main logo icon

Published on

October 1, 2026

|

23 min read

Bill C-8 Is Law: What Canada's Critical Cyber Systems Protection Act Means for Security Testing (2026)

What Bill C-8 means for security testing at Canada's federally regulated critical infrastructure operators: what is in force on 1 October 2026, what the Critical Cyber Systems Protection Act will require, and where penetration testing fits.

Arafat Afzalzada

Arafat Afzalzada

Founder

AdvisoriesNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Bill C-8, An Act respecting cyber security, received royal assent on 15 June 2026 as Statutes of Canada 2026, chapter 9. Its Telecommunications Act amendments took effect that day, including section 15.2(2)(j), which lets the Minister of Industry order a telecom provider to have assessments conducted to identify any vulnerability in its networks. The Critical Cyber Systems Protection Act in Part 2 is enacted but not in force: it starts on a day or days fixed by order of the Governor in Council, and as of 1 October 2026 no such order, no draft or final regulation and no Schedule 2 designation of operators has been published. Once a section 7 order adding its class to Schedule 2 is published in the Canada Gazette, Part II, an operator must establish a cyber security program within 90 days of the day it became a member of the class, with steps to identify and manage risks, including supply chain and third-party risks, protect its critical cyber systems from being compromised, detect incidents and minimize their impact (section 9). It must review the program on each anniversary unless regulations set other dates (section 13), report incidents to the Communications Security Establishment within a prescribed period of no more than 72 hours (section 17), keep records in Canada (section 30) and follow cyber security directions (section 20), with penalties of up to C$15 million per violation for an organization (section 91). The Act never names penetration testing. Testing is how an operator shows the protection and detection steps actually work.

Bill C-8 received royal assent on 15 June 2026 and is now Statutes of Canada 2026, chapter 9, according to LEGISinfo. Only part of it binds anyone yet. The Telecommunications Act amendments in Part 1 took effect on royal assent. The Critical Cyber Systems Protection Act in Part 2 comes into force "on a day or days to be fixed by order of the Governor in Council", and as of 1 October 2026 no such order has been published, no regulation has appeared in draft or final form, and Schedule 2, which will list the classes of designated operators, is empty.

The gap is not a reason to wait. The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026, the current edition, judges that "state-sponsored cyber threat actors are very likely targeting critical infrastructure networks in Canada and allied countries to pre-position for possible future disruptive or destructive cyber operations," and that "ransomware is the top cybercrime threat facing Canada's critical infrastructure." The new Act turns protection, detection and incident reporting for the systems behind six vital services into legal duties, with penalties of up to C$15 million per violation for an organization. This guide sets out what is law today, what the Act will require once it is switched on, and where security testing fits, with every obligation tied to its section in the royal assent text.

Quick answer: does Bill C-8 require penetration testing?

No. The word "penetration" does not appear anywhere in chapter 9. What the Act requires is an outcome, not a method:

  • Telecom providers, today. Section 15.2(2)(j) of the Telecommunications Act, in force since 15 June 2026, lets the Minister of Industry, by order, "require that assessments be conducted to identify any vulnerability" in a provider's services, networks, facilities or security plan, and paragraph (k) lets the Minister require it to take steps to mitigate any vulnerability in them.

  • Designated operators, once the Act is in force. Section 9(1) of the Critical Cyber Systems Protection Act requires a cyber security program with steps to identify and manage cyber security risks, including supply chain and third-party risks, to "protect its critical cyber systems from being compromised", to detect incidents and to minimize their impact. Section 30 requires records of the steps taken, and section 17 requires incident reports to the Communications Security Establishment within a prescribed period of no more than 72 hours.

Neither part says how an operator proves its protections work. An independent penetration test of the systems the program calls critical, a red team or purple team exercise against the detection path, and a retest showing the fixes held are the most direct evidence an operator can keep. The regulations that will set out what a program must contain (section 135(1)(a)) have not been published, so whether they will name testing is not yet known.

