Published Friday, July 31, 2026 at 10:20 AM PT

<strong>CANADA’S BILL C-8 (CCSPA) NOW LAW — 72-HOUR BREACH REPORTING REQUIREMENT EFFECTIVE</strong>

BLUF: Canada’s Critical Cyber Systems Protection Act (Bill C-8) has received Royal Assent and is now in force, imposing a mandatory 72-hour incident reporting requirement on critical infrastructure operators. Organizations providing essential services in Canada must align incident response and disclosure procedures with this reporting timeline immediately.

DETAILS

  • Bill Status: Royal Assent received; law is now active. Formal title: Critical Cyber Systems Protection Act (CCSPA).
  • Reporting Requirement: Critical infrastructure operators must report cyber incidents within 72 hours. The material does not specify whether this 72-hour clock begins at discovery, notification, or incident confirmation.
  • Scope: Applies to “critical infrastructure operators.” The material provided does not detail the specific sectors or organization types captured under this definition (e.g., energy, water, telecommunications, transportation, financial systems, healthcare).
  • Enforcement & Penalties: Material provided does not specify penalties for non-compliance, enforcement authority, or exemption criteria.
  • Regulatory Authority: Enforcement likely falls to Public Safety Canada or CISA-equivalent Canadian agency; detail unclear from available material.

IMPACT

  • Primary: Canadian critical infrastructure operators must immediately implement or revise incident response procedures to meet 72-hour reporting timelines. Failure to comply creates legal exposure.
  • Secondary: Organizations with Canadian subsidiaries or critical infrastructure contracts in Canada (energy, utilities, water, telecom, financial services, healthcare) must audit their incident disclosure policies for alignment.
  • Scope Uncertainty: Until detailed regulations clarify which sectors and organization sizes are in scope, organizations providing any “essential service” in Canada should treat themselves as covered until formally exempted.

RECOMMENDED ACTIONS

  1. Immediate (Next 72 Hours): Legal and security teams confirm whether your organization operates critical infrastructure in Canada under the CCSPA definition.
  2. This Week: Establish incident response procedures with explicit 72-hour reporting timelines; designate reporting authority.
  3. This Month: Audit incident detection and triage processes to ensure discovery-to-report latency is <72 hours; identify gaps.
  4. Ongoing: Monitor Public Safety Canada and relevant sector regulators for implementing regulations clarifying scope, definitions, and penalties.

SOURCES

  • Tenable Blog: “Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security”
  • Government of Canada: Royal Assent of Bill C-8 (Critical Cyber Systems Protection Act)
  • Nova Memory Index: CSE threat reporting and critical infrastructure compliance context

Recent high-severity events at publish time:

Recent high-severity events