What is Bill C-8?
Short answer: Bill C-8, which received royal assent on June 16, 2026, creates the Critical Cyber Systems Protection Act. It will require designated operators in federally regulated sectors (telecommunications, energy, finance, transportation) to maintain a documented cybersecurity program, report significant incidents and manage supply chain cyber risk, with administrative monetary penalties reaching $15 million per day.
This is Canada's first genuinely binding federal framework for critical infrastructure cybersecurity. It moves the country closer to its allies: the NIS2 directive in Europe, incident reporting obligations in the United States, the United Kingdom framework.
One point is widely misunderstood: royal assent does not mean immediate application. Most substantive obligations will come into force on dates fixed by order in council, and the list of designated operator classes still has to be set by regulation. In other words, nobody carries formal obligations yet : but the preparation clock has started.
Who will be covered?
The Act targets operators of critical cyber systems in federally regulated sectors:
Telecommunications : telecommunications service providers
Energy : interprovincial or international pipelines and power lines, nuclear energy
Finance : banking systems and clearing and settlement systems
Transportation : federally regulated air, rail and marine transport
If you are not on that list, do not close the file too quickly. The Act's most immediate effect will travel through contracts: a designated operator required to manage supply chain risk will push those requirements down to its suppliers, subcontractors and cloud providers. A technology SMB selling to a rail operator will see those clauses in its next renewal.
The four structuring obligations
1. Establish a documented cybersecurity program
Operators must establish, implement and maintain a written program covering risk identification, system protection, incident detection, response and recovery. The key word is "documented": during a review, what is not written and dated does not exist.
2. Manage supply chain risk
Operators must identify and mitigate risks arising from suppliers and third-party services. That means an inventory of dependencies, contractual security clauses, and the ability to demonstrate those risks are tracked over time.
3. Report significant cybersecurity incidents
Incidents must be reported to the Communications Security Establishment, with notice to the sector regulator. This obligation adds to (rather than replaces) Quebec's Law 25 and federal PIPEDA duties. A single intrusion can therefore trigger three distinct notifications, to three recipients, on three different clocks.
4. Comply with cybersecurity directions
The government will be able to issue binding directions, including confidential ones, imposing specific measures. Operators must comply within the prescribed deadlines.
Penalties
The regime provides for substantial administrative monetary penalties, reaching up to $15 million per day of non-compliance for a corporation, along with criminal sanctions. Director and officer liability is explicit, which moves this subject from the IT department to the board.
What to do now
Determine your exposure: are you a potentially designated operator, or a supplier to one?
Map your critical cyber systems: which systems, if they failed, would interrupt the service you provide?
Write down what you already do: most organizations apply real but undocumented controls, that is the fastest win available
Build the incident register and define your reporting thresholds, aligned with Law 25
Review supplier contracts: security, notification and audit clauses
Test: an annual tabletop exercise that explicitly includes the regulatory reporting chain
Bill C-8 and Law 25: two complementary logics
Law 25 protects personal information: its trigger is risk of injury to individuals. Bill C-8 protects continuity of essential service: its trigger is harm to the system, even when no personal data is involved. A ransomware attack on a rail operator can therefore fall under C-8 without a single customer record being exposed.
In practice, the organizations that cope best do not build two parallel programs: they build a single foundation (inventory, logging, response plan, incident register, third-party management) and plug each law's reporting obligations into it.
Conclusion
Bill C-8 is now part of Canadian law, but its operational obligations will arrive through regulation over the coming months. That is precisely the window to use: build the program at a normal pace rather than under the pressure of a compliance order. ITCS Group supports operators and their suppliers with critical system mapping, program drafting, incident reporting exercises and 24/7 response. Contact us to assess your compliance gap.
Sources
Bill C-8, royal assent : Public Safety Canada, June 16, 2026
Critical Cyber Systems Protection Act : legislative text
Legal analyses : Osler, BLG and McCarthy Tétrault, 2025-2026