2026-10-01
Added
The Canadian Securities Administrators publish Draft Regulation 26-101 for a 120-day comment period ending January 29, 2027, to consolidate and harmonize existing IT system requirements for market infrastructure entities (MIEs) into a single regulation. The draft introduces minor clarifications, including definitions for critical systems and specified MIEs, and extends reporting obligations for system integrity events to trade repositories and matching service utilities. It also mandates that recognized clearing agencies and trade repositories develop policies ensuring critical systems can resume operations within two hours following a disruptive event. The notice includes consequential amendments to Regulation 21-101 that remove specific notification thresholds for alternative trading systems and update related forms without creating new regulatory requirements.
AMF published 21 documents in the last 30 days — get each new one by email the day it lands.
CSA Notice of Consultation
Draft Regulation 26-101 respecting Information Technology System Integrity Draft Policy Statement to Regulation 26-101 respecting Information Technology System Integrity October 1, 2026 Introduction The Canadian Securities Administrators (the CSA or we) are publishing the following (the Draft Materials) for a 120-day comment period1 :
We are issuing this notice to solicit comments on the Draft Materials. We welcome all comments on this publication. We have also included specific questions for your consideration in Annex A “Consultation Questions for Phase 2” below. The comment period will end on January 29, 2027. The text of the Draft Materials is published with this notice and is also available on the websites of the following CSA jurisdictions:
www.asc.ca www.bcsc.bc.ca www.fcaa.gov.sk.ca www.fcnb.ca www.lautorite.qc.ca https://mbsecurities.ca www.nssc.novascotia.ca www.osc.ca Background Information technology (IT) plays a significant role in supporting Canadian financial markets. IT has enabled a substantial increase in the speed of transaction execution, provided greater market access to a broad range of market participants, and enhanced the efficiency and sophistication of trading and related functions. Specifically, IT systems allow market infrastructure entities to facilitate, among other things, order entry and routing, trade execution, clearing and settlement of transactions, trade reporting, public dissemination of data, and market surveillance. At the same time, the rapid pace of change in IT and the consequent advent of new technologies may lead to increased risks for all of these operational functions essential to financial markets. These risks will evolve, and some will likely increase as new technologies play a larger role in our capital markets. By providing a robust regulatory framework, we aim to preserve the stability, efficiency and integrity of Canadian financial markets. This will help avoid the financial losses, erosion of market confidence, and potential market instability that could arise from the disruption of market infrastructure entities’ IT systems. The Draft Regulation consolidates the current IT-related requirements for various types of market infrastructure entities into a single regulation, harmonizes similar wording and provisions, and introduces a few additional obligations for greater consistency across these entities. In our view, these additions do not constitute major changes. Currently, the following market infrastructure entities are subject to a regulatory framework that includes IT system requirements:
Having IT system requirements spread across the Source Regulations may present inefficiencies and challenges for MIEs. This fragmentation makes it more difficult to ensure consistent implementation of similar policy objectives and can result in outdated provisions that no longer reflect current international standards and industry practices. Consistently updating the various Source Regulations can be also challenging, particularly when addressing emerging risks and concerns associated with the rapid pace of development of IT and the emergence of new technologies. Since amendments to system requirements have been introduced at different times across the Source Regulations, some inconsistencies in language and interpretation have emerged. Streamlining these requirements is necessary to enhance regulatory coherence and to support more efficient compliance by MIEs. This initiative aims to eliminate drafting and interpretation inconsistencies across the Source Regulations. Having all IT system requirements consolidated into a single regulation will provide MIEs with clearer and more consistent requirements. That said, we acknowledge that applying uniform ITrelated requirements to all MIEs may not be appropriate in all circumstances, particularly when the differences across those requirements are substantive. We have also considered the distinct roles MIEs play within financial markets, in addition to international standards that may reflect these distinct roles. These include the 2012 Principles for financial market infrastructures published by the Committee on Payments and Market Infrastructures and the International Organization of Securities Commissions (PFMIs). As a result, harmonization would only occur where appropriate. If adopted, the Draft Regulation will establish a foundation from which the CSA can continue to effectively modernize IT system requirements, and that will allow us to better optimize regulatory approaches to the oversight of MIEs. The CSA will be able to respond more efficiently to future developments by eliminating the current difficulties associated with amending different Source Regulations at different times. Furthermore, the Draft Regulation will increase the clarity and efficiency of IT-related requirements applicable to MIEs by eliminating drafting discrepancies across the Source Regulations. Given the role that MIEs’ IT systems play in preserving the integrity and stability of Canadian financial markets, we are of the view that it is appropriate to consolidate the IT-related system requirements in the Source Regulations into one new regulation. (2) A foundation for future modernization Once the Draft Regulation comes into effect, we plan to modernize it to better align current IT system requirements with international standards (Phase 2). Existing IT system requirements do not completely capture international standards and current best industry practices. We expect Phase 2 to allow the CSA to better address risks
associated with, notably:
Phase 2 will also enable the CSA to:
regulatory authority to consider whether a marketplace is an exchange for purposes of Canadian securities legislation.
