Can your organization keep pace with Bill C-8 and quantum readiness?

September 10, 2026

For many Canadian organizations, cyber security planning has moved from a technical priority to a board-level business issue. New legislative requirements, evolving threat activity, growing supply chain exposure, and the long-term risk of quantum-enabled decryption are all changing what it means to be cyber ready.

In early summer, Bill C-8 received Royal Assent. The legislation strengthens the federal government’s ability to protect the telecommunications system and introduces the Critical Cyber Systems Protection Act, a regulatory framework for designated operators in sectors such as finance, telecommunications, energy, and transportation.

While many of the details are still being finalized, organizations should expect greater scrutiny of how they identify, manage, and respond to cyber risks.

At the same time, quantum readiness is becoming harder to treat as a distant concern. While Bill C-8 doesn’t directly address quantum computing, these issues make it clear that organizations need to know where their most sensitive data lives, which systems and vendors they rely on, and what would happen if that information was exposed in the future.

Raising the bar for cyber readiness

Bill C-8 introduces a more formal framework for protecting critical cyber systems tied to vital services and systems. The Government of Canada has stated that the legislation is intended to strengthen Canada’s ability to protect essential services by supporting telecommunications security and bolstering cybersecurity across sectors.

For designated operators, the Critical Cyber Systems Protection Act is expected to require cyber security programs, mitigation of supply chain and third-party risks, cyber incident reporting, compliance with cybersecurity directions, and other obligations that will be shaped through regulation.

The potential ripple effect can reach suppliers and software providers that support organizations in regulated sectors. If a business provides technology, systems, or services to a designated operator, its own cyber security posture may become part of that operator’s risk equation.

This makes readiness a practical issue. The earlier organizations understand their cyber environment, vendor dependencies, governance gaps, and incident response capabilities, the better positioned they will be to respond when requirements become more defined.

Quantum readiness planning mindset

Quantum risk is often misunderstood because it can feel complicated, abstract, and like a distant concern. The current risk is tied to “Harvest Now, Decrypt Later” activity, where threat actors collect encrypted data today in anticipation that future quantum capabilities will allow them access to it later.

That changes the way organizations should think about sensitive information. The question is less “Will a quantum computer attack my organization tomorrow?” and more “What data do we hold today that will be sensitive in 10, 15, or 20 years?”

This could include intellectual property, financial records, infrastructure data, citizen or customer information, legal files, health-related information, or other data that would still create harm if exposed in the future. The concern is especially relevant for organizations with long retention periods, legacy systems, complex vendor relationships, or limited visibility into where sensitive data is stored and encrypted.

The benefit of readiness assessments

A readiness assessment gives organizations a practical starting point. It can help leaders understand where the current cyber program is strong, where gaps exist, and what actions should be prioritized based on risk, business impact, and regulatory exposure.

For Bill C-8, this may include addressing whether the organization is part of a designated sector or supply chain, mapping systems that may be critical to vital services, reviewing cyber security governance, and evaluating incident response and third-party risk processes.

For quantum readiness, an assessment may include identifying sensitive data with long confidentiality lifetimes, reviewing where vulnerable cryptography is used, assessing vendor readiness, and building a roadmap for crypto-agility.

A practical starting point for Canadian organizations is to build a cryptographic inventory, prioritize systems that protect long-lived sensitive data, add post-quantum readiness questions to vendor due diligence, and avoid procurement decisions that lock in non-agile cryptography. This aligns with guidance from CISA and the Canadian Centre for Cyber Security, which emphasize inventory, prioritization, vendor engagement, and crypto-agility as foundational steps in a quantum readiness roadmap.

Proactive versus reactive outcomes

Proactive organizations are not waiting for certainty – they are building the visibility, governance, and flexibility they’ll need to respond as requirements and technologies evolve.

Leaders in the space understand the risks and know where to begin and how to plan for success. They know where the sensitive information is stored, how it is protected, how long it must stay confidential, and which systems or vendors introduce risk. They are also reviewing whether legacy systems, operational technology, or hardware constraints could slow future migration.

