← Back to glossary

What C-26 does

The CCSPA establishes a framework under which the Governor in Council can designate sectors and operators as subject to cyber-security obligations. Once designated, operators must establish, implement, and maintain a cyber-security programme; mitigate supply-chain and third-party risks; report cyber-security incidents to the Communications Security Establishment (CSE); and comply with cyber-security directions issued under the Act.

Who is covered

The Act applies to operators in designated sectors. At introduction, six sectors were named: telecommunications, energy (pipelines, nuclear, interprovincial power), finance (banking, clearing and settlement), and transportation (federally-regulated). Additional sectors are expected to be designated by regulation.

Supply-chain risk

The CCSPA does not prescribe technical controls — it requires "reasonable steps." Emerging guidance treats third-party cloud providers as supply-chain risks subject to assessment. A US-controlled hyperscaler holding critical operational data is a supply-chain risk under this framing.

Sovereignty pressure

C-26 doesn't explicitly require sovereignty, but its incident-reporting and oversight mechanics assume operators can produce credible evidence of system state and access. Most cloud platforms produce evidence that depends on the platform itself — "trust our logs." That is awkward when the operator is reporting an incident about the platform. Architectures producing externally-verifiable evidence answer this structurally.

How SkyeConnex maps

Multi-cloud RAID inverts supply-chain risk by construction — no single provider holds enough of any file. The audit log is dual-signed for legal-evidentiary value. The DGSI 100-8 reference implementation positions SkyeConnex as a defensible answer to CCSPA designated-operator obligations. Read the full explainer →

Penalties and enforcement

The CCSPA establishes administrative monetary penalties of up to $15M per violation for organisations. Compliance is therefore a board-level matter, not an IT-only matter.

Related terms

See also

Want to see this in production?