UK Cyber Security and Resilience Bill

Updates the NIS Regulations 2018: brings managed service providers and data centres into scope, adds a 24-hour initial incident notification, strengthens regulator powers and cost recovery. Cleared the Commons June 2026, in Lords Committee from 1 September 2026; substantive duties expected via secondary legislation around 2028.

JurisdictionUnited Kingdom
CategoryCybersecurity
StatusProposed
Latest development

Analysis

The UK Cyber Security and Resilience (Network and Information Systems) Bill is a proposed overhaul of the UK NIS regime that will bring managed service providers (MSPs) and data centres into scope, introduce a 24‑hour initial incident notification duty, strengthen regulator powers, and modernise cost‑recovery mechanisms.Summary of the Bill – UK Government Incident reporting factsheet – UK Government Cyber Security and Resilience Bill – Parliament Bill Page

Below is a structured analysis aligned to your requested sections, with direct, clickable links for every factual claim.


Key Requirements

Scope expansion: MSPs and data centres

  • Managed service providers (RMSPs) brought into NIS scope
  • Data centres classified as essential services

Incident reporting: 24‑hour initial, 72‑hour full report

  • Two‑stage incident reporting duty
  • The Government incident reporting factsheet states that the Bill introduces a two‑stage reporting structure, requiring a light‑touch initial notification within 24 hours, followed by a full report within 72 hours.Incident reporting – UK Government
  • The Bill summary similarly notes that more harmful cyber breaches will need to be reported, with initial notification within 24 hours and fuller reporting within 72 hours.Summary of the Bill – UK Government
  • Legal analysis confirms that OESs, RDSPs and RMSPs must submit an initial notification within 24 hours of becoming aware of an incident, followed by a full notification within 72 hours, with specific content requirements for each stage.United Kingdom Proposes Changes – Mayer Brown
  • Notification to NCSC / CSIRT and regulators
  • Customer notification obligations

Strengthened regulator powers and cost recovery

  • Enhanced supervisory and enforcement powers
  • Government factsheets explain that the Bill strengthens powers of NIS regulators, including enhanced inspection, information‑gathering and enforcement measures to support cyber resilience.Summary of the Bill – UK Government
  • The overarching factsheet set notes amendments to data centres, relevant digital service providers, information sharing and cost recovery to reflect Committee Stage discussions, indicating an evolving but strengthened regulatory framework.Cyber Security and Resilience Bill factsheets – overview
  • Legal commentary describes more robust enforcement and penalty structures, including alignment with higher fine levels and clearer investigative powers compared to the 2018 NIS Regulations.United Kingdom Proposes Changes – Mayer Brown
  • Updated cost recovery mechanisms

Compliance Challenges

24‑hour detection and reporting readiness

  • Continuous detection and escalation
  • Example challenge – SMEs and regional providers

Determining scope and thresholds (MSPs, data centres)

  • Identifying whether services are in scope

Integration with existing NIS and data protection obligations

  • Overlap with current NIS incident duties

Resource and cost challenges

  • Building compliance capabilities and paying regulatory costs

Implementation Best Practices

1. Establish robust incident detection and response processes

  • Implement 24/7 monitoring and triage
  • Align with recognised frameworks
  • The UK NCSC promotes the Cyber Assessment Framework (CAF) as a structured approach to managing risks in essential services.NCSC – Cyber Assessment Framework
  • Organisations can integrate NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover) into their NIS‑aligned compliance programmes.NIST Cybersecurity Framework
  • ICO’s Guide to NIS, although under review, still offers useful principles on **risk management, incident handling, and governance

Recent developments

  • — The Cyber Security and Resilience Bill is reported to have passed through the House of Commons in June 2026 and is progressing through the House of Lords, with Royal Assent expected later in 2026; the article highlights expanded scope to data centres and managed service providers, stricter 24/72‑hour incident reporting, and a new two‑tier penalty regime of up to £17m or 4% of global turnover for serious breaches.[13] (source)
  • — Pinsent Masons reports that recent UK cabinet changes could disrupt progress of the Cyber Security and Resilience Bill, noting that the Bill is prepared for its House of Lords committee stage in September 2026 and that planned consultations on key elements were due over the summer, raising some uncertainty around timelines and regulatory coordination.[14] (source)
  • — A BBC Parliament programme covers the House of Lords second reading debate on the Cyber Security and Resilience (Network and Information Systems) Bill on 14 July 2026, reflecting ongoing parliamentary scrutiny of the Bill’s general principles and its impact on essential services and digital providers.[6] (source)
  • — Mayer Brown analyses the Bill’s proposed significant amendments to the UK NIS Regulations 2018, including expanded regulatory scope, new categories of regulated entities, enhanced incident‑reporting obligations, and increased enforcement powers and penalties, highlighting divergences from the EU’s NIS2 framework and practical compliance implications for UK‑based organisations.[1] (source)
  • — The UK Department for Science, Innovation and Technology’s March 2026 cyber security newsletter notes that the Committee stage of the Cyber Security and Resilience Bill has concluded and that the Bill will move to Report Stage when parliamentary time allows, confirming legislative progress and signalling further policy development and guidance to come.[12] (source)
  • — TLT LLP provides an in‑depth explanation of the Bill as part of the UK’s 2026 legislative response to digital threats, outlining expansion of NIS scope to eligible data centres, medium and large managed service providers, load controllers and designated critical suppliers, and mandatory 24‑hour initial and 72‑hour full reporting for harmful cyber incidents, with commentary on expected operational and governance impacts across critical infrastructure sectors.[11] (source)
  • — The Comms Council UK reports on the Bill’s second reading in the House of Commons on 6 January 2026, highlighting expectations of Royal Assent in mid‑2026, new definitions for relevant digital service providers, broadened incident definitions, mandatory 24‑hour initial and 72‑hour full incident reporting, and inclusion of data centres as essential services under joint oversight from Ofcom and DSIT, with specific focus on impacts for communications providers.[5] (source)
  • — A UK government news release announces a new cyber action plan aligned with the Cyber Security and Resilience Bill’s Second Reading in the House of Commons, setting clearer expectations for firms providing services to government to boost cyber resilience and signalling forthcoming obligations and standards that will affect suppliers to public sector bodies.[7] (source)
  • — The UK government’s official summary factsheet for the Cyber Security and Resilience (Network and Information Systems) Bill explains that it will reform and add to the NIS Regulations 2018 to increase UK defences against cyber‑attacks, with phased commencement after Royal Assent and differing start dates for certain measures via future secondary legislation, shaping the implementation timeline for regulated entities and essential service providers.[4] (source)
  • — A UK government enforcement factsheet details how the Bill will simplify the existing NIS penalty band structure into a two‑band regime and introduce new maximum penalties of up to £17m or 4% worldwide turnover for serious breaches and £10m or 2% for less serious breaches, aiming for more proportionate, transparent enforcement and materially increasing financial exposure for non‑compliant organisations.[15] (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates