Canada net neutrality

CRTC's Broadened Botnet-Blocking Authority Trades Away Oversight It Didn't Have to Give Up

Decision 2026-140 lets Canadian carriers block malicious traffic by any method, but loosens the reporting that would let anyone check their work.

Canada's Expanded Botnet-Blocking Framework People of Internet Research · Canada 5 business days Complaint resolution window Extended from 2 business days unde… 8 Carriers in the proceeding Bell, Rogers, Telus, Cogeco, Quebe… -30% Global botnet C&C servers, H1 2026 Observed command-and-control serve… peopleofinternet.com
Canada's Expanded Botnet-Blocking Fram… People of Internet Research · Canada 5 business days Complaint resolution window 8 Carriers in the proceeding -30% Global botnet C&C servers, H1 2026 peopleofinternet.com

Key Takeaways

What Changed

On 18 June 2026, the Canadian Radio-television and Telecommunications Commission issued Telecom Decision CRTC 2026-140, expanding the network-level cyber security blocking framework it had built one year earlier in Decision 2025-142. The 2025 decision let carriers block botnet and malware traffic before it reached a customer's device, but restricted them to two approved tools: third-party blocklists meeting minimum vetting criteria, or vetted in-house blocklists. The 2026 decision drops that restriction. Carriers may now use any blocking method — port blocking, forged-source-address filtering, traffic-anomaly detection — provided it satisfies the framework's three guiding principles: necessity (cyber security purposes only), accuracy (minimizing false positives), and consumer privacy (collected data used only for the blocking purpose it was gathered for, absent a court order).

The complaint-resolution window for disputed blocks was also loosened, from two business days under 2025-142 to five business days under the new decision. Eight carriers participated in the proceeding — Bell, Rogers, Telus, Cogeco, Quebecor, Eastlink, SaskTel, and TekSavvy — alongside the Independent Telecommunications Providers Association and the RCMP's National Cybercrime Coordination Centre.

Commissioner Bram Abramson dissented. His central objection: the framework governs a block-by-default system that is, in his words, invisible to the people subject to it, and the majority chose this moment — precisely when carrier discretion is expanding — to narrow the transparency obligations that would let outsiders check that discretion. "Competition cannot discipline what subscribers cannot assess," he wrote, and warned that annual aggregate reporting on IOC counts and complaint totals amounts to "bookkeeping, not management": a carrier could report high blocking volumes and low complaint counts while running misconfigured rules, and nothing in the framework would catch it.

The Case for Flexibility

The Commission's instinct here is defensible on its own terms. Section 36 of the Telecommunications Act presumptively bars carriers from controlling the content of traffic on their networks — a foundational net-neutrality protection — so any blocking regime needs specific CRTC authorization, and the 2022 predecessor decision, 2022-170, set out the necessity/accuracy/privacy/accountability/transparency principles that all three decisions build on. Locking carriers into blocklists specifically, as 2025-142 did for exactly one year, made the framework brittle: attackers rotate infrastructure faster than any blocklist can be vetted and republished, and a rule that only recognizes one detection method invites the exact kind of malicious traffic that method can't see. Technology-neutral standards — define the outcome, let the regulated party pick the tool — are generally the right instrument for fast-moving security problems, and the alternative (the CRTC pre-approving every anomaly-detection algorithm a carrier wants to deploy) would slow legitimate defense without meaningfully protecting anyone.

That is a genuine tradeoff, not regulatory capture. Botnets impose real costs — DDoS-for-hire, credential-stuffing, SMS phishing infrastructure — and a framework that can't adapt its detection methods as fast as attackers change their infrastructure protects no one.

Where the Dissent Is Right

But Abramson's complaint isn't about whether carriers should get more discretion — it's about what came bundled with it. The consultation that preceded 2026-140 asked whether additional safeguards should be layered onto the 2025-142 framework, not whether the existing ones should be cut back. Extending the complaint window from two days to five is a straightforward reduction in consumer protection dressed up as administrative simplification, adopted in the same decision that hands carriers a much wider menu of blocking techniques to make mistakes with. And Abramson notes the proceeding drew no privacy interveners and no public-interest advocate to stress-test the record — a one-sided hearing is a bad place to relax privacy purpose-limitation language, whatever the merits of the underlying change.

The fix here isn't to re-impose the blocklist-only restriction; it's to pair the newly method-neutral authority with the kind of disaggregated, per-method reporting Abramson proposed — traffic volumes and complaint outcomes broken out by blocking technique and vendor, not folded into a single annual aggregate. That is exactly the proportionate move: match the granularity of oversight to the granularity of discretion being granted, rather than letting one expand while the other contracts. A regulator that trusts carriers with more powerful tools should be trusting them because it can verify how those tools are used, not asking Canadians to take carrier self-reporting on faith. As Abramson put it, "'Trusted agent' is not a status carriers hold. It is a standard to which they must be held." The CRTC got the flexibility question right and the accountability question backwards — and unlike the blocking methods themselves, that second problem doesn't require new technology to fix, just a rule the Commission already knows how to write.

Sources & Citations

  1. CRTC Telecom Decision 2026-140
  2. CRTC Telecom Decision 2025-142
  3. M3AAWG: CRTC Moves Forward with Botnet Blocking Framework
  4. Spamhaus Botnet Threat Update, H1 2026