The new terms in the Definitions section include:
(1) “critical system”
We define this term as including the essential functions of each MIE (even if those functions are outsourced). For example, the functions include order entry, routing and execution for marketplaces; clearing, settlement and depository functions for recognized clearing agencies; and trade-matching functions for matching service utilities. While the Source Regulations use various terms to describe the systems relating to an MIE's essential functions, we consider the term “critical” to be more appropriate as it aligns with the terminology used in the PFMIs. In our view the change in language will not narrow the scope of the related requirements applicable to marketplaces, information processors, matching services utilities or trade repositories. (2) “critical service” Similar to “critical system”, we define “critical service” in connection with an entity’s essential functions. In this case, however, the term applies only to a subset of MIEs in the context of outsourcing:
marketplaces, recognized clearing agencies and trade repositories (see "specified MIE" below). (3) ” MIE” An MIE includes all market infrastructure entities that are subject to the Draft Regulation – marketplaces, information processors, recognized clearing agencies, matching service utilities and trade repositories. It is not our intention for the Draft Regulation to apply to marketplaces (exchanges or ATSs, including crypto asset trading platforms) that have been exempted from the existing IT systems requirements in Regulation 21-101. (4) “market surveillance system” While this is a new definition, it was drawn from subsection 12.4(3) of Regulation 21-101, describing critical systems operated by or on behalf of regulation services providers or certain types of marketplaces that support real-time market surveillance. (5) “system integrity event” The definition of a system integrity event is based on language in the Source Regulations and refers to material malfunctions, failures, delays and security incidents in critical systems. An MIE that experiences a system integrity event must report it to the regulator, except in Québec, or the securities regulatory authority.
(6) “specified MIE”
A specified MIE means a market infrastructure entity that is a marketplace, a recognized clearing agency, or a trade repository. These entities are subject to more comprehensive IT system requirements8 than other MIEs. System Integrity Requirements for MIEs The Draft Regulation would establish a regulatory framework for critical and auxiliary systems that closely mirrors the existing provisions in the Source Regulations. As is currently the case, the critical system requirements would apply to all MIEs, while the auxiliary system requirements would apply only to marketplaces and recognized clearing agencies. To promote consistency in IT-related requirements across all MIEs, the Draft Regulation introduces three minor changes:
Requirements for Pre-operational and System Changes that are Material The Draft Regulation would make structural changes to the testing provisions in the Source Regulations. These changes are intended to provide greater clarity by separating the pre-operational and post-operational testing requirements applicable to specified MIEs and putting them in different Parts of the Draft Regulation. Part 3 of the Draft Regulation outlines the obligations specified MIEs must fulfill prior to starting operations. Part 4 then sets out the testing and access requirements applicable before a material system change can be made. Apart from these structural and related drafting changes, the requirements would remain unchanged. Business Continuity In Part 5, we consolidate the requirements related to business continuity and harmonize wording from the Source Regulations. The provisions concerning resumption of operations and industry-wide business continuity testing requirements are unchanged, with some minor exceptions. First, a recognized clearing agency or a trade repository would have to develop, maintain, and apply policies and procedures reasonably designed to ensure that its critical system could resume operations within two hours following a disruptive event. This two-hour recovery timeframe is included in the PFMIs, which are incorporated by reference into Regulation 24-102 and are therefore already a legal requirement for a recognized clearing agency under Canadian securities legislation. For a trade repository, the recovery timeframe is currently set out in the policy statement to the applicable Source Regulation and would be incorporated directly into the Draft Regulation in order to consolidate the location of this timeframe for all MIEs. It is important to note that this requirement pertains to the existence of policies and procedures that support recovery within the specified timeframe, rather than imposing a strict obligation to resume operations within two hours. In addition, we would extend the requirement to test an MIE’s business continuity plan (including its disaster recovery plan) to matching service utilities. This testing requirement currently applies to all the other MIEs. In our view, this change should not impose any new operational requirements on matching service utilities, as we would not consider a business continuity requirement to be effective if it was not tested on a regular basis. Similarly, we would remove a requirement, currently applicable only to trade repositories, that a business continuity plan must provide for the appropriate exercise of authority. In our view it is not necessary to make this requirement explicit, as a business continuity plan that did not provide for the authority to implement the plan, or that did not clearly assign roles for carrying it out, would be ineffective and therefore not compliant with the requirements of Part 5 of the Draft Regulation. Outsourcing The Draft Regulation would incorporate and
harmonize the outsourcing provisions taken from the Source Regulations, which are close to but not entirely identical. While the Draft Regulation defines the terms “critical service” and “critical system” for the entities that are subject to these requirements, it is
not our intent to reduce the scope of the current outsourcing provisions to cover only IT-related services or systems. For this reason, we added cross-references to the Draft Regulation’s outsourcing requirements into the amended Source Regulations, as appropriate. Given that the definitions of critical system and critical service would only apply in the Draft Regulation, other key outsourcing services or systems9 would continue to be covered in the Source Regulations as is the case today. The replacement of the outsourcing provisions in the Source Regulations with the cross-references to the Draft Regulation is intended to facilitate harmonization and avoid the need to amend multiple instruments going forward. As a consequential amendment arising from this approach, in order to avoid confusion between the cross-reference incorporated in Regulation 24-102 and the outsourcing provisions set out in the Draft Regulation, we would replace the term “critical service or system” currently used for recognized clearing agencies with “key service or system”. Vulnerability Assessments and System Reviews
Part 7 of the Draft Regulation reorganizes the IT system requirements related to vulnerability testing
and system reviews. While the substance of these requirements remains consistent with the Source Regulations, we are proposing two updates:
Alternatives Considered to the Draft Regulation The alternative to the Draft Materials would be not to proceed with the creation of the Draft Regulation. However, in our view, not proceeding with the consolidation and harmonization of the existing IT system requirements applicable to MIEs would fail to address the risks inherent in the current regulatory framework, where the requirements are spread across multiple Source Regulations, making it difficult to harmonize and effectively respond to emerging developments. This aggravates the risk of technological vulnerabilities in an environment where there is rapid adoption of new technologies which were not considered when the Source Regulations were created and amended. Moreover, we are considering a larger-scale modernization of the systems and outsourcing regulatory framework applicable to MIEs in Phase 2. The creation of a new foundation with the Draft Regulation is the precursor to this initiative. Unpublished Materials In developing the Draft Materials we have not relied on any significant unpublished study, report or other written materials. Local Matters An annex is being published in any local jurisdiction that is making changes to local securities laws, including local notices or other policy instruments in that jurisdiction. It also includes any additional information that is relevant to that jurisdiction only. List of Annexes This notice contains the following annexes:
Annex A – Consultation Questions for Phase 2
Annex B – Table of Concordance
Authority of the Draft Regulation and Draft Policy Statement The securities legislation in each of the CSA jurisdictions provides the regulator or the securities regulatory authority with rule-making or regulatory authority in respect of the subject matter of the Draft Regulation. How to Provide Comments We welcome your comments on the Draft Materials, and also invite comments on the consultation questions for Phase 2 which can be found in Annex A of this Notice. Please submit your comments on or before January 29, 2027.
