Critical Cyber Systems Protection Act (Bill C-26)
Canadian federal cybersecurity legislation for critical infrastructure
Overview
Bill C-26 introduced the Critical Cyber Systems Protection Act (CCSPA), Canada's framework for protecting critical infrastructure from cyber threats. It applies to federally regulated sectors including telecommunications, finance, energy, and transportation, and it requires designated operators to establish a cyber security program, report cyber incidents to the Canadian Centre for Cyber Security, manage supply chain and third-party risk, and follow cyber security directions. For security integrators and consultants serving critical infrastructure clients, C-26 raises the bar on how connected physical security systems are governed, monitored, and reported when an incident occurs.