Status, September 2026: ZoneSentry is not currently taking on new sites, and development of the platform is paused. The regulatory guides on this site remain available — last verified against primary sources on 13 September 2026.

Do These Regulations Apply to My Company?

Last updated September 13, 2026 · Canadian OT cybersecurity regulatory guide

If you operate pipeline, energy, or industrial infrastructure in Canada, cybersecurity monitoring requirements may already apply to you — and more are coming. This page covers every province and territory so you know where you stand.

The common thread: CSA Z246.1:21 (fourth edition, 2021) — the Canadian standard for security management of petroleum and natural gas industry systems. Three of the four frameworks below reference it directly; the CCSPA requires equivalent cybersecurity programs that align with its principles.

Make sure you have the amended text. CSA Z246.1:21 remains the current edition — there is no fifth — but it does not stand alone: Update No. 1 (2025) and an Errata (2026) are attached to it, and the edition was reaffirmed in 2026 as Z246.1:21 (R2026). Update No. 1 modified Clause 7, which is the cybersecurity clause family. Because Alberta, BC and the CER all reference the standard "as amended or replaced from time to time", those amendments are already part of the legal obligation — a 2021 base copy is not the text you are measured against. Updates are distributed through CSA's Standards Update Service rather than as a new catalogue edition, so a catalogue listing showing only a reaffirmation is not evidence that nothing has changed.

One detail that is easy to miss and matters: none of those instruments pins an edition. Alberta, BC and the CER all incorporate CSA Z246.1 "as amended or replaced from time to time." The obligation therefore tracks whatever CSA publishes — a new edition or an update becomes mandatory automatically, with no regulatory amendment and no regulator bulletin. We cite the 2021 fourth edition throughout because it is the current one, not because the regulations fix it.

Two regulations are already in force. Alberta and British Columbia both have active cybersecurity requirements for energy operators. This is not a future problem. If you operate in either province, compliance obligations exist today.

Federal (All Sectors) — CCSPA

LegislationCritical Cyber Systems Protection Act (CCSPA), Bill C-8
StatusLaw (Royal Assent June 15, 2026) — not yet in force
SectorsEnergy (interprovincial), finance, transportation
EnforcerCER (interprovincial energy), provincial regulators (AER, BCER) for intraprovincial energy, sector-specific regulators for others

The CCSPA will mandate cybersecurity programs for designated operators across critical infrastructure sectors. Key requirements include:

The CCSPA received Royal Assent on June 15, 2026 and is now law (Statutes of Canada 2026, c. 9). It is not yet in force — under section 16 of the enacting Act (S.C. 2026, c. 9), its provisions come into force on a day to be fixed by order of the Governor in Council, and the classes of operators it applies to are designated by later Orders in Council. Operators should be preparing now — the requirements are substantial, and the 90-day compliance window after designation leaves no room for building a program from scratch.

Read our detailed CCSPA guide →

Interprovincial (Any Province)

RegulationCER Onshore Pipeline Regulations, SOR/99-294 s.4(1)(e)
StatusIn force
StandardCSA Z246.1 compliance required (referenced as amended from time to time; currently the 2021 fourth edition plus Update No. 1 (2025) and Errata (2026))
EnforcerCanada Energy Regulator (CER)

If your pipeline crosses a provincial or international boundary, it falls under federal jurisdiction regardless of which province you're in. The CER requires CSA Z246.1 compliance for all CER-regulated pipelines under SOR/99-294 s.4(1)(e), and a security management program under s.47.1. The CER conducts cybersecurity compliance-verification activities focused on operational technology systems.

Alberta

RegulationSecurity Management for Critical Infrastructure Regulation, Alta Reg 84/2024
StatusIn force since May 31, 2025
StandardCSA Z246.1 compliance mandatory — s.1(e) defines it "as amended or replaced from time to time", so the edition is not pinned
EnforcerAlberta Energy Regulator (AER)
Key provisions.3(1) — operators must establish and implement a security management program
Expirys.5 — the Regulation expires May 31, 2030

The AER maintains a confidential critical infrastructure list. Operators are notified if their facility is placed on it. If you operate pipelines, processing plants, or other energy infrastructure in Alberta, your facility may already be designated.

