Blogs | 6clicks

A due diligence defense needs evidence: Preparing for Canada’s CCSPA before designation

Written by Heather Buker | Aug 25, 2026

 

TL;DR


  • Bill C-8 is now law, but CCSPA obligations are not yet universally in force. The Telecommunications Act amendments took effect on Royal Assent, while the Critical Cyber Systems Protection Act is expected to phase in through future government action, designation of operators, and regulations.
  • The pre-designation period is an evidence-building window. Organizations in sectors that may be affected should use this time to strengthen governance, control ownership, third-party oversight, incident evidence and compliance records.
  • A due diligence defense is only as strong as the evidence behind it. Boards and executives need more than policy intent. They need reliable proof that obligations are understood, actions are taken, controls are operating, evidence is maintained and oversight is active.

Designation is coming. Evidence takes longer.

 

For Canadian organizations operating in, or supplying into, sectors that may be affected by the Critical Cyber Systems Protection Act (CCSPA), that sentence should frame the next phase of cybersecurity governance.

 

Bill C-8, An Act Respecting Cyber Security (ARCS), has received Royal Assent. The federal government has confirmed that amendments to the Telecommunications Act took immediate effect upon Royal Assent, while the CCSPA will be implemented gradually, with certain provisions coming into force through future government action. The legislation establishes the framework for protecting critical cyber systems that support vital services and vital systems, but the practical compliance picture still depends on designation of operators, regulations, and implementation details.

 

That distinction matters.

 

This is not the moment to write as though every organization in an identified sector is already subject to active CCSPA obligations. It is also not a reason to wait. Designation may happen through government action. Evidence cannot be created overnight.

The window before designation

 

The CCSPA is designed to help protect critical cyber systems that support the continuity and security of vital services and vital systems. The Act’s stated purpose includes ensuring that cyber security risks are identified and managed, including risks associated with supply chains and third-party products and services; that critical cyber systems are protected from being compromised; that incidents are reported; and that the impacts of incidents are minimized.

 

The framework is directed at designated operators of critical cyber systems. In practical terms, this means obligations do not apply simply because an organization is large, regulated, important to the economy, or located in a relevant sector. The designation mechanism matters.

 

That is the compliance guardrail. But it should not become a readiness excuse.

 

Organizations in telecommunications, finance, energy, nuclear, transportation, and clearing and settlement should pay close attention because these are the types of vital services and systems contemplated by the legislation and official government materials. 

The wider ecosystem should pay attention too, because supply-chain and third-party cyber risk are central to the regime. Even organizations that are not directly designated may face increased assurance expectations from customers, partners, boards, insurers, or procurement teams if they provide products or services into critical environments.

 

The pre-designation period is therefore a governance opportunity. It gives organizations time to ask hard questions before formal requirements create time pressure. Some questions to consider include:

 

  • Which parts of our operating environment could be considered critical to vital services?
  • Which suppliers, managed service providers, technology vendors, and outsourced processes support those environments?
  • Which controls already exist, and which are documented only in policy?
  • What evidence would show those controls are operating?
  • Who would be accountable for producing that evidence?
  • Could leadership see the state of readiness without relying on a last-minute manual exercise?

 

This is not about manufacturing urgency. It is about recognizing that governance systems mature over time. Evidence trails are built through repeated action, consistent ownership, and reliable record-keeping. If an organization waits until after designation to build that operating model, it may find that the hardest part is not writing the policy. The hardest part is proving the policy has been working.

What organizations should prepare to demonstrate

 

Bill C-8 and the CCSPA point to several core obligation areas for designated operators. The exact details, timing, and application should be reviewed against final regulations and legal advice, but the direction of travel is clear enough for preparation.

 

The leadership task is to translate each obligation area into an evidence question.

A documented cybersecurity program

A cybersecurity program should not be treated as a binder of policies or a static framework mapping exercise. For board and executive purposes, the more important question is: Could we demonstrate that the cybersecurity program is actually operating?

 

That means being able to show more than the existence of controls. It means showing that the organization understands its critical systems, has assigned ownership, has identified risks, has implemented controls, has reviewed exceptions, and has escalated material issues.

