Critical Cyber Systems Protection Act (S.C. 2026, c. 9, s. 11)
Full Document:
- HTMLFull Document: Critical Cyber Systems Protection Act (Accessibility Buttons available) |
- XMLFull Document: Critical Cyber Systems Protection Act [284 KB] |
- PDFFull Document: Critical Cyber Systems Protection Act [718 KB]
Act current to 2026-06-17
Critical Cyber Systems Protection Act
S.C. 2026, c. 9, s. 11
Assented to 2026-06-15
An Act respecting the protection of critical cyber systems in the federally regulated sector
Preamble
Whereas the Government of Canada has a fundamental responsibility to protect Canada’s national security and the safety of Canadians;
Whereas the Government of Canada acknowledges that because some cyber systems are critically important to vital services and vital systems their disruption could have serious consequences for national security or public safety;
Whereas the Government of Canada, through its national cyber security strategy, is committed to enhancing the security and resilience of the critical cyber systems of the federally regulated sector and to exercising leadership in cyber security to foster collaboration across Canada, with the provinces and territories and around the world;
Whereas the Government of Canada is committed to working with various stakeholders, including the federally regulated sector, to help protect those systems and to encourage information sharing among the stakeholders;
And whereas the Government of Canada acknowledges the necessity to protect the privacy of Canadians with respect to their personal information in accordance with the Privacy Act;
His Majesty, by and with the advice and consent of the Senate and House of Commons of Canada, enacts as follows:
Short Title
Marginal note:Short title
1 This Act may be cited as the Critical Cyber Systems Protection Act.
Definitions
Marginal note:Definitions
2 The following definitions apply in this Act.
- appropriate regulator
appropriate regulator means, in respect of a designated operator, the regulator set out in column 2 of Schedule 2 that corresponds to the class of operators to which the designated operator belongs. (organisme réglementaire compétent)
- Bank
Bank means the Bank of Canada established by subsection 3(1) of the Bank of Canada Act. (Banque)
- Canadian Energy Regulator
Canadian Energy Regulator means the Canadian Energy Regulator established by subsection 10(1) of the Canadian Energy Regulator Act. (Régie canadienne de l’énergie)
- Canadian Nuclear Safety Commission
Canadian Nuclear Safety Commission means the Commission established by subsection 8(1) of the Nuclear Safety and Control Act. (Commission canadienne de sûreté nucléaire).
- Chief Executive Officer
Chief Executive Officer has the same meaning as in section 2 of the Canadian Energy Regulator Act. (président-directeur général)
- Commission
Commission means the Commission referred to in subsection 26(1) of the Canadian Energy Regulator Act. (Commission)
- confidential information
confidential information means any information obtained under this Act in respect of a critical cyber system that
- The following provision is not in force.
(a) concerns a vulnerability of any designated operator’s critical cyber system or the methods used to protect that system and that is consistently treated as confidential by the designated operator;
- The following provision is not in force.
(b) if disclosed could reasonably be expected to result in material financial loss or gain to, or could reasonably be expected to prejudice the competitive position of, a designated operator; or
- The following provision is not in force.
(c) if disclosed could reasonably be expected to interfere with contractual or other negotiations of a designated operator. (renseignements confidentiels)
- critical cyber system
critical cyber system means a cyber system that, if its confidentiality, integrity or availability were compromised, could affect the continuity or security of a vital service or vital system. (cybersystème essentiel)
- cyber security incident
cyber security incident, in respect of a critical cyber system, means an incident, including an act, omission or circumstance, that interferes or may interfere with
- The following provision is not in force.
(a) the continuity or security of a vital service or vital system; or
- The following provision is not in force.
(b) the confidentiality, integrity or availability of the critical cyber system. (incident de cybersécurité)
- cyber system
cyber system means a system of interdependent digital services, technologies, assets or facilities that form the infrastructure for the reception, transmission, processing or storing of information. (cybersystème)
- designated operator
designated operator means a person, partnership or unincorporated organization that belongs to any class of operators referred to in Schedule 2. (exploitant désigné)
- Governor
Governor has the same meaning as in section 2 of the Bank of Canada Act. (gouverneur)
- internal audit
internal audit means an independent and objective assurance and advisory review conducted in accordance with any internationally recognized guidance on professional practices respecting internal auditing and specified in Treasury Board policies, such as the International Professional Practices Framework of the Institute of Internal Auditors. (vérification interne)
- Minister
Minister means the Minister of Public Safety and Emergency Preparedness or, if another federal minister is designated under section 4, that minister. (ministre)
- personal information
personal information has the same meaning as in section 3 of the Privacy Act. (renseignements personnels)
- regulator
regulator means
- The following provision is not in force.
(a) the Minister of Industry;
- The following provision is not in force.
(b) the Minister of Transport;
- The following provision is not in force.
(c) the Superintendent;
- The following provision is not in force.
(d) the Bank;
- The following provision is not in force.
(e) the Canadian Energy Regulator; or
- The following provision is not in force.
(f) the Canadian Nuclear Safety Commission. (organisme réglementaire)
- responsible minister
responsible minister means the minister responsible for an Act that is ordinarily administered by an appropriate regulator with respect to any class of operators set out in Schedule 2. (ministre compétent)
- Superintendent
Superintendent means the Superintendent of Financial Institutions appointed under subsection 5(1) of the Office of the Superintendent of Financial Institutions Act. (surintendant)
- Tribunal
Tribunal means the Transportation Appeal Tribunal of Canada that is established under subsection 2(1) of the Transportation Appeal Tribunal of Canada Act. (Tribunal)
- vital service
vital service means a service that is referred to in Schedule 1. (service critique)
- vital system
vital system means a system that is referred to in Schedule 1. (système critique)
Application
Marginal note:Binding on His Majesty
3 This Act is binding on His Majesty in right of Canada.
Marginal note:Designation of Minister
4 The Governor in Council may, by order, designate any federal minister to be the Minister referred to in this Act.
Purpose
Marginal note:Purpose
5 The purpose of this Act is to help to protect critical cyber systems in order to support the continuity and security of vital services and vital systems by ensuring that, among other things,
- The following provision is not in force.
