Status, September 2026: ZoneSentry is not currently taking on new sites, and development of the platform is paused. The regulatory guides on this site remain available — last verified against primary sources on 13 September 2026.
Free · Ungated · Primary sources only

Four layers of Canadian cybersecurity regulation.
Most operators don't know which ones bind them.

We wrote the guide we couldn't find. Province by province, checked against the statutes, regulations and regulator decisions themselves — not against somebody else's summary of them.

4
Regulatory layers
3
In force today
$15M
CCSPA penalty ceiling
$0
Cost of these guides

Where to start

If you operate pipeline, energy or industrial infrastructure in Canada, at least one of these probably already applies to you. None of it is gated and none of it asks for your email.

Do these regulations apply to me?

The province-by-province guide. Federal, interprovincial, Alberta, BC, Ontario, Manitoba, Quebec, Saskatchewan — what is in force, who enforces it, and which standard it points at.

Alta Reg 84/2024

Alberta's Security Management for Critical Infrastructure Regulation, in force since May 2025. What it requires, what the AER can do about it, and the ambulatory CSA reference that moves your obligation without telling you.

CCSPA / Bill C-8

Royal Assent June 2026, still not in force. What the Act actually says about programs, 72-hour reporting and penalties — including the penalty figures that are widely misreported.

Regulation isn't coming. It's here.

Canadian pipeline and energy operators face four layers of cybersecurity regulation, and most of them converge on the same baseline standard. Here is the short version of each. The detail, province by province, is in the guide.

Alta Reg 84/2024 — In Force Now

Alberta's Security Management for Critical Infrastructure Regulation (Alta Reg 84/2024) is already active as of May 31, 2025. Operators of designated facilities must have a security management program per CSA Z246.1:21 — and the AER can order operations to cease under REDA authority.

Read our plain-language guide →

BCER Security Management Regulation — In Force Now

British Columbia's Security Management Regulation (BC Reg 181/2022) is already in force — BC Reg 181/2022 reads "should" in CSA Z246.1:21 as "must," making advisory language mandatory, and applies to all permit holders. Cybersecurity measures must also meet NIST CSF objectives or an equivalent approved standard.

See BC requirements →

📋

Bill C-8 / CCSPA — Now Law (Royal Assent June 15, 2026), Not Yet in Force

The Critical Cyber Systems Protection Act received Royal Assent on June 15, 2026 and is now law (Statutes of Canada 2026, c. 9). It is not yet in force — under section 16 of the enacting Act (S.C. 2026, c. 9), its provisions come into force on a day fixed by order of the Governor in Council, and the classes of operators it applies to are designated by later Orders in Council. When in force, the Act will require mandatory cybersecurity programs, 72-hour incident reporting to CSE, and is expected to impose Canadian data residency requirements for incident reports and security program records via implementing regulations. Potential penalties: up to $15M per violation.

What this means for you →

And what is ZoneSentry?

Fair question, given the rest of this site is a regulatory guide. ZoneSentry is an OT network anomaly detection platform built by Fortified ICS in Canada. It reads the syslog a firewall already produces, learns what normal looks like for each device crossing a zone boundary, and flags deviations — no hardware, no agents, and nothing wired into the OT network.

It is not currently available. Development is paused and we are not taking on new sites. The guides on this site came out of building it, and they stay up because they are useful on their own.

Found something wrong in the guides?

Every citation here is checked against the primary source rather than a secondary summary. We still get things wrong. If you spot one, we would rather hear it than not.

Get in touch