Where Stingrai fits: Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

For an operator heading toward designation, that means human-led testing of the systems a Critical Cyber Systems Protection Act program will call critical: the external perimeter and remote access, internal lateral movement, Kerberos and delegation attack paths in Active Directory, AWS, Azure with Entra ID and Google Cloud from control plane to workload, and segmentation testing that shows whether the corporate network can reach the critical systems at all. Red teaming runs as assumed breach, black-box full chain or threat intelligence-led scenarios, and purple teaming runs real-world TTPs with your SOC to test the detection a 72-hour report depends on. Two named penetration testers staff each human-led engagement, reviewed by the team lead and an engagement partner, and the team has published 18 CVEs. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept. Retesting of remediated findings is included, and every human-led and hybrid report comes with an attestation letter and a verified badge: records an operator whose program includes testing can keep under section 30 as evidence of steps taken. Stingrai runs both one-time annual engagements and continuous programs, and its penetration testing supports OSFI B-13 programs at federally regulated financial institutions.

Status board of Bill C-8 on 1 October 2026, showing which parts are in force

What is in force on 1 October 2026

Chapter 9 has three parts, and they do not share a start date. Part 2 carries its own commencement clause. Under section 5(4) of the Interpretation Act, when an Act sets a different commencement for some provisions, "the remaining provisions of the Act are deemed to have come into force on the date of assent to the Act", so Parts 1 and 3 began on 15 June 2026.

Part of S.C. 2026, c. 9

What it does

Status on 1 October 2026

Primary source

Part 1, sections 1 to 10

Amends the Telecommunications Act: security policy objective, cabinet and ministerial orders, information demands, penalties

In force since 15 June 2026

Public Safety Canada release of 16 June 2026; Justice Laws consolidation of the Telecommunications Act, current to 21 September 2026 and last amended 15 June 2026

Part 2, section 11

Enacts the Critical Cyber Systems Protection Act

Enacted, not in force

Section 16 of chapter 9; Justice Laws consolidation of the Act, current to 21 September 2026, marks every provision "not in force"

Part 2, sections 12 to 15

Consequential amendments to the OSFI Act, the Nuclear Safety and Control Act and the Transportation Appeal Tribunal of Canada Act

Not in force

Section 16 of chapter 9; the OSFI Act consolidation lists sections 12 and 13 of chapter 9 as amendments not in force

Part 3, section 17

Five-year review of everything the Act enacted or amended

In force since 15 June 2026; review due by 15 June 2031

Interpretation Act section 5(4); section 17 of chapter 9

Coming-into-force order for Part 2

Switches on some or all of the new Act

None published

Orders in Council database, searched 1 October 2026; Canada Gazette, Part II, issues of 17 June to 23 September 2026

Regulations under section 135

Program content, incident reporting form and timing, records, penalty amounts

None published

Canada Gazette, Part I, issues of 20 June to 26 September 2026, and Part II as above

Schedule 2

Classes of designated operators and their regulators

Empty: column headings only

Royal assent text; Justice Laws consolidation

How we established this. We read the royal assent text in full and checked it against the LEGISinfo record, the Justice Laws consolidations of the Critical Cyber Systems Protection Act, the Telecommunications Act and the Office of the Superintendent of Financial Institutions Act, every issue of the Canada Gazette, Part II from 17 June to 23 September 2026, every issue of Part I from 20 June to 26 September 2026, and the federal Orders in Council database, searched on 1 October 2026 by chapter number, statute name, department and keyword. None shows a coming-into-force order, a Schedule 2 designation or a draft regulation under the Act. One limit: the database posts an order on the third working day after it is approved. On 1 October it showed orders up to P.C. 2026-0875 of 25 September, plus one released early, so P.C. 2026-0876 to 2026-0924 were not yet public. Check the Justice Laws page for the Act before relying on this table.

