ComplianceBack to Blog

Cyber Security and Resilience Bill: Lords Second Reading Scheduled for 14 July 2026

The House of Lords has fixed 14 July 2026 for its Second Reading of the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, with a dedicated Lords Library briefing published to accompany the debate. Here is what a Lords Second Reading actually does, the reservations peers are most likely to put on the record, and how the remaining stages shape your compliance timeline.

Precursor Security
26 June 2026
7 min read
1,100 words

Precursor Security

Precursor Security is a UK-based penetration testing and offensive security testing company with 24/7 security operations centres. We are CREST certified in both penetration testing and security operations, providing comprehensive cyber security services to help organisations achieve regulatory compliance and enhance their security posture.

Share:

The Cyber Security and Resilience Bill (CSRB) - formally the Cyber Security and Resilience (Network and Information Systems) Bill - has taken its next formal step through Parliament. The House of Lords has confirmed that the Second Reading of HL Bill 32 is scheduled for 14 July 2026, marking the Lords' first substantive debate on the legislation and opening the formal clock on what is expected to be several months of upper house scrutiny before Royal Assent later in 2026.

The House of Lords Library has published a dedicated research briefing - LLN-2026-0032 - to accompany the debate, providing an authoritative summary of the Bill's provisions and identifying the principal questions the upper house is likely to raise.

What Is a Lords Second Reading?

A Second Reading in the House of Lords is a general debate on the principles of a Bill as a whole - not line-by-line scrutiny. No amendments are moved at this stage. Lords use it to signal support for, or reservations about, the legislation's overall approach, often previewing the themes they intend to pursue once Committee Stage begins.

Because HL Bill 32 arrived from the Commons with cross-party support and passed its Third Reading there without a division, this Second Reading is unlikely to divide the House on whether the legislation should proceed at all. The more revealing aspect will be which concerns and caveats Lords choose to put on the record - those statements effectively set the agenda for Committee.

What the Lords Are Likely to Scrutinise

The Bill that arrives in the Lords is broadly the same one the Commons passed. However, several themes emerged during Commons passage that were not resolved there and are highly likely to resurface in the upper house.

Secondary Legislation and Ministerial Powers

The Bill's most persistent criticism - flagged by industry, legal practitioners and MPs throughout the Commons stages - is the volume of detail left to secondary legislation and statutory codes of practice. The core compliance obligations (how the Cyber Assessment Framework will be applied, specific incident reporting thresholds, the mechanics of critical supplier designation) will be set out in regulations and codes made after Royal Assent, not in the Bill itself.

Part 3 of the Bill also grants the Secretary of State powers to amend the NIS Regulations by statutory instrument - powers sometimes described as "Henry VIII" powers because they allow primary legislation to be modified without a new Act of Parliament. The Lords Delegated Powers and Regulatory Reform Committee and the Constitution Committee typically examine such provisions closely. Lords scrutiny is likely to seek either tighter limits on those powers or stronger parliamentary oversight mechanisms when they are exercised - for example, affirmative rather than negative resolution procedures for the most significant changes.

This is not a trivial concern. For organisations trying to plan compliance, the provisions of the Bill set the general architecture, but it is the secondary legislation that will determine exactly what they must do and by when. The sooner that secondary legislation is consulted on and laid, the more lead time in-scope organisations will have.

Scope: Which Sectors Should Be Covered?

The Bill brings managed service providers, data centres, large load controllers and critical suppliers into scope for the first time. However, calls for even broader coverage - notably to include retail and manufacturing, which can pose significant systemic risk when disrupted by cyber attacks - were not accepted during the Commons passage. The Lords may return to this question, particularly given the Government's stated ambition to make the UK a leading nation in cyber resilience.

For those sectors that are already in scope, the boundary conditions matter enormously. The data centre thresholds (1 MW rated IT load for general operators, 10 MW for enterprise-only operations), the definition of "relevant managed service provider", and the critical supplier designation process will all receive scrutiny. Data centre operators in particular will note that the Commons amendment making Ofcom the sole regulator - rather than a joint regime with the Secretary of State - raised questions about Ofcom's capacity and resourcing that were not fully addressed before the Bill left the Commons.

Administrative Burden and Proportionality

Smaller managed service providers and their trade bodies argued throughout the Commons passage that the compliance obligations - registration, security measures, 24/72-hour incident reporting, customer notification requirements - create a disproportionate burden for firms without dedicated in-house legal and compliance resource. While micro and small enterprises are generally exempt unless designated as critical suppliers, the threshold between exempt and in-scope is not always clear cut, particularly for fast-growing MSPs. Lords may push for greater clarity on these boundaries and for guidance to be published before commencement, rather than only after Royal Assent.

Digital Sovereignty and Information Sharing

Three Commons amendments on digital sovereignty, hostile state actors and information sharing with overseas authorities were voted down before Third Reading. Lords members who supported those positions may raise them again, particularly in the context of supply chain security and UK technology independence. Part 4 of the Bill gives the Secretary of State broad national security directions powers, but some Lords may argue for a more explicit statutory framework around foreign-technology dependencies in critical national infrastructure.

