The Cyber Security and Resilience Bill (CSRB) - formally the Cyber Security and Resilience (Network and Information Systems) Bill - has taken its next formal step through Parliament. The House of Lords has confirmed that the Second Reading of HL Bill 32 is scheduled for 14 July 2026, marking the Lords' first substantive debate on the legislation and opening the formal clock on what is expected to be several months of upper house scrutiny before Royal Assent later in 2026.
The House of Lords Library has published a dedicated research briefing - LLN-2026-0032 - to accompany the debate, providing an authoritative summary of the Bill's provisions and identifying the principal questions the upper house is likely to raise.
What Is a Lords Second Reading?
A Second Reading in the House of Lords is a general debate on the principles of a Bill as a whole - not line-by-line scrutiny. No amendments are moved at this stage. Lords use it to signal support for, or reservations about, the legislation's overall approach, often previewing the themes they intend to pursue once Committee Stage begins.
Because HL Bill 32 arrived from the Commons with cross-party support and passed its Third Reading there without a division, this Second Reading is unlikely to divide the House on whether the legislation should proceed at all. The more revealing aspect will be which concerns and caveats Lords choose to put on the record - those statements effectively set the agenda for Committee.
What the Lords Are Likely to Scrutinise
The Bill that arrives in the Lords is broadly the same one the Commons passed. However, several themes emerged during Commons passage that were not resolved there and are highly likely to resurface in the upper house.
Secondary Legislation and Ministerial Powers
The Bill's most persistent criticism - flagged by industry, legal practitioners and MPs throughout the Commons stages - is the volume of detail left to secondary legislation and statutory codes of practice. The core compliance obligations (how the Cyber Assessment Framework will be applied, specific incident reporting thresholds, the mechanics of critical supplier designation) will be set out in regulations and codes made after Royal Assent, not in the Bill itself.
Part 3 of the Bill also grants the Secretary of State powers to amend the NIS Regulations by statutory instrument - powers sometimes described as "Henry VIII" powers because they allow primary legislation to be modified without a new Act of Parliament. The Lords Delegated Powers and Regulatory Reform Committee and the Constitution Committee typically examine such provisions closely. Lords scrutiny is likely to seek either tighter limits on those powers or stronger parliamentary oversight mechanisms when they are exercised - for example, affirmative rather than negative resolution procedures for the most significant changes.
This is not a trivial concern. For organisations trying to plan compliance, the provisions of the Bill set the general architecture, but it is the secondary legislation that will determine exactly what they must do and by when. The sooner that secondary legislation is consulted on and laid, the more lead time in-scope organisations will have.
Scope: Which Sectors Should Be Covered?
The Bill brings managed service providers, data centres, large load controllers and critical suppliers into scope for the first time. However, calls for even broader coverage - notably to include retail and manufacturing, which can pose significant systemic risk when disrupted by cyber attacks - were not accepted during the Commons passage. The Lords may return to this question, particularly given the Government's stated ambition to make the UK a leading nation in cyber resilience.
For those sectors that are already in scope, the boundary conditions matter enormously. The data centre thresholds (1 MW rated IT load for general operators, 10 MW for enterprise-only operations), the definition of "relevant managed service provider", and the critical supplier designation process will all receive scrutiny. Data centre operators in particular will note that the Commons amendment making Ofcom the sole regulator - rather than a joint regime with the Secretary of State - raised questions about Ofcom's capacity and resourcing that were not fully addressed before the Bill left the Commons.
Administrative Burden and Proportionality
Smaller managed service providers and their trade bodies argued throughout the Commons passage that the compliance obligations - registration, security measures, 24/72-hour incident reporting, customer notification requirements - create a disproportionate burden for firms without dedicated in-house legal and compliance resource. While micro and small enterprises are generally exempt unless designated as critical suppliers, the threshold between exempt and in-scope is not always clear cut, particularly for fast-growing MSPs. Lords may push for greater clarity on these boundaries and for guidance to be published before commencement, rather than only after Royal Assent.
Three Commons amendments on digital sovereignty, hostile state actors and information sharing with overseas authorities were voted down before Third Reading. Lords members who supported those positions may raise them again, particularly in the context of supply chain security and UK technology independence. Part 4 of the Bill gives the Secretary of State broad national security directions powers, but some Lords may argue for a more explicit statutory framework around foreign-technology dependencies in critical national infrastructure.
The Path From Here to Royal Assent
After Second Reading, the Bill moves to Committee Stage. Unlike the Commons - where the Committee took place in a Public Bill Committee of around twenty MPs - Lords Committee Stage is typically taken on the floor of the chamber, allowing all Lords to participate in detailed line-by-line scrutiny and move amendments.
Following Committee, there is Report Stage (where amendments passed in Committee can be reconsidered and further changes made), then Third Reading. Any amendments made in the Lords must then be agreed by the Commons. Where the two Houses disagree, the Bill passes back and forth - a process known as ping-pong - until agreement is reached.
If the Lords move efficiently through their stages, Royal Assent in autumn or winter 2026 remains achievable. An extended Committee Stage - particularly if there are contested amendments to the skeleton-bill provisions or scope - could push the timetable into early 2027.
Key Milestones at a Glance
| Milestone |
Date / Status |
| Commons Report Stage and 3rd Reading |
16 June 2026 (completed) |
| Lords 1st Reading |
17 June 2026 (completed) |
| Lords 2nd Reading |
14 July 2026 (scheduled) |
| Lords Committee Stage |
To be confirmed |
| Lords Report and 3rd Reading |
To be confirmed |
| Royal Assent |
Expected late 2026 |
| DSIT implementation consultation |
2026 (not yet launched) |
What Organisations Should Do Now
The scheduling of the Lords Second Reading confirms the Bill is very much on track. For the organisations caught by its scope - managed service providers, data centre operators, operators of essential services and critical suppliers - this is a reminder that the window to prepare is compressing.
Practical priorities at this stage:
-
Confirm whether you are in scope. The full Bill text (HL Bill 32) and the what is it guide set out the regulated entity categories in detail. Scope determination is the essential first step.
-
Build and test a 24/72-hour incident notification workflow. The rapid-reporting obligation is one of the most operationally demanding requirements in the Bill. Tabletop exercises before it becomes a live legal duty are far more valuable than improvising under pressure during an actual incident.
-
Track the Lords stages and engage with the forthcoming DSIT implementation consultation. The consultation - expected during 2026 - will set out the detail that actually defines day-to-day compliance obligations. Participating in it is the most direct way to influence the secondary legislation that will follow.
-
Use the Cyber Assessment Framework (CAF) as a benchmark now. The CAF is expected to underpin how regulators assess compliance under the Bill. Aligning to it before commencement reduces the gap organisations will need to close when duties take effect, and demonstrates a proactive approach to regulators.
-
Review contracts and supply chain arrangements. The critical supplier designation regime and the customer notification requirements under Section 16 have contractual as well as operational implications. Now is the right time to review supplier and customer agreements against the Bill's requirements.
For the most up-to-date parliamentary position, the official UK Parliament Bill page and the House of Lords Library briefing LLN-2026-0032 are the authoritative sources. The complete text of HL Bill 32 and a full summary of what the Bill changes are available on this site.
This article reflects the position as of 26th June 2026. The Lords 2nd Reading date of 14 July 2026 is confirmed by the House of Lords Library research briefing LLN-2026-0032 and the official Parliament Bill page. For the latest position, see bills.parliament.uk/bills/4035.