What comes next. Public Safety Canada's royal assent release says the Act "will be implemented gradually, with certain provisions coming into force through a phased approach." Public Safety Canada's committee notes on the predecessor Bill C-26 (page last modified 3 March 2025) said the government "will consult Canadians, including provinces and territories at all stages of the regulatory process, including prior to pre-publication in the Canada Gazette Part I through until the regulations are approved and published in the Canada Gazette Part II." The June 2026 release makes no consultation commitment of its own. Watch for three publications: a coming-into-force order, draft regulations in Part I, and an order under section 7 adding a class of operators to Schedule 2. The last one triggers section 9(1) for the operators in that class.

How Bill C-8 got here

This is the second attempt. Bill C-26, with the same title, was introduced on 14 June 2022 and was still awaiting House consideration of Senate amendments when the session ended on 6 January 2025. Bill C-8 was introduced on 18 June 2025, reported back by the House public safety committee with amendments on 11 March 2026, passed the House on 26 March 2026, passed the Senate without amendment on 4 June 2026, and received royal assent on 15 June 2026. Public Safety Canada's release is dated 16 June 2026, a day after royal assent, so 16 June is the release date, not the assent date.

Part 1 is already law for telecom providers

Part 1 adds a new objective to section 7 of the Telecommunications Act, "to promote the security of the Canadian telecommunications system", and gives the government two order-making powers.

  • Section 15.1 lets the Governor in Council prohibit a provider from using all products and services of a specified person, or direct it to remove that person's products, where that is necessary to secure the system against threats including "interference, manipulation, disruption or degradation."

  • Section 15.2(2) lets the Minister of Industry, on a similar test, order a provider to subject its networks, facilities and procurement plans to specified review processes (paragraph (h)), develop a security plan (i), have vulnerability assessments conducted (j), take steps to mitigate any vulnerability (k), implement specified standards (l) and use a backup system (n).

Paragraph (j) is the closest the statute comes to testing:

(j) require that assessments be conducted to identify any vulnerability in a telecommunications service provider's telecommunications services, telecommunications networks or telecommunications facilities or its security plan referred to in paragraph (i);

The teeth are real. Contravening an order or regulation is a violation carrying an administrative monetary penalty of up to C$10 million for an organization, or C$15 million for a subsequent contravention, and up to C$25,000 or C$50,000 for an individual (section 72.131), with each day a separate violation (section 72.132). Officers and directors who direct, authorize, assent to, acquiesce in or participate in a violation are liable for it (section 72.138), and contravention is also an offence (section 73(3.1)). The Minister can demand information needed to make an order or verify compliance (section 15.4).

No order under either section has been published in the Canada Gazette through its late September 2026 issues. That does not prove none exists: an order may prohibit disclosure of its own existence (sections 15.1(3) and 15.2(5)), and publication is required within 90 days of the order being made unless the order directs otherwise (sections 15.1(6) and 15.2(8)).

What it means in practice: a provider served with a paragraph (j) order has to produce assessments on the Minister's terms. One that already has independent testing of its edge devices, management networks, identity systems and customer-facing channels, with a record of what was fixed and retested, starts with evidence rather than a blank page. Our telecom penetration testing guide covers that attack surface in detail.

Who the Critical Cyber Systems Protection Act will cover

The Act applies to designated operators: persons, partnerships or unincorporated organizations that belong to a class of operators listed in Schedule 2 (section 2). A class can include only operators of a work, undertaking or business within the legislative authority of Parliament, and only in respect of a vital service or vital system in Schedule 1 (section 7). The Act binds the federal Crown too (section 3).

Schedule 1 lists six vital services and systems, and the Governor in Council can add, amend or delete items by order (section 6):

  1. Telecommunications services

  2. Interprovincial or international pipeline and power line systems

  3. Nuclear energy systems

  4. Transportation systems that are within the legislative authority of Parliament

  5. Banking systems

  6. Clearing and settlement systems

Each class in Schedule 2 will be paired with one of six regulators named in section 2: the Minister of Industry, the Minister of Transport, the Superintendent of Financial Institutions, the Bank of Canada, the Canadian Energy Regulator (Canada Energy Regulator) or the Canadian Nuclear Safety Commission. Until a class is listed with its regulator, which regulator oversees which operators is a matter of expectation, not law.

