Security & Compliance
Lynx Compliance - Bill C-26 (CCSPA)
Canada's Critical Cyber Systems Protection Act as an assessable control set - cyber security programme, supply-chain risk, CSE incident reporting, directions and record-keeping in Canada.
lynx_compliance_billc26
· v19.0.1.0.0
· Add-on
Beta
What this solves
Lynx Compliance - Bill C-26 (CCSPA)
Bill C-26 created the Critical Cyber Systems Protection Act, which binds designated operators in federally regulated telecommunications, banking, clearing and settlement, energy, transportation and nuclear sectors. Its obligations are statutory rather than contractual: a missed incident report is not a failed audit finding, it is an administrative monetary penalty.
This pack turns the Act into controls you can assess, evidence and hand to a regulator. It is deliberately narrow. The Act does not prescribe security controls, so the pack states the statutory duty and points at the Lynx records that evidence it, rather than inventing a control catalogue the legislation never wrote.
Scope honesty matters here. If your organisation is not a designated operator you have no obligations under the CCSPA, and the pack should be run as a readiness baseline rather than a compliance profile. The framework description says so, and so does the guidance on section 9.
Key Features
21 controls across five functions - programme, supply chain, directions, incident reporting, and records - keyed to the statutory sections.
Section codes that cross-reference automatically - controls are coded CCSPA s.9 and so on, matching the billc26_refs values already carried on the NIST CSF 2.0 controls, so a CSF assessment propagates without further wiring.
The two-report duty split - reporting to the Communications Security Establishment and notifying the sector regulator are separate controls, because they are separate obligations and operators miss the second.
Records-in-Canada treated as data residency - section 20 is assessed against hosting region and cross-border transfer records, not filed as a paperwork control.
Evidence guidance naming real records - incident notifications, DR plans with recovery objectives, vendor posture, policy versions and the audit log, rather than "retain appropriate documentation".
Residual-risk examples per control - each written as a realistic partial state, since almost no operator is fully green on day one.
Integrates With
lynx_compliance - the CSF 2.0 controls already reference CCSPA sections, so profiles cross-populate in both directions.
lynx_compliance_incident - incident notifications to the CSE and the regulator are the primary evidence for sections 17 and 18.
lynx_compliance_vendor_posture - supplier assessments evidence sections 13 and 14.
Depends on
Try Lynx Compliance - Bill C-26 (CCSPA) on your team.
Free trial, no credit card. Talk to sales when you're ready.