Ontario Now Mandates Cyber Security Programs and Maturity Assessments for Key Public Organizations – Deadline July 1, 2027

Ontario’s new cyber security regulation under the Enhancing Digital Security and Trust Act, 2024 came into force on July 1, 2026. If your organization is covered by this law, you’re required to set up a cyber security program and complete a cyber security maturity assessment (CMA) by July 1, 2027.
Who's In Scope
The cyber security regulation applies to the following categories of prescribed public-sector entities:
Children’s Aid Societies, including Indigenous Child and Family Well-being Agencies
School Boards
Colleges and Universities
Public Hospitals graded as a Group A, B or C hospital under the Public Hospitals Act
The University of Ottawa Heart Institute
For organizations that are not currently in scope, the Ministry’s Implementation Guidance states that the requirements and its guidance may be used by other organizations on a voluntary basis.
What Do Covered Organizations Have to Do?
At a minimum, covered entities must:
Develop and implement a cyber security program
Covered entities are now required to have a formal cyber security program.
Designate a primary cyber security point of contact and an alternate point of contact
This individual needs to be a senior management employee with decision-making authority over cyber security matters.
Complete an initial CMA
This involves evaluating the organization’s cyber security strengths, weaknesses, and readiness to manage cyber risk.
Submit a summary of the CMA to the Ministry of Public and Business Service Delivery and Procurement’s (Ministry) Chief Information Security Officer (CISO)
The summary must be approved by the organization’s primary point of contact before it is submitted.
Repeat the CMA at least every two years.
After the initial CMA, the next assessment must be completed no later than the second anniversary of the initial assessment, and at least once within every two-year period after that.
Report critical cyber security incidents.
In-scope organizations must report critical cyber security incidents to the Ministry within 72 hours after confirming an incident.
CMA Requirements
A CMA is an assessment or evaluation of the entity’s status or progress with respect to cyber security, aligned with NIST CSF 2.0.
The assessment summary must include a description of the assessment method, the model or framework used, the organization’s overall maturity score and along with a summary of other scores from the NIST assessment, and a summary of areas for future improvement.
Programs for Ensuring Cyber Security
The regulation does not prescribe a detailed control-by-control cyber security program, but it requires the program to include at least the following key governance and reporting components:
Roles and responsibilities of specified individuals within the public sector entity relating to ensuring cyber security;
Reporting on the public sector entity’s progress with respect to ensuring cyber security;
Education and awareness measures respecting cyber security;
Response and recovery measures for incidents relating to cyber security; and
Oversight measures for implementation of the program.
Key Timeline
July 1, 2026: O. Reg. 51/26 comes into force.
By July 1, 2027: Initial CMA due.
Within 30 business days after completing the assessment: Summary due to the Ministry’s CISO.
Every two years after the initial CMA: Repeat maturity assessments are required.





