Who needs to consider these requirements?
Begin with the railway's federal regulatory position and whether it is a host, passenger or small passenger company. Then assess any designation under the new critical cyber systems framework. A supplier supporting cross-border fleets should keep Canadian and US reporting and security requirements distinct, even where one technical platform supports both fleets.
Key regulations and frameworks
Passenger Rail Transportation Security Regulations
Existing regulations — requirements vary by company type
Transport Canada identifies requirements for host and passenger companies operating on federally regulated track, including a security coordinator, reporting and awareness training. Passenger companies other than small passenger companies also require risk assessments, security plans and exercises. These are broader rail security obligations; determine how cyber risks affecting the service fit into the company's assessment and response arrangements.
Official source: Passenger Rail Transportation Security Regulations
Critical Cyber Systems Protection Act
Enacted — phased implementation
Public Safety Canada confirms Royal Assent to Bill C-8 on 16 June 2026. It introduces the Critical Cyber Systems Protection Act, with a framework for designated operators in sectors including transportation. The government explicitly distinguishes immediate telecommunications amendments from gradual implementation of the critical cyber systems provisions. Check commencement, regulations and designation before assuming all duties apply to a particular railway.
Practical steps for rail teams
Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.
- Record the railway's regulatory category and identify the security coordinator. Connect the cyber incident process to the existing rail security reporting arrangements.
- Build an inventory of systems and suppliers that could interrupt the passenger or freight service, including maintenance platforms operated outside the railway's own network.
- Assign an owner to track critical cyber systems commencement and designation. Prepare evidence of risk decisions, recovery exercises and supplier controls so it can support the applicable requirements as they take effect.
Using this guide
This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.