Submit your comments here: https://www.securities-administrators.ca/consultations/. By using the link, your comments will be submitted to the following CSA members:
Alberta Securities Commission
Autorité des marchés financiers
BC Securities Commission
Financial and Consumer Affairs Authority of Saskatchewan Financial and Consumer Services Commission of New Brunswick Manitoba Securities Commission Northwest Territories Office of the Superintendent of Securities Nova Scotia Securities Commission Nunavut Securities Office Office of the Superintendent of Securities, Service NL Office of the Yukon Superintendent of Securities Ontario Securities Commission Superintendent of Securities, Department of Justice and Public Safety, Prince Edward Island If Québec is a participating jurisdiction, and you are submitting your comments through the link above, you are also submitting your comments to:
Me Philippe Lebel
Corporate Secretary and Executive Director, Legal Affairs Autorité des marchés financiers Place de la Cité, tour PwC 2640, boulevard Laurier, bureau 400 Québec (Québec) G1V 5C1 Fax: 514 864-6381 E-mail: consultation-en-cours@lautorite.qc.ca We cannot keep submissions confidential because securities legislation in certain provinces requires publication of the written comments received during the comment period. Comments received will be posted on the websites of each of the Alberta Securities Commission at www.albertasecurities.com, the Autorité des marchés financiers at www.lautorite.qc.ca and the Ontario Securities Commission at www.osc.ca. You should not include personal information directly in comments as the comments will be published and publicly available. It is important that you state on whose behalf you are making the submission.
Questions
Please refer your questions to any of the following CSA staff:
Autorité des marchés financiers
Julie Boyer
Senior Policy Advisor
Email: julie.boyer@lautorite.qc.ca
Alberta Securities Commission
Julio Arboleda Ramirez
Senior Legal Counsel
Email: julio.arboledaramirez@asc.ca
BC Securities Commission
Catherine Tearoe
Senior Legal Counsel
Email: ctearoe@bcsc.bc.ca
Financial and Consumer Affairs Authority of Saskatchewan Curtis Brezinski Acting Director, Capital Markets, Securities Division Email: curtis.brezinski@gov.sk.ca Financial and Consumer Services Commission of New Brunswick Nick Doyle Legal Counsel Email: nick.doyle@fcnb.ca The Manitoba Securities Commission Angela Duong Deputy Director, Compliance and Oversight Email: angela.duong@gov.mb.ca
Nova Scotia Securities Commission
Doug Harris
General Counsel, Director of Market Regulation and Policy and Secretary Email: doug.harris@novascotia.ca Ontario Securities Commission Stacey Barker Senior Accountant, Trading & Markets Email: sbarker@osc.ca Stephanie Wakefield Senior Legal Counsel, Trading & Markets Email: swakefield@osc.ca
Annex A
Consultation Questions for Phase 2
We welcome your comments on the consultation questions for Phase 2 listed below. Please provide your comments in writing on or before January 29, 2027. Harmonization of current requirements Question 1:
Should we impose different requirements for different types of entities, or have a single set of requirements that applies to all entities? Please explain. Question 2:
Should distinct requirements be imposed according to the entity’s relative importance or function within the market? Please explain. Scope of entities Question 3:
Should Phase 2 include registered entities such as registrant firms and investment fund issuers? Please explain. Question 4:
Should other types of entities be included in Phase 2 to better align with international standards and facilitate harmonized regulatory treatment across entities? For example:
a) Should Phase 2 include market structure entities other than MIEs, such as benchmark administrators? Please explain. b) Should regulation services providers or self-regulatory authorities be brought into Phase 2? Please explain. Question 5:
What factors should be considered in determining whether an entity should be included in Phase 2? Outsourcing and third-party risks management Question 6:
Should the outsourcing provisions be extended beyond specified MIEs and apply to all MIEs? Please explain.
