Bill C-8, Canada's new cybersecurity legislation, received Royal Assent on June 15, 2026. While its headline obligations target large federally regulated operators in telecommunications, energy, banking, and transportation, the law's reach extends further than many small and medium-sized businesses realize. If your company supplies goods or services to a critical infrastructure operator, contractual cybersecurity requirements may already be heading your way.

This article explains how the Critical Cyber Systems Protection Act (CCSPA) affects SMB suppliers indirectly, what contract changes to expect, and what steps you can take now to prepare.

What Is Bill C-8?

Bill C-8 is the successor to Bill C-26, which passed both the House of Commons and the Senate in the previous Parliament but died on the Order Paper when Parliament was prorogued in January 2025. The government reintroduced the legislation in substantially similar form, and it completed its passage in 2026. House third reading occurred on March 26, 2026, with Senate third reading following on June 4, 2026.

Part 2 of Bill C-8 enacts the Critical Cyber Systems Protection Act. The CCSPA creates mandatory cybersecurity obligations for "designated operators" of "critical cyber systems" across six federally regulated sectors:

  • Telecommunications services
  • Interprovincial or international pipeline and power line systems
  • Nuclear energy systems
  • Transportation systems within federal jurisdiction
  • Banking systems
  • Clearing and settlement systems

The Act is now law, though its substantive obligations are not yet in force. The Governor in Council will set the coming-into-force date by order, with regulations expected within 12 to 24 months of Royal Assent.

Why SMB Suppliers Should Pay Attention

If you supply a telecom, bank, pipeline company, nuclear facility, or federally regulated transportation provider, this legislation will affect your business through your contracts, even if you are not directly regulated.

Section 15 of the CCSPA requires designated operators to mitigate supply-chain and third-party risks "as soon as they are identified." This obligation is broad and ongoing. It will drive operators to push cybersecurity requirements downstream to their vendors, including SMBs that provide IT services, software, consulting, logistics, maintenance, or professional services.

Operators face administrative monetary penalties of up to $15 million per violation, with each day a violation continues treated as a separate violation. Directors and officers who participate in a violation face personal liability. With exposure of that magnitude, expect your customers in regulated sectors to take vendor risk management seriously.

The Supply-Chain Risk Obligation

The CCSPA's supply-chain provisions go beyond general risk management. Section 9 requires designated operators to establish cybersecurity programs that address "supply-chain and third-party risks" as one of the mandatory program elements. Section 15 then imposes a standalone duty to mitigate such risks in accordance with any guidance issued by the Communications Security Establishment (CSE).

This structure means operators will need to:

  • Identify which suppliers have access to or could affect their critical cyber systems
  • Assess the cybersecurity posture of those suppliers
  • Impose contractual requirements on suppliers to reduce risk
  • Document mitigation steps and keep records in Canada

For SMB suppliers, this translates into new contractual obligations, questionnaires, audit rights, and potentially certification requirements. We covered how third-party risk affects SMBs in our article on vendor risk from an SMB perspective.

The 72-Hour Incident Notification Requirement

Section 17 of the CCSPA requires designated operators to report cyber security incidents affecting their critical cyber systems to the CSE within a period prescribed by regulation, capped at 72 hours. Immediately after reporting to the CSE, the operator must notify its sector regulator.

While this obligation applies directly to designated operators, it has implications for suppliers. If a cybersecurity incident at your company affects a customer's critical cyber system, your customer will need to report within that window. This means operators will likely require suppliers to:

  • Notify the operator immediately upon discovering a security incident
  • Provide incident details sufficient for the operator's own CSE report
  • Cooperate with incident investigation and response

Contracts may specify notification windows shorter than 72 hours to give operators time to assess the incident and prepare their own report.

Records Must Stay in Canada

Section 30 of the CCSPA requires designated operators to keep records "in Canada" documenting their cybersecurity program implementation, reported incidents, supply-chain mitigation steps, and measures taken to comply with cyber security directions.

This record-keeping obligation may flow through to suppliers. Operators may require that any data related to their critical cyber systems, or any documentation of your security controls and incident response, be stored in Canada. If you use cloud services hosted outside Canada, this could require changes to your data residency arrangements.

Practical Checklist for SMB Suppliers

If your business supplies federally regulated critical infrastructure operators, here are concrete steps to prepare:

1. Identify Your Regulated Customers

Review your customer list for telecommunications providers, banks and credit unions, pipeline companies, energy utilities, nuclear facilities, and federally regulated transportation companies (airlines, railways, interprovincial trucking). These are the customers most likely to pass CCSPA requirements through to you.

