Date: July 2, 2026

From:

Stephen D. Burt

Associate Deputy Minister and Chief Strategy, Artificial Intelligence and Data Officer

Ministry of Public and Business Service Delivery and Procurement 

Mohammad Qureshi

Associate Deputy Minister and Corporate Chief Information Officer

Office of the Corporate Chief Information Officer 

Government Information Technology Ontario (GovTechON) 

Ministry of Public and Business Service Delivery and Procurement

Subject: EDSTA Regulations Now in Force – Operational Support Resources Available

Effective July 1, 2026, new regulations under the Enhancing Digital Security and Trust Act, 2024 (EDSTA) came into force. These regulations strengthen cyber security protection across select broader public sector (BPS) organizations and improve transparency in how school boards manage children’s data. These regulations establish requirements for in‑scope BPS organizations and support Ontario’s commitment to protecting public data and digital services.

Organizations in scope:

 The initial phase of the cyber security regulation applies to:

  • School boards
  • Acute care hospitals
  • Children’s aid societies
  • Colleges and universities

Available resources:

To support implementation Cyber Security Ontario has expanded tools and guidance available on its website including:

EDSTA Overview: A practical and easy-to-understand summary of the regulations that outlines what in-scope organizations must do to meet the cyber security requirements and the resources available to support compliance, including sector-specific frequently asked questions.

Cyber Security Maturity Assessment (CMA) Tool: An easy-to-use tool designed to minimize administrative burden and help organizations assess their cyber security posture, identify gaps and prioritize improvements. While the tool supports EDSTA readiness, it is available to all BPS organizations.

Cyber Contact Registry: Allows only in-scope organizations to submit required cyber security contact information in alignment with the EDSTA cyber security regulation.

Critical Incident Reporting: Provides a standard way for all BPS organizations to report critical cyber security incidents to Ontario’s Cyber Security Operations Centre.

For detailed requirements about the cyber security regulation, including examples and timelines, please refer to the Implementation Guidance for the Cyber Security Regulation.

For detailed requirements about the regulation for digital technology affecting individuals under 18 years of age, please refer to Implementation Guidance for School Boards.

If you have any questions, please contact cybersecurity@ontario.ca.

Original signed by

Stephen D. Burt

Associate Deputy Minister and Chief Strategy, Artificial Intelligence and Data Officer

Ministry of Public and Business Service Delivery and Procurement 

Mohammad Qureshi

Associate Deputy Minister and Corporate Chief Information Officer

Office of the Corporate Chief Information Officer 

Government Information Technology Ontario (GovTechON) 

Ministry of Public and Business Service Delivery and Procurement