Sentrix

Explainer · Critical systems

Critical Cyber Systems Protection Act: what changes

Assented to on June 15, 2026 and not yet in force, Canada's Critical Cyber Systems Protection Act sets a program, a 72-hour cap and supplier oversight.

By Sentrix · Published 2026-10-01

A software vendor in Lyon, Boston or Quebec City supplies a monitoring platform to an interprovincial pipeline operator. The day that operator falls into a designated class, it will have 90 days to establish a cyber security program that covers its supply chain, and its supplier will receive a contract amendment. The Critical Cyber Systems Protection Act is not in force yet, but its text already shows what that amendment will contain.

What the Act says

Status. The Act (S.C. 2026, c. 9, s. 11) was assented to on June 15, 2026. The Justice Laws website, current to September 21, 2026, marks it as not in force, and Public Safety Canada's news release of June 16, 2026 says it will be implemented gradually.

Who is designated. Schedule 1 lists six vital services and vital systems: telecommunications, interprovincial or international pipelines and power lines, nuclear energy, transportation within the legislative authority of Parliament, banking, clearing and settlement. A designated operator is one that belongs to a class referred to in Schedule 2, which does not list any class yet. The Governor in Council may add classes, each with its regulator (section 7): the Minister of Industry, the Minister of Transport, the Superintendent of Financial Institutions, the Bank of Canada, the Canadian Energy Regulator or the Canadian Nuclear Safety Commission.

The cyber security program. Within 90 days of becoming a member of a class, the operator establishes a program (subsection 9(1)) that includes steps to:

  • identify and manage organizational cyber security risks, including those tied to the supply chain and to third-party products and services;
  • protect its critical cyber systems from being compromised;
  • detect cyber security incidents affecting them, or with the potential to;
  • minimize the impact of those incidents.

It provides the program to its regulator within the same period (section 10), implements and maintains it (section 12), then reviews it on every anniversary, unless the regulations prescribe other dates (section 13).

The supply chain. As soon as a risk associated with the supply chain or with third-party products and services has been identified, the operator must mitigate it (section 15). It notifies its regulator of any material change in that supply chain, in its ownership or in its control (section 14). The Communications Security Establishment may develop guidelines on these risks, taking into account frameworks such as those of the International Organization for Standardization on cybersecurity in supplier relationships (section 15.1).

Incidents. Section 17 requires the operator to report to the Communications Security Establishment any cyber security incident in respect of a critical cyber system, within a period prescribed by regulation that must not exceed 72 hours. Immediately afterwards, the operator notifies its regulator and gives it a copy of the report (section 18).

Penalties. Administrative monetary penalties will be fixed by regulation, capped at $500,000 for an individual and $15,000,000 in any other case (section 91). Each day on which a violation continues counts as a separate violation (section 94). Offences come on top: contravening subsection 9(1) or sections 12 or 15 exposes the offender to a fine in the discretion of the court and, for an individual, to imprisonment (section 137).

Why it matters to a supplier

The Act binds the designated operator, not its suppliers. Yet its duties cannot be met without them: the supplier is a risk to identify and then mitigate, an incident that starts at the supplier must reach the operator early enough to be reported within the prescribed period, and the operator keeps records of its mitigation steps, held in Canada (section 30).

One provision reaches the supplier directly. An operator subject to a cyber security direction may disclose its existence or content only to the extent necessary to comply with it, and the person who receives that information must not disclose it without the operator's authorization (sections 24 and 25).

The rest is our reading, not the text of the Act: an operator that answers to its regulator on these points will ask for them by contract. Expect:

  • an incident notification deadline well under 72 hours;
  • advance notice of any material change (subcontractor, ownership, control);
  • evidence of your controls on request, and a right to audit;
  • a confidentiality clause covering cyber security directions.

What to do, in order

  1. Spot the customers concerned. Which of them operate one of the six services or systems in Schedule 1?
  2. Map what you touch. Which products, accesses and data reach a customer's critical cyber system?
  3. Set your incident clock. Who notifies the customer of an incident, through which channel, in how many hours?
  4. Keep the evidence file. Controls in place, subcontractors, a log of material changes.
  5. Reread your standard contracts. Better to propose your own notification, change and audit clause than to receive the customer's.
  6. Follow the texts to come. The classes in Schedule 2, the regulations and the coming-into-force dates will set the real calendar.

The next step

Take your largest contract with a customer in telecommunications, energy, transportation or finance, and look for three things in it: a notification deadline in hours, a material change clause, a right to audit. Whatever is missing is your work plan, and our third-party risk page shows the same relationship from the operator's side.

Sources

Frequently asked questions

Is the Critical Cyber Systems Protection Act in force?
No. Assented to on June 15, 2026 (S.C. 2026, c. 9, s. 11), it is marked as not in force on the Justice Laws website, current to September 21, 2026. Public Safety Canada's news release of June 16, 2026 says the Act will be implemented gradually, with certain provisions coming into force through a phased approach. The classes of operators in Schedule 2 and the regulations are still to come.
Who will be a designated operator?
Any person, partnership or unincorporated organization that belongs to a class of operators referred to in Schedule 2, which does not list any class yet. Schedule 1 sets the perimeter: telecommunications, interprovincial or international pipelines and power lines, nuclear energy, federally regulated transportation, banking, clearing and settlement. Each class will have its own regulator, for example the Superintendent of Financial Institutions or the Canadian Energy Regulator.
Is a supplier directly covered by the Act?
For the most part, no. The duties sit with the designated operator, which must identify, manage and mitigate the risks tied to its supply chain and to its use of third-party products and services (paragraph 9(1)(a) and section 15). The supplier will receive them by contract. One exception: a person who learns of a cyber security direction must not disclose it without the operator's authorization (subsection 25(2)).

Let's talk about your compliance program.

Last updated: 2026-10-01