Real risk of significant harm from a privacy breach. | Privacy Commissioner of Canada and affected individuals. | Up to CAD 100,000 per offence, plus reputational impact. |
| PHIPA (Ontario) | Ontario health-information custodians and their agents. | Loss, theft, or unauthorized use of personal health information. | IPC of Ontario and affected patients. | Fines up to CAD 200,000 individuals, CAD 1,000,000 organizations. |
| Quebec Law 25 | Quebec-connected processing of personal information. | Confidentiality incident with risk of serious injury. | CAI Quebec and affected individuals. | Up to 4 percent of worldwide turnover or CAD 25 million. |
Watch the privacy half too: Bill C-36
Bill C-8 is the cybersecurity half of Canada’s digital-law overhaul. The privacy half is moving again. On June 15, 2026, the same day C-8 received Royal Assent, the government introduced Bill C-36, the Protecting Privacy and Consumer Data Act. It is the third attempt to modernize PIPEDA.
Bill C-36 proposes a new federal regulator, the Digital Safety and Data Protection Commission of Canada. It sat at first reading through the summer of 2026, and second reading is expected after the House resumes on September 21, 2026. Build your cyber security program now and it carries into whatever that reform finalizes.
For most Canadian SMBs: keep complying with PIPEDA, PHIPA, or Law 25 as applicable, and treat C-8 as the supplier-program standard regulated clients will use.
What does a Canadian SMB supplier of a regulated entity need to know?
If your business sells software, services, support, or hosted infrastructure to a bank, telecom, transport operator, energy company, or nuclear operator, expect three changes once Bill C-8 obligations start. Vendor questionnaires get longer, contract clauses get firmer, and audit rights get exercised.
None of that requires you to be a designated operator. It only requires that your client is one. Defence-sector suppliers face a parallel, harder gate: CPCSC Level 1 certification is required at contract award on select federal defence contracts beginning summer 2026.
The Insurance Bureau of Canada has reported Canadian cyber-incident costs rising sharply, and regulated buyers cite that data when justifying tighter supplier controls. Practical readiness starts with three artifacts:
- A framework mapping, usually CIS Controls v8.1 or NIST CSF 2.0.
- An incident-response plan with named contacts and a written notification path.
- A vendor-risk register covering the SMB’s own providers.
Two of our clients in Toronto produced all three inside 6 weeks once someone owned the file. Have Fusion Computing build the three artifacts with you →
Book a Bill C-8 Readiness Review
How do you prepare for Bill C-8 compliance?
Designated operators have 90 days from designation to build the program, satisfy the reporting clock, and align supply-chain reviews to the statute. Canadian SMBs that sell into those operators face a lighter version of the same path. The artifacts are the same, the deadline is contractual rather than statutory, and the review usually lands at contract renewal.
The seven-step supplier readiness checklist
Fusion Computing publishes this checklist as an FC internal benchmark from Q2 2026, built from anonymized client data across our supplier-readiness engagements. We benchmarked it against the questionnaires regulated buyers actually send.
Fusion Computing runs it as a fixed-scope readiness review with our CISSP-led team. Managed detection and response sits at the core of most readiness plans.
| Action | Outcome |
|---|---|
| Map regulated clients in your customer base. | Know which contracts will trigger C-8 supplier clauses. |
| Adopt CIS Controls v8.1 or NIST CSF as your baseline. | Provides the framework regulated buyers expect to see. |
| Document and rehearse an incident-response plan. | Meets the supplier-notification clauses your client carries. |
| Stand up endpoint detection and response (EDR or MDR). | Closes the most common questionnaire gap for SMB suppliers. |
| Maintain a vendor-risk register for your own providers. | Demonstrates supply-chain hygiene downstream of your client. |
| Confirm cyber insurance coverage aligns to the new control bar. | Avoids renewal surprises as insurers raise minimum standards. |
| Brief leadership annually on Canadian cyber regulation. | Keeps officer and director risk visible at board level. |
Most of those actions a competent cybersecurity services partner can stand up in under a quarter for a typical 30 to 150-employee Canadian business. The deciding factor is sequence more than budget.
For a dated starting point, the federal Get Cyber Safe campaign each October gives smaller firms a 4-week runway; our Cyber Security Awareness Month playbook sequences it.
Frequently asked questions
What is Bill C-8 in simple terms?
Bill C-8 is now Canadian law. It creates the Critical Cyber Systems Protection Act for critical infrastructure and amends the Telecommunications Act. Designated operators in telecommunications, banking, transport, energy, nuclear, and clearing and settlement must run a documented cyber program, report significant incidents to the federal government, and manage supplier risk. Most Canadian SMBs fall outside its direct reach but feel it through the supplier expectations of regulated clients.
Has Bill C-8 received royal assent?
Yes. Bill C-8 received Royal Assent on June 15, 2026 and is now law. The Telecommunications Act amendments are in force immediately. The Critical Cyber Systems Protection Act obligations on designated operators come into force on dates fixed by order in council, with reporting windows, operator classes, and penalty schedules set by regulation. Designated operators then have 90 days from designation to establish their cybersecurity program.
When do Bill C-8 and the CCSPA come into force?
It depends on the part. The Telecommunications Act powers took effect on Royal Assent, June 15, 2026. The CCSPA obligations on designated operators come into force on dates fixed by order of the Governor in Council, and no coming-into-force date had been announced as of August 4, 2026. Schedule 2, which lists the designated-operator classes, is still empty, and the order will appear in the Canada Gazette, Part II.
For SMB suppliers, the practical trigger is not a government date at all. It is the moment a regulated client sends a C-8-aligned vendor questionnaire or contract clause, which is already happening.
Does Bill C-8 weaken encryption?
No. Bill C-8 amends the Telecommunications Act, and the final text prohibits the government from ordering a provider to intercept a private communication or to decode an encrypted private communication. That language was added to address the central civil-liberties concern raised during the bill’s passage.
Amendments in 2026 also raised the threshold for ministerial action to serious, systematic threats and added a mandatory review within 5 years. Privacy advocates still flag the breadth of information sharing among federal agencies, so the central concern is addressed even as those debates continue.
Does Bill C-8 apply to small businesses?
Bill C-8’s direct obligations apply to designated operators in federally regulated critical sectors, not to typical Canadian small businesses. The practical effect arrives through the supply chain. A small business selling to a regulated bank, telecom, transport operator, energy company, or nuclear operator will see C-8-aligned cyber requirements flow down through procurement and vendor questionnaires.
What sectors does Bill C-8 cover?
Bill C-8 covers six categories of vital services and systems named in Schedule 1 of the CCSPA. They are telecommunications, banking, interprovincial and international pipelines and power lines, the nuclear sector, federally regulated transportation, and clearing and settlement systems. Sector regulators such as OSFI, the CRTC, the Canadian Nuclear Safety Commission, and the Bank of Canada set the operational rules within their domains.
What are the penalties under Bill C-8?
Under the CCSPA, administrative monetary penalties reach up to $15 million CAD for organizations and up to $1 million CAD for individuals. A violation continued on more than one day counts as a separate violation each day. The exact amounts for specific violations are set by regulation. The Telecommunications Act side of Bill C-8 runs its own ceilings, $10 million CAD rising to $15 million CAD for organizations.
Certain contraventions can be prosecuted as criminal offences, with imprisonment of up to 5 years on indictment. Officers and directors who direct or acquiesce in a violation carry personal exposure, and a due-diligence defence rewards documented compliance.
How does Bill C-8 differ from PIPEDA?
PIPEDA is a privacy law triggered by real risk of significant harm from a privacy breach. Bill C-8 is a cybersecurity statute triggered by cyber incidents on critical cyber systems. PIPEDA reports go to the Privacy Commissioner; C-8 reports go to the federal government and sector regulators. They overlap when an incident at a designated operator also exposes personal information, and Bill C-8 expressly preserves PIPEDA so both regimes apply in parallel.
What incident reporting does Bill C-8 require?
Designated operators must report significant cyber incidents to the federal government within a window capped at 72 hours, with the exact timeline fixed by regulation. The Canadian Centre for Cyber Security receives the technical report; the sector regulator receives the operational notice. The trigger captures both completed breaches and active intrusions that interfere, or may interfere, with the regulated service.
How should a Canadian SMB prepare for Bill C-8?
Start by mapping which clients are federally regulated. Then adopt CIS Controls v8.1 or NIST CSF 2.0 as a written baseline, document and rehearse an incident-response plan, and deploy endpoint or managed detection and response. Finish with a vendor-risk register and confirmation that cyber-insurance coverage aligns to the new control bar. Those six artifacts answer most C-8-driven supplier questionnaires on first pass.
Is Bill C-8 the same as Bill C-26?
Functionally yes. Bill C-26 was the original Critical Cyber Systems Protection Act bill introduced in the 44th Parliament; it died on the Order Paper when Parliament was dissolved. Bill C-8 reintroduced the framework in the 45th Parliament with amendments, and it is the version that received Royal Assent on June 15, 2026. Check older C-26 articles against the enacted C-8 text before relying on details.
What should a small business do first about Bill C-8?
Start with your customer list, not the statute: identify which clients are banks, telecoms, energy, transport, nuclear, or clearing-and-settlement operators, because their procurement teams carry the compliance pressure to you. Then close the three artifacts questionnaires ask for: a framework baseline (CIS Controls v8.1 or NIST CSF), a rehearsed incident-response plan, and a vendor-risk register.
Related Resources
- PIPEDA compliance for Canadian small business
- Cyber insurance requirements in Canada
- Ontario Bill 194 and non-profits
- State of cybersecurity in Canada 2026
Part of the Canadian IT Compliance Hub. PIPEDA, PHIPA, OSFI B-13, Bill C-8, CyberSecure Canada and cyber-insurance guidance for Canadian SMBs, in one place.