 

A useful evidence trail may include:

  • approved governance structures and accountabilities;
  • risk assessments tied to critical systems and vital services;
  • control mappings to relevant obligations and internal policies;
  • testing or review results;
  • exceptions, risk acceptances, and approvals;
  • remediation plans and completion evidence;
  • management and board reporting

 

Executives should be wary of any program that looks complete on paper but cannot show how work happens in practice. A documented program is the starting point, but a demonstrated program is the governance objective.

Supply-chain and third-party cyber risk management

The CCSPA specifically recognizes supply-chain and third-party risks. That is significant because critical cyber systems rarely operate in isolation. They depend on software, infrastructure, managed services, contractors, cloud services, telecommunications providers, data processors, maintenance providers, and specialist vendors.

 

The board-level evidence question is: Can we show how third-party cyber risks are identified, assessed, managed, and escalated over time?

 

This is not only a procurement question. It is a resilience and accountability question.

 

For a critical service, a weak supplier control can become an operational risk, a reporting issue, a contractual issue, and a governance issue at the same time. Organizations should therefore be able to show:

  • which third parties support critical operations or critical systems;
  • how suppliers are risk-rated;
  • what assurance is required before onboarding;
  • how supplier controls are assessed;
  • how material weaknesses are tracked;
  • whether remediation is completed;
  • how ongoing monitoring occurs;
  • when supplier risks are escalated to leadership

 

This is where many organizations discover a gap between vendor management and cyber assurance. A supplier register may show who the vendors are. It may not show whether the organization can prove that high-risk third parties are being governed in line with the organization’s cyber risk appetite.

Cyber incident reporting

The CCSPA framework includes reporting of cyber security incidents to the Communications Security Establishment, through the Canadian Centre for Cyber Security, for designated operators. The details of reportable incidents, timing, and process should be verified against final requirements and applicable regulations.

 

The practical evidence question is: Can we demonstrate what happened before, during, and after an incident?

 

Incident reporting is not only a communications workflow. It depends on evidence quality.

 

If an incident occurs, leaders may need to understand:

  • when the issue was detected;
  • which systems were affected or potentially affected;
  • what containment steps were taken;
  • who made key decisions;
  • whether escalation thresholds were met;
  • whether external reporting was required;
  • what was communicated, when, and to whom;
  • what lessons were captured;
  • whether remediation was completed

 

This matters because the credibility of an incident response is often judged after the fact. It is not enough to say the organization responded appropriately. The organization needs records that show the sequence of events, the rationale for decisions, the effectiveness of actions, and the follow-through.

For boards and audit committees, the question becomes whether incident governance is visible, repeatable, and defensible.

Compliance records and Canadian record residency

The CCSPA includes record-keeping requirements for designated operators. Parliamentary legislative summary materials describe records relating to cyber security programs, supply-chain and third-party risk mitigation, reported cyber security incidents, cyber security directions, and other prescribed matters. They also state that these records must be kept within Canada, at a place and in a manner prescribed by regulation, or, where regulations do not provide further precision, at the designated operator’s place of business.

 

The executive evidence question is: Can we produce the right records, in the right place, with enough context to support oversight and review?

 

Record-keeping is often treated as administrative. Under a cyber governance regime, it becomes strategic. Records are what connect obligation to action. They show whether governance was real, whether decisions were made by accountable people, whether controls were operating, and whether known gaps were managed.

 

Canadian record residency also connects the CCSPA conversation to the wider sovereignty discussion. Data location is relevant, but it is not the whole story. Organizations also need to understand control, access, retention, jurisdiction, third-party involvement, and whether records can be reliably produced when needed.

The key is not simply “Do we store something in Canada?” It is: Can we demonstrate control over the evidence that proves our cyber governance?

Why due diligence becomes an evidence problem

 

This is the heart of the issue.

 

A due diligence defense is not the same thing as good intentions. It is not the same thing as a policy. It is not the same thing as a project plan that was approved but never operationalized. In business terms, due diligence asks whether reasonable steps were taken. In governance terms, the challenge is whether those steps can be demonstrated.

 

There is a material difference between saying: “We took reasonable steps to manage cyber risk.”

 

And being able to show:

  • the obligation was identified;
  • accountable owners were assigned;
  • controls were selected and implemented;
  • evidence was collected;
  • exceptions were reviewed;
  • suppliers were assessed;
  • incidents were escalated;
  • remediation was tracked;
  • leadership received accurate reporting;
  • the board had visibility into material issues

 

That is why due diligence becomes an evidence problem.

 

The chain is simple: obligation → action → control → evidence → oversight

If any part of that chain is missing, the governance story weakens. An obligation without action is awareness without execution. An action without a control is activity without structure. A control without evidence is a claim. Evidence without oversight is operational detail that may never reach accountable leaders. Oversight without traceability risks becoming a report that cannot be defended under scrutiny. This is why the CCSPA conversation belongs at board level.

Cybersecurity teams can operate controls. GRC teams can manage frameworks. Legal teams can interpret obligations. Procurement teams can manage supplier contracts. But executives and boards are responsible for ensuring that governance is coherent, resourced, visible, and accountable.

 

A director or officer does not need to personally operate a security control to care about evidence. They need confidence that the organization can show:

  • what it knew;
  • what it decided;
  • what it did;
  • what it monitored;
  • what it escalated;
  • what it remediated;
  • what remains unresolved

 

The phrase “reasonable steps” only has practical value if the organization can reconstruct those steps with reliable records. Otherwise, leaders may discover too late that the organization has policies without proof, dashboards without traceability, and assurances that depend on manual reconstruction.

 

The preparation window matters because evidence quality improves through operating discipline. You cannot retroactively create months of control performance. You cannot instantly prove supplier oversight that was never recorded. You cannot easily reconstruct incident decisions if the evidence lives across inboxes, tickets, spreadsheets, and meeting notes.

 

Due diligence is built before it is needed.

From documented to demonstrated

A Canadian organization may have strong policies, local infrastructure, reputable suppliers, and mature security teams. But if evidence is fragmented, outdated, or disconnected from governance, the organization may struggle to demonstrate control when leadership, regulators, customers, or auditors ask.

Moving from documented to demonstrated means connecting the governance system end to end:

  • obligations mapped to risks;
  • risks mapped to controls;
  • controls mapped to evidence;
  • evidence mapped to owners;
  • findings mapped to remediation;
  • remediation mapped to reporting;
  • reporting mapped to executive and board oversight


This is how organizations reduce the gap between what they believe is happening and what they can prove is happening.

 

For Canadian digital sovereignty, that matters because control should be an operating capability. It includes where records are held, who can access them, which third parties support them, how obligations are interpreted, and how evidence is maintained over time.

Why point-in-time evidence creates problems

Most organizations have an evidence problem because evidence is usually collected for a point in time. That model can work for a narrow audit but it is weaker for continuous cyber governance.

 

Common failure patterns include:

  • spreadsheets that are accurate only on the day they are updated;
  • policy documents that do not show whether controls are operating;
  • supplier assessments that become stale between review cycles;
  • evidence stored in inboxes, shared drives, tickets, or disconnected tools;
  • remediation actions that are tracked separately from risks and obligations;
  • board reports that summarize risk without traceability to source records

 

The problem is that evidence can become disconnected from the control it is supposed to support. When that happens, teams end up chasing evidence. They chase supplier attestations. They chase control owners. They chase audit artefacts. They chase records after incidents. They chase proof at the very moment they need confidence.

 

This creates lag, because evidence arrives after leadership needs it; it creates drift, because the evidence may no longer reflect the current environment; and it creates false confidence, because a green status may hide weak traceability.

 

For a board-level governance conversation, this is the operational issue: Can leaders rely on the evidence behind the assurance they receive?

 

If the answer is “not yet,” the preparation window should be used to fix the system before the obligation arrives. Stop chasing evidence.

What readiness should look like now

The right response to the pre-designation period is disciplined preparation. Organizations that may be affected by the CCSPA can use this period to strengthen governance before final obligations are already in force. Practical readiness actions include:

Identify potentially applicable obligations

Start with the legislation, official government materials, and reputable legal analysis. Identify which parts of the organization may be relevant to vital services, vital systems, critical cyber systems, regulated operations, or critical supply chains. Do not overstate applicability. Do not assume designation. But do create a clear view of where exposure may exist.

Map obligations to controls

For each likely obligation area, identify existing controls and gaps. The goal is not to create a perfect compliance map before regulations are finalized. The goal is to understand whether the organization has a control structure capable of adapting when final details arrive. This may include mapping cybersecurity program governance, third-party risk management, incident response, record-keeping, reporting, and executive oversight.

Establish evidence ownership

Every important control and evidence item should have an owner. Every recurring evidence requirement should have a cadence. If nobody owns the evidence, the organization will chase it later.

Understand critical third parties

Create a clear view of suppliers that support critical operations, critical systems, or regulated services. Identify where the organization relies on vendor controls, subcontractors, managed services, cloud infrastructure, outsourced processes, or cross-border support. Then ask whether assurance is proportional to the risk.

Document cybersecurity governance

Leadership should be able to see how cyber risk decisions are made, who approves exceptions, how material risks are escalated, and how remediation is governed. This is especially important because due diligence is not only a technical defense. It is a governance story.

Establish repeatable evidence collection

Evidence should be collected as part of normal operations, not only during audits. Where automation is appropriate, automate. Where manual evidence is still required, standardize the format, owner, review cadence, and storage location. The objective is consistency over time.

Create executive and board visibility

Boards need reliable reporting that shows material risks, control performance, unresolved gaps, supplier exposure, incident trends, and remediation progress. The best reporting connects summary to source evidence. That gives leaders confidence that what they are seeing can be defended.

Identify gaps before time pressure arrives

The pre-designation period is the time to find weak points: unclear ownership, missing supplier evidence, outdated assessments, fragmented records, inconsistent control testing, slow remediation, or weak reporting. Preparation now creates evidence over time. Waiting creates remediation under pressure.

How 6clicks supports continuous assurance

Once the governance argument is clear, the platform requirement becomes clearer too. Organizations preparing for CCSPA should not only ask whether they have documents. They should ask whether they have infrastructure for continuous assurance.

 

6clicks supports this by helping organizations connect: requirements → risks → controls → evidence → remediation → reporting

 

With 6clicks, organizations can move from documented compliance toward demonstrated assurance through capabilities such as:

  • Automated compliance mapping, so obligations can be connected to the controls, evidence, systems, and risks they impact
  • Continuous evidence collection, so teams reduce manual evidence chasing and maintain proof over time;
  • Third-party risk management, so supplier assurance, assessments, findings, and remediation can be governed consistently;
  • Issue and remediation tracking, so gaps are visible, owned, followed through, and reportable;
  • Executive-ready dashboards and reports, so leadership can see assurance status, not just activity;
  • Multi-entity governance, supporting organizations that need centralized oversight across business units, regions, suppliers, or operating entities;
  • Sovereign deployment, for organizations with governance workflows that involve data residency, operational limitations, or restricted environments.

 

6clicks provides the assurance infrastructure to help organizations build, connect, and maintain the evidence they need to demonstrate cyber governance, third-party oversight, remediation, and leadership visibility. That is the difference between preparing a document and operating a defensible governance model.

Conclusion

The CCSPA is not yet a universal compliance obligation across every Canadian organization in the sectors it may affect, but building evidence takes time.

 

If an organization becomes a designated operator, supplies into a designated environment, or faces rising assurance expectations from customers and boards, the preparation window should not be wasted.

A due diligence defense is only as strong as the evidence behind it. That evidence is built through governance discipline: identifying obligations, taking action, operating controls, maintaining records, and giving leadership reliable oversight. Designation is coming. Evidence takes longer.

Start building the evidence before designation arrives

Explore how 6clicks helps Canadian organizations connect requirements, risks, controls, third-party assurance, evidence, remediation, and board-ready reporting in one continuous assurance model. Book a CCSPA readiness walkthrough with us.