The obligations attach to critical cyber systems, defined as cyber systems that, "if its confidentiality, integrity or availability were compromised, could affect the continuity or security of a vital service or vital system" (section 2). That definition reaches past the control systems that deliver the service. An identity platform, a remote access gateway or a shared cloud tenant whose compromise could stop the service can meet it as well, so a program scoped to control systems alone will miss part of what the Act covers. An organization regulated only provincially is outside the Act unless a class is drawn to include a federal work or undertaking it operates.

What designated operators will have to do

Timeline of Critical Cyber Systems Protection Act obligations once a class of operators is designated

A cyber security program within 90 days (sections 9 to 14)

Section 9(1) applies once a section 7 order adding the operator's class is published in the Canada Gazette, Part II, and the 90 days run from the day the operator became a member of that class, which can be earlier than the publication date. Within that period the operator must establish a cyber security program for its critical cyber systems that includes steps, "in accordance with any regulations", to (section 9(1)):

  • (a) identify and manage any organizational cyber security risks, including risks associated with its supply chain and its use of third-party products and services;

  • (b) protect its critical cyber systems from being compromised;

  • (c) detect any cyber security incidents affecting, or having the potential to affect, its critical cyber systems;

  • (d) minimize the impact of cyber security incidents affecting critical cyber systems; and

  • (e) do anything that is prescribed by the regulations.

Immediately after establishing the program, the operator must notify its regulator in writing (section 9(2)), and within the same 90 days it must provide the program or make it available to the regulator (section 10). The regulator can extend the 90 days on written request, more than once (section 11). After that, the operator must implement the program by taking the steps it contains, and maintain it (section 12).

By default the program is reviewed every year. The review starts on each date set by regulation or, if none is set, on each anniversary of the program's establishment. It must be completed within 60 days unless regulations set other periods, with the program amended if needed, and the regulator told within 30 days, again unless regulations set other periods, whether anything changed (section 13). A material change in ownership or control, or in the supply chain or use of third-party products and services, must be notified within a prescribed period, followed within 90 days by notice of whether the program changed as a result (section 14).

Supply chain and third-party risk (sections 15 and 15.1)

As soon as a supply chain or third-party risk is identified under section 9(1)(a), the operator "must mitigate those risks" (section 15). The Communications Security Establishment may develop guidelines on mitigating these risks, "taking into consideration internationally recognized frameworks such as those developed by the International Organization for Standardization on cybersecurity in supplier relationships" (section 15.1).

Incident reporting within 72 hours at most (sections 17 to 19)

A designated operator "must, within a period prescribed by the regulations, not to exceed 72 hours, report a cyber security incident in respect of any of its critical cyber systems to the Communications Security Establishment" (section 17). Immediately after reporting, it must notify its regulator and give it a copy (section 18), and the Communications Security Establishment must give a regulator a copy of a report on request for compliance purposes (section 19). Public Safety Canada's 2022 backgrounder on the original bill described the destination as the Cyber Centre, which its 2026 release places "within the Communications Security Establishment."

Two details widen the duty. A cyber security incident is anything, "including an act, omission or circumstance", that "interferes or may interfere" with the continuity or security of the vital service or with the confidentiality, integrity or availability of the critical cyber system (section 2), so an attempt can qualify before anything breaks. And section 18.1 says nothing in sections 17 and 18 affects PIPEDA, so a breach of personal information at a designated operator can still require a separate privacy breach report.

Cyber security directions (sections 20 to 25)

The Governor in Council can direct an operator or a whole class to comply with specified measures, within a set period, to protect a critical cyber system (sections 20 and 21). Every operator subject to a direction must comply (section 20(4)). A direction is exempt from sections 3, 5 and 11 of the Statutory Instruments Act, the rules on examination, registration and publication in the Canada Gazette (section 22), and the operator may disclose that it received one, and what it says, only to the extent necessary to comply (sections 24 and 25).

