Bill C-8: Canada’s New Cybersecurity Law Explained

By Rodrigo Lamadrid 15 July, 2026
Bill C-8

Bill C-8 received Royal Assent on June 16, 2026, turning a three-year cybersecurity fight through two separate Parliaments into a live legal regime for Canada’s critical infrastructure.

It gives Ottawa new authority to compel action from telecom providers and creates mandatory cybersecurity obligations, with penalties of up to $15 million per day for operators in banking, energy, transportation, and telecommunications across the country’s critical infrastructure.

In this article, we’ll explain what this new law actually does, who it applies to, what it requires, the real-world consequences of simply not complying at all with this brand new federal cybersecurity law today, and how your own organization can comply with this mandate using Mindsec now that it’s law and fully enforceable.

What Is Bill C-8?

At its core, this is a national security law. It treats cyber risk to essential services in the same way Canada has long treated physical threats to critical infrastructure and public safety.

Bill C-8, formally titled An Act Respecting Cyber Security (ARCS), is Canada’s most significant federal cybersecurity legislation to date. It’s built around two operative parts that work together.

Part 1 amends the Telecommunications Act. It adds security as an explicit policy objective and gives the Governor in Council and the Minister of Industry new authority to direct telecom providers to take (or stop) specific actions to secure the network.

Part 2 enacts an entirely new statute: the Critical Cyber Systems Protection Act (CCSPA). It sets mandatory cybersecurity obligations for designated operators across critical infrastructure.

The Telecommunications Act amendments took effect immediately upon Royal Assent. The Critical Cyber Systems Protection Act (CCSPA) obligations come into force gradually, on dates still to be fixed by order of the Governor in Council.

Who Must Comply: Bill C-8 Canada’s Scope

The CCSPA applies to “designated operators” in federally regulated sectors: 

  • Telecommunications
  • Banking
  • Energy (including nuclear)
  • Interprovincial transportation
  • Clearing and settlement systems

The key word is “designated.” Not every company in these sectors is automatically covered the same way. The regime depends on specific classes of operators and critical cyber systems named in the Act and in future regulations.

Once an operator is designated, they have 90 days to establish a documented cybersecurity program covering the systems the government has identified as critical.

The Core Obligations Under the CCSPA

Designated operators face four main obligations under Bill C-8. They turn general cybersecurity awareness into an enforceable legal program with deadlines.

  • Establish and maintain a documented cybersecurity program addressing risk identification, protection, incident detection, and impact reduction. Also including risks tied to supply chains and third-party products.
  • Mitigate supply chain and third-party risk specifically. Not just risk to internally managed systems. Since the Act explicitly calls out vendor and product risk as in scope.
  • Report cyber security incidents affecting a critical cyber system to the Communications Security Establishment within a prescribed reporting window.
  • Comply with cyber security directions issued by the government, and report any material changes to systems. Especially ones with national security implications.

These obligations echo similar regimes among Canada’s allies. Including the U.S. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), the EU’s NIS2 Directive, and the UK’s Network and Information Systems Regulations.

Penalties for Non-Compliance

The CCSPA’s penalties are steep by Canadian regulatory standards, among the highest of any federal statute currently in place for Bill C-8’s covered sectors. 

  • Organizations can face administrative monetary penalties of up to $15 million per day for violations, with continuing violations counted separately for each day they persist.
  • Individuals can face penalties of up to $1 million per day. Directors and officers who directed, authorized, assented to, or participated in a violation can be held personally liable, whether or not the organization itself is prosecuted.

A due diligence defence is available for most violations and offences under this law. This puts a real premium on documented, board-visible compliance efforts rather than after-the-fact justifications.

The Act also preserves solicitor-client privilege. This allows information-sharing among federal bodies, including the CSE, the Canadian Security Intelligence Service (CSIS), and the Department of National Defence, under defined circumstances that restrict how recipients can use shared information.

Bill C-8 Timeline: From Bill C-26 to Royal Assent

This law is a direct successor to Bill C-26, introduced three years earlier, which died when Parliament was prorogued in January 2025.

Budget 2019 had already committed $144.9 million to build a critical cyber systems framework. So the policy groundwork for Bill C-8 long predated the bill itself.

It was reintroduced in substantially similar form in the current Parliament. It then passed Third Reading in the House of Commons on March 26, 2026, cleared the Senate, and received Royal Assent on June 16, 2026.

Three late amendments shaped the final text: 

  • An explicit bar on ordering the decryption of encrypted communications;
  • A higher threshold before the government can take ministerial action; and 
  • A mandatory five-year parliamentary review of the whole Act

Privacy advocates, including the Office of the Privacy Commissioner, told the Senate that Parliament had made meaningful improvements during committee study, including proportionality language and after-the-fact notice requirements. That fuller legislative record is worth knowing if your organization ever needs to interpret how this law should apply in a borderline case.

How Mindsec Facilitates Fast And Easy Bill C-8 Compliance

Mindsec is a compliance automation platform that helps organizations document, monitor, and evidence the security controls that laws like this one require

We also support ISO 27001, NIST CSF, SOC 2, and a dozen more regulations. We have cross-mapping tech to streamline compliance for multiple frameworks simultaneously with the exact same evidence.

Book a 15-minute demo to see how Mindsec keeps your organization ready as Canada’s critical infrastructure rules take effect.

Frequently Asked Questions

What Is the Current Bill C-8 Status?

Bill C-8 has already received Royal Assent and is now law. The Telecommunications Act amendments are already in force, while the CCSPA’s operator obligations are being phased in gradually through regulations still being developed by Ottawa and its federal partners.

Public Safety Canada and the Communications Security Establishment are both expected to lead detailed consultation on those regulations. They’ll define exactly which companies count as designated operators, which systems count as critical cyber systems within each covered sector of the economy, and how much longer that whole process might still take.

That distinction matters. The government has new powers over telecom providers, but designated critical infrastructure operators still don’t yet have any fixed date for when their specific obligations actually begin. They won’t until the necessary regulations are drafted, consulted on, finalized, and published in the Canada Gazette. That timeline is worth tracking closely if your organization operates in any of the covered sectors.

Has Bill C-8 Canada Passed?

Yes. Bill C-8 Canada passed Third Reading in the House of Commons on March 26, 2026, cleared the Senate afterward, and received Royal Assent on June 16, 2026, completing its full legislative process from introduction to law.

Passage doesn’t mean every obligation is active yet, though. Most of the CCSPA’s substantive requirements will come into force gradually, on dates the Governor in Council still has to fix by order, sector by sector, likely over the next one to two years.

For most designated operators, that means there’s still a window, though a narrowing one, to build a documented cybersecurity program before an actual compliance deadline forces the issue under threat of penalty.

Waiting for the final regulations before starting is a common but costly mistake. Most of the work, mapping systems, documenting processes, training staff, takes far longer than the 90-day window the Act allows once designation actually happens.

If you want professional guidance on what you can start doing now so you don’t get a late start on this new bill, book a free, 15-minute demo to learn how the Mindsec platform works and how our experts can walk you through the adoption of this new legislation.

Is Bill C-8 the Same as Bill C-9?

No. Bill C-8 is the cybersecurity law covered in this article. Bill C-9 is the Combatting Hate Act, a Criminal Code amendment with nothing to do with cybersecurity.

What You Should Do Now To Adopt Bill C-8

  • Determine whether your organization operates in a covered sector: telecom, banking, energy, interprovincial transport, or clearing and settlement.
  • Watch for designation. Being in a covered sector doesn’t automatically mean you’re a designated operator. That depends on forthcoming regulations.
  • Start building a documented cybersecurity program now rather than waiting for your 90-day clock to start. Most of the real work is documentation and process, not new technology. You can rely on Mindsec for this.
  • Map your supply chain and vendor risk specifically, since the CCSPA calls this out as its own obligation. You can complete this using Mindsec’s built-in Third-Party Risk Management Tool.
  • Get your incident reporting process ready before you need it. A prescribed reporting window is not the moment to improvise who calls whom.

Rodrigo Lamadrid

Mindsec staff

Why Stall? Book A Call

Want to comply with Bill C-8 and other regulations? Book a call with our team and learn how we streamline this for you.

See Mindsec In Action