The Path From Here to Royal Assent

After Second Reading, the Bill moves to Committee Stage. Unlike the Commons - where the Committee took place in a Public Bill Committee of around twenty MPs - Lords Committee Stage is typically taken on the floor of the chamber, allowing all Lords to participate in detailed line-by-line scrutiny and move amendments.

Following Committee, there is Report Stage (where amendments passed in Committee can be reconsidered and further changes made), then Third Reading. Any amendments made in the Lords must then be agreed by the Commons. Where the two Houses disagree, the Bill passes back and forth - a process known as ping-pong - until agreement is reached.

If the Lords move efficiently through their stages, Royal Assent in autumn or winter 2026 remains achievable. An extended Committee Stage - particularly if there are contested amendments to the skeleton-bill provisions or scope - could push the timetable into early 2027.

Key Milestones at a Glance

Milestone Date / Status
Commons Report Stage and 3rd Reading 16 June 2026 (completed)
Lords 1st Reading 17 June 2026 (completed)
Lords 2nd Reading 14 July 2026 (scheduled)
Lords Committee Stage To be confirmed
Lords Report and 3rd Reading To be confirmed
Royal Assent Expected late 2026
DSIT implementation consultation 2026 (not yet launched)

What Organisations Should Do Now

The scheduling of the Lords Second Reading confirms the Bill is very much on track. For the organisations caught by its scope - managed service providers, data centre operators, operators of essential services and critical suppliers - this is a reminder that the window to prepare is compressing.

Practical priorities at this stage:

  1. Confirm whether you are in scope. The full Bill text (HL Bill 32) and the what is it guide set out the regulated entity categories in detail. Scope determination is the essential first step.

  2. Build and test a 24/72-hour incident notification workflow. The rapid-reporting obligation is one of the most operationally demanding requirements in the Bill. Tabletop exercises before it becomes a live legal duty are far more valuable than improvising under pressure during an actual incident.

  3. Track the Lords stages and engage with the forthcoming DSIT implementation consultation. The consultation - expected during 2026 - will set out the detail that actually defines day-to-day compliance obligations. Participating in it is the most direct way to influence the secondary legislation that will follow.

  4. Use the Cyber Assessment Framework (CAF) as a benchmark now. The CAF is expected to underpin how regulators assess compliance under the Bill. Aligning to it before commencement reduces the gap organisations will need to close when duties take effect, and demonstrates a proactive approach to regulators.

  5. Review contracts and supply chain arrangements. The critical supplier designation regime and the customer notification requirements under Section 16 have contractual as well as operational implications. Now is the right time to review supplier and customer agreements against the Bill's requirements.

For the most up-to-date parliamentary position, the official UK Parliament Bill page and the House of Lords Library briefing LLN-2026-0032 are the authoritative sources. The complete text of HL Bill 32 and a full summary of what the Bill changes are available on this site.

This article reflects the position as of 26th June 2026. The Lords 2nd Reading date of 14 July 2026 is confirmed by the House of Lords Library research briefing LLN-2026-0032 and the official Parliament Bill page. For the latest position, see bills.parliament.uk/bills/4035.

Tags:
CSRBcyber securityUK legislationcomplianceHouse of LordsHL Bill 32Lords second readingNISsecondary legislationHenry VIII powersincident reportingRoyal Assent
Last updated: 3 August 2026
Share:

You Might Also Like

Explore more insights and guidance on the Cyber Security and Resilience Bill.

Precursor Security
22 Jul 2026

Lords Complete Cyber Security and Resilience Bill Second Reading: Key Themes and Committee Stage on 1 September

The Lords gave the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, cross-party support at Second Reading on 14 July 2026 without calling a division - but they put five pointed themes on the record, from the public sector exemption to the Bill's total silence on AI. Committee Stage begins on 1 September, and those themes are the working agenda. Here is what each one means for in-scope organisations.

CSRBcyber security+19 more
Read Article
Precursor Security
21 Jun 2026

Cyber Security and Resilience Bill Clears the Commons: Where It Stands in 2026

The Cyber Security and Resilience Bill (CSRB) has cleared every House of Commons stage and passed to the Lords as HL Bill 32. The core architecture survived intact - expanded scope, 24/72-hour reporting, £17m penalties - with one headline change: Ofcom is now the sole regulator for data centres. Here is the confirmed timeline and what to do before Royal Assent, expected late 2026.

CSRBcyber security+12 more
Read Article
Precursor Security
3 Jul 2026

UK Cyber Breaches Survey 2026: The Cyber Security and Resilience Bill Compliance Gap

DSIT's Cyber Security Breaches Survey 2025/2026 put 43% of UK businesses on the wrong end of a breach. The more revealing numbers sit beneath that headline: only 40% told anyone outside the organisation, and only 25% hold a formal incident response plan. Here is what that gap means once the Cyber Security and Resilience Bill (CSRB) makes 24/72-hour reporting a legal duty.

CSRBcyber security+12 more
Read Article