Records kept in Canada (section 30)

Every designated operator must keep records of the steps taken to implement its program, every incident reported under section 17, the steps taken under section 15 to mitigate supply chain and third-party risks, the measures taken to implement any direction, and anything prescribed (section 30(1)). The records "must be kept in Canada", at a prescribed place or, if none is prescribed, at the operator's place of business, in the manner and for the period the regulator sets unless regulations say otherwise (section 30(2)). Entries in those records are, absent evidence to the contrary, proof of what they state against the operator that kept them (section 144). The Act does not require test records as such, but where an operator's program includes testing, its penetration test reports, remediation tickets and retest letters are evidence of steps taken, so it should keep its own copies in Canada rather than rely on a supplier's platform hosted elsewhere.

Enforcement and penalties

Each regulator gets a similar toolkit: requests for information (section 29), powers to enter a place and use any cyber system there to examine information (for the Superintendent of Financial Institutions, section 32), orders to conduct an internal audit and report the results (section 34 and its counterparts), and compliance orders (section 36 and its counterparts). The Act defines an internal audit as "an independent and objective assurance and advisory review" conducted under internationally recognized internal auditing guidance (section 2).

  • Administrative monetary penalties. Regulations designate which provisions can lead to a violation (section 90) and fix the amounts, which cannot exceed C$500,000 for an individual or C$15 million in any other case (section 91). Each day a violation continues is a separate violation (section 94), and directors and officers who direct, authorize, assent to, acquiesce in or participate in a violation are parties to it (section 93). Due diligence is a defence (section 92).

  • Offences. Failing to provide the program, review it, notify changes, report an incident, notify the regulator or keep records is a summary conviction offence (section 136). Failing to establish or implement the program, mitigate supply chain risks or comply with a direction is a more serious offence: on conviction on indictment, an individual faces a fine at the court's discretion, up to five years' imprisonment, or both, and a corporation a fine at the court's discretion (section 137). Directors and officers can be liable (section 138), and due diligence is a defence to most offences (section 141).

None of this can be applied yet. The Act is not in force, and administrative penalties also need regulations that designate violations and fix amounts.

Where penetration testing fits, and where it does not

The Act tells an operator what its program must achieve and what it must record. It does not say how the operator shows that a step works, and it does not require test records by name. The table maps each requirement to the testing evidence that answers it, which an operator can keep alongside its section 30 record of steps taken.

Requirement

What testing evidences

Evidence for the section 30 record of steps taken

Section 9(1)(a): identify and manage risks, including supply chain and third parties

Threat-led scoping of the critical cyber systems, and testing of supplier remote access, integrations and managed service connections

Scope rationale tied to the risk assessment; supplier connection findings

Section 9(1)(b): protect critical cyber systems from being compromised

External, internal, Active Directory, cloud and application penetration tests, plus segmentation testing between corporate networks and critical systems

Reports with proof of concept; remediation tickets; retest letters

Section 9(1)(c): detect incidents

Purple team and red team exercises that measure whether the SOC sees and escalates the activity

Exercise report with a detection gap log and timings

Section 9(1)(d): minimize impact

Assumed breach exercises that test containment and how far an intruder gets from a foothold

Attack path findings and the containment changes made

Section 12: implement and maintain

Retests after fixes, and testing on change, one-time or continuous

Retest evidence showing closure

Section 13: program review, on each anniversary by default

The period's test results as an input to the review

Review notes that cite the results

Sections 14 and 15: material changes and supply chain mitigation

Testing after a new supplier, an acquisition or a major platform change

Change-triggered test report and mitigation record

Sections 17 and 18: report within 72 hours at most

Exercises that rehearse detection, decision and filing

Tabletop exercise timeline and decision log

Three cautions keep that mapping honest.

