
Bill C-8
Bill C-8 (formerly Bill C-26) enacts Canada's Critical Cyber Systems Protection Act, imposing mandatory cybersecurity obligations on telecoms, finance, energy and transport critical infrastructure and granting binding executive powers to prohibit high-risk supplier equipment; cleared the Senate in June 2026.
Last refreshed: 14 June 2026 · Appears in 1 active topic
What does Canada's Bill C-8 require critical infrastructure operators to do?
Timeline for Bill C-8
Cleared the Canadian Senate awaiting Royal Assent, mirroring the UK bill's passage
Cybersecurity: Threats and Defences: UK cyber bill drops payment regimeBackground
Bill C-8, formally the Critical Cyber Systems Protection Act, cleared Canada's Senate in June 2026 after a lengthy legislative journey that began under the earlier designation Bill c-26 in the 44th Parliament. The legislation imposes mandatory cybersecurity obligations on operators of critical infrastructure across four sectors: telecommunications, banking and financial services, energy, and transport. It also grants federal ministers binding powers to issue directions prohibiting the use of specific supplier products or services deemed a national security risk. Royal Assent follows Senate passage.
The bill's design reflects Five Eyes coordination: it passed in the same week as the UK Cyber Security and Resilience Bill's Commons third reading, establishing near-parallel critical infrastructure cyber obligations across two G7 members. Both frameworks concentrate on mandatory incident reporting, baseline security standards, and executive powers to exclude high-risk vendors, though the UK bill's scope extends to managed service providers and cloud services in ways the Canadian text does not directly mirror. The Canadian framework notably includes fines for non-compliance and a civil liability carve-out for operators who follow a ministerial direction in good faith.
For multinational operators, Bill C-8 creates a new regulatory layer alongside existing US CISA obligations and the EU's NIS 2 Directive. Compliance programmes will need to reconcile differing incident-reporting timelines and sector definitions across jurisdictions. The supply-chain security provisions (principally the power to exclude specific vendors) have been the most commercially sensitive element, drawing comparisons with US actions against Huawei equipment in telecommunications networks.