Federal · O-2.7 was amendedIn force March 26, 2026 · detected October 1, 2026

Upcoming changes will add cybersecurity law to OSFI's oversight and cost-recovery scope

Office of the Superintendent of Financial Institutions Act

Plain-language summary · AI-assisted · not legal advice

Two amendments that are not yet in force will extend the Superintendent of Financial Institutions' administrative reach to include the Critical Cyber Systems Protection Act. Once in force, OSFI will be required to include expenses related to administering that Act when calculating the annual levy it assesses on regulated financial institutions. The Critical Cyber Systems Protection Act will also be added to the schedule of laws listed under the Act. Federally regulated financial institutions—banks, insurance companies, trust and loan companies, cooperative credit associations, and Green Shield Canada—should expect that costs tied to OSFI's cyber-systems oversight activities may be factored into future assessments. No action is required now, but compliance and finance teams at affected institutions should monitor when these provisions come into force.

Who this affects: federally regulated banks · federally regulated insurance companies · trust and loan companies · cooperative credit associations · Green Shield Canada

Source of truth: O-2.7 on the official source

Legislative text © King's Printer for Ontario. This page is not an official version of the law and is not legal advice. Verify against the official source before acting.

Get changes like this in your inbox, every Friday.