Canada: OSFI B-13, E-21 And The 2035 Quantum Readiness Horizon
Canada pairs a dated post-quantum roadmap for federal systems with OSFI guidelines for banks and insurers. Here is what is binding, what is guidance, and which dates matter, as of October 2026.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Canada runs two separate tracks on post-quantum cryptography. The federal government has set itself dated migration targets for its own non-classified systems. Financial institutions are steered by the Office of the Superintendent of Financial Institutions (OSFI), whose guidelines already cover cryptography in general terms and whose newer quantum bulletin points towards 2035.
This article sets out both tracks as of October 2026, explains the legal weight of each document, and flags the one piece of legislation still waiting to take effect. It is general information, not legal advice. For the wider picture, start with the regional overview, and for the detail of how roadmaps compare across countries, see Cryptography Compliance.
The Federal Government Track
The Canadian Centre for Cyber Security published its roadmap for migrating Government of Canada systems to post-quantum cryptography, ITSM.40.001, in June 2025. It covers non-classified systems and reads as a government strategy rather than a rule for the private sector.1 Departments were to have an initial migration plan by April 2026 and report on progress every year from then. High-priority systems should finish migrating by the end of 2031 and the remaining systems by the end of 2035.1
The roadmap is precise about what “complete” means. A system counts as migrated when its quantum-vulnerable algorithms have been switched off, isolated or tunnelled through a protected channel.1 That definition is useful for any organisation writing its own plan, because it rules out the comfortable assumption that adding post-quantum support is the same as removing the old risk.
For private organisations, the Canadian Forum for Digital Infrastructure Resilience (CFDIR) has published, on the Innovation, Science and Economic Development Canada website, voluntary quantum-readiness best practices (version 3, June 2023). They are guidance.2
The Financial Sector Track
OSFI supervises federally regulated banks and insurers. Its guidelines are supervisory expectations: OSFI does not describe them as statutes, but supervised institutions are assessed against them.
Guideline B-13, Technology and Cyber Risk Management (Supervisory). Issued in July 2022 and effective since 1 January 2024, B-13 contains the clearest cryptography expectation in Canadian financial supervision. Section 3.2.2 asks institutions to use strong cryptographic technologies, protect keys across their full lifecycle, and check from time to time whether new attacks have weakened the cryptography they rely on.3 Quantum computing is not named, but a regular review against emerging threats is exactly where a quantum risk assessment belongs.
Guideline E-21, Operational Risk Management and Resilience (Supervisory). Published on 22 August 2024, E-21 says nothing specific about cryptography. It matters because of its dates. OSFI expected full adherence to section 4 by 1 September 2025 and full adherence to the whole guideline by 1 September 2026, by which point institutions should have identified and mapped their critical operations and set tolerances for disruption. Scenario testing of all critical operations should be complete by 1 September 2027.4 A cryptographic failure, such as an expired root certificate or a broken algorithm, is one of the disruptions those scenarios can cover.
Quantum Readiness Phases and Timelines (Guidance). OSFI’s Technology Risk Bulletin on quantum readiness first appeared in March 2026 and was last modified on 13 July 2026. It describes five phases: build competency and awareness, inventory cryptographic assets, assess risk and plan the migration, carry out the transition, then test, validate and anticipate. It notes that guidelines generally recommend reaching quantum readiness across all systems by 2035.5 The wording throughout is permissive, telling institutions what they can consider rather than what they must do.
- Departmental Migration Plans Due; Yearly Reporting Begins
Cyber Centre roadmap ITSM.40.001. Government strategy.
- Federal High-Priority Systems MigratedUpcoming
ITSM.40.001. Government strategy.
- Remaining Federal Non-Classified Systems MigratedUpcoming
ITSM.40.001. Government strategy.
- OSFI B-13 In Effect, Including Cryptography In Section 3.2.2
Supervisory.
- Full Adherence To OSFI E-21
Supervisory. Critical operations mapped, tolerances set.
- E-21 Scenario Testing CompleteUpcoming
Supervisory.
- Quantum Readiness Across All SystemsUpcoming
OSFI quantum bulletin. Guidance.
Legislation Still Waiting
Bill C-8 received Royal Assent on 15 June 2026 as Statutes of Canada 2026, chapter 9. Part 2 enacts the Critical Cyber Systems Protection Act, which covers federally regulated sectors including banking and clearing and settlement systems.6 As of October 2026 that part is not yet in force: it needs an Order in Council, and no date had been set in the sources reviewed for this article. When it does take effect, designated operators will face binding cyber security programme duties. The enacted text does not mention quantum computing or cryptography.
Deadlines To Watch
- In effect
Canada · Office of the Superintendent of Financial Institutions (OSFI) Supervisory
Full adherence to the guideline, including identifying and mapping critical operations and setting tolerances for disruption.
- Upcoming
Canada · Office of the Superintendent of Financial Institutions (OSFI) Supervisory
Complete scenario testing for all critical operations.
- Upcoming
Canada · Canadian Centre for Cyber Security Guidance
Migrate high-priority non-classified government systems.
- Upcoming
Canada · Canadian Centre for Cyber Security Guidance
Complete migration of the remaining non-classified government systems.
- Upcoming
Canada · Office of the Superintendent of Financial Institutions (OSFI) Guidance
Reach quantum readiness across all systems, the target the bulletin says guidelines generally recommend.
A Note On AI
As of October 2026, Canada has no federal AI statute. A new federal privacy bill, C-36, was introduced on 15 June 2026 and remains a draft.7 Ontario’s Bill 194 received Royal Assent on 25 November 2024 and gives the province powers over cyber security and AI use in its public sector, much of it exercised through regulations.8 The AI regulation at a glance article compares Canada with other regions, and AI Governance And Regulation covers the frameworks in depth.
What This Means In Practice
For a Canadian bank or insurer, the practical starting point is the B-13 expectation to keep checking whether new attacks have weakened the cryptography in use. Building a cryptographic inventory, the second of the five phases in OSFI’s bulletin, is the evidence that such a review has happened. Linking that inventory to the critical operations mapped under E-21 shows which cryptography protects which critical service, and that in turn gives the 2027 scenario tests something concrete to exercise.
Footnotes
-
Canadian Centre for Cyber Security, “Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)”, 23 June 2025. cyber.gc.ca ↩ ↩2 ↩3
-
Canadian Forum for Digital Infrastructure Resilience, “Canadian National Quantum-Readiness: Best Practices and Guidelines”, version 03, 12 June 2023. ised-isde.canada.ca ↩
-
OSFI, “Guideline B-13: Technology and Cyber Risk Management”, July 2022, effective 1 January 2024. osfi-bsif.gc.ca ↩
-
OSFI, “Operational Risk Management and Resilience: Letter” accompanying Guideline E-21, 22 August 2024. osfi-bsif.gc.ca ↩
-
OSFI, Technology Risk Bulletin, “Quantum Readiness Phases and Timelines”, March 2026, modified 13 July 2026. osfi-bsif.gc.ca ↩
-
Parliament of Canada, LEGISinfo, “Bill C-8 (45th Parliament, 1st Session)”, Royal Assent 15 June 2026. parl.ca ↩
-
Parliament of Canada, LEGISinfo, “Bill C-36 (45th Parliament, 1st Session)”, introduced 15 June 2026. parl.ca ↩
-
Legislative Assembly of Ontario, “Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024”, Royal Assent 25 November 2024. ola.org ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.