Home / Insights / The 90-Day Clock

The 90-Day Clock Hasn't Started Yet — That's Exactly Why You Should Start Now

Every few weeks I get a version of the same question from a board member or a CISO at a Canadian bank, energy operator, or telecom: "Is the new federal cyber law actually going to pass, or is this another one that dies on the Order Paper?"

It's a fair question. The legislation now known as Bill C-8 has had a long and complicated life. It started as Bill C-26 back in 2022, got tangled in a numbering conflict with another bill, was rescued by Senate amendments, and then died entirely when Parliament was prorogued in January 2025. The Carney government re-tabled nearly identical provisions as C-8 in June 2025. The bill passed the House of Commons and received First Reading in the Senate on March 26, 2026. Second Reading and committee study are still ahead of it.

So no, it's not law yet. And I understand the temptation to wait until it is.

I want to make the case for the opposite.

What the bill actually does

Strip away the parliamentary history and Bill C-8 is two things bolted together. The first part amends the Telecommunications Act to let the government issue security directions to telecom providers — the part that lets Ottawa keep high-risk suppliers out of Canadian networks. The second part is the one that matters for most of the organizations I work with: the Critical Cyber Systems Protection Act, or CCSPA.

The CCSPA creates Canada's first federal, cross-sector, legally binding cybersecurity regime. It targets four sectors to start — finance, energy, transportation, and telecommunications — and gives the Governor in Council the power to add more over time. Health systems have already been flagged as a likely future addition.

If you're designated as an operator of a critical cyber system, the obligations are not vague:

  • Establish a cybersecurity program within 90 days of being designated, then maintain and review it annually.
  • Mitigate cyber risks arising from your supply chain and third-party products and services.
  • Report cybersecurity incidents — the proposed window is 72 hours from detection — to the Communications Security Establishment.
  • Notify your sector regulator of material changes to your program.
  • Keep records, and be prepared to share your program on request.

Non-compliance carries administrative monetary penalties that are separate from any other legal liability you might face. For individuals, the original framework even contemplated imprisonment.

There's one more provision worth flagging because it changes how you have to think about resilience: the government can issue confidential cybersecurity directions, and operators may be barred from disclosing that a direction was even issued. Privacy and civil-liberties groups have raised concerns about this, and those concerns are legitimate. But from an operational standpoint, the lesson is simpler — you may one day be ordered to act fast and quietly, and you'd better have the muscle to do it.

Why 90 days is shorter than it sounds

Here's the trap I watch organizations walk into. They read "90 days to establish a cybersecurity program" and they think: that's three months, we'll deal with it when the order comes.

I have run nearly 600 cases over 17 years, and I can tell you that 90 days is not enough time to build a credible program from a standing start. It is barely enough time to document one you've already built. The work that actually consumes the clock — inventorying your critical systems, mapping your third-party dependencies, standing up incident detection and reporting workflows, writing and testing response playbooks — takes far longer than three months when you're starting cold.

The 90-day clock isn't time to build. It's time to prove. And you can't prove something that doesn't exist yet.

The supply chain is where I'd start

If I were advising a designated operator today and could only push on one thing, it would be third-party risk.

The CCSPA explicitly puts supply chain risk at the centre of the regime. This is not an accident. The pattern I see across DFIR engagements is consistent: the breach rarely starts with the regulated institution itself. It starts with a vendor — a managed service provider, a cloud platform, a software supplier — with weaker controls and trusted access. A single soft third party can become a systemic threat to an entire operation.

For Canadian financial institutions, this should sound familiar, because OSFI has been here for two years already. Guideline B-13 on technology and cyber risk management came into effect at the start of 2024, and it works hand-in-hand with the updated Guideline B-10 on third-party risk. If you're a federally regulated financial institution and you've done the B-13 and B-10 work properly, you have a real head start on CCSPA. The frameworks rhyme.

If you haven't done that work — or if you're in energy, transport, or telecom and don't have an OSFI-style regulator pushing you — this is the gap to close first.

You don't need to wait for the regulations

A common and understandable objection: the bill doesn't prescribe a specific framework, and the detailed sector regulations won't be finalized until after Royal Assent. So how can anyone comply with rules that don't exist yet?

The answer is that the core obligations are already clear, and they map cleanly onto frameworks that already exist. NIST CSF 2.0 is the natural fit — its six functions, including the newer Govern function covering supply chain risk, oversight, and continuous improvement, line up well with what the CCSPA is asking for. The point isn't which framework you pick. The point is that you pick one and implement it consistently, so that when the regulations land you're refining a working program instead of inventing one.

The roadmap I'd put in front of any operator right now is unglamorous and effective:

  • Inventory every system that could affect a vital service if compromised. You cannot protect what you can't see.
  • Map your third parties and assess each one proportionate to the risk it carries.
  • Stand up incident detection and a 72-hour reporting workflow — and actually test that you can hit the window.
  • Run the self-assessment against NIST CSF 2.0, function by function, and close the obvious gaps.
  • Write and exercise your playbooks. A plan you've never rehearsed is a document, not a capability.

None of this requires the bill to pass. All of it makes you better tomorrow regardless of what Parliament does.

The real reason to move

I'll be honest about why I keep pushing clients on this, and it isn't the penalties.

The threat actors aren't waiting for Bill C-8 to receive Royal Assent. The ransomware crews, the access brokers, the state-aligned groups probing Canadian infrastructure — they are operating on their timeline, not Ottawa's. The legislation is Canada finally writing down a baseline that serious operators should already be meeting. Treating it as a compliance deadline to be met at the last possible moment misses the point entirely.

The organizations that come through the next few years well won't be the ones with the fewest incidents. Everyone has incidents. They'll be the ones who can detect fast, respond cleanly, recover seamlessly, and prove they did.

That's a capability you build over quarters, not in a 90-day scramble after a designation letter arrives.

The clock hasn't started. Start anyway.