Bill update - now in the House of Lords (HL Bill 32)

The Cyber Security and Resilience Billexplained - UK 2026 guide

What it means, who it affects, and how to stay compliant - in plain English.

Executive summary

What is the Cyber Security and Resilience Bill?

The Cyber Security and Resilience Bill (Bill 329) is the UK's response to the evolving digital threat landscape. Introduced to Parliament on 12 November 2025, it cleared all its House of Commons stages and is now before the House of Lords (HL Bill 32, since 17 June 2026), with Royal Assent expected in late 2026. It updates the 2018 NIS Regulations to secure critical national infrastructure and digital supply chains.

Crucially, it expands regulatory scope to include Managed Service Providers (MSPs) and Data Centres, designating them as critical infrastructure. It mandates 24-hour incident reporting, introduces "near miss" reporting duties, and empowers regulators (ICO, Ofcom) to levy fines up to the greater of £17 million and 4% of global turnover.

Legislative dashboard

The Bill at a glance

Key metrics, thresholds and status for compliance leaders.

Bill Status

House of Lords (HL Bill 32)

UK Parliament

Maximum Penalty

Greater of £17M and 4% turnover

Section 21

Incident Reporting

24h initial / 72h full

Section 15 · Regulation 11

Data Centre Threshold

1 MW (general)

Schedule 2

Enterprise Data Centre

10 MW IT load

Schedule 2

Royal Assent

Expected late 2026

Then phased commencement

Overview

What is the Cyber Security and Resilience Bill?

The Cyber Security and Resilience (Network and Information Systems) Bill was introduced to Parliament on 12th November 2025 as Bill 329. It cleared all its House of Commons stages and was passed to the House of Lords on 17 June 2026 (now HL Bill 32), where it is progressing towards Royal Assent. It is the UK's most comprehensive update to cyber legislation in over a decade, significantly expanding the scope of the existing NIS Regulations 2018 to include managed service providers, cloud platforms, data centres, and critical suppliers.

Mandatory incident reporting

Initial notification within 24 hours and a full report within 72 hours, copied to the CSIRT.

Stronger regulatory oversight

New information-gathering, inspection and enforcement powers for regulators, with significant penalties.

Tougher compliance standards

Proactive risk management across your organisation and supply chain, aligned to the NCSC CAF.

Under Part 2, organisations delivering essential or digital services must proactively manage cyber risk, including across their supply chains. The Bill introduces mandatory incident reporting within 24 hours (Section 15), with full reports due within 72 hours. Failing to comply may result in penalties of up to the greater of £17,000,000 and 4% of global turnover (Section 21), with a standard maximum of the greater of £10,000,000 and 2% of turnover for registration and information-provision failures. Part 4 national security directions are enforced separately under Section 49, where contravening a direction carries a maximum of £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues. Neither the 10% figure nor the daily penalty forms part of the NIS Regulations regime.

Part 4 grants the Secretary of State new powers to issue national security directions, while Part 3 establishes strategic priorities and codes of practice. Now is the time to assess your readiness - the Cyber Security and Resilience Bill (CSRB) will reshape how UK organisations approach resilience, compliance, and security.

Key Changes

The Cyber Security and Resilience Bill introduces several major reforms to the UK's cybersecurity landscape. Here's what you need to know:

Bringing More Organisations Into the Frame

Part 2, Chapter 1 of the Bill significantly expands who must comply with cyber regulations. Section 9 brings Managed Service Providers (MSPs) into scope as 'Relevant Managed Service Providers' (RMSPs), subject to security duties under Section 10. Section 4 designates data centres as essential services with thresholds of 1MW (general) or 10MW (enterprise-only). Section 6 brings large load controllers (300MW+) into scope. Section 12 allows designation of critical suppliers. These changes close major gaps in the UK's cyber defence chain, bringing hundreds of previously unregulated entities under oversight.

Need help preparing?

Our compliance team can guide you through the new requirements

Talk to our compliance team
Compliance challenges

What it takes to stay secure - and within the law

With 5 Parts and 61 sections, the Cyber Security and Resilience Bill is a fundamental shift in how organisations govern, secure, and audit their digital infrastructure.

24 / 72-hour incident reporting

Section 15 mandates initial notification within 24 hours and a full report within 72 hours - to the competent authority and the CSIRT. Customer notification follows 'as soon as reasonably practicable' (Section 16).

Registration & information duties

Sections 13-14 require registration within 3 months of becoming regulated - company details, directors, and contacts. Updates within 7 days; non-UK entities must nominate a UK representative.

Supply chain & critical suppliers

Section 12 allows designation of critical suppliers, and Section 30(3) enables requirements on 'activity-critical supplies'. You must actively manage cyber risk across your supply chain.

Regulatory inspections & requests

Section 20 grants powers to require information and documents. Schedule 1 strengthens inspection powers - on-site inspections, document examination, and system testing.

Financial penalties: the greater of £17M and 4%

Section 21 sets a higher maximum of the greater of £17,000,000 and 4% of global turnover for security-duty and incident-notification failures, and a standard maximum of the greater of £10,000,000 and 2% of turnover for registration and information-provision failures. The daily penalties of up to £100,000 in Section 49 apply only to continuing contravention of a Part 4 national security direction; the NIS Regulations regime has no daily penalty.

Are you ready for the Cyber Security and Resilience Bill?

Most organisations will need to overhaul their cyber policies, documentation, and infrastructure to comply.

  • Demonstrate secure, mapped supply chains
  • Respond to incidents in real time
  • Produce regulator reports within 24/72 hours
  • Pass on-site inspections and audits
Get a readiness assessment
Precursor Security
How we help

How Precursor Security can help

Tailored solutions that keep your organisation compliant with the Cyber Security and Resilience Bill while strengthening your overall security posture.

Managed SOC / MDR

Mandatory Reporting Response

Our SOC workflows are engineered to meet Section 15 mandates - the triage and forensics you need for the regulator within the strict 24-hour statutory window.

Learn more

Penetration Testing

Attack Vector Validation

Don't just scan - validate. Our ethical hackers test against 'state of the art' vectors to ensure you meet the specific security duties in Regulation 14B.

Learn more

The "Section 15" insurance

Incident Response Retainer

Buyers fear the deadline. Our retainer guarantees regulatory notification assistance - we handle the forensics required for your 72-hour full report.

Learn more

Latest Insights

Stay updated with the latest developments, compliance guidance, and expert analysis on the Cyber Security and Resilience Bill.

The Cyber Security and Resilience Bill Skills Gap: Can UK Firms Resource the New Duties?

A new think-tank report warns the Cyber Security and Resilience Bill (CSRB) risks becoming a "paper tiger" unless the UK's cyber skills shortage is addressed. With 49% of businesses and 58% of government bodies reporting a basic skills gap, the people needed to run 24/72-hour reporting and ongoing risk management may not be there. Here is what in-scope organisations should do about it before the duties commence.

Precursor Security
28 Jul 2026
7 min read

Lords Complete Cyber Security and Resilience Bill Second Reading: Key Themes and Committee Stage on 1 September

The Lords gave the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, cross-party support at Second Reading on 14 July 2026 without calling a division - but they put five pointed themes on the record, from the public sector exemption to the Bill's total silence on AI. Committee Stage begins on 1 September, and those themes are the working agenda. Here is what each one means for in-scope organisations.

Precursor Security
22 Jul 2026
7 min read

UK Cyber Resilience Pledge: 60 Firms Commit Ahead of the Cyber Security and Resilience Bill

Technology Secretary Liz Kendall launched the Cyber Resilience Pledge at Number 10 on 7 July 2026, and more than 60 organisations signed on day one - M&S, Nationwide, Vodafone, NCC Group and, to some comment, Capita. Each of its three time-bound commitments maps onto a duty that the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, will make mandatory. Here is how to use the voluntary track to get ahead of the statutory one.

Precursor Security
9 Jul 2026
9 min read

UK Cyber Breaches Survey 2026: The Cyber Security and Resilience Bill Compliance Gap

DSIT's Cyber Security Breaches Survey 2025/2026 put 43% of UK businesses on the wrong end of a breach. The more revealing numbers sit beneath that headline: only 40% told anyone outside the organisation, and only 25% hold a formal incident response plan. Here is what that gap means once the Cyber Security and Resilience Bill (CSRB) makes 24/72-hour reporting a legal duty.

Precursor Security
3 Jul 2026
6 min read

Cyber Security and Resilience Bill: Lords Second Reading Scheduled for 14 July 2026

The House of Lords has fixed 14 July 2026 for its Second Reading of the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, with a dedicated Lords Library briefing published to accompany the debate. Here is what a Lords Second Reading actually does, the reservations peers are most likely to put on the record, and how the remaining stages shape your compliance timeline.

Precursor Security
26 Jun 2026
6 min read

Five Eyes AI Warning and the Cyber Security and Resilience Bill: What Boards Must Know

In the same week the Cyber Security and Resilience Bill (CSRB) reached the Lords as HL Bill 32, NCSC CEO Richard Horne told RUSI that 75% of the 200-plus CNI incidents it handled were state-linked - and five days later all five Five Eyes agencies warned that AI is compressing threat timelines to months, not years. Two signals, one message for boards: the case for the CSRB is now on the public record, and preparation cannot wait for Royal Assent.

Precursor Security
23 Jun 2026
7 min read

Stay Informed About Cyber Security and Resilience Bill Updates

Be the first to hear about updates on the Cyber Security and Resilience Bill. Get notified about compliance requirements, key changes, and important announcements.

We respect your privacy. Unsubscribe at any time.

Implementation Timeline

Key milestones in the Cyber Security and Resilience Bill's journey from announcement to enforcement.

17 July 2024

Cyber Security and Resilience Bill announced in the King's Speech

The Government commits to strengthening UK cyber security through new legislation during the State Opening of Parliament.

1 April 2025

Cyber Security and Resilience Bill Policy Statement published

Government outlines planned measures and legislative intent, including MSPs, data centres, and reporting mandates.

12 November 2025

Introduced to the Commons (Bill 329)

The Cyber Security and Resilience (Network and Information Systems) Bill receives its First Reading in the House of Commons as Bill 329.

Jan - Feb 2026

Second Reading & Committee Stage

Second Reading on 6 January 2026, followed by Committee Stage from 3 February. The Bill is amended in committee and reprinted (Bill 385) on 25 February 2026.

16 June 2026

Passed by the House of Commons

After being carried over into the 2026-27 session, the Bill completes Report Stage and Third Reading in the Commons and passes to the House of Lords.

17 June 2026

Introduced to the House of Lords (HL Bill 32)

The Bill is brought from the Commons and receives its First Reading in the Lords as HL Bill 32.

14 July 2026

Lords Second Reading (completed)

The House of Lords completed its Second Reading of HL Bill 32 on 14 July 2026. Cross-party support given in principle. Key themes raised: scope gaps, AI, delegated powers, and digital sovereignty.

1 September 2026

Lords Committee Stage (scheduled)

Line-by-line scrutiny of HL Bill 32 on the floor of the Lords Chamber. All Lords may participate and move amendments. Key areas expected to include scope, delegated powers, AI provisions, and reporting obligations.

Expected late 2026

Royal Assent & Commencement

Once the Lords stages conclude and Royal Assent is granted, provisions come into force as set out in the Bill - some immediately, others by regulation. Organisations should prepare now.

Free Cyber Security and Resilience Bill Consultation

Ready to Secure Your Future?

Book a free consultation with our Cyber Security and Resilience Bill experts and discover how we can help your organisation achieve compliance while strengthening your cyber resilience.

What You'll Get

Personalised Cyber Security and Resilience Bill Assessment

Understand exactly how the Cyber Security and Resilience Bill affects your organisation

Compliance Roadmap

Clear next steps to achieve and maintain compliance

Expert Guidance

Direct access to our cybersecurity compliance specialists