Fast-Track · Weeks, Not Months

Bill C-26 / CCSPA Readiness Canada

Cyber Security Readiness for Canadian Critical Infrastructure under Bill C-26 / CCSPA

Praxis-Q prepares Canadian critical-infrastructure operators - telecom, finance, energy, transport - for the Critical Cyber Systems Protection Act (CCSPA) under Bill C-26: cyber security program design, incident reporting workflows and supply-chain risk controls aligned to expected regulatory direction.

Canada's critical-infrastructure cybersecurity bill died on the order paper as C-26 when Parliament prorogued in January 2025, and was reintroduced as Bill C-8. As of early 2026 it remains under study by the House Standing Committee on Public Safety and National Security, but the substance is expected to survive: mandatory cybersecurity programmes, supply-chain risk assessments and incident reporting for designated operators in telecommunications, finance, energy and transport. Praxis-Q helps in-scope operators build the security programme and reporting process now, ahead of the bill's eventual passage.

At a Glance

ActCCSPA / C-26
Penaltyto $15M
ReportingMandatory
MarketCanada

Bill C-26 Canada

Bill C-26 / CCSPA Readiness Canada

Cyber Security Readiness for Canadian Critical Infrastructure under Bill C-26 / CCSPA

The Problem

Canada Bill C-26 (CCSPA) will compel critical-infrastructure operators to harden systems and report incidents on strict timelines, with penalties up to $15M. Most designated operators are not yet ready.

What We Do

  • Scoping
  • Program Design
  • Controls
  • Incident Reporting
  • Assurance

What You Get

  • Designation and scope assessment
  • Cyber Security Program (CSP) design
  • Mandatory incident reporting workflows
  • Supply-chain and third-party risk controls
  • Maps to NIST CSF and ISO 27001
  • Sector-regulator alignment (OSFI, CRTC)
  • Tabletop exercises and IR readiness
  • Board and executive reporting

Frequently Asked Questions

Who does Bill C-26 apply to?
Operators of vital services and systems in federally regulated sectors - telecommunications, finance, energy and transportation - designated under the Critical Cyber Systems Protection Act.
What are the penalties under Bill C-26?
Significant administrative monetary penalties - up to $15M for organizations - plus potential personal liability and enforceable directions from the regulator.
Is Bill C-26 in force yet?
It is advancing through Parliament with regulations expected to follow. Designated operators should build readiness now, as compliance timelines are expected to be tight once in force.

Ready to Get Started?

Free gap analysis · Proposal in 24hrs · Delivery in weeks