UK Cyber Security and Resilience Bill
Updates the NIS Regulations 2018: brings managed service providers and data centres into scope, adds a 24-hour initial incident notification, strengthens regulator powers and cost recovery. Cleared the Commons June 2026, in Lords Committee from 1 September 2026; substantive duties expected via secondary legislation around 2028.
| Jurisdiction | United Kingdom |
|---|---|
| Category | Cybersecurity |
| Status | Proposed |
| Latest development |
Analysis
The UK Cyber Security and Resilience (Network and Information Systems) Bill is a proposed overhaul of the UK NIS regime that will bring managed service providers (MSPs) and data centres into scope, introduce a 24‑hour initial incident notification duty, strengthen regulator powers, and modernise cost‑recovery mechanisms.Summary of the Bill – UK Government Incident reporting factsheet – UK Government Cyber Security and Resilience Bill – Parliament Bill Page
Below is a structured analysis aligned to your requested sections, with direct, clickable links for every factual claim.
Key Requirements
Scope expansion: MSPs and data centres
- Managed service providers (RMSPs) brought into NIS scope
- The UK Government’s NIS Regulations 2018 collection page confirms policy intent to bring managed service providers into scope to secure digital supply chains.The NIS Regulations 2018 – GOV.UK collection
- Factsheets for the Bill explain that the reforms will extend the existing NIS framework to relevant managed service providers, with detailed thresholds and definitions to be set in secondary legislation.Summary of the Bill – UK Government Cyber Security and Resilience Bill factsheets – overview
- Legal analysis notes that RMSPs with privileged access to client IT environments will be in scope, aligning UK rules with supply‑chain risk concerns reflected in NIS2‑style reforms.United Kingdom Proposes Changes in the Cyber Security and Resilience Bill – Mayer Brown
- Data centres classified as essential services
- Government factsheets state that data centres will be classed as operators of essential services (OES), and “data infrastructure” will become a NIS sector.Summary of the Bill – UK Government
- The incident reporting factsheet confirms that data centre operators will be subject to specific reporting criteria when incidents significantly impact the operation or continuity of data centre services, or have significant UK-wide impact.Incident reporting – UK Government
- Legal commentary explains that data centre providers meeting thresholds such as a rated IT load of 1 MW or above (non‑enterprise) and 10 MW or above (enterprise) will be deemed OES and subject to full NIS obligations.Regulating data centres: the Cyber Security and Resilience Bill – Gowling WLG United Kingdom Proposes Changes – Mayer Brown
Incident reporting: 24‑hour initial, 72‑hour full report
- Two‑stage incident reporting duty
- The Government incident reporting factsheet states that the Bill introduces a two‑stage reporting structure, requiring a light‑touch initial notification within 24 hours, followed by a full report within 72 hours.Incident reporting – UK Government
- The Bill summary similarly notes that more harmful cyber breaches will need to be reported, with initial notification within 24 hours and fuller reporting within 72 hours.Summary of the Bill – UK Government
- Legal analysis confirms that OESs, RDSPs and RMSPs must submit an initial notification within 24 hours of becoming aware of an incident, followed by a full notification within 72 hours, with specific content requirements for each stage.United Kingdom Proposes Changes – Mayer Brown
- Notification to NCSC / CSIRT and regulators
- Government guidance explains that the initial notification must be sent to the relevant regulator, with the National Cyber Security Centre (NCSC) sighted at the same time, enabling early support.Incident reporting – UK Government
- Legal commentary notes that copies of all incident notifications must also be sent to the Computer Security Incident Response Team (CSIRT) at the same time as submission to the competent authority or Information Commissioner.United Kingdom Proposes Changes – Mayer Brown
- Industry briefings describe that organisations will be required to share incident information with NCSC alongside regulators as part of the new reporting regime.Cyber Security and Resilience Bill: what you need to know – Howden Group
- Customer notification obligations
- Legal analysis highlights that data centre service providers, RDSPs and RMSPs must notify UK customers likely to be adversely affected “as soon as reasonably practicable” after submitting a full report.United Kingdom Proposes Changes – Mayer Brown
- Industry guides emphasize new expectations that RMSPs inform affected customers following significant incidents, aligning incident reporting with contractual and transparency obligations.Cyber Security and Resilience Bill: UK MSP Guide – Assurix
- Sector commentary describes these customer‑notification duties as a key driver for enhanced breach communication processes and customer trust measures.Resilience Bill: 5 Proven Steps to Avoid a 4% Turnover Fine – Indiott
Strengthened regulator powers and cost recovery
- Enhanced supervisory and enforcement powers
- Government factsheets explain that the Bill strengthens powers of NIS regulators, including enhanced inspection, information‑gathering and enforcement measures to support cyber resilience.Summary of the Bill – UK Government
- The overarching factsheet set notes amendments to data centres, relevant digital service providers, information sharing and cost recovery to reflect Committee Stage discussions, indicating an evolving but strengthened regulatory framework.Cyber Security and Resilience Bill factsheets – overview
- Legal commentary describes more robust enforcement and penalty structures, including alignment with higher fine levels and clearer investigative powers compared to the 2018 NIS Regulations.United Kingdom Proposes Changes – Mayer Brown
- Updated cost recovery mechanisms
- The Government materials outline reforms to cost recovery, allowing regulators to better recover costs of supervision and incident handling from regulated entities.Summary of the Bill – UK Government
- Factsheet updates mention minor amendments to the information‑sharing and cost‑recovery aspects of the Bill following Committee discussions, indicating active refinement.Cyber Security and Resilience Bill factsheets – overview
- Industry commentary notes that operators should anticipate regulatory fees or levies linked to oversight activities, similar to other UK sector regulators’ cost‑recovery models.Cyber Security and Resilience Bill: what changes and who is affected – Tickbox Solutions
Compliance Challenges
24‑hour detection and reporting readiness
- Continuous detection and escalation
- The incident reporting factsheet emphasizes that an initial notification must be submitted within 24 hours of becoming aware an incident is taking place, even if only limited information is known.Incident reporting – UK Government
- Industry analysis points out that this single‑day deadline requires continuous monitoring, clear escalation routes, and documented incident response playbooks, which many organisations currently lack.UK Cyber Security and Resilience Bill Committee Stage – Meridian Micro
- Industry guidance notes that organisations will need to submit initial notifications within 24 hours and fuller reports within 72 hours, representing a tightening compared to current NIS practice.Cyber Security and Resilience Bill: what you need to know – Howden Group
- Example challenge – SMEs and regional providers
- SMEs and regional MSPs are highlighted as facing disproportionate difficulty in building 24/7 monitoring and response capability needed for the new reporting regime.UK Cyber Security and Resilience Bill Committee Stage – Meridian Micro
- Industry MSP guidance notes that many MSPs do not yet have automated incident correlation and client‑impact assessment, making 24‑hour reporting operationally challenging.Cyber Security and Resilience Bill: UK MSP Guide – Assurix
- Case‑study style advisory content describes the risk of regulatory breaches and fines if organisations misjudge whether an incident meets reporting thresholds within the short timeframe.Resilience Bill: 5 Proven Steps to Avoid a 4% Turnover Fine – Indiott
Determining scope and thresholds (MSPs, data centres)
- Identifying whether services are in scope
- The NIS Regulations 2018 already require OES and RDSPs to assess whether they meet sector definitions and thresholds.The Network and Information Systems Regulations 2018 – legislation.gov.uk
- The Bill introduces new thresholds for data centres (e.g., 1 MW and 10 MW rated IT load), requiring accurate measurement and classification of data centre capacity.Regulating data centres: the Cyber Security and Resilience Bill – Gowling WLG United Kingdom Proposes Changes – Mayer Brown
- Industry commentary stresses that many MSPs and hosting providers must reassess service portfolios to determine whether they qualify as RMSPs or data centres under the new definitions.Cyber Security and Resilience Bill: what changes and who is affected – Tickbox Solutions
Integration with existing NIS and data protection obligations
- Overlap with current NIS incident duties
- The existing NIS Regulations 2018 already require OES and RDSPs to notify competent authorities or the ICO of incidents having significant or substantial impact.The Network and Information Systems Regulations 2018 – legislation.gov.uk
- ICO’s Guide to NIS indicates that existing guidance is under review because of the Data (Use and Access) Act and forthcoming changes, creating a moving compliance target for organisations.Guide to NIS – ICO
- Legal commentary warns that organisations must reconcile NIS incident reporting, data‑protection breach notification, and contractual incident reporting obligations under the new Bill.United Kingdom Proposes Changes – Mayer Brown
Resource and cost challenges
- Building compliance capabilities and paying regulatory costs
- Government materials note reforms to cost recovery, giving regulators more scope to recover supervision costs from regulated entities.Summary of the Bill – UK Government
- Industry analysis highlights the financial impact of compliance investments for data centres and MSPs, including monitoring tools, staffing and regulatory fees.Regulating data centres: the Cyber Security and Resilience Bill – Gowling WLG
- Practical guidance warns that organisations may face fines up to a percentage of global turnover for serious non‑compliance, incentivising investment but also creating cost pressure.Resilience Bill: 5 Proven Steps to Avoid a 4% Turnover Fine – Indiott
Implementation Best Practices
1. Establish robust incident detection and response processes
- Implement 24/7 monitoring and triage
- Given the 24‑hour initial notification requirement, organisations should implement continuous monitoring of critical systems to spot incidents early.Incident reporting – UK Government