Reactive organizations may struggle because they lack the basic information needed to make decisions quickly. If they don’t know which systems are critical, where vulnerabilities exist, or which suppliers they depend on, they may face higher costs, operational disruption, or compliance pressure when expectations become more urgent.

The goal isn’t to solve every challenge today, but rather to build a clear, defensible understanding of current risk and build a practical plan for what comes next.

Readiness starts with inventory

Whether an organization is preparing for Bill C-8, quantum risk, or broader cyber resilience, the first step is visibility.

Organizations should better understand what needs protecting. To do this, there are three ways to build momentum:

  1. Identify critical data and systems
    Determine which information and systems are most important to operations, compliance, reputation, public safety, customer trust, and long-term competitiveness. Consider what would create the greatest harm if it were unavailable, unaltered, exposed, or decrypted in the future.
  1. Review cryptography and vendor dependencies
    Take stock of where encryption, cipher suites, certificates, and cryptographic protocols are used across the environment. Ask key suppliers how they are preparing and whether their products or services can support future migration.
  1. Strengthen governance and planning
    Bring cyber risk into leadership conversations, assign accountability, document decisions, and begin planning for budget, resources, incident response, vendor management, and future compliance obligations.

Common FAQs

Does Bill C-8 apply to my organization?

It depends on whether your organization is designated under the Critical Cyber Systems Protection Act or supports organizations that operate vital services or systems. Even if your organization isn’t directly designated, customers, regulators, insurers, or supply chain partners may still expect stronger evidence of your cyber readiness.

Is quantum risk that urgent if quantum computers can’t break encryption yet?

The risk isn’t about what quantum computers can do today but about data being collected now for potential decryption in the future. Organizations that hold sensitive long-lived data should start planning before migration becomes urgent.

What’s the first step?

Start with inventory. Identify critical systems, sensitive data, encryption use, key vendors, and legacy technology. This creates the foundation for both regulatory and quantum readiness.

Do we need to replace our encryption now?

Not necessarily. A more practical first step is to understand where cryptography is used, which systems depend on vulnerable algorithms, and whether your vendors are preparing for post-quantum standards.

The bottom line

Bill C-8 and quantum risk may seem like separate conversations, but they both point to the same need: organizations must get better at understanding what they have, what matters most, who they rely on, and how prepared they are to adapt.

Cyber readiness has shifted from responding to incidents to building the governance, visibility, and resilience needed to protect systems, data, and services as risks continue to evolve.

Organizations that start now will be better positioned to manage regulatory change, supply chain expectations, and long-term cryptographic risk. Those that wait may find themselves try to answer difficult questions under pressure.

Our team of experienced advisors can support organizations in assessing readiness, identifying priority risks, evaluating vendor and cryptographic exposure, and building a practical roadmap for strengthening cyber resilience.

We can support organizations through:

  • Bill C-8 readiness assessments
  • Critical systems and data inventory
  • Cybersecurity program and governance reviews
  • Incident response and reporting readiness
  • Third-party and supply chain risk assessments
  • Quantum readiness planning
  • Cryptographic inventory
  • Threat intelligence monitoring

Together, these services help organizations understand whether they may be directly or indirectly affected, where their most important risks sit, and what practical steps should be prioritized before regulatory expectations become more defined.

Visit our page to learn more and reach out to your local advisor today to see how your organization can become better prepared.

Authors

Eugene Ng

MNP’s Cyber Security Leader, Eugene oversees research and development activities and formulates long-term vision and strategies at the executive management level to help the firm better serve clients.

Sam Smagala

Senior Manager, Cyber Incident Management, MNP Digital

Chris McLeish

Senior Threat Intelligent Specialist, MNP Digital

Connect with us to get started

Our team of dedicated professionals can help you determine which options are best for you and how adopting these kinds of solutions could transform the way your organization works. For more information, and for extra support along the way, contact our team.