Bill C-8 is a Canadian cybersecurity law that will require designated critical infrastructure operators to establish programs to identify and manage cyber risk, protect critical cyber systems, detect cybersecurity incidents, and minimize their impact. The law, which received Royal Assent on June 15, 2026, also introduces cybersecurity incident reporting requirements.
At the heart of Bill C-8 is the Critical Cyber Systems Protection Act (CCSPA), which creates a new cybersecurity framework for critical infrastructure in federally regulated sectors. The CCSPA defines a critical cyber system as a cyber system whose compromise could affect the continuity or security of a vital service or system.
The Act initially applies to critical infrastructure across telecommunications, finance, energy, and transportation, including telecommunications services, banking and clearing systems, interprovincial or international pipeline and power line systems, nuclear energy systems, and federally regulated transportation systems. More services and systems may be added in the future, and specific classes of operators will be designated through regulation.
The CCSPA will be implemented gradually, with certain provisions coming into force in phases and additional details defined through regulations. Still, the core security expectations are clear, and critical infrastructure operators should be preparing now to put in place stronger controls around access to critical systems, third-party connectivity, activity monitoring, and incident containment.
The CCSPA will require designated operators to establish and maintain cybersecurity programs for their critical cyber systems. These programs must address four core cybersecurity outcomes:
Identify and manage cybersecurity risks, including risks associated with supply chains and third-party products and services.
Protect critical cyber systems from compromise.
Detect cybersecurity incidents that affect or could affect critical cyber systems.
Minimize the impact of cybersecurity incidents.
These requirements create a full cybersecurity lifecycle that extends from risk management and prevention to detection and containment. For OT and critical infrastructure operators, the most important areas of focus include third-party vendor access, in-session visibility, and threat containment.
Third-party access is routine in many operational technology (OT) environments. Equipment manufacturers, maintenance providers, contractors, and other specialists regularly need to connect to critical systems for a variety of purposes, including troubleshooting, maintenance, and updates.
But while third-party access is necessary, it can introduce substantial risk if vendors are given broader network access than they need, privileged credentials are exposed, or organizations lack visibility into what happens after a connection is established.
The CCSPA places explicit emphasis on these risks. Once a cybersecurity risk associated with a designated operator’s supply chain or use of third-party products and services has been identified, the CCSPA will require the operator to mitigate that risk.
For OT security teams, this makes third-party connectivity more than an access-control issue. Organizations need to understand which external users can reach critical systems, limit that access to what is necessary, and maintain visibility throughout the connection.
The CCSPA also establishes cybersecurity incident reporting requirements.
Designated operators subject to the reporting provisions will be required to report cybersecurity incidents involving their critical cyber systems to the Communications Security Establishment (CSE). The specific reporting period will be prescribed by regulation, but under the CCSPA it cannot exceed 72 hours. After making the report, the operator must also immediately notify the appropriate regulator and provide it with a copy.
Meeting an incident reporting requirement, however, depends on being able to determine what happened.
For organizations managing complex OT environments, visibility into access and activity is therefore vital. Security teams need to know who accessed critical systems, when they connected, what occurred during the session, and whether risky activity took place. This helps them investigate incidents faster, determine scope, and gather the information needed for timely reporting.
The CCSPA goes beyond preventing and detecting incidents. It also requires cybersecurity programs to include measures for minimizing their impact.
This is particularly important in interconnected OT environments, where systems that were once isolated now communicate with IT networks, remote users, third-party systems, and other operational assets. These connections are essential to modern operations, but they can create new pathways for a threat to spread.
If an attacker compromises a user account, endpoint, vendor connection, or vulnerable asset, the initial compromise does not necessarily determine the ultimate severity of the incident. The ability to move laterally to additional systems can turn an isolated event into widespread operational disruption.
Restricting unnecessary communication between systems and limiting access to critical assets can help contain an incident before it spreads. By reducing the pathways available to an attacker, organizations can reduce the blast radius of a compromise and reduce its potential impact on critical operations.
For organizations preparing for the CCSPA, a useful starting point is to assess these issues across their critical systems: who and what can connect today, what visibility exists once those connections are established, and what controls are in place to prevent a compromise from moving beyond its initial point of entry.
The Cyolo Secure Connectivity Platform brings together secure remote privileged access and Zero Trust microsegmentation to help critical infrastructure organizations control connections to critical systems, monitor activity after access is granted, and contain threats before they disrupt operations. These capabilities support several of the cybersecurity objectives established by the CCSPA.
The CCSPA requires designated operators to protect critical cyber systems from compromise and address cybersecurity risks associated with supply chains and third-party products and services.
