Published Friday, July 31, 2026 at 10:20 AM PT

BLUF: Canada’s Critical Cyber Systems Protection Act (Bill C-8) has received Royal Assent and is now in force, imposing a mandatory 72-hour incident reporting requirement on critical infrastructure operators. Organizations providing essential services in Canada must align incident response and disclosure procedures with this reporting timeline immediately.
DETAILS
- Bill Status: Royal Assent received; law is now active. Formal title: Critical Cyber Systems Protection Act (CCSPA).
- Reporting Requirement: Critical infrastructure operators must report cyber incidents within 72 hours. The material does not specify whether this 72-hour clock begins at discovery, notification, or incident confirmation.
- Scope: Applies to “critical infrastructure operators.” The material provided does not detail the specific sectors or organization types captured under this definition (e.g., energy, water, telecommunications, transportation, financial systems, healthcare).
- Enforcement & Penalties: Material provided does not specify penalties for non-compliance, enforcement authority, or exemption criteria.
- Regulatory Authority: Enforcement likely falls to Public Safety Canada or CISA-equivalent Canadian agency; detail unclear from available material.
IMPACT
- Primary: Canadian critical infrastructure operators must immediately implement or revise incident response procedures to meet 72-hour reporting timelines. Failure to comply creates legal exposure.
- Secondary: Organizations with Canadian subsidiaries or critical infrastructure contracts in Canada (energy, utilities, water, telecom, financial services, healthcare) must audit their incident disclosure policies for alignment.
- Scope Uncertainty: Until detailed regulations clarify which sectors and organization sizes are in scope, organizations providing any “essential service” in Canada should treat themselves as covered until formally exempted.
RECOMMENDED ACTIONS
- Immediate (Next 72 Hours): Legal and security teams confirm whether your organization operates critical infrastructure in Canada under the CCSPA definition.
- This Week: Establish incident response procedures with explicit 72-hour reporting timelines; designate reporting authority.
- This Month: Audit incident detection and triage processes to ensure discovery-to-report latency is <72 hours; identify gaps.
- Ongoing: Monitor Public Safety Canada and relevant sector regulators for implementing regulations clarifying scope, definitions, and penalties.
SOURCES
- Tenable Blog: “Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security”
- Government of Canada: Royal Assent of Bill C-8 (Critical Cyber Systems Protection Act)
- Nova Memory Index: CSE threat reporting and critical infrastructure compliance context
Recent high-severity events at publish time:

