Whatsapp
Get a quote
Email Us
Call
Skip to content
Compliance & Cybersecurity Consulting

Bill C-8 Is Now Law: What Canada's New Cybersecurity Act Means for Your Business

Noor FatimaJul 30, 202611 min read
Share

On June 15, 2026, Bill C-8, officially titled An Act Respecting Cyber Security, received Royal Assent. If that name doesn't ring a bell yet, it will soon. This is the most significant change to Canadian cybersecurity regulation in years, and it arrives at a moment when ransomware groups are hitting Canadian organizations at a pace almost nobody predicted five years ago.

For business owners, IT managers, and compliance leads across the country, the timing couldn't be more relevant. Just a few weeks before Bill C-8 became law, the Office of the Privacy Commissioner of Canada confirmed that WestJet had committed to strengthening its security following a 2025 cyberattack that affected more than five million current and former customers and employees. The attacker didn't need some exotic zero day exploit. They used social engineering to get around multi factor authentication on a single employee account with administrative access, then used that foothold to reach WestJet's cloud storage and pull data out. One compromised login. Five million people affected.

That's the backdrop Bill C-8 is arriving into, and it's exactly why every Canadian company, not just the ones directly named in the legislation, should take the time to understand what's changing.

  • What Bill C-8 Actually Does

Bill C-8 does two things. First, it amends the Telecommunications Act to make security an explicit policy objective, giving the federal government new authority to direct telecom carriers to address specific threats. That part took effect immediately upon Royal Assent.

Second, and this is the part getting most of the attention, it creates an entirely new law called the Critical Cyber Systems Protection Act, or CCSPA. This is Canada's first dedicated piece of cybersecurity legislation aimed squarely at critical infrastructure, and it's been a long time coming. An earlier version, Bill C-26, was tabled back in 2022 and never made it through Parliament before dying on the order paper. Bill C-8 picks up where that attempt left off, and this time it actually passed.

The CCSPA applies to what the legislation calls designated operators, meaning organizations that run vital services or vital systems in banking, telecommunications, energy, transportation, nuclear power, and clearing and settlement systems. If your organization falls into one of those categories, you'll be expected to stand up a documented cybersecurity program, report significant incidents to the federal government, manage risk coming from your suppliers and third party vendors, and follow directions issued by the relevant regulator when threats emerge.

The penalties attached to this aren't symbolic. Non compliance can bring fines of up to fifteen million dollars per day for an organization. That's not a one time number either, it's a daily figure, which tells you how seriously Ottawa intends for this to be taken.

The one piece of breathing room is that the CCSPA won't switch on all at once. Its provisions come into force gradually, through orders made by the Governor in Council, so designated operators will get some runway to prepare rather than facing every obligation on day one.

  • You Might Not Be a Designated Operator, But You're Still in the Blast Radius

Here's where a lot of business owners tune out, because they read "banking, telecom, energy, transportation, nuclear" and assume none of it touches them. Fair enough, on paper. But a few things are worth thinking through before you move on.

First, think about supply chains. If you sell software, IT services, logistics, or professional services to a designated operator, expect that client to start asking sharper questions about your own security posture. Vendor risk management is written directly into the CCSPA's requirements, which means the compliance burden doesn't stop at the edge of the regulated company. It flows downstream to every supplier they depend on, including you.

Second, this law is a signal about direction, not a one off event. It reflects where Canadian regulation is heading in general: more mandatory reporting, more accountability sitting with boards and executives, and a lot less tolerance for "we didn't know." Provincial privacy law is moving the same way. Quebec's Law 25 already carries its own breach notification duties and steep penalties for any organization handling the personal information of Quebec residents, no matter where that company is headquartered. Federal law under PIPEDA has required mandatory breach reporting to the Privacy Commissioner since 2018, for any breach that creates a real risk of significant harm to the people affected.

Third, cyber insurance underwriters and enterprise procurement teams are already tightening what they expect to see before they'll write a policy or sign a contract. Recent industry research found that 69 percent of Canadian organizations now rank data sovereignty as their top factor when choosing a security vendor, up sharply from a couple of years earlier, and more than half say they've reconsidered American security providers within the past year. Whether or not the CCSPA technically names your business, the market around you is already raising the bar on its own.

  • Why This Matters Right Now: Ransomware Isn't Slowing Down

None of this legislation exists in a vacuum. The Canadian Centre for Cyber Security's National Cyber Threat Assessment for 2025 to 2026 names ransomware as the top cybercrime threat facing the country's critical infrastructure, and it isn't a close call. Statistics Canada's most recent Survey of Cyber Security and Cybercrime found that among businesses reporting a cyber incident, roughly 13 percent pointed to ransomware as the method of attack, a figure that keeps climbing year over year.

What's changed is the playbook. A few years back, ransomware meant your files got encrypted and you either paid to get them back or restored from backup and moved on. That's not how it works anymore. Attackers steal the data first, encrypt second if they even bother, and then threaten to publish everything on a leak site whether you pay or not. Good backups still matter, but they no longer guarantee a clean recovery, because the extortion has shifted from "give us access back" to "don't let us publish this."

The scale is hard to ignore too. One global threat report counted well over seven thousand confirmed ransomware victims in its latest reporting window, an increase of nearly four times over the year before, with AI tooling cited as a major reason attacks are moving faster and reaching more targets. Identity attacks are a big part of the story as well. Recent research into ransomware incidents found that roughly two thirds of victims traced their breach back to a compromised identity, whether that was a stolen password, a hijacked session, or a social engineering trick like the one used against WestJet.

Industry estimates for 2025 put the average ransomware demand against Canadian small and mid sized businesses somewhere around forty six thousand dollars, though the real cost, once you factor in downtime, forensic investigation, legal fees, notification obligations, and reputational damage, runs far higher than that number suggests. Broader 2026 reporting puts the average total cost of a data breach for a Canadian organization close to seven million dollars, with financial services firms carrying the steepest bills of any sector.

Attackers aren't just moving faster, they're getting smarter too. The Cyber Centre's threat assessment flags artificial intelligence as one of the defining shifts in the current landscape, noting that generative AI is already being used to write far more convincing phishing emails and build believable fake identities. The skill that used to be required to run a good social engineering campaign is now available to almost anyone with an internet connection.

  • The Rest of the Compliance Picture Canadian Businesses Deal With

Bill C-8 is the newest addition, but it joins a landscape that was already fairly crowded for anyone doing serious business in Canada. Depending on your industry and the type of data you handle, you're likely already navigating some combination of the following.

PIPEDA governs how private sector organizations collect, use, and disclose personal information across most of the country, and it requires reporting material breaches to the Privacy Commissioner along with notifying the people affected.

Provincial privacy laws, most notably Quebec's Law 25, layer on additional obligations for any organization handling the personal information of Quebec residents, regardless of where the company itself operates from.

Sector specific frameworks come into play depending on what you do: PCI DSS if you process card payments, PHIPA or HIPAA aligned controls if you're in healthcare, and ITSG-33 if you work with the federal government or bid on government contracts.

Voluntary but increasingly expected certifications, like SOC 2 Type II and ISO 27001, are now requested by many enterprise clients and partners before they'll even sign a contract, especially in finance, SaaS, and professional services.

Trying to juggle all of these separately is exhausting, and honestly, it doesn't need to work that way. A recent Canadian industry study described what it called a "maturity paradox," where executive confidence and security spending keep rising while foundational disciplines like identity management, third party risk, and operational resilience don't always keep pace. The lesson in that finding is simple. Most of these frameworks overlap heavily on the fundamentals, things like access control, encryption, logging, and incident response. Build a security program around solid fundamentals, and mapping it to each specific framework becomes a documentation exercise rather than a rebuild from scratch every time a new requirement shows up.

  • What Canadian Businesses Should Actually Do Right Now

None of this needs to feel overwhelming, and you don't need an enterprise sized budget to make real progress. A handful of practical steps go a long way.

Start with a gap assessment. Before fixing anything, you need an honest picture of where your defenses stand against a recognized standard, whether that's the CCSPA's expectations, SOC 2, ISO 27001, or the Cyber Centre's baseline controls for small and medium organizations. Guessing isn't a strategy, and it's not something you want to explain to a regulator or a client after the fact.

Get a real penetration test, not just an automated vulnerability scan. Scanners are useful for catching low hanging fruit, but they consistently miss the business logic flaws and chained vulnerabilities that a skilled human attacker would actually exploit. A proper penetration test simulates that attacker, finds the gaps a scanner walks right past, and gives you documented evidence you can hand to an auditor, a regulator, or your board.