Cyolo PRO (Privileged Remote Operations) applies identity-based, least-privilege controls to remote access for employees, contractors, vendors, OEMs, and other third parties. Organizations can require multi-factor authentication (MFA), grant access only to authorized applications and assets, implement just-in-time access, and keep privileged credentials hidden from users.
Rather than placing remote users directly on the OT network, Cyolo PRO provides application-level access to the specific resources they are authorized to use. Granular policies can determine who is permitted to connect, which systems they can reach, when access is allowed, and what actions they can perform.
This enables organizations to provide the employee and third-party access necessary for operations while reducing unnecessary exposure and the risk that a compromised identity or vendor connection can expose the wider OT environment.
Because Cyolo PRO is agentless on target systems, these controls can also be extended to legacy OT assets that cannot natively support modern identity and authentication capabilities.
Controlling access is only part of the challenge. Organizations also need visibility into what happens after an authorized user connects — both to identify potentially risky activity and to support investigation and reporting when an incident occurs.
Cyolo PRO provides comprehensive logging, session recording, and real-time supervision of privileged remote activity. In addition, the AI-powered Session Intelligence capability turns session recordings into searchable, plain-language summaries, helping security and operations teams quickly understand what occurred without manually reviewing hours of footage.
Live Risk Detection extends this visibility into active sessions, analyzing remote session activity in real time and alerting teams within seconds when it identifies potentially malicious, unsafe, or unexpected behavior. This enables human operators to investigate and intervene while the session is still underway.
Together, these capabilities help organizations detect suspicious activity sooner and provide valuable information to support incident investigation and reporting.
The CCSPA requires designated operators not only to protect and detect but also to take measures that minimize the impact of cybersecurity incidents.
Cyolo CPS Segmentation applies Zero Trust microsegmentation to machine-to-machine communications across OT environments. It discovers assets and communication flows, helps teams create granular connectivity policies, and allows policies to be simulated against real traffic before enforcement.
By restricting systems to the communications they actually require, organizations can isolate critical assets, prevent unnecessary IT-to-OT connectivity, protect vulnerable legacy systems, and reduce opportunities for lateral movement.
If an attacker does gain an initial foothold, segmentation can help stop that compromise from spreading across the operational environment, reducing blast radius and protecting the continuity of critical operations.
Although Bill C-8 has received Royal Assent, the CCSPA is not yet in force. However, organizations that may ultimately be designated under the Act do not need to wait for every implementation detail to begin working toward compliance.
Assessing how users, third parties, applications, and systems connect to critical infrastructure — and what happens after those connections are established — can reveal gaps that matter both for future compliance and for operational resilience.
For organizations preparing for the CCSPA, the priorities are straightforward: control access to critical systems, maintain visibility into activity, and prevent a compromise from spreading. By securing both human-to-machine and machine-to-machine connections, Cyolo helps critical infrastructure organizations translate these priorities into practical controls that reduce third-party risk, improve visibility, limit the spread and impact of cyber threats, and better prepare for additional requirements that may be defined as the CCSPA is implemented.
Canada Bill C-8 is cybersecurity legislation that strengthens the protection of critical infrastructure and telecommunications systems in Canada. It received Royal Assent on June 15, 2026. Among other measures, Bill C-8 enacts the Critical Cyber Systems Protection Act (CCSPA), which establishes a cybersecurity framework for critical cyber systems in federally regulated sectors.
The CCSPA will apply to designated operators that own, control, or operate critical cyber systems supporting vital services and systems in federally regulated sectors. The legislation identifies vital services and systems in telecommunications, finance, energy, and transportation, with specific classes of operators designated through regulation.
The CCSPA will require designated operators to establish cybersecurity programs that identify and manage cybersecurity risks, protect critical cyber systems from compromise, detect cybersecurity incidents, and minimize their impact. The Act specifically addresses supply-chain and third-party cybersecurity risks and establishes incident reporting obligations.
No. Bill C-8 received Royal Assent on June 15, 2026, but the CCSPA’s operative provisions are not yet in force. The Government of Canada has said the Act will be implemented gradually through a phased approach, with additional details defined through regulation.
Organizations can prepare by assessing which critical systems and connections may fall within scope, strengthening access controls, addressing third-party and supply-chain risk, improving visibility into activity on critical systems, and implementing controls that can contain incidents and limit lateral movement.
Author
Jennifer Tullman-Botzer has over a decade of experience in cybersecurity marketing and is as tired as you are of hackers-in-hoodies stock images. She joined Cyolo in 2021 and currently serves as director of content marketing.