New Federal Cyber Rules Are Reshaping Who Can Win Canada's Shipbuilding Work as a Mississauga Summit Convenes the Sector September 29
Photo Courtesy: Unsplash.com

New Federal Cyber Rules Are Reshaping Who Can Win Canada’s Shipbuilding Work as a Mississauga Summit Convenes the Sector September 29

Canadian firms competing for defense and marine contracts are working against a federal certification requirement that did not exist a year ago, introduced by Public Services and Procurement Canada in April and reinforced by a critical infrastructure law that received Royal Assent in June. The C-SCRM Summit, a one-day event at the Luxe Convention Center in Mississauga on Tuesday, September 29, has built its 2026 program around that shift, adding a marine track curated with the Canadian Marine Industries and Shipbuilding Association.

Key Takeaways

● Level 1 of the Canadian Program for Cyber Security Certification took effect April 14, requiring an annual self-assessment against 13 controls. Levels 2 and 3 phase in from April 2027.

● The United States suspended Phase II of its comparable CMMC program on July 13, leaving firms that sell on both sides of the border facing divergent requirements.

● A cyberattack detected on August 4 forced the North Carolina State Ports Authority’s three facilities to process cargo manually for several days.

● Verizon’s 2026 Data Breach Investigations Report found third parties involved in 48% of breaches, up 60% from the previous year’s 30%.

● The summit’s speakers page still lists several main-hall presenters as “to be announced.”

The significance is less the conference than the compliance calendar behind it. Canada is standing up a supplier certification regime at the same moment Washington has paused its own, while roughly $180 billion in defense procurement opportunities move through a ten-year pipeline.

What Ottawa Changed This Year

Level 1 is an annual self-attestation against 13 controls drawn from ITSP.10.171, the Canadian Center for Cyber Security’s standard, itself adapted from American NIST guidance. It applies to select defense contracts, and PSPC has been explicit that certification “will not be required throughout the bidding process, rather, only upon contract award.” Level 2, an external assessment against 98 controls, and Level 3, assessed by the Government of Canada against 200, are to be phased in between April 2027 and March 2028.

Bill C-8 received Royal Assent on June 15, bringing the Critical Cyber Systems Protection Act onto the statute books. The Act is not yet in force. Its provisions await regulations naming the classes of operators captured. Its designated vital services include transportation systems within the legislative authority of Parliament, a category expected to reach federally regulated marine operators, and it obliges those operators to mitigate third-party risk once identified. Penalties reach $15 million per violation for organizations.

Why Did Washington Pause Its Own Program?

On July 13, the U.S. Department of War, formerly the Department of Defense, suspended Phase II of the Cybersecurity Maturity Model Certification program, due to take effect November 10. The department said it had “created prohibitive compliance costs and bureaucratic burdens,” and cited Small Business Administration data indicating compliance was “forcing innovative companies out of the Defense Industrial Base.” Phase I self-assessments and NIST SP 800-171 controls remain in force.

A CMMC Reform Task Force was given 60 days to report, putting its recommendations due in mid-September. Its request for information closed August 14. The summit’s defense panel, which lists CMMC among its subjects, convenes after that deadline.

The Incidents Are Not Hypothetical

A cyberattack detected on Tuesday, August 4, hit the North Carolina State Ports Authority’s systems, affecting the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port. Vessel calls continued, but cargo processing dropped to manual operations and gate openings were delayed. A port spokesperson said the breach had been contained but that “operations are still being processed manually.” No group claimed responsibility.

The Canadian Center for Cyber Security assessed in February that ransomware is “almost certainly the most likely” disruptive cyber threat to the marine transportation system, citing the July 2023 attack attributed to LockBit 3.0 that halted container operations at the Port of Nagoya for several days. Marine transportation carried 24% of Canadian merchandise imports in 2023.

The rules are widening rather than settling. The U.S. Coast Guard’s maritime cyber rule requires American-flagged vessels, regulated facilities and offshore installations to submit cybersecurity plans by July 2027, with training obligations that took effect in January. The International Maritime Organization adopted its first code for autonomous surface ships in May. It is non-mandatory, with a mandatory instrument targeted for adoption in 2030 and entry into force in 2032.

What the Summit Has Programmed

The CMISA marine track runs parallel to the main hall. CMISA board chair Marlene Conway Diels moderates a panel on legal and operational response, Tyson Macaulay of the National Center for Critical Infrastructure Protection, Security and Resilience leads a workshop on infrastructure mapping, and Seaspan cyber security control specialist George Browne closes the track.

The commercial backdrop explains why the track exists. The keel for the future HMCS Fraser, the first River-class destroyer, was laid at Irving Shipbuilding on June 12 under an initial $8 billion contract funding the first six years of construction and the delivery of three ships. Ottawa announced in March that Canada had reached NATO’s 2% of GDP defense benchmark in the 2025-26 fiscal year, and February’s Defense Industrial Strategy set a target of 70% of acquisitions going to Canadian firms. Tier-two work packages are being awarded now.

Whether a single day in Mississauga moves any of that is unknowable in advance. What is measurable is narrower: how many mid-market suppliers feeding those programs complete a Level 1 attestation before a buyer asks for it, rather than after.

This article features branded content from a third party. Opinions in this article do not reflect the opinions and beliefs of New York Weekly.