ComplianceBack to Blog

Cyber Security and Resilience Bill Clears the Commons: Where It Stands in 2026

The Cyber Security and Resilience Bill (CSRB) has cleared every House of Commons stage and passed to the Lords as HL Bill 32. The core architecture survived intact - expanded scope, 24/72-hour reporting, £17m penalties - with one headline change: Ofcom is now the sole regulator for data centres. Here is the confirmed timeline and what to do before Royal Assent, expected late 2026.

Precursor Security
21 June 2026
9 min read
1,500 words

Precursor Security

Precursor Security is a UK-based penetration testing and offensive security testing company with 24/7 security operations centres. We are CREST certified in both penetration testing and security operations, providing comprehensive cyber security services to help organisations achieve regulatory compliance and enhance their security posture.

Share:

The Cyber Security and Resilience Bill (CSRB) - formally the Cyber Security and Resilience (Network and Information Systems) Bill - has reached a decisive stage. After being introduced to the House of Commons as Bill 329 on 12th November 2025, the Bill completed all of its Commons stages and passed to the House of Lords on 17th June 2026, where it is now known as HL Bill 32.

For the thousands of organisations that will fall within scope - managed service providers, data centres, cloud and digital service providers, operators of essential services and their critical suppliers - this is the clearest signal yet that the legislation is on track to become law. With Royal Assent widely expected in late 2026, the window to prepare is narrowing. This article brings the Bill's journey up to date and explains what has changed since it was introduced.

Where the Bill Stands in June 2026

The Bill has moved steadily through Parliament over the first half of 2026. Here is the confirmed sequence of stages:

  • First Reading (Commons) - 12th November 2025: The Bill was formally introduced as Bill 329, presented by the Secretary of State for Science, Innovation and Technology.
  • Second Reading (Commons) - 6th January 2026: MPs debated and approved the general principles of the Bill. Debate focused on regulator capacity, proportionality for smaller managed service providers, the breadth of the "managed service provider" definition, and the practicality of the 24/72-hour incident reporting timeline.
  • Committee Stage (Commons) - 3rd to 24th February 2026: A Public Bill Committee scrutinised the Bill line by line across seven sittings, taking oral and written evidence from industry and legal experts. The Bill was amended and reprinted as Bill 385 on 25th February 2026.
  • Carry-over and reintroduction - 14th May 2026: Following the change of parliamentary session, the Bill was carried over into the 2026-27 session and reprinted (Bill 002 2026-27) to continue its remaining stages.
  • Report Stage and Third Reading (Commons) - 16th June 2026: The Bill completed its remaining Commons stages and was read the third time and passed without a division.
  • First Reading (House of Lords) - 17th June 2026: The Bill was brought from the Commons and reprinted as HL Bill 32. Its Second Reading in the Lords is scheduled for 14th July 2026.

In short: the Bill has cleared the House of Commons in full and is now beginning its passage through the House of Lords. It is not yet an Act, and no provisions are in force.

What Changed During the Bill's Passage

The Bill that emerged from the Commons is broadly the same as the one introduced in November 2025 - its scope, penalty regime and reporting duties remain intact. Amendments were relatively few, but several are worth noting.

Ofcom Becomes the Sole Regulator for Data Centres

The most significant substantive change came at Committee Stage. As introduced, the Bill provided for the data infrastructure subsector (including data centres) to be regulated jointly by the Secretary of State for Science, Innovation and Technology and the Office of Communications (Ofcom). In response to concerns about complexity and accountability, this was amended so that Ofcom acts as the sole regulator for the sector. This gives data centre operators a single, clearly identified competent authority to engage with.

Opposition Amendments Rejected at Report Stage

Three notable opposition amendments were debated and rejected on division before Third Reading:

  • New Clause 13 would have required the Government to publish a Digital Sovereignty Strategy addressing reliance on foreign technology. Rejected.
  • New Clause 14 would have required the maintenance of a register of hostile state actors. Rejected.
  • Amendment 3 would have restricted information sharing with overseas authorities where fair-trial rights are not guaranteed. Rejected.

The Bill then passed Third Reading without a division, indicating broad cross-party support for its core measures.

What Has Not Changed: The Core Obligations

The fundamentals that organisations need to plan for remain as set out when the Bill was introduced:

  • Expanded scope: Managed service providers (as "Relevant Managed Service Providers"), data centres (1MW rated IT load, or 10MW for enterprise-only operations), large load controllers (300MW+), cloud and other digital service providers, and designated critical suppliers are all brought within the regulatory perimeter.
  • Mandatory incident reporting: An initial notification within 24 hours and a fuller report within 72 hours of becoming aware of a significant incident, copied to the relevant CSIRT, with affected customers notified as soon as reasonably practicable. The Bill is explicitly designed to capture incidents such as ransomware.
  • Tougher penalties: A two-tier regime of up to the greater of £17 million and 4% of global turnover for the most serious failures, and up to the greater of £10 million and 2% of global turnover for other breaches. Separately, contravening a Part 4 national security direction carries a maximum of £17 million, rising to the greater of £17 million and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 a day while the contravention continues.
  • Stronger oversight and supply chain duties: New information-gathering and inspection powers for regulators, codes of practice, statements of strategic priorities, and a designation regime for critical suppliers whose failure could disrupt essential services.