Question 7:
Should the outsourcing provisions include more specific obligations for managing risks related to outsourced technologies, such as AI? This could include governance, due diligence, certification, or reporting on the robustness and reliability of an outsourced technology. Question 8:
In your view, which aspects of outsourcing (increasingly referred to as “third-party risk management”) should be strengthened? Please explain. In particular, we invite feedback on the following:
Question 12:
Given the increasing use of AI systems in capital markets, should Phase 2 include specific requirements regarding AI risk management consistent with the guidance in CSA Staff Notice and Consultation 11- 348 Applicability of Canadian Securities Laws and the Use of Artificial Intelligence Systems in Capital Markets? a) Should there be minimum standards for AI system oversight and transparency regarding AIdriven decision-making? b) Should there be requirements for documenting and reporting to regulators on AI system uses in connection with a critical system or critical service? Other Question 13:
What other issues should we consider in Phase 2? Please explain.
Annex B
Table of Concordance
Regulation 26-101 Provisions Regulation
21-101
Regulation
24-102
Trade
Reporting
Rules1
Regulation
21-101 -
Information
Processor
Regulation
24-101 -
Matching
Service Utility
Part 2 – System Integrity Requirements
Operational risk management framework s. 2(1) s. 21(1) s. 2(2) s. 21(2) Requirements for critical systems s. 3(a) s. 12.1(a) s. 4.6(a) s. 21(3)(a) s. 14.5(a) s. 3(b) s. 12.1(b) s. 4.6(b) s. 21(3)(b) s. 14.5(b) s. 6.5(a)(i) s. 6.5(a)(ii) System integrity event s. 4(1) s. 12.1(c) s. 4.6(c) s. 21(3)(c) s. 14.5(e) s. 6.5(c) s. 4(2) s. 12.1(c) s. 4.6(c) s. 14.5(e) s. 4(3) s. 12.1(c) s. 4.6(c) s. 21(3)(c) s. 14.5(e) Recordkeeping for system incidents s. 5 s. 12.1(d) s. 4.6(d) s. 14.5(f) s. 6.4(1) Requirements for auxiliary systems s. 6(1) s. 12.1.1(a) s. 4.6.1(2)(a) s. 6(2) s. 12.1.1(c) s. 4.6.1(2)(c) s. 6(3) s. 12.1.1(b) s. 4.6.1(2)(b) s. 6(4) s. 12.1.1(b) s. 4.6.1(2)(b)
Part 3 – Pre-operational Requirements – Specified
MIE
Availability of technology requirements and testing facilities 1 Local and multi-jurisdictional trade reporting regulations: Manitoba Securities Commission Rule 91-507 Derivatives: Trade Reporting; Ontario Securities Commission Rule 91-507 Derivatives: Trade Reporting; Regulation 91-507 respecting Trade Repositories and Derivatives Data Reporting (Québec); and Multilateral Instrument 96-101 Derivatives: Trade Reporting.
