An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts
C-26 (44)
LEGISinfo Bills
summary <div>A legislative
summary is currently being prepared for this bill by the Parliamentary Information, Education and Research Services of the Library of Parliament. Meanwhile, the following executive
summary is available.<br/><br/>On June 2022, the Minister of Public Safety introduced Bill C-26,
An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts, and it was given first reading. <br/><br/>Part amends the Telecommunications Act to add the promotion of the security of the Canadian telecommunications system as an objective of the Canadian telecommunications policy and to authorize the Governor in Council and the Minister of Industry to direct telecommunications service providers to do anything, or refrain from doing anything, that is necessary to secure the Canadian telecommunications system.
It also establishes an administrative monetary penalty scheme to promote compliance with orders and regulations made by the Governor in Council and the Minister of Industry to secure the Canadian telecommunications system as well as rules for judicial review of those orders and regulations.<br/><br/>This Part also makes a consequential amendment to the Canada Evidence Act.<br/><br/>Part enacts the Critical Cyber Systems Protection Act to provide a framework for the protection of the critical cyber systems of services and systems that are vital to national security or public safety and that are delivered or operated as part of a work, undertaking or business that is within the legislative authority of Parliament.
It also, among other things,<br/><br/>(
a) authorizes the Governor in Council to designate any service or system as a vital service or vital system;<br/><br/>(
b) authorizes the Governor in Council to establish classes of operators in respect of a vital service or vital system;<br/><br/>(
c) requires designated operators to, among other things, establish and implement cyber security programs, mitigate supply-chain and third-party risks, report cyber security incidents and comply with cyber security directions;<br/><br/>(
d) provides for the exchange of information between relevant parties; and<br/><br/>(
e) authorizes the enforcement of the obligations under the Act and imposes consequences for non-compliance.<br/><br/>This Part also makes consequential amendments to certain Acts.</div> House of Commons — First reading: Completed (2022-06-14) House of Commons — Second reading: Completed (2023-03-27) House of Commons — Consideration in committee: Completed (2024-04-19) House of Commons — Report stage: Completed (2024-06-19) House of Commons — Third reading: Completed (2024-06-19) Senate — First reading: Completed (2024-06-19) Senate — Second reading: Completed (2024-10-23) Senate — Consideration in committee: Completed (2024-12-03) Senate — Report stage: Completed (2024-12-04) Senate — Third reading: Completed (2024-12-05) Full bill text is not included in the LEGISinfo JSON export.
Open the official Parliament of Canada bill page for the complete document.