Country guide

Rail cyber security regulations in Canada

Canada combines existing rail transportation security requirements with a new critical cyber systems framework. Bill C-8 received Royal Assent in June 2026, so describing it simply as a proposal is out of date. However, the critical cyber systems provisions are being implemented in phases: enactment and an operator's active obligations are separate questions.

Official sources checked

Who needs to consider these requirements?

Begin with the railway's federal regulatory position and whether it is a host, passenger or small passenger company. Then assess any designation under the new critical cyber systems framework. A supplier supporting cross-border fleets should keep Canadian and US reporting and security requirements distinct, even where one technical platform supports both fleets.

Key regulations and frameworks

Passenger Rail Transportation Security Regulations

Existing regulations — requirements vary by company type

Transport Canada identifies requirements for host and passenger companies operating on federally regulated track, including a security coordinator, reporting and awareness training. Passenger companies other than small passenger companies also require risk assessments, security plans and exercises. These are broader rail security obligations; determine how cyber risks affecting the service fit into the company's assessment and response arrangements.

Official source: Passenger Rail Transportation Security Regulations

Critical Cyber Systems Protection Act

Enacted — phased implementation

Public Safety Canada confirms Royal Assent to Bill C-8 on 16 June 2026. It introduces the Critical Cyber Systems Protection Act, with a framework for designated operators in sectors including transportation. The government explicitly distinguishes immediate telecommunications amendments from gradual implementation of the critical cyber systems provisions. Check commencement, regulations and designation before assuming all duties apply to a particular railway.

Official source: Critical Cyber Systems Protection Act

Practical steps for rail teams

Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.

  1. Record the railway's regulatory category and identify the security coordinator. Connect the cyber incident process to the existing rail security reporting arrangements.
  2. Build an inventory of systems and suppliers that could interrupt the passenger or freight service, including maintenance platforms operated outside the railway's own network.
  3. Assign an owner to track critical cyber systems commencement and designation. Prepare evidence of risk decisions, recovery exercises and supplier controls so it can support the applicable requirements as they take effect.

Using this guide

This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.