- Industry guidance for MSPs recommends deploying SIEM/SOAR tools, automated alerting, and playbooks mapped to the 24‑ and 72‑hour reporting deadlines.Cyber Security and Resilience Bill: UK MSP Guide – Assurix
- Incident response standards such as NCSC’s Cyber Incident Management guidance can be leveraged to design process flows and stakeholder engagement.NCSC – Cyber incident management guidance
- Align with recognised frameworks
- The UK NCSC promotes the Cyber Assessment Framework (CAF) as a structured approach to managing risks in essential services.NCSC – Cyber Assessment Framework
- Organisations can integrate NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover) into their NIS‑aligned compliance programmes.NIST Cybersecurity Framework
- ICO’s Guide to NIS, although under review, still offers useful principles on **risk management, incident handling, and governance
Recent developments
- — The Cyber Security and Resilience Bill is reported to have passed through the House of Commons in June 2026 and is progressing through the House of Lords, with Royal Assent expected later in 2026; the article highlights expanded scope to data centres and managed service providers, stricter 24/72‑hour incident reporting, and a new two‑tier penalty regime of up to £17m or 4% of global turnover for serious breaches.[13] (source)
- — Pinsent Masons reports that recent UK cabinet changes could disrupt progress of the Cyber Security and Resilience Bill, noting that the Bill is prepared for its House of Lords committee stage in September 2026 and that planned consultations on key elements were due over the summer, raising some uncertainty around timelines and regulatory coordination.[14] (source)
- — A BBC Parliament programme covers the House of Lords second reading debate on the Cyber Security and Resilience (Network and Information Systems) Bill on 14 July 2026, reflecting ongoing parliamentary scrutiny of the Bill’s general principles and its impact on essential services and digital providers.[6] (source)
- — Mayer Brown analyses the Bill’s proposed significant amendments to the UK NIS Regulations 2018, including expanded regulatory scope, new categories of regulated entities, enhanced incident‑reporting obligations, and increased enforcement powers and penalties, highlighting divergences from the EU’s NIS2 framework and practical compliance implications for UK‑based organisations.[1] (source)
- — The UK Department for Science, Innovation and Technology’s March 2026 cyber security newsletter notes that the Committee stage of the Cyber Security and Resilience Bill has concluded and that the Bill will move to Report Stage when parliamentary time allows, confirming legislative progress and signalling further policy development and guidance to come.[12] (source)
- — TLT LLP provides an in‑depth explanation of the Bill as part of the UK’s 2026 legislative response to digital threats, outlining expansion of NIS scope to eligible data centres, medium and large managed service providers, load controllers and designated critical suppliers, and mandatory 24‑hour initial and 72‑hour full reporting for harmful cyber incidents, with commentary on expected operational and governance impacts across critical infrastructure sectors.[11] (source)
- — The Comms Council UK reports on the Bill’s second reading in the House of Commons on 6 January 2026, highlighting expectations of Royal Assent in mid‑2026, new definitions for relevant digital service providers, broadened incident definitions, mandatory 24‑hour initial and 72‑hour full incident reporting, and inclusion of data centres as essential services under joint oversight from Ofcom and DSIT, with specific focus on impacts for communications providers.[5] (source)
- — A UK government news release announces a new cyber action plan aligned with the Cyber Security and Resilience Bill’s Second Reading in the House of Commons, setting clearer expectations for firms providing services to government to boost cyber resilience and signalling forthcoming obligations and standards that will affect suppliers to public sector bodies.[7] (source)
- — The UK government’s official summary factsheet for the Cyber Security and Resilience (Network and Information Systems) Bill explains that it will reform and add to the NIS Regulations 2018 to increase UK defences against cyber‑attacks, with phased commencement after Royal Assent and differing start dates for certain measures via future secondary legislation, shaping the implementation timeline for regulated entities and essential service providers.[4] (source)
- — A UK government enforcement factsheet details how the Bill will simplify the existing NIS penalty band structure into a two‑band regime and introduce new maximum penalties of up to £17m or 4% worldwide turnover for serious breaches and £10m or 2% for less serious breaches, aiming for more proportionate, transparent enforcement and materially increasing financial exposure for non‑compliant organisations.[15] (source)
Related regulations
- UK Data Protection Act 2018 — United Kingdom, Active
- UK Data Use and Access Act (DUAA) — United Kingdom, Phased, effective 2026-02-05
- NYDFS Cybersecurity Regulation — New York, Active, effective 2025-11-01
- Law on Cybersecurity of Vietnam — Vietnam, Active
- Austria NIS2 Act — Austria, Upcoming
- Luxembourg NIS2 Transposition — Luxembourg, Active
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
Put it into practice
- Generate the policy: NIST CSF policy generator (generatepolicy.com)
- Buy the policy pack: Enterprise Security Bundle (cyberpolicy.shop)
- Build it yourself: Compliance Program Starter (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates