Canada
Canada's Bill C-8 is law: what the Critical Cyber Systems Protection Act changes
Royal assent on 15 June 2026 created a federal cyber duty for telecom, banking, energy, transport and nuclear operators. The Act is on the books but not yet in force.

What does Canada's Bill C-8 require?
Bill C-8 enacts the Critical Cyber Systems Protection Act, which received royal assent on 15 June 2026. It creates a federal cyber security duty for designated operators in telecommunications, banking, energy, transport and nuclear, including cyber security programmes, third party risk management and mandatory incident reporting. The Act is on the books but not yet in force, so obligations begin when it is proclaimed and regulations follow.
Key facts
Bill C-8 received royal assent on 15 June 2026, Statutes of Canada 2026, c. 9.
Part 2 enacts the Critical Cyber Systems Protection Act (CCSPA) for federally regulated sectors.
The CCSPA text states it is not in force yet, so timelines come from future orders and regulations.
What actually happened
Bill C-8, an Act respecting cyber security, was introduced in the House of Commons on 18 June 2025, passed second reading on 3 October 2025 and received royal assent on 15 June 2026. Public Safety Canada announced it publicly on 16 June 2026.
Part 1 amends the Telecommunications Act. Part 2 enacts the Critical Cyber Systems Protection Act, published in the federal statute book as S.C. 2026, c. 9, s. 11, with the note that it is not in force.
Who it reaches
The CCSPA is aimed at the federally regulated sector: telecommunications, banking, clearing and settlement, energy including interprovincial pipelines and nuclear, and federally regulated transportation.
Once designated classes and operators are set through regulation, those operators are expected to run a cyber security programme, manage supply chain and third party risk, report incidents and follow cyber directions.
Why this matters for GRC careers in Canada
New statutory duties create hiring demand in the same places GRC analysts already work: control design, evidence, incident reporting workflows and third party risk registers.
Nothing here is theoretical for candidates. Being able to explain what the CCSPA covers, and what still waits on regulations, is a credible interview answer right now.
What it means for you
Treat C-8 as the start of a build cycle, not a deadline. Learn the duties, follow the regulations as they are published, and be honest in interviews that commencement dates are still pending.
Current CTA
Regulation only pays you if you can show the work.
The GRC Experience Program builds practical project experience, interview-ready stories and the positioning to prove it.
Turn This Into Something You Can Prove.
Short fit call. Clear next step. If neither program is right for you, we'll tell you.
Related posts

OSFI's B-13 and B-10 remain the backbone of Canadian financial GRC work
Technology and cyber risk management, plus third party risk, are where most Canadian bank and insurer control testing actually happens.
Read article
Critical infrastructure is the front line, and the intrusions are no longer about intelligence
Former deputy US national security adviser Anne Neuberger argues Chinese access to US communications, energy and transport networks is pre-positioning for sabotage. A summer of water utility compromises and a 7.49 million record utility breach made the point domestically.
Read article
The EU AI Act's 2 August 2026 date passed, and the Digital Omnibus moved the hard part
Regulation (EU) 2026/1744 entered into force on 27 July 2026 and pushed most high-risk obligations to December 2027 and August 2028. Transparency and general-purpose model duties kept their dates.
Read article