0
min read

Bill C-8: What It Actually Means for Your Business (Even If You've Never Heard of It)

Published on
July 24, 2026
Tags
Compliance
Cybersecurity
Share this post

This is the third in a series featuring insights from Accurate Network Services on Canada's evolving cybersecurity landscape. In the most recent post, Booker Zaytsoff, Director of Professional Services, explored the rising bar for cybersecurity compliance in Canada and what leaders can do to stay ahead. Now, Tyler Brooks, Manager of Cybersecurity, turns the conversation from awareness to action — breaking down who's actually affected, what's coming, and how to get ahead of the impact Bill C-8 may have on your business.

If you haven't yet heard of Bill C-8, you're about to. Canada just passed its first comprehensive federal cybersecurity law, and while the headlines are all about banks, telecoms, and pipelines, the ripple effects are going to reach a lot further that that.

(To be clear, "C-8" isn't a droid from a galaxy far, far away, though we admit the naming commitee didn't exactly go out of their way to make it memorable.)

Here's the good news: understanding this now, before it becomes an urgent problem, puts you in a much better position than most of your competitors. Let's break down what it actually says, in plain language, no legal degree required.

So what is Bill C-8, exactly?

Bill C-8 received Royal Assent (the final step to becoming law) on June 15, 2026. It is Canada's first major piece of comprehensive cybersecurity legislation, and it has two key components:

  1. It amends the Telecommunications Act, giving the federal government new powers to protect Canada's telecommunications networks, including the ability to restrict or prohibit the use of specific vendors or equipment that are considered security risks.
  2. It enacts a new law called the Critical Cyber Systems Protection Act (CCSPA), which establishes cybersecurity requirements for designated organizations operating in federally regulated critical infrastructure sectors, including telecommunications, finance, energy, and transportation.

The second component is the one that will be most relevant to many organizations following these developments.

Who's actually "directly regulated"?

This is the part people get wrong most often, so let's be precise about it. The CCSPA applies to companies in exactly six sectors:

  • Telecommunications (phone and internet providers)
  • Banking (federally regulated banks)
  • Clearing and settlement systems (the behind-the-scenes infrastructure banks use to move money between each other)
  • Energy (specifically interprovincial or international pipelines and power lines)
  • Nuclear energy
  • Transportation (the federally regulated kind: rail, aviation, and shipping that crosses provincial or international lines)

If your business isn't in one of these six categories, you're not directly regulated. No exceptions for company size, either. A small federally regulated pipeline operator is just as "in scope" as a national bank.

So, if you're a law firm, an insurance brokerage, an engineering consultancy, a nonprofit, or honestly most businesses in Canada, you might be tempted to stop reading right here. Not your problem, right?

Not so fast. That's exactly the assumption that catches businesses off guard, because "not directly regulated" and "not affected" turn out to be two very different things.

What do the regulated companies actually do?

For the businesses that are directly covered, the requirements are real and they have teeth:

  • Build a documented cybersecurity program within 90 days of being designated, covering how they identify risk, protect their systems, detect problems, and respond when something goes wrong.
  • Manage risk from their vendors and suppliers. This is the part that matters most for everyone else, more on that in a second.
  • Report cybersecurity incidents to the government within a tight window (up to 72 hours), not just confirmed breaches, but anything that could interfere with their systems.
  • Comply with government security directives on short notice, sometimes without much warning.

The penalties are serious. Organizations can face fines up to $15 million per day. Here's the detail that tends to get people's attention, though: executives and board members can be personally fined up to $1 million per day, and in serious cases, face criminal charges (if they knew about a violation and didn't act on it). This isn't just a corporate cost of doing business anymore. It's personal, for the people making the decisions, which tends to have a wonderful effect on how quickly those decisions get made.

Okay, but why should I care if I'm not on that list?

"Not directly regulated" doesn't mean "not affected". Here's the mechanism, and it's simpler than it sounds:

Those regulated companies are legally required to manage risk from their vendors and suppliers. That means they have to start asking the businesses they work with harder questions about security, and those businesses might, in turn, ask harder questions of the businesses they work with.

Picture it like a line of dominoes. A bank (regulated) pushes new security requirements onto its insurance provider. That insurance provider now needs to tighten things up, so it pushes new requirements onto the law firm handling its claims. That law firm might be your client, or might be you. Nobody set out to knock over your particlular domino, but here you are, mid-wobble.

You can be two, three, even four steps removed from an actual regulated company and still feel the pressure, usually in one of these forms:

  • A vendor security questionnaire lands in your inbox out of nowhere, from a client you've worked with for years.
  • Your cyber insurance renewal suddenly asks more detailed questions about your security practices.
  • A new contract shows up with clauses requiring a "documented cybersecurity program" or specific incident reporting commitments.

None of this means you're breaking any law. It means the businesses around you are adjusting to a new legal reality, and that adjustment doesn't stop at the edge of the regulated sectors. It keeps rolling outwards.

Here's the part that's actually good news for you

Most businesses are going to treat this the way most businesses treat everything uncomfortable: they'll wait until a client actually sends them that questionnaire, then scramble.

That's a mistake, and it's an opportunity for you.

Think about it from the other direction for a second. If you're a company that's starting to feel pressure to tighten uo your vendor requirements (because your own bank, insurer, or big client is asking you to), who do you want to work with? The vendor that has their documentation ready, can answer your questions in a day, and clearly already takes this seriously? Or the vendor who needs three weeks and a panicked phone call to their IT provider before they can even answer your email?

Being ready isn't just about avoiding risk. It's a selling point. Increasingly, businesses are going to choose their partners and vendors based on who can move fast on security questions, not who has to catch up first. Ifyour current or future clients are shopping around for a partner who's already squared away on this, and you are that partner, you win the deal before your competitor even finishes reading the RFP.

Getting ahead of Bill C-8 isn't about fear. It's about being the business who doesn't blink when the questionnaire shows up, because you've already done the work.

What "getting ahead of it" actually looks like

This isn't about becoming a regulated entity's version of compliant, but it also isn't a checklist you knock out over a weekend. It takes an honest look at where your risk actually sits, and decisions about what to prioritize first, decisions that are easy to get wrong if you're not the one who does this for a living:

  • A written cybersecurity program that reflects how your business actually operates, not a generic template.
  • The right protections in place and configured correctly, not just switched on and forgotton.
  • A clear picture of the risk your own vendors and software bring into your business, and a plan for the ones that don't measure up.

Get this right and answering a vendor questionnaire or an insurance renewal question becomes a straightforward task instead of a fire drill. Get it wrong, or skip it entirely, and you're the one scrambling when the questionnaire lands, or worse, explaining to a client why you weren't ready.

The bottom line

Bill C-8 directly regulates six specific industries. If you're not in one of them, you're not legally required to do anything. The businesses around you, however, your clients, your insurers, your partners, are adjusting to a new standard, and that standard has a way of becoming the expectation for everyone eventually.

The businesses that prepare now won't just avoid the scramble later. They'll stand out to the clients and partners who are already looking for exactly that kind of readiness. Waiting to be reactive isn't a neutral choice; it's a competitive disadvantage waiting to happen, and it's the kind of gap that's much cheaper to close now than after a client has already asked the question.

Want to know where you actually stand? Join our August 20th briefing on Bill C-8, where we walk through exactly who's affected, what's coming next, and how to get ahead of it before a client or insurer asks first.

Claim your spot. Register for our free Microsoft Teams webinar here.

Prefer a more direct route? Reach out to your Account Manager for a straightforward conversation about where your business stands and what getting ahead of this would actually take. No pressure, no jargon, just a clear answer.