
Bill C-26 and the CCSPA: What Designated Operators Must Prepare For
A cyber security programme, supply chain risk management, rapid incident reporting and binding government directions. What Canadian critical infrastructure should build now.
GuardsArm Team
Security Experts

Canada's Critical Cyber Systems Protection Act, introduced through Bill C-26, establishes mandatory cyber security obligations for operators in federally regulated critical sectors — telecommunications, banking, energy including pipelines and nuclear, and federally regulated transport.
For operators used to voluntary frameworks and sector guidance, the change in character matters more than any single requirement: this is a regulatory regime, with a regulator, audits, binding directions and financial penalties.
The four obligations
1. Establish and maintain a cyber security programme. Documented, covering identification of risks to critical cyber systems, protection against compromise, detection of incidents, and minimising the impact of those that occur. It must be reviewed and kept current, not written once.
2. Manage supply chain and third-party risk. Operators must identify and manage risks arising from their supply chain and from third-party products and services. This is the obligation most operators are least prepared for, because it requires visibility into vendors that many have never assessed. See third-party risk management.
3. Report cyber security incidents. Reportable incidents go to the Communications Security Establishment within a prescribed timeframe, with the appropriate regulator also informed.
4. Comply with cyber security directions. Government may issue binding directions requiring an operator to take, or stop taking, specific measures. Directions can carry confidentiality requirements.
The reporting clock is the operational problem
A short statutory reporting window is a detection and triage problem long before it is a legal one. You cannot report within a prescribed period an incident you will not notice for a fortnight.
Meeting it requires:
| Capability | Why the clock needs it |
|---|---|
| Monitoring that actually alerts | Nothing starts until someone knows |
| A defined severity threshold | Someone must decide "this is reportable" quickly |
| A named decision-maker, 24/7 | Waiting for Monday consumes the whole window |
| A pre-drafted report format | Composing under pressure loses hours |
| Legal and communications on standby | Reporting duties interact with disclosure duties |
Operators with a mature SOC find this manageable. Operators relying on business hours monitoring do not, and that gap is the single largest programme cost for most designated operators. See modern SOC options for how the build-or-buy decision tends to resolve.
Where the OT estate complicates everything
In energy, pipelines and transport, the critical cyber systems are frequently operational technology — systems that cannot be patched on a normal cycle, cannot be scanned aggressively, and in some cases cannot be taken offline at all without a safety case.
The realistic path is segmentation, passive monitoring and rigorous access control around systems that cannot themselves be hardened. See OT and ICS security and, for Alberta energy operators, the separate provincial requirements in Alberta Regulation 84/2024.
What to do now
The obligations reward preparation, and none of the following is wasted even if timelines move:
- Identify your critical cyber systems — the inventory is the foundation of everything else and is rarely complete
- Write the programme document, mapped to a recognised framework so it is defensible
- Build the incident reporting runbook, including who can declare at 3am
- Start supply chain assessment with your highest-dependency vendors
- Close the monitoring gap if your coverage is business hours only
Penalties, and why this becomes a board item
The CCSPA carries administrative monetary penalties, and the regime contemplates liability attaching to directors and officers who directed, authorised or acquiesced in a contravention. That is the provision that moves this out of the IT budget conversation.
Boards of designated operators should be receiving, at minimum:
| Reporting item | Cadence |
|---|---|
| Status of the cyber security programme against the regulation | Quarterly |
| Critical cyber system inventory completeness | Quarterly |
| Supply chain assessment coverage | Quarterly |
| Incident reporting readiness, including out-of-hours decision authority | Annually, and after any test |
| Any direction received, and compliance status | Immediately |
Documented board oversight is also the practical answer to the question of whether the organisation took the obligation seriously. See security metrics boards understand for how to present this without drowning the discussion in tooling detail.
GuardsArm supports designated operators with programme development, OT assessment and incident readiness. See CCSPA compliance or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