(a) any cyber security risks in respect of critical cyber systems are identified and managed, including risks associated with supply chains and the use of third-party products and services;
- The following provision is not in force.
(b) critical cyber systems are protected from being compromised;
- The following provision is not in force.
(c) any cyber security incidents affecting, or having the potential to affect, critical cyber systems are detected; and
- The following provision is not in force.
(d) the impacts of cyber security incidents affecting critical cyber systems are minimized.
Vital Services and Vital Systems
Marginal note:Addition to Schedule 1
- The following provision is not in force.
6 (1) The Governor in Council may, by order, add to Schedule 1 a service that is delivered, or a system that is operated, as part of a work, undertaking or business that is within the legislative authority of Parliament, if the Governor in Council is satisfied that the service or system is vital to national security or public safety.
- The following provision is not in force.
Marginal note:Amendment to Schedule 1
(2) The Governor in Council may, by order, amend or delete any service or system set out in Schedule 1.
Designated Operators of Critical Cyber Systems
Marginal note:Class of operators and corresponding regulator
7 The Governor in Council may, by order, amend Schedule 2 by
- The following provision is not in force.
(a) adding
(i) a class of operators — consisting of persons, partnerships or unincorporated organizations that operate a work or carry on an undertaking or business that is within the legislative authority of Parliament — in respect of a vital service or vital system, and
(ii) the regulator for that class; or
- The following provision is not in force.
(b) amending or deleting a class of operators or the regulator for that class.
Marginal note:Critical cyber system — obligation of designated operator
8 A designated operator that owns, controls or operates a critical cyber system must comply with the requirements of this Act and the regulations with respect to that critical cyber system.
Cyber Security Program
Marginal note:Establishing cyber security program
- The following provision is not in force.
9 (1) After an order that is made under section 7 is published in the Canada Gazette, Part II, a designated operator that belongs to a class of operators set out in Schedule 2 must, within 90 days after the day on which the designated operator becomes a member of that class, establish a cyber security program in respect of its critical cyber systems and include in the program steps to, in accordance with any regulations,
- The following provision is not in force.
(a) identify and manage any organizational cyber security risks, including risks associated with the designated operator’s supply chain and its use of third-party products and services;
- The following provision is not in force.
(b) protect its critical cyber systems from being compromised;
- The following provision is not in force.
(c) detect any cyber security incidents affecting, or having the potential to affect, its critical cyber systems;
- The following provision is not in force.
(d) minimize the impact of cyber security incidents affecting critical cyber systems; and
- The following provision is not in force.
(e) do anything that is prescribed by the regulations.
- The following provision is not in force.
Marginal note:Notice
(2) Immediately after the program has been established, the designated operator must notify the appropriate regulator in writing that the program has been established.
Marginal note:Providing program to appropriate regulator
10 The designated operator must, within 90 days after the day on which the designated operator becomes a member of a class of operators that is set out in Schedule 2, provide the cyber security program or make it available to the appropriate regulator in the manner prescribed by the regulations or, if no manner is so prescribed, in the manner that the appropriate regulator considers appropriate.
Marginal note:Extension of 90-day period
11 The appropriate regulator may, at the designated operator’s written request, extend the 90-day period for complying with either subsection 9(1) or section 10, or both. The 90-day period may be extended more than once at the discretion of the appropriate regulator.
Marginal note:Implementation and maintenance of program
12 After a cyber security program is established, the designated operator must implement that program by taking the steps that are included in the program under section 9 and maintain the program.
Marginal note:Review of cyber security program — commencement
- The following provision is not in force.
13 (1) A designated operator must commence a review of its cyber security program on each date that is prescribed by the regulations or, if no dates are prescribed, on every anniversary of the day on which its cyber security program was established under section 9.
- The following provision is not in force.
Marginal note:Completion of review
(2) The designated operator must complete the review within 60 days after the day on which the review was commenced under subsection (1), unless another period is prescribed by the regulations, and amend the program as a result of the review if needed.
- The following provision is not in force.
Marginal note:Notification — changes to program
(3) The designated operator must, within 30 days after the day on which the review is completed, unless another period is prescribed by the regulations, notify the appropriate regulator of whether or not any changes were made to the program after the previous review.
Marginal note:Notification — other changes
- The following provision is not in force.
14 (1) A designated operator must, within a period prescribed by the regulations, notify the appropriate regulator of
- The following provision is not in force.
(a) any material change in the designated operator’s ownership or control;
- The following provision is not in force.
(b) any material change in the designated operator’s supply chain or in its use of third-party products and services; and
- The following provision is not in force.
(c) any circumstances that are prescribed by the regulations.
- The following provision is not in force.
Marginal note:Further notification — changes to program
(2) The designated operator must, within 90 days after the day on which a notification was provided under subsection (1), also notify the appropriate regulator whether or not any changes were made to the program as a result of any material changes or any circumstances described in paragraph (1)(a), (b) or (c) and, if changes were made, the nature of those changes.
- The following provision is not in force.
Marginal note:Extension of 90-day period
(3) The appropriate regulator may, at the designated operator’s written request, extend the 90-day period for complying with subsection (2). The 90-day period may be extended more than once at the discretion of the appropriate regulator.
Page Details
- Date modified: