A law with no one bound by it yet
Bill C-8, the Critical Cyber Systems Protection Act, received Royal Assent on June 15, 2026, creating what the government calls the country's most significant federal cybersecurity framework — mandatory security programs, incident reporting, and enforcement powers for operators in telecommunications, finance, energy, and transportation (Parliament of Canada). Six weeks later, none of it applies to anyone. Schedule 2 — the list naming which companies count as "designated operators" — remains empty, and no coming-into-force date has been set for the CCSPA's substantive obligations. Only the bill's amendments to the Telecommunications Act took effect immediately.
That gap is not a technicality. It is the second time in three years Ottawa has passed sweeping platform or infrastructure legislation, declared victory, and then discovered that writing a statute is the easy part.
The case for the law
The underlying problem C-8 targets is real. Ransomware and state-linked intrusions against pipelines, grid operators, and telecom carriers have escalated globally, and Canada's critical infrastructure has historically had no statutory floor for cybersecurity hygiene or breach reporting. A framework that compels operators to report incidents and maintain security programs — rather than relying on voluntary disclosure — gives regulators visibility they currently lack. The Communications Security Establishment's expanded authority to direct telecom providers is defended on the same logic: in a live intrusion, the government needs the power to compel action quickly, not just to ask nicely. That is a legitimate governance objective, and other G7 states have moved in the same direction.
Where the bill oversteps
But the Office of the Privacy Commissioner, in a submission to the Senate committee reviewing the bill, flagged that the powers granted go further than the threat justifies. The OPC's own account is that the CCSPA lets the government direct telecom providers "to do anything or refrain from doing anything," a standard broad enough to sweep in subscriber information, metadata, and location data without the specificity that normally accompanies a surveillance power (OPC submission, May 22, 2026). The Commissioner asked, unsuccessfully, that "personal information" be added to the Act's definition of confidential information — a change that would have imposed sharing limits and higher thresholds for sending Canadians' data to foreign governments.
The second, more basic gap: there is no mechanism requiring the Communications Security Establishment to notify the OPC when an incident report reveals a systemic privacy risk. As the Commissioner put it, a single infrastructure vulnerability could generate dozens of discrete breach notifications under PIPEDA "without the OPC ever becoming aware of the underlying vulnerability" — meaning the regulator responsible for protecting Canadians' data has no guaranteed line of sight into the reports a sister agency is already collecting. The Canadian Civil Liberties Association raised parallel objections about secrecy and telecom order powers during committee review (as reported by The Deep Dive).
None of this required killing the bill. It required narrower drafting — a defined threshold for ministerial directives, a mandatory OPC notification loop, a sunset or review clause. Parliament passed the broader version anyway, betting that regulations to follow would fill in the restraint the statute itself doesn't provide.
Canada has run this experiment before
That bet looks worse in light of the Online News Act. Bill C-18 was designed to force Google and Meta to compensate Canadian publishers for linked news content — a "link tax" model. Google negotiated and now pays roughly $100 million a year under a CRTC-brokered exemption. Meta simply stopped carrying news links in Canada instead, a compliance path the statute itself left open. Three years later, that block is still in effect, and in December 2025 CRTC staff confirmed they have no plans to force the issue, saying only that they "will continue to monitor the situation" (Michael Geist). The law that was supposed to fund Canadian journalism instead permanently cut off one of its two largest distribution channels, and the regulator with enforcement authority chose not to use it.
The common thread isn't the subject matter — cybersecurity and news bargaining are unrelated policy problems. It's the pattern: pass an ambitious framework, leave the operative details to future regulatory action, and let the gap between Royal Assent and implementation absorb the accountability. With C-18, that gap let Meta exit the obligation entirely. With C-8, the equivalent risk is that CSE's directive powers and the information-sharing gaps the OPC flagged become operational defaults before Parliament revisits them, simply because no one is forced to.
The fix is procedural, not ideological
Ottawa doesn't need to choose between cybersecurity and privacy, or between platform accountability and press freedom — it needs to stop treating statutory passage as the finish line. Naming Schedule 2 operators, publishing a firm coming-into-force timetable, and implementing the OPC's breach-notification recommendation before the CCSPA takes effect would cost nothing and close the exact gap that let the Online News Act underperform its own goals. A cybersecurity law that sits half-implemented for months is not stronger for being ambitious; it is just unaccountable for longer.