Back to Blog
Compliance
4 min read

Bill C-26 and the CCSPA: What Designated Operators Must Prepare For

A cyber security programme, supply chain risk management, rapid incident reporting and binding government directions. What Canadian critical infrastructure should build now.

GuardsArm Team

Security Experts

September 25, 2026

Bill C-26 and the Critical Cyber Systems Protection Act

Canada's Critical Cyber Systems Protection Act, introduced through Bill C-26, establishes mandatory cyber security obligations for operators in federally regulated critical sectors — telecommunications, banking, energy including pipelines and nuclear, and federally regulated transport.

For operators used to voluntary frameworks and sector guidance, the change in character matters more than any single requirement: this is a regulatory regime, with a regulator, audits, binding directions and financial penalties.

A regulator, not guidance
Audits, binding directions and financial penalties
Supply chain is explicit
The duty operators are least ready for
The clock needs a SOC
Business-hours monitoring cannot meet a short window

The four obligations

1. Establish and maintain a cyber security programme. Documented, covering identification of risks to critical cyber systems, protection against compromise, detection of incidents, and minimising the impact of those that occur. It must be reviewed and kept current, not written once.

2. Manage supply chain and third-party risk. Operators must identify and manage risks arising from their supply chain and from third-party products and services. This is the obligation most operators are least prepared for, because it requires visibility into vendors that many have never assessed. See third-party risk management.

3. Report cyber security incidents. Reportable incidents go to the Communications Security Establishment within a prescribed timeframe, with the appropriate regulator also informed.

4. Comply with cyber security directions. Government may issue binding directions requiring an operator to take, or stop taking, specific measures. Directions can carry confidentiality requirements.

The CCSPA obligation chainEstablish a cyber security programme, manage supply chain risk, detect incidents, report them within the prescribed window, and comply with any cyber security direction issued.Programmedocumented, maintainedSupply chainrisks identified, managedDetectmonitoring that alertsReportto CSE within the windowDirectionscomply when issued
Each step assumes the one before it works.

The reporting clock is the operational problem

A short statutory reporting window is a detection and triage problem long before it is a legal one. You cannot report within a prescribed period an incident you will not notice for a fortnight.

Meeting it requires:

CapabilityWhy the clock needs it
Monitoring that actually alertsNothing starts until someone knows
A defined severity thresholdSomeone must decide "this is reportable" quickly
A named decision-maker, 24/7Waiting for Monday consumes the whole window
A pre-drafted report formatComposing under pressure loses hours
Legal and communications on standbyReporting duties interact with disclosure duties

Operators with a mature SOC find this manageable. Operators relying on business hours monitoring do not, and that gap is the single largest programme cost for most designated operators. See modern SOC options for how the build-or-buy decision tends to resolve.


Where the OT estate complicates everything

In energy, pipelines and transport, the critical cyber systems are frequently operational technology — systems that cannot be patched on a normal cycle, cannot be scanned aggressively, and in some cases cannot be taken offline at all without a safety case.

OT assets rarely meet the standard on their own terms
A controller that cannot be patched, scanned or rebooted will not satisfy a protection obligation directly. The defensible answer is a compensating architecture — segmentation, passive monitoring, brokered access — documented as such in the programme rather than left as an unexplained gap.

The realistic path is segmentation, passive monitoring and rigorous access control around systems that cannot themselves be hardened. See OT and ICS security and, for Alberta energy operators, the separate provincial requirements in Alberta Regulation 84/2024.


What to do now

The obligations reward preparation, and none of the following is wasted even if timelines move:

  1. Identify your critical cyber systems — the inventory is the foundation of everything else and is rarely complete
  2. Write the programme document, mapped to a recognised framework so it is defensible
  3. Build the incident reporting runbook, including who can declare at 3am
  4. Start supply chain assessment with your highest-dependency vendors
  5. Close the monitoring gap if your coverage is business hours only

Penalties, and why this becomes a board item

The CCSPA carries administrative monetary penalties, and the regime contemplates liability attaching to directors and officers who directed, authorised or acquiesced in a contravention. That is the provision that moves this out of the IT budget conversation.

Boards of designated operators should be receiving, at minimum:

Reporting itemCadence
Status of the cyber security programme against the regulationQuarterly
Critical cyber system inventory completenessQuarterly
Supply chain assessment coverageQuarterly
Incident reporting readiness, including out-of-hours decision authorityAnnually, and after any test
Any direction received, and compliance statusImmediately

Documented board oversight is also the practical answer to the question of whether the organisation took the obligation seriously. See security metrics boards understand for how to present this without drowning the discussion in tooling detail.


GuardsArm supports designated operators with programme development, OT assessment and incident readiness. See CCSPA compliance or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.