Skip to content
FortaRisks
Back to blogCompliance

Canada accelerates: C-8, CPCSC, C-36, the end of voluntary cybersecurity

July 24, 2026 · 4 min read

On June 15, 2026, two things happened in Ottawa on the same day. Bill C-8 received royal assent, giving Canada its first law protecting critical cyber systems. And the government introduced Bill C-36, which will replace PIPEDA, the federal private-sector privacy law, with fines of up to 25 million dollars or 5% of global revenue.

Two months earlier, in April, the Canadian Program for Cyber Security Certification (CPCSC) officially launched, and its requirements have been appearing in defence contracts since the summer. For years, Canadian cybersecurity rested on voluntary frameworks and recommendations. That era is ending, and it is ending fast. Here is the map of what is changing, and what an executive should conclude from it.

Three regimes in three months

The acceleration is not an impression, it is a calendar.

  • Bill C-8, assented June 15. It enacts the Critical Cyber Systems Protection Act: a mandatory cybersecurity program, incident reporting to the Canadian Centre for Cyber Security, imposed supply chain risk management, penalties of up to 15 million dollars per violation with each day counting separately, and personal liability for directors. It initially targets four federal sectors (finance, telecommunications, energy, transportation), but its effects will propagate by contract to all their suppliers. We covered what it changes for critical infrastructure.
  • The CPCSC, live in procurement. Launched in April 2026, it makes access to defence contracts conditional on a cybersecurity certification built on ITSP.10.171, the Canadian equivalent of NIST SP 800-171. Without a Level 1 self-attestation, eligibility disappears, for prime contractors and subcontractors alike. Our Level 1 guide details its 13 requirements.
  • Bill C-36, introduced June 15. It proposes replacing PIPEDA with a modern regime, a new regulator and penalties at international standards: up to 25 million dollars or 5% of global revenue. It is not law yet, but its direction is clear, and Quebec has shown the way: Law 25, fully in force, already imposes comparable obligations on any organization handling Quebecers' personal information.

And the movement has older foundations: OSFI's Guideline B-13 has governed technology and cyber risk management at federally regulated financial institutions since 2024, and the 2025 National Cyber Security Strategy explicitly announced the shift to a more binding posture.

Why now

Three forces are converging. First, the threat, documented and attributed: July's joint advisory, co-signed by the Canadian Centre for Cyber Security, names Canadian critical sectors as targets of state actors. Second, alignment with allies: the CPCSC mirrors the American CMMC, the entry ticket to Pentagon contracts; C-8 follows the logic of Europe's NIS2 directive; B-13 echoes the DORA regulation. A Canadian supplier that wants to sell to Washington or Brussels will have to demonstrate these controls anyway; Ottawa is aligning its domestic market with that reality. Third, economics: incidents against infrastructure and supply chains now cost enough that voluntary incentives have proven insufficient.

For an executive, the conclusion is structural: cyber compliance is ceasing to be a specialist topic and becoming a condition of access to markets, financing and insurance.

The trap: treating each regime as a separate project

The instinctive reaction to this wave is to launch one project per regulation: a C-8 project, a CPCSC project, a Law 25 project, each with its consultant and its binder. That is a guarantee of paying three times for the same controls.

Because beneath the acronyms, the requirements overlap massively: asset inventory, access management and multi-factor authentication, incident detection, response and continuity planning, third-party risk management, documented governance with a named owner. What each regime adds are thresholds, reporting deadlines and specific evidence, not a different kind of security.

The rational approach inverts the logic: build a single foundation of controls, mapped once to each framework, with a measured gap per requirement. The same authentication control then serves the CPCSC self-attestation, the C-8 program and the Law 25 defence, and every new regulation becomes one more column in the matrix rather than one more project in the portfolio.

What a board should ask this quarter

  • Is our regulatory exposure mapped? Which regimes apply to us today, which will apply in 18 months, directly or by contractual cascade from our customers?
  • Do we have a foundation or silos? How many times are we paying to demonstrate the same control?
  • Could we report an incident on time? The windows are now counted in hours. A reporting process that has never been exercised does not exist.
  • Who carries the accountability? C-8 introduces personal liability for directors. The risk register must name owners, not committees.

The current window is an opportunity: C-8's regulations are not yet published, C-36 is still in Parliament, and the CPCSC is ramping up progressively. Organizations that build their foundation now will meet each deadline from a position of evidence; the others will discover the bill at the same time as the deadlines.

Where FortaRisks comes in

This is precisely the problem FortaRisks, a Canadian platform, solves: the Compliance module maps your controls once across more than 30 frameworks, including the CPCSC's ITSP.10.171, Law 25, NIS2 and DORA, and turns each regime into prioritized, documented gaps rather than a separate project. To establish your starting point for free, our CPCSC Level 1 and Law 25 readiness checks take about ten minutes each.

See your real risk in a 30-minute demo.

A member of our team walks you through FortaRisks on threats relevant to your sector. No chatbot.