There is no small-business exemption in the regulation. A junior producer with a single pipeline faces the same obligation as a major integrated operator. The scoping happens earlier, at listing: s.2(2)(a) lets the Regulator consider "the size and type of the facility" when deciding what goes on the critical infrastructure list. Non-compliance can result in AER enforcement action, including potential facility shutdown under REDA authority.

Read our detailed Alta Reg 84/2024 guide →

British Columbia

RegulationSecurity Management Regulation, BC Reg 181/2022
StatusIn force
StandardCSA Z246.1:21 compliance mandatory + NIST CSF objectives
EnforcerBC Energy Regulator (BCER)
GuidelineBCER Security Management Regulation Guideline

BC and Alberta enforce the same standard (CSA Z246.1:21) — but BC's regulation makes more of it binding. BC Reg 181/2022 reads "should" in CSA Z246.1:21 as "must" (s.2(3)), turning the standard's advisory clauses into hard requirements.

Additionally, cybersecurity measures per Clause 7 of the standard must also meet NIST Cybersecurity Framework (CSF) objectives — or a comparable national or international standard, if approved by the regulator (s.5). The BC regulation applies to permit holders generally rather than only to facilities designated "critical", which is a broader scope than Alberta's designated-facility model. Two qualifications on that breadth: Class 1 and Class 2 hydrogen facilities are excluded (s.1.1, added by B.C. Reg. 26/2025 effective April 1, 2025), and officials hold a discretionary exemption power under s.11.

Ontario

Ontario has two enforceable cybersecurity hooks that reach municipal operators — one in drinking water, one in electricity distribution. Neither follows the CSA Z246.1 pipeline pattern; they sit on top of sector-specific licensing regimes administered by the Ministry of the Environment, Conservation and Parks (MECP) and the Ontario Energy Board (OEB).

DWQMS Element 7 — Drinking Water

RegulationDrinking Water Quality Management Standard (DWQMS), Element 7 — Risk Assessment
StatusIn force
Standard / FrameworkDWQMS, issued under the Safe Drinking Water Act, 2002 (SO 2002 c 32) + O. Reg. 188/07 (Licensing of Municipal Drinking Water Systems). The Minister approved version 3 of the DWQMS on February 10, 2026 via ERO 019-8413; operating authorities must transition prior to their first audit in 2028.
EnforcerMinistry of the Environment, Conservation and Parks (MECP)
Key provisionElement 7 — operating authorities must identify, assess, and prioritize risks to the drinking-water system, including cybersecurity threats

Every accredited operating authority for a municipal residential drinking-water system in Ontario must consider cybersecurity threats as part of its Element 7 risk assessment. DWQMS version 3 was approved by the Minister on February 10, 2026 under s.21 of the Safe Drinking Water Act, 2002 (ERO posting 019-8413) and further codifies the cybersecurity expectation. Note that operating authorities have runway: the transition must be complete before the first audit of a system that occurs in 2028, so not every operating authority is working to version 3 today.

Enforcement runs through accreditation. Non-conformance is grounds for the Director to revoke an operating authority's accreditation, which in turn revokes the system's Drinking Water Works Permit. The cybersecurity obligation is not a stand-alone statute — it is woven into the same accreditation regime that already governs sampling, treatment, and operator certification.

Continuous boundary monitoring, anomaly detection and incident evidence are the kind of ongoing record the Element 7 obligation to identify, assess, and prioritize cybersecurity threats calls for. That is the gap ZoneSentry was built to fill, though it is not currently available.

