Status, September 2026: ZoneSentry is not currently taking on new sites, and development of the platform is paused. The regulatory guides on this site remain available — last verified against primary sources on 13 September 2026.

AER Regulation 84/2024: What Alberta Operators Need to Know

Last updated September 13, 2026 · Educational resource

This regulation is in force now. AER Regulation 84/2024 — Security Management for Critical Infrastructure — took effect May 31, 2025. If you operate a facility on the AER's critical infrastructure list, compliance is not optional.

What Is Regulation 84/2024?

Alta Reg 84/2024, formally titled the Security Management for Critical Infrastructure Regulation, was enacted under Alberta's Responsible Energy Development Act (REDA). It requires operators of designated critical energy facilities in Alberta to establish and implement a security management program in accordance with CSA Z246.1 — the Canadian standard for security management for petroleum and natural gas industry systems. The current edition is the fourth, 2021.

The regulation does not pin an edition. s.1(e) defines the standard as CSA Z246.1 "as amended or replaced from time to time." That means a new edition or update published by CSA becomes mandatory in Alberta automatically — no amendment to the regulation, and no AER bulletin telling you it happened. Silence from the regulator is not evidence that nothing has changed; check the standard itself.

This is not hypothetical, and it is the practical point of this section. CSA Z246.1:21 remains the current edition — there is no fifth — but it does not stand alone: Update No. 1 (2025) and an Errata (2026) are attached to it, and the edition was reaffirmed in 2026 as Z246.1:21 (R2026). Update No. 1 modified Clause 7, which is the cybersecurity clause family. Because Alberta, BC and the CER all reference the standard "as amended or replaced from time to time", those amendments are already part of the legal obligation — a 2021 base copy is not the text you are measured against. Updates are distributed through CSA's Standards Update Service rather than as a new catalogue edition, so a catalogue listing showing only a reaffirmation is not evidence that nothing has changed.

One more date worth having in your calendar: under s.5, the Regulation expires on May 31, 2030.

The AER maintains a confidential list of designated critical facilities. If you operate pipelines, processing plants, or other energy infrastructure in Alberta, your facility may be on that list.

Who Does It Apply To?

The regulation applies to operators of facilities that the AER has designated as critical infrastructure. While the specific list is confidential, the scope of REDA means many petroleum and natural gas systems in Alberta may be designated. The specific designation is determined by the AER.

Critically, there is no small-business exemption once your facility is on the list. A junior producer with a single pipeline faces the same obligation as a major integrated operator. The regulation targets the criticality of the infrastructure, not the size of the company operating it. Size does enter earlier, at the listing stage: under s.2(2)(a) the Regulator may consider "the size and type of the facility" when deciding what is designated in the first place.

What Does It Require?

At its core, the regulation requires a security management program that aligns with CSA Z246.1. That standard covers both physical and cybersecurity, but for network and OT environments, the key requirements include:

What Can the AER Do?

The AER has enforcement tools that go well beyond fines:

Enforcement goes beyond fines. Under the Responsible Energy Development Act (REDA), the AER has broad enforcement authority including the power to order operations to cease. For a junior producer running on thin margins, non-compliance with Regulation 84/2024 is an existential risk.

The CSA Z246.1:21 Connection

CSA Z246.1 (fourth edition, 2021, as amended by Update No. 1 (2025) and Errata (2026)) is the standard that Alta Reg 84/2024 points to. It's also referenced by federal regulations (CER Onshore Pipeline Regulations, s.4(1)(e)), BC's Security Management Regulation, and Bill C-8 / CCSPA (received Royal Assent June 15, 2026 — now law, S.C. 2026 c. 9; not yet in force). Compliance with Z246.1:21 covers significant ground across all four regulatory layers simultaneously.

For OT cybersecurity specifically, Z246.1:21 aligns closely with IEC 62443 concepts: zones and conduits, defence in depth, and risk-based security program management.

How ZoneSentry Helps

ZoneSentry directly addresses several Z246.1 requirements for OT network environments:

Z246.1 RequirementZoneSentry Coverage
Network monitoring & detection Continuous firewall syslog monitoring with AI-powered anomaly detection
Boundary-observed device inventory Automatic inventory of all devices observed crossing zone boundaries
Network segmentation visibility (Clause 7.2.3 + IEC 62443 alignment) Zone-aware architecture maps VLANs to IEC-62443 / Purdue levels
Incident detection & alerting Confidence-scored alerts with plain-language narratives
Audit-ready documentation Compliance PDF reports, device inventory, alert history
Program review evidence Annual rollup reports: device changes, alert trends, baseline evolution

ZoneSentry is not a complete Z246.1 compliance solution — no single product is. It covers the network monitoring and detection components. Your security management program will also need policy governance, personnel training, physical security measures, and incident response procedures. If you work with an integrator, these gaps are where their consulting services complement ZoneSentry's automated monitoring.

What Should You Do Now?

If you operate energy infrastructure in Alberta:

  1. Determine your status. Contact the AER if you're unsure whether your facility is designated.
  2. Get a copy of CSA Z246.1:21. This is the standard you'll be measured against. The current edition is the fourth, 2021. Make sure you also pull Update No. 1 (2025) and the Errata (2026) — they are attached to the same edition and Update No. 1 modified Clause 7, the cybersecurity clauses. CSA Group makes the standard available as a free download, but two conditions apply: access is restricted to Canada, and it requires a CSA account. Updates come through CSA's Standards Update Service.
  3. Assess your current gaps. Do you have a documented security management program? Network monitoring? Incident response?
  4. Start with what you have. Your firewall is already generating the data. ZoneSentry turns it into monitoring, alerting, and compliance evidence.

The best time to start was May 2025. The second best time is today. None of the steps above depend on buying anything, and ZoneSentry is not available to sell you — development is paused. Determining your designation status, obtaining the standard, and assessing your gaps are the work, and they are yours to do either way.

How this page is checked. Every statute, regulation, section number and figure here is read from the primary source — the enacted text on Justice Laws, the provincial registry, or the regulator's own decision — not from a secondary summary. Where we could not confirm something first-hand, the page says so rather than asserting it.

Last verified against primary sources: 13 September 2026. We are not promising a review schedule. Regulation moves, this page will drift, and a dated check you can see is worth more than a cadence we might not keep. If you find something out of date, tell us.

Spotted something out of date?

This guide is checked against primary sources. If you believe something here is wrong, tell us — corrections are genuinely welcome.

Get in touch