Testing is evidence, not the program. A stack of reports does not establish a program, notify a regulator or complete a section 13 review. Sections 9 to 14 require all three, on deadlines.

The regulations may change the picture. Section 9(1) requires the steps to follow "any regulations", section 9(1)(e) lets regulations add steps, and section 135(1)(b) lets them set conditions and criteria for internal audits. Section 135(2) requires the government, to the extent possible, to keep its regulations consistent with existing regulatory and standards regimes, and section 135(3) lets regulations treat compliance with one of those regimes as compliance with the Act. Banks already work under one that names testing: section 3.1.2 of OSFI's Guideline B-13 asks federally regulated financial institutions to "regularly perform tests and exercises, to identify vulnerabilities or control gaps in its cyber security programs (e.g., penetration testing and red teaming) using an intelligence-led approach."

Testing critical systems has to be safe. A test that disrupts a critical cyber system could itself meet the Act's definition of a cyber security incident, which turns on anything that "interferes or may interfere" with availability. Rules of engagement need named excluded systems, stop conditions, agreed windows and a test environment for anything fragile. Our red team rules of engagement checklist sets out what to demand before signing, and the purple team scoping guide covers the detection evidence relevant to section 9(1)(c).

What to test, sector by sector

Banking systems

Banks already answer to OSFI Guideline B-13, dated 31 July 2022, which names "penetration testing and red teaming" in section 3.1.2 and leaves the frequency to the institution. The Act names the Superintendent of Financial Institutions as one of its six regulators, and section 135(2) asks for consistency, to the extent possible, with existing regimes, which could include B-13. Scope should follow critical business functions: online and mobile banking, payment initiation and partner APIs, privileged access to core banking, Microsoft 365 and Entra ID, Active Directory, and the fintech and service provider connections that section 9(1)(a) calls third-party risk. Our OSFI B-13 guide, the I-CRT explainer and the banking penetration testing ranking go deeper.

Clearing and settlement systems

The Bank of Canada is a named regulator with its own entry, audit and compliance-order powers (sections 49 to 57). Testing priorities: participant connectivity and messaging gateways, operator workstations and privileged access paths, the reach of the corporate network into settlement infrastructure, and vendor support access. Much of this estate cannot be exercised in production, so test environments that mirror production carry more of the work.

Telecommunications services

Telecom providers face both regimes: Part 1 orders today, and the Act once a telecom class is designated. Priorities: edge and perimeter network devices, management and lawful intercept networks, OSS and BSS platforms, customer portals and the support channels where SIM swap fraud happens, and Active Directory and cloud identity. The telecom guide maps the surface.

Interprovincial or international pipeline and power line systems

Federally regulated pipeline companies must design, construct, operate and abandon their pipelines in accordance with the applicable provisions of CSA Z246.1, Security Management for Petroleum and Natural Gas Industry Systems, under section 4(1)(e) of the Canadian Energy Regulator Onshore Pipeline Regulations, and section 47.1 requires a security management program. Where a province has adopted NERC's reliability standards, entities with high or medium impact BES Cyber Systems already work to CIP-010-4, whose Table R3 requires a paper or active vulnerability assessment at least once every 15 calendar months. Active testing belongs on the corporate side and at the boundary into control networks, with passive, architecture-first assessment inside them. The energy and utilities guide covers both regimes.

Nuclear energy systems

The Canadian Nuclear Safety Commission is a named regulator, and once Part 2 is in force, chapter 9 lets the Commission charge prescribed fees for information, products or services it provides under other Acts (section 14 of chapter 9). Testing priorities are the corporate network, remote and vendor access, and the boundary into plant networks, with plant systems assessed through architecture and configuration review rather than live exploitation.