Regulation 26-101 Provisions Regulation
21-101
Regulation
24-102
Trade
Reporting
Rules1
Regulation
21-101 -
Information
Processor
Regulation
24-101 -
Matching
Service Utility s. 7(1)(a) s. 12.3(1)(a) s. 4.8(1)(a) s. 21(8)(a) s. 7(1)(b) s. 12.3(2)(a) s. 4.8(2)(a) s. 21(9)(a) s. 7(2) s. 12.3(1) s. 21(8) s. 7(3) s. 4.8(1) Time period for availability - marketplace s. 8(a) s. 12.3(1)(a) s. 8(b) s. 12.3(2)(a) Time period for availability – clearing agency and trade repository s. 9 s. 4.8(2)(a) s. 21(9)(a) Confirmation and certification s. 10 s. 12.3(3)(b) s. 11 s. 12.3(3)(c) s. 4.8(3)(b)
Part 4 – Requirements for Changes that are Material
Availability of technology requirements and testing facilities s. 12(1)(a) s. 12.3(1)(b) s. 4.8(1)(b) s. 21(8)(b) s. 12(1)(b) s. 12.3(2)(b) s. 4.8(2)(b) s. 21(9)(b) s. 12(2) s. 12.3(1) s. 21(8) s. 12(3) s. 4.8(1)(b) Time period for availability – marketplace 13(a) 12.3(1)(b) 13(b) 12.3(2)(b) Time period of availability - clearing agency and trade repository s. 14 s. 4.8(1)(b) s. 4.8(2)(b) s. 21(8)(b) s. 21(9)(b)
Regulation 26-101 Provisions Regulation
21-101
Regulation
24-102
Trade
Reporting
Rules1
Regulation
21-101 -
Information
Processor
Regulation
24-101 -
Matching
Service Utility
Compliance and certification s. 15(1) s.12.3(3.1)(b) s. 4.8(4)(b) s. 15(2) Emergency exception s. 16(1)(a) s. 12.3(4) s. 4.8(5) s. 21(11)(a) s. 16(1)(b) s. 12.3(4)(a) s. 4.8(5)(a) s. 21(11)(b) s. 16(1)(c) s. 12.3(4)(b) s. 4.8(5)(b) s. 21(11)(c) s. 16(2) s. 12.3.(4)(b) s. 21(11)(c) s. 16(3) s. 4.8(5)(b) Uniform test symbols s. 17 s. 12.3.1
Part 5 – Business Continuity
Business continuity planning s. 18(1) s.12.4(1)(a) s. 4.9(a) s. 21(4) s. 14.6(a) s. 6.5(a)(v) s. 18(2) s.12.4(1)(b) s. 4.9(b) s. 21(5) s. 14.6(b) Resumption of operations s. 19(1) s. 19(1)(a) s. 14(6)(c) s. 19(1)(b) s. 12.4(2) s. 19(1)(c) s. 3.1: PFMI Principle 17 – Key Consideration s. 19(2) s. 19(2)(a) s. 12.4(3) s. 19(2)(b) s. 12.4(4) Industry-wide business continuity tests
Regulation 26-101 Provisions Regulation
21-101
Regulation
24-102
Trade
Reporting
Rules1
Regulation
21-101 -
Information
Processor
Regulation
24-101 -
Matching
Service Utility s. 20 s. 12.4.1 s. 12.4.1 of
Regulation
21-101 s. 12.4.1
Part 6 – Outsourcing
Outsourcing s. 21(a) s. 5.12(a) s. 4.10(a) s. 24(a) s. 21(b) s. 5.12(b) s. 4.10(b) s. 24(b) s. 21(c) s. 5.12(c) s. 4.10(c) s. 24(c) s. 21(d) s. 5.12(d) s. 4.10(d) s. 24(d) s. 21(e) s. 5.12(e) s. 4.10(e) s. 24(e) s. 21(f) s. 5.12(f) s. 4.10(g) s. 24(g) s. 21(g) s. 4.10(f) s. 24(f) s. 21(h) s. 5.12(g) s. 4.10(h) s. 24(h) s. 21(i) s. 4.10(h) s. 21(j) s. 5.12(h) s. 4.10(i) s. 24(i)
Part 7 - Vulnerability Testing and System Reviews
Vulnerability assessments s. 22 s. 12.1.2 s. 4.7(1)(b) s. 14.5.1 s. 6.5(a)(iv) System reviews s. 23(1) s. 12.2(1) s. 4.7(1)(a) s. 21(6) s. 14.5(c) s. 6.5(b) s. 23(2) s. 12.2(1) s. 4.7(1)(a) s. 14.5(c) s. 23(3) s. 12.2(2) s. 4.7(2) s. 21(7) s. 14.5(d)
Part 8 – Books and Records
s. 24(1) s. 11.1 s. 5.1(1) s. 18 relates to derivatives data s. 14.4(3) s. 6.4(2) s. 24(2) S 11.3(1) s. 5.1(2) s. 18 relates to derivatives data
Read the rest free
Source: Autorite des marches financiers Quebec — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from AMF
AMF published 21 documents in the last 30 days. We email you each new one the day it's published.