Turn on multi factor authentication everywhere it's available, and choose phishing resistant methods where you can. The WestJet incident is a reminder that MFA alone isn't bulletproof against a determined attacker using social engineering, but skipping it entirely remains one of the easiest ways to hand someone the keys to your systems.

Write an incident response plan, and actually rehearse it. A plan that has never been tested tends to fall apart the moment a real incident hits. Run a tabletop exercise with your leadership team at least once a year so people know their roles before it matters.

Take a hard look at your vendors and suppliers. Under the CCSPA, and honestly under plain common sense, your security is only as strong as the weakest link in your supply chain. Know exactly who has access to your systems and data, and hold them to the same standard you hold yourself.

Train your people regularly. Most incidents still start with a phishing email or a convincing phone call rather than a sophisticated technical exploit. Ongoing, realistic training consistently beats a once a year slideshow that nobody remembers by March.

  • Where Professional Testing and Compliance Support Fit In

This is exactly the kind of work PlutoSec handles for organizations across Canada every day. We run manual first penetration testing across web applications, networks, cloud environments, and Active Directory, the kind of testing that surfaces real, exploitable vulnerabilities instead of a long list of low priority scanner noise. Our engagements map directly to the frameworks that matter most to Canadian businesses, including SOC 2 Type II, ISO 27001, PCI DSS, and the ITSG-33 controls that federal and provincial contracts increasingly expect to see.

Whether you're a designated operator preparing for the CCSPA's phased rollout, a supplier trying to satisfy a bigger client's vendor risk questionnaire, or a growing business that simply wants to know where the real gaps are before an attacker finds them first, a proper security assessment gives you something a checklist alone never can. Proof.

  • Final Thoughts

Bill C-8 is a milestone, but it's really just one more sign of where Canadian cybersecurity regulation and Canadian corporate risk are both heading. Reporting obligations are expanding. Penalties are getting sharper. Ransomware crews aren't taking a break, and clients up and down the supply chain are asking harder questions than they were even a year ago.

The businesses that come out ahead won't be the ones scrambling once a regulator or a client forces their hand. They'll be the ones that treated security as an ongoing practice long before any deadline showed up on the calendar. If you're not sure where your organization stands today, that's exactly the kind of question a proper assessment answers, and it's a conversation worth having before the next headline in this space is about you instead of someone else.

Book a free security consultation with PlutoSec and get a clear, practical view of where your current defenses may be exposed.


Noor Fatima

Written by

Noor Fatima

Share

Frequently asked questions

Does Bill C-8 apply to small businesses in Canada?
Directly, only if your organization is designated as operating a vital service or vital system in banking, telecommunications, energy, transportation, nuclear, or clearing and settlement. Most small and mid sized businesses fall outside that direct scope. Indirectly, though, small businesses that supply designated operators, or that want to compete for contracts with them, should expect vendor security questionnaires to get more demanding as the law rolls out.
What's the difference between Bill C-8 and the earlier Bill C-26?
Bill C-26 proposed similar critical infrastructure protections back in 2022 but never passed before Parliament's session ended. Bill C-8 revives that framework, refines it, and successfully carried it through to Royal Assent on June 15, 2026.
What happens if a designated operator doesn't comply with the CCSPA?
Penalties can reach fifteen million dollars per day for organizations, along with compliance orders and audit requirements from the relevant federal regulator.
Do I still need to worry about privacy law if Bill C-8 doesn't apply to my business?
Yes. PIPEDA's breach reporting rules apply broadly to private sector organizations across Canada, and Quebec's Law 25 applies to any business handling the personal information of Quebec residents. Bill C-8 adds a new layer for critical infrastructure, it doesn't replace anything else.
How does penetration testing help with Bill C-8 or general compliance readiness?
A penetration test gives you documented, evidence-based proof of where your defences hold and where they don't, mapped against recognised frameworks. That's exactly the kind of evidence auditors, regulators, cyber insurers, and enterprise clients are increasingly asking to see.

Leave a Comment

Comments (0)

No comments yet. Be the first to comment!

Get Started

Ready to See What Your Current Security Is Missing?

Book a short consultation with PlutoSec and get a practical view of where your current security model may be exposed.

Book Your Free Security Consultation