Bill C-26 brought two things into force: amendments to the Telecommunications Act, and a new statute called the Critical Cyber Systems Protection Act (CCSPA). For anyone who designs, installs, or advises on physical security in regulated sectors, the CCSPA is the part to understand. It sets baseline cyber obligations for the operators of Canada’s most important systems, and connected security equipment now sits inside that perimeter.
Who it applies to
The CCSPA targets federally regulated critical infrastructure. That covers telecommunications, banking, energy (interprovincial and international pipelines and power lines), and transportation (aviation, rail, marine). The government designates classes of operators and the vital systems they run. If a client falls into one of those classes, the obligations flow down to the systems they depend on, including the IP networks that carry video surveillance, access control, and building systems.
What operators have to do
Designated operators carry four core duties. They must establish and maintain a cyber security program. They must report cyber incidents to the Canadian Centre for Cyber Security within the required window. They must manage supply chain and third-party risk, which reaches the vendors and integrators they buy from. And they must comply with cyber security directions, which can require specific action on short notice.
Why it reaches physical security
Cameras, controllers, intercoms, and building automation now live on enterprise networks. A poorly segmented VMS or an access control server with weak credentials is a route into the wider environment, and that route is exactly what the CCSPA asks operators to close. For integrators and consultants, the practical effect is that hardening, patching, network segmentation, and vendor risk are no longer optional extras. They are part of what a compliant operator has to be able to show.
What to do about it
Treat connected security systems as part of the client’s critical cyber systems, not as an isolated island. Document how devices are segmented, how firmware is kept current, and how access is controlled. Keep supplier records that a client can point to during a review. Where a client is a designated operator, align incident handling with their reporting duties so a security-system compromise gets escalated the same way any other cyber incident would. The standards are new, but the practices are familiar to anyone who already treats the network side of a security install as seriously as the hardware.