34 / 63Bill C-26 Readiness

Bill C-26 is now Bill C-8, and the clock starts when you're designated

Bill C-26 became Bill C-8, now Canadian law, and designation starts a 90-day statutory clock.

  • CCIE Security-led programme design
  • Six Schedule 1 sectors, mapped
  • Canadian records, Canadian residency
THE WORK

Bill C-8 readiness, three pillars, one operator.

One Canadian team scopes the exposure, builds the programme, and rehearses the report. The Critical Cyber Systems Protection Act is the Canadian cyber legislation people still search for as Bill C-26, and it reaches six sectors, not everybody.

  1. 1

    Scope, honestly

    Six federally regulated sectors are named in Schedule 1, and most Canadian organisations sit outside them. Schedule 2, the list of designated operators, is still empty, so we settle whether the Act can reach you before we quote anything.

  2. 2

    The programme, built early

    Risk identification, system protection, incident detection and impact limits, designed before designation makes it urgent. Ninety days is enough to document a programme you already run. It isn't enough to build one from a standing start.

  3. 3

    Reporting you've rehearsed

    The incident report to CSE, the notice to your sector regulator, and the records held in Canada. We write the report once while nothing is on fire, so your first real submission isn't also your first draft.

THE PROOF

Built to last. Evidence over promises.

Bill C-8 became law on 2026-06-15 as Statutes of Canada 2026, chapter 9. The CCSPA itself waits on an order in council, so no operator is designated yet and nothing binds anyone.

IN PRODUCTION

Ready before Canada names the classes.

Our board asked whether we were compliant and the honest answer was that there was nothing to comply with yet. SMEnode built the programme anyway and told us which parts were worth doing regardless. When our class gets named we won't be starting.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

Bill C-8 and the CCSPA in Canada, made real.

Nobody is designated yet. That's the opening, and most operators are reading it as permission to wait.

Start with scope, because it has the cheapest answer.

The Bill C-26 requirements people bookmarked two Parliaments ago are the Bill C-8 requirements now, and they reach six federally regulated sectors: telecoms, interprovincial and international pipelines and power lines, nuclear, federally regulated transportation, banking, and clearing and settlement. Outside those, you have no obligation coming and we'll say so on the first call. Inside them, the question isn't whether to prepare. It's whether you'd rather build a cyber security programme over months, or in the 90 days the statute gives you once your class is named.

Four required outcomes, and the two places the risk sits.

We build the programme against the Act's four required outcomes: identify the risks, protect the system, detect incidents, and limit the damage. The risk sits in two places. Treating this as a documentation exercise, which satisfies nobody the first time a regulator asks. And leaving the supply chain out, because the duty to mitigate a supplier's risk starts as soon as you identify it, and most operators have never inventoried who touches their critical systems (source: Osler, 2026-06-17).

Where the statute actually stands, as of 2026-09-02.

Bill C-8 received royal assent on 2026-06-15 as Statutes of Canada 2026, chapter 9. Part 1 amends the Telecommunications Act to add security powers, which is the half people mean when they search for a telecom security act, and it's in force now. Part 2, the Critical Cyber Systems Protection Act itself, is law but waits on a Governor in Council order, and Schedule 2, which lists the designated classes, is still empty. Once your class is named you get 90 days for the programme, and incident reports go to CSE inside a window regulations will set, capped at 72 hours (source: Osler, 2026-06-17).

Control checklist
THE METHOD

How Critical Cyber Systems Protection Act readiness work runs.

Four steps, and step 01 ends the engagement for about half the organisations that ask. Scope under this Act is narrow, and being outside it is good news nobody else on this subject seems willing to deliver. For operators genuinely in a Schedule 1 sector, the rest is worth doing on its own merits, which is the test we apply before anything goes in the plan.

  1. Step 01

    Settle the scope

    Whether you sit in one of the six sectors, which systems would count as critical, and what a class designation would capture. We put it in writing, including the answer that says the Act won't reach you.

  2. Step 02

    Design the programme

    Risk identification, system protection, incident detection and impact limits, written so it survives a regulator reading it, not a consultant filing it.

  3. Step 03

    Map the supply chain

    Who touches the critical systems, what each supplier could introduce, and the mitigation you owe once a risk is identified. That duty starts on identification, not on designation.

  4. Step 04

    Rehearse the report

    The CSE submission, the regulator notice, and the Canadian record. Then a tabletop, because the first real incident is the wrong time to read the procedure for the first time.

QUESTIONS

Bill C-26 and Bill C-8 questions, answered straight.

Answers first, including the one where we tell you the Act will never reach you. An architect takes the call.

Both, in different Parliaments, and that's why searching it is confusing. The cyber bill was Bill C-26 in the 44th Parliament and it died before passing. It came back as Bill C-8, which received royal assent on 2026-06-15. In the current Parliament, Bill C-26 is housing legislation authorising payments to the provinces. If you're here for critical infrastructure cyber rules, you want Bill C-8.

Only if you operate in one of six federally regulated sectors: telecommunications, interprovincial or international pipelines and power lines, nuclear energy, federally regulated transportation, banking, or clearing and settlement. Most Canadian organisations are in none of them and will never carry an obligation under this Act. Even inside those sectors, the duties attach to classes the government has yet to name. We settle this before quoting anything.

Because of the 90 days. Once your class is designated you have that long to have a cyber security programme covering risk identification, protection, detection and impact limits. Ninety days is enough to document a programme you already run. It is not enough to build one, inventory a supply chain, and rehearse a reporting process from a standing start. Starting now turns a deadline into a schedule.

Once the Act is in force, up to $500K per violation for an individual and up to $15M per violation for an organisation, and the Governor in Council can also direct an operator to take specific measures. None of that is live yet, because Part 2 awaits an order in council. The honest reason to act is the 90-day clock, not the fine, and any consultant leading with the penalty is selling you something that doesn't exist yet.

When you're outside the six sectors, which is most organisations and the first thing we check. When your sector regulator already holds you to a stricter standard, since the work is largely done and duplicating it wastes money. And when you have no inventory of your own systems, because that comes first and it's cheaper as its own piece of work. We'd rather say that than sell a programme.

The trigger is an order in council fixing the coming into force day for Part 2, plus any regulation naming classes in Schedule 2. Both land in the Canada Gazette, Part II. We watch it for the clients we've scoped, so you hear about your sector the week it's named rather than the quarter after.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.