Key Takeaways
- With Bill C-8, designated operators may need to strengthen cybersecurity programs, incident response planning, supply chain risk management, and reporting processes.
- The Critical Cyber Systems Protection Act (CCSPA) will be implemented in phases, but organizations should begin assessing readiness now.
- Compliance should be treated as the starting point. The larger goal is building resilience across the critical systems people rely on.
Why Bill C-8 Matters Now
Canada took a major step toward strengthening cybersecurity across essential services. Bill C-8, An Act Respecting Cyber Security, received Royal Assent on June 15, 2026, moving Canada’s critical infrastructure cybersecurity framework from proposal to law.
At its core, the law is about improving the resilience of systems that support essential services, including finance, telecommunications, energy, and transportation.
But while Bill C-8 is an important milestone, cybersecurity experts caution that it should be viewed as a baseline, not a finish line. As Brent Arnold, Partner at INQ Law, said on The Art of Security podcast, “I'm glad it’s in. I’m not impressed that it’s in.”
Arnold’s point captures the reality facing many critical infrastructure organizations: Bill C-8 may be new law, but the expectations behind it are not new cybersecurity concepts.
What Bill C-8 Does
For business and security leaders, Bill C-8 breaks down into two main areas.
First, it amends the Telecommunications Act to make the security of Canada’s telecommunications system an explicit policy objective. It also gives the federal government new authority to direct telecommunications service providers to take, or avoid taking, certain actions when needed to help secure Canadian telecom systems.
Second, Bill C-8 introduces the Critical Cyber Systems Protection Act (CCSPA), which creates cybersecurity requirements for designated operators of vital systems and services under federal jurisdiction. In practice, that means designated operators will need formal cybersecurity programs, stronger oversight of third-party and supply chain risk, incident reporting processes, and the ability to comply with government-issued cybersecurity directions.
“This is essentially table-stakes-level regulation of critical infrastructure: You have to have a plan, and you have to have some minimum things in place in the event of a cyberattack,” said Arnold.
That “table-stakes” framing matters. Bill C-8 is not asking critical infrastructure organizations to adopt experimental or highly advanced cyber practices. It formalizes core expectations around planning, preparedness, risk management, and accountability.
Why Critical Infrastructure Readiness Matters
For major organizations in sectors like finance, telecommunications, energy, and transportation, cybersecurity is already a mature operational priority. Many large operators have dedicated security teams, established incident response processes, and significant investments in resilience.
But critical infrastructure ecosystems are not only made up of large, well-resourced organizations. They also include smaller operators, suppliers, service providers, and third parties that may not have the same level of cybersecurity maturity.
That lack of readiness is exactly what Bill C-8 is intended to address. Cyberattacks against essential services can have consequences that extend far beyond one organization. Disruption in a vital system can affect public safety, economic stability, customer trust, and national resilience.
For designated operators, this means cybersecurity can no longer be treated as a best-practice exercise or an internal IT concern. It is becoming a regulatory expectation.
Incident Response Planning Is No Longer Optional
One practical implication of Bill C-8 is the need for organizations to demonstrate that they are prepared for cyber incidents before they happen.
That begins with having an incident response plan, but that’s just the first step. Under Bill C-8’s CCSPA, designated operators are expected to establish cybersecurity programs and report cybersecurity incidents, making response readiness a key part of compliance preparation.
A static document won’t be enough. Incident response plans should be tested, updated, and aligned with the organization’s operational risk, regulatory obligations, and threat environment.
Bill C-8 reinforces that cybersecurity readiness goes beyond prevention. Organizations must also be able to respond quickly, recover effectively, and demonstrate that appropriate safeguards were in place.
Compliance Is the Floor, Not the Ceiling
Bill C-8 establishes minimum expectations for designated critical infrastructure operators. But organizations should be careful not to treat minimum compliance as the end goal.
Rather than waiting for every implementation detail to be finalized, critical infrastructure organizations can use Bill C-8 as a reason to strengthen their broader cybersecurity posture now. That starts with understanding which systems are most critical, validating whether current controls are effective, clarifying who owns cyber risk, and aligning leadership around cyber resilience as an operational priority.
Supply Chain Risk Needs More Than Contract Language
An important area covered by Bill C-8 is third-party and supply chain risk. Under CCSPA, designated operators are expected to mitigate these risks as part of their broader cybersecurity obligations. The CCSPA also introduces cyber incident reporting obligations. Public Safety Canada has identified Communications Security Establishment Canada (CSE), through the Canadian Centre for Cyber Security (CCCS), as the reporting channel for cybersecurity incidents.
For organizations preparing for Bill C-8, incident readiness needs to extend beyond their own environment. If a supplier-related incident could affect critical cyber systems, teams need a clear process to identify, escalate, document, and report it.
That distinction matters because many cyber incidents do not start inside the primary organization. They begin with a vendor, service provider, software supplier, or other third parties connected to critical operations.
Contracts with third-party vendors matter, but they are not security controls. As Arnold put it, “Pointing to your contract and saying you breached the contract doesn’t stop the breach.”
For organizations affected by Bill C-8, third-party risk management should include ongoing vendor assessments, technical validation where appropriate, incident notification expectations, backup and recovery verification, and clear escalation processes, including potential reporting through the CCCS where required.
Bill C-8 Is the Baseline. Resilience Is the Goal.
Bill C-8 marks an important shift in Canada’s approach to critical infrastructure cybersecurity, moving key expectations around cyber readiness, incident reporting, and third-party risk into a more formal regulatory framework.
For organizations that may be affected, the next step is readiness: understanding potential applicability, identifying critical systems, and strengthening the programs and processes needed to protect them.
Bill C-8 may set the baseline, but resilience is the larger goal. When a cyber incident occurs, organizations need to do more than show good intentions. They need to respond, recover, and prove they were prepared.
Explore How Fortra Can Help Your Organization Strengthen Cyber Resilience.
As Canada’s cybersecurity requirements evolve, Fortra helps organizations strengthen security readiness, reduce risk, and protect critical assets across today’s complex threat landscape.