A practical, step-by-step checklist covering the four core obligations under Canada’s critical infrastructure cybersecurity legislation, including the AI layer most operators have missed.
By Krikor Tengerian · Co-founder, SecuritAI Technologies Ltd. · Updated June 21, 2026

The clock is running
Bill C-8 received Royal Assent on June 16, 2026. Once an operator is designated, it has 90 days to have a cybersecurity program in place. Penalties under the Critical Cyber Systems Protection Act reach $15 million per day for organizations, and directors can be held personally liable. Use this checklist to start now, before designation.
Bill C-8 compliance is not a one-time project, it is an ongoing program. The four core obligations (cybersecurity program, incident reporting, cybersecurity directions, supply chain protection) each require documented evidence, tested processes, and continuous monitoring. This checklist gives you the practical action items for each obligation, including the AI-specific controls that most operators have not yet addressed.
For context on what Bill C-8 is and which sectors it covers, see: What is Bill C-8? Canada’s critical infrastructure cybersecurity law explained. For how SecuritAI supports a Bill C-8 cybersecurity program, see Bill C-8 compliance.
A cybersecurity program under Bill C-8 must be documented, implemented, and kept current. It is not enough to have policies on paper, regulators expect evidence of operation.
Incident reporting under Bill C-8 is time-sensitive. You cannot build detection and escalation processes after an incident occurs. They must be ready and tested in advance.
The government can issue binding cybersecurity directions to designated operators, specific technical or operational requirements that must be implemented on short notice. Being ready to act quickly is a compliance requirement in itself.
Bill C-8 requires operators to assess and address cybersecurity risks originating in their supply chain. For organizations using cloud-hosted AI or third-party AI APIs, this directly includes your AI vendor relationships.
Every item above that references AI represents a gap in the vast majority of C-8 compliance programs being built right now. Traditional cybersecurity programs were designed before AI became operational in critical infrastructure, they cover networks, endpoints, and applications. They do not cover prompt injection attacks, adversarial model manipulation, AI output filtering, or AI audit logging.
Regulators are beginning to ask these questions explicitly. The organizations that answer them now, with documented evidence, will be in a far stronger position than those that address the AI layer after an incident or a direction.
Not sure where you stand? The free AI Security Readiness Check scores your AI setup in 60 seconds, no signup.
SecuritAI, AI red teaming (adversarial testing evidence) + AI firewall (runtime monitoring + audit logs). Covers the AI-specific items in Obligations 1 and 2 above.
SecuritComply, compliance automation platform for the full C-8 program: policy documentation, evidence management, risk register, and audit readiness across all four obligations.
Book a 15-minute briefing to map your current AI controls against Bill C-8 cybersecurity program requirements.
Designated operators must: (1) establish and implement a cybersecurity program, (2) report significant cyber incidents to the relevant regulator, (3) comply with government cybersecurity directions, and (4) assess and address cybersecurity risks in their supply chain. Each obligation requires documented evidence and tested processes.
Yes. Bill C-8’s cybersecurity program requirement covers all critical systems. If you operate AI systems that touch operations, process sensitive data, or provide public-facing services in a designated sector, those systems must be included in scope, with documented risk assessments, security testing evidence, and runtime controls.
The cybersecurity program must include documented security testing with evidence. For AI systems, that means adversarial testing (red teaming) covering prompt injection, jailbreaks, data exfiltration, and agent manipulation, the attack categories in the OWASP LLM Top 10. Testing should be scheduled, documented, and produce a findings report with remediation evidence.
If you use a third-party AI API or cloud-hosted AI model in critical operations, that vendor is part of your supply chain. You must assess their security posture, understand their data residency and incident notification practices, and document your risk acceptance or mitigation. For Canadian data sovereignty requirements, on-premises or Canadian-hosted AI deployment eliminates many supply chain risks.
Krikor Tengerian
Co-founder, SecuritAI Technologies Ltd.
Krikor Tengerian is the co-founder of SecuritAI Technologies and has over 25 years of experience in cybersecurity and IT infrastructure. He leads the company’s AI security platform and works with Canadian organizations and government bodies to secure their AI deployments against adversarial threats.