Transportation systems within federal jurisdiction

The Minister of Transport is a named regulator, and once Part 2 is in force, reviews and appeals of the Minister's penalties under the Act will go to the Transportation Appeal Tribunal of Canada (section 15 of chapter 9). Which transport operators will be designated is not yet known. Typical critical cyber systems include reservation and booking platforms, crew and dispatch systems, operations networks, and the logistics integrations and partner APIs that tie them together. The logistics and transportation guide covers testing for carriers, shippers and logistics operators, including the US rail and maritime rules that cross-border operators also face.

How to prepare before your class is designated

  1. Confirm whether you could be designated. Check whether you operate a federal work, undertaking or business that delivers one of the six Schedule 1 services, and watch the Orders in Council database and the Canada Gazette, Part II for the section 7 order that names your class.

  2. Name your critical cyber systems. Apply the section 2 test to every system whose compromise could affect the continuity or security of the service, including identity, remote access, cloud tenants and the managed services that touch them.

  3. Draft the program around section 9(1) now. Write down how you identify and manage risk, protect, detect and minimize impact, so the 90-day window is spent finishing a program rather than starting one.

  4. Test what you will call critical. Run external, internal, Active Directory, cloud and application penetration tests against those systems, with segmentation testing at the boundary into operational networks.

  5. Test detection, not only prevention. Use a purple team or red team exercise to measure whether your SOC sees and escalates real attacker activity, because a 72-hour report depends on noticing the incident first.

  6. Fix, retest and file the evidence in Canada. Close findings, retest them, and keep reports, tickets and retest letters in Canada alongside the records section 30(2) requires you to keep there.

  7. Map suppliers and third-party access. List the vendors and service providers connected to critical systems, test those connections, and record the mitigations section 15 will require.

  8. Rehearse the 72-hour report. Decide who declares an incident, who files with the Communications Security Establishment and who notifies the regulator, and time a tabletop exercise against the deadline.

  9. Watch for the regulations. Comment when draft regulations appear in the Canada Gazette, Part I, and set your testing cadence to feed the section 13 review, which falls on each anniversary unless regulations set other dates.

What testing a critical infrastructure scope costs

Stingrai publishes two fixed packages for web applications on its pricing page. The Autonomous Pentest, run by Snipe, Stingrai's autonomous AI penetration testing agent for web applications and their APIs, is at US$3,000 per assessment or US$650 per month on a 12-month plan. The Hybrid Pentest, where Snipe and penetration testers test together throughout, is at US$6,800 per assessment or US$1,275 per month on a 12-month continuous plan. Each covers exactly one web application and its APIs, and the "No High or Critical Finding = Don't Pay" guarantee applies to the Autonomous Pentest only.

A critical infrastructure scope is rarely one web application. Networks, Active Directory, cloud, segmentation, red and purple teaming and social engineering are quoted to the systems in scope through get a quote, as one-time annual engagements or continuous programs. The Canadian penetration testing cost guide explains what moves a quote.

Frequently Asked Questions

Is Bill C-8 law in Canada?

Yes. Bill C-8, An Act respecting cyber security, received royal assent on 15 June 2026 as Statutes of Canada 2026, chapter 9. Its Telecommunications Act amendments took effect that day. The Critical Cyber Systems Protection Act it enacts is not in force: it comes into force on a day or days fixed by order of the Governor in Council, and none had been published as of 1 October 2026.

Does Bill C-8 require penetration testing?

No. The word does not appear in the Act. Section 15.2(2)(j) of the Telecommunications Act lets the Minister of Industry order a telecom provider to have assessments conducted to identify vulnerabilities, and the Critical Cyber Systems Protection Act will require designated operators to protect critical cyber systems from being compromised, detect incidents and keep records of the steps taken. A penetration test with a retest is the most direct evidence that those steps work.

When does the Critical Cyber Systems Protection Act come into force?

On a day or days fixed by order of the Governor in Council under section 16 of chapter 9. As of 1 October 2026 no order appears in the Orders in Council database or the Canada Gazette, and the Justice Laws consolidation current to 21 September 2026 marks every provision not in force. Public Safety Canada says the Act will be implemented gradually through a phased approach.

Who will be a designated operator under the Critical Cyber Systems Protection Act?

