We wrote the guide we couldn't find. Province by province, checked against the statutes, regulations and regulator decisions themselves — not against somebody else's summary of them.
If you operate pipeline, energy or industrial infrastructure in Canada, at least one of these probably already applies to you. None of it is gated and none of it asks for your email.
The province-by-province guide. Federal, interprovincial, Alberta, BC, Ontario, Manitoba, Quebec, Saskatchewan — what is in force, who enforces it, and which standard it points at.
Alberta's Security Management for Critical Infrastructure Regulation, in force since May 2025. What it requires, what the AER can do about it, and the ambulatory CSA reference that moves your obligation without telling you.
Royal Assent June 2026, still not in force. What the Act actually says about programs, 72-hour reporting and penalties — including the penalty figures that are widely misreported.
Canadian pipeline and energy operators face four layers of cybersecurity regulation, and most of them converge on the same baseline standard. Here is the short version of each. The detail, province by province, is in the guide.
Fair question, given the rest of this site is a regulatory guide. ZoneSentry is an OT network anomaly detection platform built by Fortified ICS in Canada. It reads the syslog a firewall already produces, learns what normal looks like for each device crossing a zone boundary, and flags deviations — no hardware, no agents, and nothing wired into the OT network.
It is not currently available. Development is paused and we are not taking on new sites. The guides on this site came out of building it, and they stay up because they are useful on their own.
Every citation here is checked against the primary source rather than a secondary summary. We still get things wrong. If you spot one, we would rather hear it than not.
Get in touch