OEB Cyber Security Framework + Cyber Security Standard — Electricity Distribution

RegulationOntario Cyber Security Framework (OCSF) v1.1 + Ontario Cyber Security Standard v3.1 (issued November 6, 2025; the Standard first took effect October 1, 2024)
StatusIn force (licence condition)
Standard / FrameworkNIST Cybersecurity Framework + US DoE C2M2; four Maturity Indicator Levels (MIL0–MIL3)
EnforcerOntario Energy Board (OEB), with IESO "Lighthouse" sector monitoring
Key provisionLicence condition under the Ontario Energy Board Act, 1998 — applies to every licensed electricity transmitter and distributor in Ontario, including municipally-owned LDCs

The OCSF is built on NIST CSF and the US Department of Energy's C2M2 maturity model. Licensed transmitters and distributors must self-assess against the framework and progress through the maturity indicator levels. The Ontario Cyber Security Standard sits alongside the framework and tightens specific control expectations.

Because the obligation rides on the OEB licence, it reaches every Ontario electricity distributor — including municipally-owned local distribution companies. OEB enforcement applies, and IESO operates a "Lighthouse" sector monitoring function that gives the regulator visibility into utility cyber posture between formal reviews.

ZoneSentry's continuous syslog ingestion, boundary monitoring, and 72-hour incident reports map to OCSF Detect (DE.AE, DE.CM) and Respond (RS.AN, RS.CO) domains on the OT side of an LDC network.

Saskatchewan

There is no provincial equivalent of Alta Reg 84/2024 in Saskatchewan. CSA Z662, which Saskatchewan references for pipelines, is an integrity standard and is not cybersecurity-specific — it should not be read as a cyber obligation.

Saskatchewan's mandatory reliability-standards arrangement works through a corporate mechanism rather than a provincial regulation, which makes it different in kind from the Alberta and BC models above. We have not verified its current scope to the standard we hold ourselves to on this page, so we are not going to characterise it here.

Interprovincial pipeline operators in Saskatchewan are covered by CER requirements above. When the CCSPA is brought into force and operators are designated, designated operators in Saskatchewan will face the same federal obligations as every other province.

Manitoba

RegulationReliability Standards Regulation, amendment — M.R. 57/2026 (amending M.R. 25/2012), under The Manitoba Hydro Act, C.C.S.M. c. H190
StatusIn force since July 1, 2026
Standard / FrameworkNERC Critical Infrastructure Protection (CIP) reliability standards
RegisteredJune 19, 2026

Manitoba brought a full set of NERC CIP cyber-security standards into force on July 1, 2026. Schedule 1 of the amended regulation makes CIP-002-7, CIP-004-8, CIP-005-8, CIP-006-7, CIP-007-7, CIP-008-7, CIP-009-7, CIP-010-5, CIP-011-4 and CIP-013-3 effective on that date, carrying forward CIP-003-8, CIP-012-1 and CIP-014-3 from earlier dates.

This is a different regulatory model from Alberta and BC: it reaches the bulk power system through reliability standards rather than reaching designated energy facilities through CSA Z246.1. If you operate on Manitoba's bulk power system, the CIP family — not Z246.1 — is the relevant baseline.

Quebec

Quebec has a standing mandatory reliability-standards regime administered by the Régie de l'énergie, which adopts NERC reliability standards including the CIP family and fixes their entry-into-force dates. It is not a CSA Z246.1 regime.

Most recently, in decision D-2026-097 (dossier R-4335-2026, August 24, 2026) the Régie adopted CIP-015-1, fixing entry into force at October 1, 2029 for responsible entities with control centres and backup control centres, and October 1, 2031 for other responsible entities with routably connected systems.

A caution that applies beyond Quebec: a regulator's published summary table can lag its own decisions. The Régie's list of standards coming into force at a later date did not yet show CIP-015-1 three weeks after the decision adopting it. Check the decisions, not the summary.

Atlantic Provinces, Territories

We have not identified a CSA Z246.1-style OT cybersecurity regulation at the provincial or territorial level in these jurisdictions. Drinking-water statutes outside Ontario focus on water quality, treatment, sampling, and operator certification — not cybersecurity. Note the scope limit below: this page does not comprehensively cover electric reliability standards, and several provinces impose NERC CIP obligations through that route.

Interprovincial pipeline operators are covered by CER requirements regardless of province. When the CCSPA is brought into force and operators are designated, designated operators in any jurisdiction will be subject to federal requirements.

Provincial regulators may adopt CSA Z246.1:21 requirements following Alberta and BC's lead, or follow Ontario's licence-condition model for electricity distributors and drinking-water operating authorities. We monitor for changes and will update this page promptly.

At a Glance

Jurisdiction Regulation Status Standard / Framework
Federal (CCSPA) Bill C-8 Law (Royal Assent June 15, 2026) — not yet in force CSA Z246.1:21 expected
Interprovincial CER OPR s.4(1)(e) In Force CSA Z246.1 required (as amended — incl. Update No. 1 + Errata)
Alberta Alta Reg 84/2024 In Force CSA Z246.1 mandatory (as amended — incl. Update No. 1 + Errata)
British Columbia BC Reg 181/2022 In Force CSA Z246.1 mandatory, as amended ("should" = "must") + NIST CSF
Ontario (water) DWQMS Element 7 In Force DWQMS / Safe Drinking Water Act, 2002
Ontario (electricity LDC) OEB OCSF v1.1 + Ontario Cyber Security Standard v3.1 In Force NIST CSF + DoE C2M2
Manitoba M.R. 57/2026 (Reliability Standards Regulation) In Force NERC CIP family
Quebec Régie de l'énergie reliability-standards decisions In Force NERC CIP family
Saskatchewan No CSA Z246.1-style provincial reg Via CER; reliability standards via a corporate mechanism
Atlantic / Territories None identified Via CER only

What This Means for You

If you're reading this page, you're already ahead of most operators. Here's the practical takeaway:

  1. Start with CSA Z246.1:21. It's the common denominator across every regulatory framework above. Building compliance with Z246.1:21 now is future-proof regardless of what happens with CCSPA or other provincial regulators. Free download from CSA Group — access is restricted to Canada and requires a CSA account.
  2. Get network monitoring in place. Every framework requires the ability to detect and respond to cybersecurity events. ZoneSentry delivers this using the syslog your firewall already generates — no hardware, no agents, no process disruption.
  3. Whether you're on the AER's list or not, being ready is cheaper than scrambling when you get the call. The AER's confidential designation process means you may not know you're covered until an audit letter arrives.
  4. Don't wait for CCSPA. Two provincial regulations are already in force. CER already requires it for interprovincial pipelines. CCSPA adds federal teeth, but the obligation to monitor is already here.

ZoneSentry provides the monitoring component of your security management program — continuous boundary monitoring, anomaly detection, compliance reporting, and incident evidence. It is not a complete compliance solution (no single product is), but it covers the network monitoring and detection requirements that every framework above mandates.

Primary Regulatory Sources

We link to primary sources throughout this page. Here they are collected for reference:

Scope limit, stated plainly. This page covers the CSA Z246.1-based regimes that apply to petroleum and natural gas operations, plus Ontario's two licence-condition hooks. It does not comprehensively cover mandatory electric reliability standards — the NERC CIP family adopted by several provinces through their energy regulators. That is a substantial separate layer of binding Canadian OT cybersecurity obligation, and if you operate on a bulk power system you should treat this page as incomplete for your situation and go to your provincial regulator.

How this page is checked. Every statute, regulation, section number and figure here is read from the primary source — the enacted text on Justice Laws, the provincial registry, or the regulator's own decision — not from a secondary summary. Where we could not confirm something first-hand, the page says so rather than asserting it.

Last verified against primary sources: 13 September 2026. We are not promising a review schedule. Regulation moves, this page will drift, and a dated check you can see is worth more than a cadence we might not keep. If you find something out of date, tell us.

Spotted something out of date?

This guide is checked against primary sources. If you believe something here is wrong, tell us — corrections are genuinely welcome.

Get in touch