Government Guidance and What Comes Next

Alongside the Bill's progress, the Government has continued to publish supporting material. The Department for Science, Innovation and Technology (DSIT) published a set of Bill factsheets on gov.uk in March 2026, including a plain-English summary of the Bill, and has used its cyber security newsletters to track the Bill's progress and frame it as strengthening resilience across the NHS, transport and energy.

Crucially, much of the detail that will determine day-to-day compliance - incident reporting thresholds, how the NCSC Cyber Assessment Framework (CAF) will be applied, and registration mechanics - will be set out in secondary legislation. The Government has signalled its intention to consult during 2026 on this implementation detail. That consultation had not been formally launched at the time of writing and is the single most important thing for in-scope organisations to watch for next.

Expected Timeline From Here

  • 14th July 2026: Lords Second Reading (scheduled). The House of Lords Library has published briefing LLN-2026-0032 for the debate.
  • Mid to late 2026: Remaining House of Lords stages (Committee, Report, Third Reading), followed by consideration of any amendments between the Houses.
  • Late 2026: Royal Assent expected (not yet confirmed).
  • 2026 onwards: Government consultation on implementation detail, followed by the secondary legislation that brings the substantive duties into force - likely phased, with an adjustment period for affected organisations into 2027 and beyond.

What Organisations Should Do Now

The legislative direction is now clear, and waiting for Royal Assent before acting would leave very little time to comply. Practical steps include:

  1. Determine whether you are in scope. Map your services and group structure against the categories of operator of essential service, relevant digital service provider, relevant managed service provider, and critical supplier. If you operate or rely on data centres, note that Ofcom will be your regulator.
  2. Build a 24/72-hour incident notification workflow. Make sure your security operations, incident response and legal teams can produce an initial notification within 24 hours and a fuller report within 72 hours, and tabletop-test it before it is ever needed.
  3. Review your supply chain and contracts. Identify critical suppliers and dependencies, and ensure contractual arrangements support the security, reporting and notification duties the Bill introduces.
  4. Align to the Cyber Assessment Framework (CAF). The CAF is expected to underpin how compliance is assessed; using it now as a benchmark will reduce the gap when duties take effect.
  5. Track the Lords stages and the forthcoming DSIT consultation. The consultation will define the obligations that actually bite. Engaging with it is the best way to understand - and influence - the detailed requirements.

Conclusion

The Cyber Security and Resilience Bill has cleared the House of Commons and is now before the House of Lords, with Royal Assent expected in late 2026. The core architecture of the Bill - expanded scope, mandatory rapid incident reporting, tougher penalties and stronger supply chain duties - has survived its Commons passage largely intact, with the headline change being the move to Ofcom as the sole regulator for data centres. The remaining uncertainty lies in the implementation detail, which will be settled through a 2026 consultation and subsequent secondary legislation.

For organisations across the UK's essential and digital services, the message from this stage of the Bill's journey is straightforward: the legislation is coming, its shape is now clear, and preparation should already be under way.

This article was originally published on 21st June 2026 and updated on 26th June 2026 to reflect the scheduling of the Lords Second Reading for 14th July 2026. For the latest position and the current version of the Bill, see the UK Parliament Bill page. If you need help assessing your readiness, book a free compliance call or take our readiness assessment.

Tags:
CSRBcyber securityUK legislationcomplianceresilienceregulationsNISHouse of LordsHL Bill 32Bill 329Ofcomdata centresincident reportingRoyal Assent
Last updated: 3 August 2026
Share:

You Might Also Like

Explore more insights and guidance on the Cyber Security and Resilience Bill.

Precursor Security
22 Jul 2026

Lords Complete Cyber Security and Resilience Bill Second Reading: Key Themes and Committee Stage on 1 September

The Lords gave the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, cross-party support at Second Reading on 14 July 2026 without calling a division - but they put five pointed themes on the record, from the public sector exemption to the Bill's total silence on AI. Committee Stage begins on 1 September, and those themes are the working agenda. Here is what each one means for in-scope organisations.

CSRBcyber security+19 more
Read Article
Precursor Security
26 Jun 2026

Cyber Security and Resilience Bill: Lords Second Reading Scheduled for 14 July 2026

The House of Lords has fixed 14 July 2026 for its Second Reading of the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, with a dedicated Lords Library briefing published to accompany the debate. Here is what a Lords Second Reading actually does, the reservations peers are most likely to put on the record, and how the remaining stages shape your compliance timeline.

CSRBcyber security+10 more
Read Article
Precursor Security
13 Nov 2025

Cyber Security and Resilience Bill Introduced to Parliament: Key Changes and What to Expect

The Cyber Security and Resilience Bill (CSRB), Bill 329, was formally introduced to Parliament on 12th November 2025: 61 sections across 5 Parts and 2 Schedules, and the most substantial update to UK cyber security law since the NIS Regulations 2018. This is the section-by-section walkthrough - who the expanded scope catches, exactly what the 24 and 72-hour notifications must contain, and which provisions bite on Royal Assent.

CSRBcyber security+9 more
Read Article