Canada’s critical infrastructure cyber law received Royal Assent on 15 June 2026. It is now an Act of Parliament. It also binds nobody yet: every substantive provision of the Critical Cyber Systems Protection Act is marked “not in force”, and the Public Safety announcement says it will be implemented gradually.
That gap between “passed” and “in force” is where a lot of readiness is currently being sold. Here is what the Act actually says, and what is sensible to do while it waits.
What the Act will require, once it starts
- It applies to designated operators: organisations in classes listed in Schedule 2 that provide the vital services and systems listed in Schedule 1. Both schedules are currently empty in the published text, so nobody can yet say for certain which organisations are in.
- A designated operator must establish a cyber security program within 90 days of becoming a member of a class (section 9).
- It must report a cyber security incident to the Communications Security Establishment within a period set by regulation that cannot exceed 72 hours (section 17).
- Administrative monetary penalties are capped at $15 million for an organisation (section 92). The amounts for individual violations are for regulations still to be made.
What this means for most organisations
If you run a federally regulated operation such as a bank, a pipeline or a telecoms network, expect your regulator to tell you whether you are named once the schedules are filled. If you supply one of those operators, the Act will reach you through their contracts, and it will probably reach you first as a questionnaire asking whether you can report incidents quickly and prove what controls you have.
Everyone else is outside the Act, and should be wary of anyone saying otherwise.
What is worth doing now, and what is not
- Worth doing: find out whether any of your customers are likely designated operators, and ask them now what they will want from suppliers.
- Worth doing: test whether you could describe a serious incident, in writing, within 72 hours. The clock is the part that catches organisations out, and it is good practice regardless.
- Not worth paying for yet: a “compliance programme” against schedules and regulations that have not been published.
The question your board should ask
“Do we sell to anyone who is likely to be a designated operator, and if they asked us tomorrow to report an incident within 72 hours, could we?”
We will note the coming-into-force order and the schedules on this site the day they appear. Until then, the honest position is that the Act is law and asks nothing of you today. We never assess work we have advised on, and we never sell the fix for anything we assess. If you want a view on where you sit, the first conversation is free.
Checked on 30 September 2026 against the Justice Laws Website (S.C. 2026, c. 9, and the Critical Cyber Systems Protection Act, current to 17 June 2026) and Public Safety Canada.