Cybersecurity ยท Canada
Cybersecurity law & regulation in Canada (2026)
Canada shaded by its cybersecurity status
Cybersecurity in Canada: sectoral rules.
FrameworkCritical Cyber Systems Protection Act (Bill C-8, enacted June 2026 but not yet in force) plus sector-specific regimes: PIPEDA breach-reporting (in force since Nov 2018), OSFI Guideline B-13 for federally regulated financial institutions (effective Jan 2024), and Telecommunications Act cybersecurity amendments (in force June 2026). Guidance and threat coordination are led by the Canadian Centre for Cyber Security (part of the Communications Security Establishment) and the RCMP's National Cybercrime Coordination Centre.
Canada's cybersecurity obligations today are sectoral. A comprehensive framework โ the Critical Cyber Systems Protection Act (Part 2 of Bill C-8) โ received Royal Assent on 15 June 2026, but its substantive obligations on designated operators are not yet in force and await Governor-in-Council commencement orders. In the meantime, federal cybersecurity duties flow from PIPEDA breach-reporting rules, OSFI Guideline B-13 (financial institutions), Telecommunications Act powers over telecom providers (Part 1 of C-8, now in force), and voluntary CCCS guidance.
Key points
Bill C-8 received Royal Assent on 15 June 2026, enacting the Critical Cyber Systems Protection Act (S.C. 2026, c. 9). Part 2 (CCSPA) will impose cyber-programme, incident-reporting and directives obligations on 'designated operators' in six federally regulated sectors, but comes into force only on dates fixed by Governor in Council โ no dates announced as of mid-2026.
Part 1 of Bill C-8 (amendments to the Telecommunications Act) took effect on Royal Assent, giving the Minister of Industry authority to order telecom providers to secure networks, prohibit specified equipment/services (e.g. Huawei/ZTE), and mandate compliance measures โ with monetary penalties for non-compliance.
Since 1 November 2018, organizations subject to the Personal Information Protection and Electronic Documents Act must report breaches of security safeguards involving personal information to the Office of the Privacy Commissioner and notify affected individuals 'as soon as feasible' where there is a real risk of significant harm; records of all breaches must be kept. Knowing non-compliance is an offence.
OSFI's Guideline B-13 on Technology and Cyber Risk Management, effective 1 January 2024, requires federally regulated financial institutions to maintain technology and cyber risk governance and controls. A parallel OSFI advisory requires prompt reporting of material technology or cyber incidents to the primary supervisor.
Once commenced, the CCSPA will designate operators in six Schedule 1 classes โ telecommunications, interprovincial/international pipelines and power lines, nuclear energy, federally regulated transportation, banking, and clearing and settlement systems. Operators must establish a cyber-security programme, report cyber incidents to the Communications Security Establishment, and can face administrative monetary penalties of up to C$15 million per violation.
The February 2025 National Cyber Security Strategy sets Canada's strategic direction, building on the 2018 strategy. Operationally, the Canadian Centre for Cyber Security (within the Communications Security Establishment) is the technical authority for cyber defence and advisory, while the RCMP's National Cybercrime Coordination Centre (NC3) leads cybercrime coordination.
Timeline - major decisions & events
After substantive committee amendments, the cyber security bill (which enacts the Critical Cyber Systems Protection Act and amends the Telecommunications Act) cleared Third Reading in the House and proceeded to the Senate, the final step before Canada's first mandatory critical-infrastructure cyber regime becomes law.
Parliament of Canada (LEGISinfo) โThe Carney government re-tabled the lapsed C-26 provisions as Bill C-8, enacting the Critical Cyber Systems Protection Act to require designated operators in telecom, finance, energy, transport and nuclear to run cyber programs, mitigate supply-chain risk, and report incidents.
Parliament of Canada โPublic Safety Canada launched a new NCSS with a whole-of-society approach, backed by an initial $37.8M over six years and a new Canadian Cyber Defence Collective, replacing the 2018 strategy as the framework for protecting critical infrastructure.
Public Safety Canada โParliament was prorogued, causing the cyber-security bill C-26 (CCSPA) and the privacy/AI bill C-27 (CPPA, AIDA) to die on the Order Paper, leaving Canada operating under PIPEDA (2000) with no enacted critical-infrastructure cyber law.
Parliament of Canada (LEGISinfo) โThe OPC tabled a special report to Parliament finding CRA and ESDC failed to adequately safeguard personal information during the 2020 credential-stuffing attacks, sharpening expectations for federal cyber safeguards and breach handling.
Office of the Privacy Commissioner of Canada โCanada's banking and insurance regulator issued binding expectations for federally regulated financial institutions across governance, technology resilience and cyber security (effective Jan 1, 2024), establishing the sector's core cyber obligations.
OSFI โCredential-stuffing attacks compromised tens of thousands of Government of Canada online accounts via GCKey and CRA portals, enabling CERB fraud and exposing weaknesses that drove later reforms and an $8.7M class-action settlement.
CBC News โPart of the National Security Act 2017, the CSE Act gave Canada's signals-intelligence agency explicit cyber-security, defensive and active cyber-operations mandates, the statutory backbone for federal cyber defence.
Communications Security Establishment โUnder the Breach of Security Safeguards Regulations (SOR/2018-64), private-sector organizations must report breaches posing a real risk of significant harm to the Privacy Commissioner, notify affected individuals, and keep breach records for 24 months.
Canada Gazette โUnder the 2018 National Cyber Security Strategy, Canada consolidated federal cyber operations into a single Cyber Centre within CSE, creating the national authoritative source for cyber guidance, advisories and incident response.
Canadian Centre for Cyber Security โThe Personal Information Protection and Electronic Documents Act became Canada's foundational private-sector privacy law, requiring organizations to protect personal information with safeguards appropriate to its sensitivity, the bedrock cyber obligation still in force.
Justice Laws Website โCanada - other topics
Cybersecurity in other countries
Last verified 8/20/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