Bill C-26
An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts. Introduced June 2022. The substantive component for most operators is Part 2: the Critical Cyber Systems Protection Act (CCSPA).
What C-26 does
The CCSPA establishes a framework under which the Governor in Council can designate sectors and operators as subject to cyber-security obligations. Once designated, operators must establish, implement, and maintain a cyber-security programme; mitigate supply-chain and third-party risks; report cyber-security incidents to the Communications Security Establishment (CSE); and comply with cyber-security directions issued under the Act.
Who is covered
The Act applies to operators in designated sectors. At introduction, six sectors were named: telecommunications, energy (pipelines, nuclear, interprovincial power), finance (banking, clearing and settlement), and transportation (federally-regulated). Additional sectors are expected to be designated by regulation.
Supply-chain risk
The CCSPA does not prescribe technical controls — it requires "reasonable steps." Emerging guidance treats third-party cloud providers as supply-chain risks subject to assessment. A US-controlled hyperscaler holding critical operational data is a supply-chain risk under this framing.
Sovereignty pressure
C-26 doesn't explicitly require sovereignty, but its incident-reporting and oversight mechanics assume operators can produce credible evidence of system state and access. Most cloud platforms produce evidence that depends on the platform itself — "trust our logs." That is awkward when the operator is reporting an incident about the platform. Architectures producing externally-verifiable evidence answer this structurally.
How SkyeConnex maps
Multi-cloud RAID inverts supply-chain risk by construction — no single provider holds enough of any file. The audit log is dual-signed for legal-evidentiary value. The DGSI 100-8 reference implementation positions SkyeConnex as a defensible answer to CCSPA designated-operator obligations. Read the full explainer →
Penalties and enforcement
The CCSPA establishes administrative monetary penalties of up to $15M per violation for organisations. Compliance is therefore a board-level matter, not an IT-only matter.
Related terms
See also
Posts that mention Bill C-26
Schrems II two years on: what actually changed for EU-US data transfers
The 2020 CJEU ruling invalidated Privacy Shield. Five years and one EU-US Data Privacy Framework later, the underlying problem remains. Here…
Read → Regulation · 8 min readWhat a CLOUD Act subpoena actually looks like in practice
Most board conversations about the CLOUD Act stay abstract. Here's a concrete walkthrough of how the mechanism works — and why architectural…
Read → Regulation · 8 min readThe CLOUD Act and why data residency isn't enough
The CLOUD Act extends US legal reach to data held by US-controlled cloud providers anywhere in the world. Choosing a Frankfurt or Toronto re…
Read →