Canada’s Bill C-8 is now law, but its cybersecurity duties are being introduced in stages. Here is what has changed, which organizations may be directly affected and how smaller businesses can prepare for customer security expectations.

Glowing maple leaf over a blue circuit board

What changed in Bill C-8

Bill C-8 received royal assent on June 15, 2026. It revived the central approach of the earlier Bill C-26, which did not become law. The enacted legislation has two main parts: amendments to the Telecommunications Act and the new Critical Cyber Systems Protection Act (CCSPA).

Where things stand: The telecommunications amendments took effect at royal assent. The CCSPA is being brought into force in phases. A business should check the applicable commencement orders, designations and regulations before treating a proposed requirement as a current obligation.

The telecommunications changes give the federal government powers to direct providers to take measures to secure the Canadian telecommunications system. The CCSPA creates a framework for designated operators of vital services and systems under federal jurisdiction.

Who may have direct duties

The CCSPA focuses on designated operators, rather than every Canadian business. Its framework covers vital services and systems in finance, telecommunications, energy and transportation. The government can establish classes of operators and corresponding regulators. Being a vendor to a regulated organization does not, by itself, make your company a designated operator.

Direct legal duties and supplier expectations
Your roleWhat to assess
Designated operatorConfirm the applicable class, regulator, commencement date, regulations and obligations for the critical cyber systems you operate.
Supplier to an operatorReview contractual security, incident notice, access and audit terms. A client's obligations may flow into procurement requirements without making you directly regulated under the CCSPA.
Other businessReview cyber risk and existing privacy, contract and industry requirements. Bill C-8 does not create a blanket reporting rule for all Canadian businesses.

If your role is uncertain, map the services you operate and the clients you support, then seek advice on the precise legal scope.

What the framework expects of designated operators

As the relevant provisions take effect, designated operators will be required to establish and maintain a cyber security program for critical cyber systems, address supply-chain and third-party risk, report qualifying cyber security incidents, keep required records and comply with applicable cyber security directions. The details depend on the enacted provisions, regulations and each operator's designation.

Core duties for designated operators
DutyWhat it means
Security programIdentify and manage risks to critical cyber systems, with a program the appropriate regulator can review.
Third-party riskAssess suppliers and dependencies that could affect the security or reliability of a vital service.
Incident reportingPrepare to recognize reportable incidents and send information to the prescribed recipients within the applicable rules.
Records and directionsKeep evidence of the program and response, and be ready to act on a lawful cyber security direction.

Enforcement tools include inspections, compliance orders and monetary penalties. They apply within the statutory framework, not automatically to every organization that uses technology.

Why smaller suppliers should pay attention

A smaller company may sit outside the CCSPA's direct scope and still face a more demanding customer review. A bank, carrier, energy company or transportation operator needs to understand the risks created by software, cloud services, managed IT and other external providers.

That can lead to requests for a current asset inventory, access controls, patching evidence, an incident response contact, tested backups, contractual notification terms or a security assessment. The exact requests depend on the client and contract. Treat these as business and security requirements, rather than claiming that Bill C-8 directly regulates every supplier.

A practical readiness checklist

  • Map exposure. Identify critical clients, the services you provide to them and the systems they depend on.
  • Know your assets and access. Inventory important systems, restrict privileged access and use multifactor authentication where appropriate.
  • Reduce known gaps. Establish patching, vulnerability review and monitoring processes that fit the systems you operate.
  • Plan the first hour of an incident. Assign owners, preserve evidence, list contacts and check reporting and contractual notice triggers.
  • Test recovery. Keep protected backups and rehearse restoration for business-critical services.
  • Document the work. Maintain policies, risk decisions, training and records that show what is actually in place.

For a designated operator, this checklist is a starting point, not a substitute for the law, regulations or regulator guidance. For a supplier, it also makes customer due diligence easier to answer.

Where ThinkSwift can help

ThinkSwift's Cyber360 offering brings together security monitoring and practical support for managing cyber risk. The original article also describes vulnerability reviews, incident planning, staff awareness and policy work. Scope and availability should be confirmed for the specific engagement.

Financial protection needs a careful distinction. ThinkSwift's Cyber Insurance Protection page describes a protection warranty included with Cyber360 at an advertised limit of up to $500,000, subject to its agreement and eligibility. It separately describes optional comprehensive cyber insurance quotes. A warranty is not the same as an insurance policy, and neither makes a business compliant with Bill C-8 on its own.

Questions answered

FAQ

Clear answers for business leaders.

01Is Bill C-8 law now?

Yes. It received royal assent on June 15, 2026. The telecommunications amendments took immediate effect, while the CCSPA is being implemented in phases.

02Does every Canadian business have to report incidents under it?

No. The CCSPA's reporting framework concerns designated operators and qualifying incidents under the applicable provisions and regulations. Other reporting duties may arise under privacy law, sector rules or contracts.

03Does supplying a regulated company make us a designated operator?

Not automatically. A supplier may face security and notice requirements through its contract, while direct CCSPA obligations depend on whether it falls within a designated class of operators.

Make your cyber readiness practical.

Talk with us about the systems you depend on, the requirements your clients are asking for and the security work to prioritize.

Talk it through

Sources: Parliament of Canada, Bill C-8 status; enacted text; Public Safety Canada, June 2026. Checked September 23, 2026.

ThinkSwift Cybersecurity Team