
On June 15, 2026, Bill C-8 received Royal Assent. Part 1 amends the Telecommunications Act and took effect immediately. Part 2 enacts the Critical Cyber Systems Protection Act (CCSPA), Canada's first cross-sector cybersecurity law for critical infrastructure. Part 2 comes into force by order in council, and its obligations apply only to operators the government designates. At the time of writing, in early October 2026, neither step had happened. That gives you a window, and the operators who use it well will be the ones who start their OT cybersecurity compliance work with their control systems rather than their policy binder.
The CCSPA covers six vital services and systems, each with its own regulator:
Note what is missing. Water and wastewater, provincially regulated electricity distribution, hospitals, food production and commercial real estate fall outside federal jurisdiction. The October 2025 hacktivist incidents the Canadian Centre for Cyber Security reported, at a water facility, an oil and gas company and a farm, would mostly sit outside this Act.
The Act defines a critical cyber system as one whose compromise could affect the continuity or security of a vital service. That definition is not limited to IT. The PLCs on a pipeline, the SCADA system on a transmission line, airport and rail control systems, and the building systems that keep a telecom switching site cool all qualify if their failure affects the service. Many organizations have written their IT security programs with care and left these systems out.
Administrative monetary penalties reach $15 million per violation for organizations and $500,000 for individuals, with each day of a continuing violation counted separately. Directors and officers can be personally liable.
Vendors, integrators and landlords who serve designated operators should expect these requirements to appear in their contracts, even though the Act does not name them.
Regulation sets a floor. It does not tell you which of your control systems matter most or how to keep them running when one fails. That work takes longer than 90 days, so start before the order arrives. Other articles in this series will follow developments as regulations are published.
It is Part 2 of Bill C-8 and Canada's first cross-sector critical infrastructure cybersecurity law. It requires designated operators in six vital services to run a cyber security program, report incidents and manage supply chain risk.
Only if the government designates you as an operator in one of the six federally regulated sectors. Water, hospitals, food production, commercial real estate and provincially regulated electricity distribution fall outside federal jurisdiction. Vendors and integrators who serve designated operators should still expect the requirements in their contracts.
Part 2 comes into force by order in council, and obligations apply only after an operator is designated. A designated operator then has 90 days to establish its program.
Need help with OT cybersecurity compliance? Talk to Actimeta, an OT cybersecurity company focused on smart buildings and critical infrastructure.