An organization that belongs to a class of operators listed in Schedule 2. The Governor in Council adds classes by order, limited to operators of federal works, undertakings or businesses delivering a vital service or system in Schedule 1: telecommunications, interprovincial or international pipelines and power lines, nuclear energy, federally regulated transportation, banking, and clearing and settlement. Schedule 2 is empty, so no organization is designated yet.

How quickly must a cyber security incident be reported?

Within a period set by regulations that cannot exceed 72 hours, to the Communications Security Establishment, under section 17. Immediately after reporting, the operator must notify its regulator and give it a copy under section 18. The regulations that fix the exact period, the form and the types of incident to report have not been published.

What are the penalties under the Critical Cyber Systems Protection Act?

Administrative monetary penalties of up to C$500,000 for an individual and C$15 million in any other case per violation under section 91, with each day of a continuing violation a separate violation. Failing to establish or implement the program, mitigate supply chain risks or comply with a direction is an offence under section 137, punishable on indictment for an individual by up to five years' imprisonment, and directors and officers who take part can be liable.

What records must a designated operator keep?

Section 30 requires records of the steps taken to implement the program, every incident reported under section 17, the steps taken to mitigate supply chain and third-party risks, the measures taken to implement a cyber security direction, and anything prescribed. They must be kept in Canada, at a prescribed place or the operator's place of business, in the manner and for the period the regulator sets unless regulations say otherwise.

Does OSFI Guideline B-13 already cover what the Act asks of banks?

They overlap but are not the same. B-13 is an OSFI guideline, and section 3.1.2 asks federally regulated financial institutions to regularly perform tests and exercises such as penetration testing and red teaming. The Act is a statute with deadlines, incident reports to the Communications Security Establishment and penalties. Section 135(2) requires the government, to the extent possible, to keep its regulations consistent with existing regulatory and standards regimes, and section 135(3) lets regulations treat compliance with another regime as compliance with the Act.

Should we test before our class is designated?

Yes, if you expect to be designated. Once a section 7 order adding your class is published in the Canada Gazette, Part II, you must establish the program within 90 days of the day you became a member of the class, unless the regulator extends the deadline. Testing the systems you expect to call critical now gives the program real findings to manage, a remediation record and a baseline for the first review under section 13.


Ready to test the systems your program will call critical?

The Act will ask designated operators to protect their critical cyber systems, detect incidents, report them within 72 hours at most and keep records of the steps they take, in Canada. Stingrai is a CREST-accredited penetration testing service provider headquartered in Toronto whose testing supports OSFI B-13, SOC 2, ISO 27001 and PCI DSS programs, delivered as one-time annual engagements or continuous programs, with named penetration testers, retesting and an attestation letter. Book a free scoping call, get a quote for a network, Active Directory, cloud or red team scope, or see the published package prices on the pricing page.

0 views

0

X

Related reading

Cyber Attacks in Canada: Statistics for 2026
AdvisoriesNetwork Security

Cyber Attacks in Canada: Statistics for 2026

Canada cyber attack statistics for 2026: 3,216 Cyber Centre incidents, $704M in reported fraud losses, a record CA$7.11M breach cost, all from primary sources.

28 min read

Penetration Testing Requirements by Framework: The 2026 Matrix
AdvisoriesNetwork Security

Penetration Testing Requirements by Framework: The 2026 Matrix

Which compliance frameworks actually require penetration testing? PCI DSS, NYDFS and FedRAMP do. SOC 2, ISO 27001 and HIPAA do not. The 2026 matrix.

22 min read

Data Breach Statistics 2026: Cost, Frequency, Causes and Timelines
AdvisoriesNetwork Security

Data Breach Statistics 2026: Cost, Frequency, Causes and Timelines

Average data breach cost hit a record US$4.99M globally and US$11.5M in the US in 2026. Cost, cause, frequency and timeline stats from IBM, Verizon and the FBI.

19 min read

Contents

X