October 11, 2026

OT Cybersecurity Compliance Under Bill C-8: Operator Guide

OT Cybersecurity Compliance Under Bill C-8: Operator Guide

Canadian OT Regulatory Watch Part 1: Bill C-8 Is Law. What It Means for OT Cybersecurity Compliance

On June 15, 2026, Bill C-8 received Royal Assent. Part 1 amends the Telecommunications Act and took effect immediately. Part 2 enacts the Critical Cyber Systems Protection Act (CCSPA), Canada's first cross-sector cybersecurity law for critical infrastructure. Part 2 comes into force by order in council, and its obligations apply only to operators the government designates. At the time of writing, in early October 2026, neither step had happened. That gives you a window, and the operators who use it well will be the ones who start their OT cybersecurity compliance work with their control systems rather than their policy binder.

Who is in scope of the Critical Cyber Systems Protection Act

The CCSPA covers six vital services and systems, each with its own regulator:

  • Telecommunications (Minister of Industry)
  • Banking (OSFI)
  • Clearing and settlement systems (Bank of Canada)
  • Interprovincial and international pipelines and power lines (Canada Energy Regulator)
  • Nuclear energy (Canadian Nuclear Safety Commission)
  • Federally regulated transportation (Minister of Transport)

Note what is missing. Water and wastewater, provincially regulated electricity distribution, hospitals, food production and commercial real estate fall outside federal jurisdiction. The October 2025 hacktivist incidents the Canadian Centre for Cyber Security reported, at a water facility, an oil and gas company and a farm, would mostly sit outside this Act.

Why Bill C-8 is an OT cybersecurity law

The Act defines a critical cyber system as one whose compromise could affect the continuity or security of a vital service. That definition is not limited to IT. The PLCs on a pipeline, the SCADA system on a transmission line, airport and rail control systems, and the building systems that keep a telecom switching site cool all qualify if their failure affects the service. Many organizations have written their IT security programs with care and left these systems out.

OT cybersecurity compliance: what designated operators must do

  • Establish a cyber security program within 90 days of designation, covering identification of risk, protection, detection and minimizing the impact of incidents.
  • Report cyber security incidents to the Communications Security Establishment within a prescribed time of no more than 72 hours, and notify the sector regulator.
  • Identify and mitigate supply chain and third-party risk, not only monitor it.
  • Keep records in Canada of the program, incidents, third-party mitigation and compliance with directions.
  • Comply with cyber security directions issued by the government, which can be confidential.

Administrative monetary penalties reach $15 million per violation for organizations and $500,000 for individuals, with each day of a continuing violation counted separately. Directors and officers can be personally liable.

What to do before designation

  • Find your critical cyber systems. Trace each vital service back to the control systems and supporting building systems it depends on. You cannot do this from a list of IT applications.
  • Test your 72-hour clock. Could your team detect an incident on an OT system, confirm it and report it within three days? In many buildings and plants, nobody reviews OT logs routinely.
  • Map your vendors. The supply chain duty reaches integrators, OEMs and service providers with remote access. Their contracts will need security and notification clauses.
  • Check where your records live. If your OT asset data, logs or compliance evidence sit in a vendor's foreign cloud, confirm what the record-keeping regulations will require.

Vendors, integrators and landlords who serve designated operators should expect these requirements to appear in their contracts, even though the Act does not name them.

Regulation sets a floor. It does not tell you which of your control systems matter most or how to keep them running when one fails. That work takes longer than 90 days, so start before the order arrives. Other articles in this series will follow developments as regulations are published.

Frequently asked questions

What is the Critical Cyber Systems Protection Act?

It is Part 2 of Bill C-8 and Canada's first cross-sector critical infrastructure cybersecurity law. It requires designated operators in six vital services to run a cyber security program, report incidents and manage supply chain risk.

Does Bill C-8 apply to my plant or building?

Only if the government designates you as an operator in one of the six federally regulated sectors. Water, hospitals, food production, commercial real estate and provincially regulated electricity distribution fall outside federal jurisdiction. Vendors and integrators who serve designated operators should still expect the requirements in their contracts.

When do the CCSPA obligations start?

Part 2 comes into force by order in council, and obligations apply only after an operator is designated. A designated operator then has 90 days to establish its program.

Need help with OT cybersecurity compliance? Talk to Actimeta, an OT cybersecurity company focused on smart buildings and critical infrastructure.

References

‍

Author:
Team Actimeta