2. Review Existing Contracts

Check your current agreements for cybersecurity clauses, audit rights, incident notification requirements, and data residency provisions. Contracts signed before Bill C-8 may need amendments. New contracts will likely include CCSPA-specific language.

3. Document Your Security Controls

Build a record of your current cybersecurity practices. This includes your security policies, access controls, patching procedures, backup practices, and incident response plans. Our small business cybersecurity checklist covers the foundational controls most relevant to SMBs.

4. Establish an Incident Response Process

Create or update your incident response plan with specific provisions for notifying customers. Define who has authority to make notifications, what information to include, and how quickly you can realistically detect and report incidents.

5. Review Data Residency

Determine where your customer data is stored and processed. If you use cloud services, verify their data center locations. If any data related to a regulated customer's operations is stored outside Canada, plan for how you would address a Canadian residency requirement.

6. Prepare for Questionnaires and Audits

Expect regulated customers to send vendor security questionnaires. Be ready to provide documentation of your security controls, certifications, and incident history. Some customers may require audit rights or third-party assessments.

7. Train Your Team

Ensure staff understand the importance of security practices and incident reporting. A delay in internal escalation can cascade into a delay in customer notification, which can then affect the customer's ability to meet its own reporting obligations.

Penalties in Context

The CCSPA establishes significant penalties for designated operators: administrative monetary penalties of up to $15 million per violation for organizations, with each day of a continuing violation treated as a separate violation. Individuals face penalties of up to $500,000 per violation. Certain contraventions are also criminal offences, with imprisonment of up to five years on indictment.

These penalties apply directly to designated operators, not to their suppliers. However, the magnitude of the penalties explains why operators will scrutinize their supply chains. If a supplier's security failure contributes to a violation, the operator faces the penalty. Operators will therefore seek contractual protections, including indemnification clauses, to manage that risk.

For SMBs, the practical risk is contractual liability and relationship damage, not direct regulatory enforcement. That makes the stakes serious even without direct government oversight.

PIPEDA Still Applies

Bill C-8 expressly preserves the Personal Information Protection and Electronic Documents Act (PIPEDA). The CCSPA's incident reporting requirements run in parallel with, not in place of, PIPEDA's breach notification obligations. If a cybersecurity incident involves personal information and creates a real risk of significant harm, you still need to notify the Privacy Commissioner and affected individuals under PIPEDA.

For businesses subject to provincial privacy legislation, such as Quebec's Law 25, those requirements also remain in effect. We discussed the Canadian privacy landscape in our article on Canada's privacy regulations for small businesses.

Distinguishing Bill C-8 from Bill C-26

If you followed cybersecurity policy discussions before 2025, you may have heard of Bill C-26. That bill passed both chambers of Parliament but did not receive Royal Assent before Parliament was prorogued in January 2025. Bill C-8 is its successor. The two bills are substantially similar, with minor changes to ensure coordination with other legislation like the Countering Foreign Interference Act (Bill C-70).

If you prepared for Bill C-26, your preparations remain relevant. If you postponed action because Bill C-26 died, the time to act is now.

Assess Your Security Baseline

Whether or not you supply regulated customers, understanding your current cybersecurity posture is the first step toward improvement. Our free cybersecurity assessment for Canadian businesses evaluates your organization against the Canadian Centre for Cyber Security's Baseline Controls. It takes under 30 minutes, requires no technical expertise, and provides actionable recommendations.

For a quick check across 20 critical security areas, try our free quick security assessment on cyberunit.com.

What Comes Next

The CCSPA is enacted but not yet in force. Regulations will determine which specific entities are designated operators, the precise incident reporting timeline within the 72-hour cap, and detailed program requirements. The government has indicated a 12 to 24 month timeline for regulations.

For SMB suppliers, that window is an opportunity to prepare. When your regulated customers begin updating their vendor management programs, you can be ready with documented controls, clear incident response processes, and an understanding of what the law requires of them.

Proactive preparation is less disruptive than reactive scrambling. Start now.


This article is intended for general informational purposes only and does not constitute legal, compliance, or professional security advice. Details about Bill C-8 and the Critical Cyber Systems Protection Act are based on the enacted legislation and public sources as of the date of publication. Organizations should consult qualified legal and cybersecurity professionals before making operational decisions based on this article.