All articles

Canada

Canada's Bill C-8 is law: what the Critical Cyber Systems Protection Act changes

Royal assent on 15 June 2026 created a federal cyber duty for telecom, banking, energy, transport and nuclear operators. The Act is on the books but not yet in force.

SkillHat Editorial Team5 min read
Canada's Bill C-8 is law: what the Critical Cyber Systems Protection Act changes

What does Canada's Bill C-8 require?

Bill C-8 enacts the Critical Cyber Systems Protection Act, which received royal assent on 15 June 2026. It creates a federal cyber security duty for designated operators in telecommunications, banking, energy, transport and nuclear, including cyber security programmes, third party risk management and mandatory incident reporting. The Act is on the books but not yet in force, so obligations begin when it is proclaimed and regulations follow.

Key facts

Bill C-8 received royal assent on 15 June 2026, Statutes of Canada 2026, c. 9.

Part 2 enacts the Critical Cyber Systems Protection Act (CCSPA) for federally regulated sectors.

The CCSPA text states it is not in force yet, so timelines come from future orders and regulations.

What actually happened

Bill C-8, an Act respecting cyber security, was introduced in the House of Commons on 18 June 2025, passed second reading on 3 October 2025 and received royal assent on 15 June 2026. Public Safety Canada announced it publicly on 16 June 2026.

Part 1 amends the Telecommunications Act. Part 2 enacts the Critical Cyber Systems Protection Act, published in the federal statute book as S.C. 2026, c. 9, s. 11, with the note that it is not in force.

Who it reaches

The CCSPA is aimed at the federally regulated sector: telecommunications, banking, clearing and settlement, energy including interprovincial pipelines and nuclear, and federally regulated transportation.

Once designated classes and operators are set through regulation, those operators are expected to run a cyber security programme, manage supply chain and third party risk, report incidents and follow cyber directions.

Why this matters for GRC careers in Canada

New statutory duties create hiring demand in the same places GRC analysts already work: control design, evidence, incident reporting workflows and third party risk registers.

Nothing here is theoretical for candidates. Being able to explain what the CCSPA covers, and what still waits on regulations, is a credible interview answer right now.

What it means for you

Treat C-8 as the start of a build cycle, not a deadline. Learn the duties, follow the regulations as they are published, and be honest in interviews that commencement dates are still pending.

Current CTA

Regulation only pays you if you can show the work.

The GRC Experience Program builds practical project experience, interview-ready stories and the positioning to prove it.

Turn This Into Something You Can Prove.

Short fit call. Clear next step. If neither program is right for you, we'll tell you.

Build Experience You Can Explain.

Explore SkillHat’s practical programs for GRC careers and expertise-led businesses.