ComplianceBack to Blog

Cyber Security and Resilience Bill Introduced to Parliament: Key Changes and What to Expect

The Cyber Security and Resilience Bill (CSRB), Bill 329, was formally introduced to Parliament on 12th November 2025: 61 sections across 5 Parts and 2 Schedules, and the most substantial update to UK cyber security law since the NIS Regulations 2018. This is the section-by-section walkthrough - who the expanded scope catches, exactly what the 24 and 72-hour notifications must contain, and which provisions bite on Royal Assent.

Precursor Security
13 November 2025
20 min read
4,200 words

Precursor Security

Precursor Security is a UK-based penetration testing and offensive security testing company with 24/7 security operations centres. We are CREST certified in both penetration testing and security operations, providing comprehensive cyber security services to help organisations achieve regulatory compliance and enhance their security posture.

Share:

Update (June 2026): Since this article was published, the Bill has completed all of its House of Commons stages and moved to the House of Lords on 17th June 2026 (now HL Bill 32), with Royal Assent expected in late 2026. For the current status, read our latest update: Cyber Security and Resilience Bill Clears the Commons: Where It Stands in 2026.

On 12th November 2025, the Cyber Security and Resilience Bill (CSRB) - formally the Cyber Security and Resilience (Network and Information Systems) Bill, Bill 329 - was formally introduced to the UK Parliament, marking a significant milestone in the UK's approach to cyber security regulation. Presented by Secretary Liz Kendall and supported by the Prime Minister and senior ministers, this comprehensive legislation represents the most substantial update to UK Cyber Security law since the Network and Information Systems (NIS) Regulations 2018.

The Bill's introduction follows its announcement in the 2024 King's Speech and the publication of a formal policy paper in April 2025. With 61 sections across 5 Parts and 2 Schedules, the legislation will fundamentally reshape how organisations manage cyber security risks, respond to incidents, and maintain operational resilience.

For thousands of UK organisations - from managed service providers and data centres to critical infrastructure operators and their supply chains - the Bill's introduction signals that compliance preparation is no longer optional. It's time to act.

The Bill Has Been Introduced: What This Means

The formal introduction of the Cyber Security and Resilience Bill to Parliament on 12th November 2025 triggers the legislative process that will ultimately make these requirements law. While the Bill must still pass through both Houses of Parliament and receive Royal Assent, its introduction represents a clear statement of intent from the UK Government.

Section 60 of the Bill provides for phased commencement:

  • Immediate effect on Royal Assent: Part 1 (Introduction), Chapters 1, 3 and 6 of Part 3, Section 40 (Reports), and Part 5 (General provisions)
  • Two months after Royal Assent: Section 18(3) and (4) (Information sharing), Chapter 2 of Part 3 (Statement of Strategic Priorities), and certain Schedule 2 provisions
  • Appointed day by regulations: All other provisions, with different days possible for different purposes

This phased approach means organisations have a window to prepare, but that window is closing. The most significant changes - including expanded scope, mandatory incident reporting, and new enforcement powers - will come into effect once the Bill receives Royal Assent and the Secretary of State makes commencement regulations.

Key Changes in the Bill

The Cyber Security and Resilience Bill introduces sweeping changes that will affect organisations across multiple sectors. Here are the most significant updates:

1. Dramatically Expanded Scope of Regulation

New Sectors and Services Brought Under Regulation:

  • Managed Service Providers (MSPs) - Section 9 introduces "Relevant Managed Service Providers" (RMSPs) as a new category of regulated persons. Any MSP providing ongoing management of IT systems in the UK (whether on-premises or remotely) will be subject to security duties under Regulation 14B and mandatory registration under Regulation 14C.
  • Data Centres - Section 4 brings data centre services into scope as essential services. Data centres with a rated IT load of 1MW or more (or 10MW for enterprise data centres) must comply with operator of essential service (OES) duties, including mandatory information provision under Regulation 8ZA and incident reporting under Regulation 11A.
  • Large Load Controllers - Section 6 designates load controllers managing 300MW or more of potential electrical control as operators of essential services, bringing energy demand management systems under regulatory oversight.
  • Critical Suppliers - Section 12 introduces Regulation 14H, allowing designated competent authorities and the Information Commission to designate "critical suppliers" whose failure could disrupt essential services. This extends regulatory reach deep into supply chains.
  • Cloud Computing Services Redefined - Section 7 redefines cloud computing services as "relevant digital services" (RDSPs), with updated definitions emphasising scalability, elasticity, and broad remote access.

2. Mandatory Incident Reporting with Strict Timelines

Section 15 fundamentally changes incident reporting requirements:

  • Expanded Definition of "Incident" - Section 15(2) amends the definition to include incidents "capable of having" an impact, not just those with actual impacts. This lower threshold means more incidents must be reported.
  • 24-Hour Initial Notification - Regulation 11 (OES), Regulation 12A (RDSP), and Regulation 14E (RMSP) require initial notification within 24 hours of becoming aware of an incident. This must include the organisation's name, the service affected, and brief details.
  • 72-Hour Full Notification - A comprehensive report must be provided within 72 hours, including:
    • Time, duration, and ongoing status
    • Nature of the incident
    • Details of any related incidents affecting other regulated persons
    • Impact assessment (including cross-border impact)
    • Any other information that may assist the regulator
  • Dual Reporting - Notifications must be sent simultaneously to both the designated competent authority (or Information Commission) and the Computer Security Incident Response Team (CSIRT).
  • Customer Notification Requirements - Section 16 introduces Regulations 11C, 12C, and 14G, requiring organisations to notify affected UK customers "as soon as reasonably practicable" after providing the full notification. This includes explaining why the customer is likely to be adversely affected.

3. Enhanced Enforcement and Penalty Powers

Section 21 and Schedule 1 significantly strengthen enforcement:

  • Financial Penalties - Maximum penalties are tiered:
  • Serious failures (security duties, incident reporting): Up to the greater of £17,000,000 and 4% of global turnover
  • Standard failures (registration, notification timing): Up to the greater of £10,000,000 and 2% of global turnover
  • Information Gathering Powers - Section 20 introduces Regulation 15, giving regulators power to require information and documents from regulated persons and others. This includes power to require generation of new information and collection of data that wouldn't otherwise be retained.
  • Enhanced Inspection Powers - Schedule 1 strengthens Regulation 16, allowing:
    • On-site inspections of premises
    • Examination, copying, and removal of documents
    • System testing and interviews
    • Requirements to maintain evidence without alteration
  • Enforcement Notices - Schedule 1 (Regulation 17) enables enforcement notices requiring immediate action to remedy failures, with civil proceedings available for non-compliance.

4. National Security Directions (Part 4)

Part 4 introduces unprecedented powers for national security scenarios:

  • Section 43 allows the Secretary of State to give directions to regulated persons when threats pose a risk to national security. These directions can:
    • Require specific security measures
    • Prohibit or restrict use of goods, services, or facilities
    • Require removal, disabling, or modification of systems
    • Require appointment of skilled persons
    • Apply to activities outside the UK
  • Section 44 provides that compliance with national security directions takes priority over conflicting regulatory requirements.
  • Section 49 sets maximum penalties for non-compliance with directions:
    • Up to £17,000,000 for undertakings, rising to the greater of £17,000,000 and 10% of global turnover only where regulations under Section 49(5) are in force (none have yet been made)
    • Daily penalties of up to £100,000 per day while a contravention of a direction continues
    • Up to £50,000 per day for information/inspection failures

5. Strategic Priorities and Codes of Practice (Part 3)

Part 3 introduces new governance frameworks:

  • Statement of Strategic Priorities - Section 25 allows the Secretary of State to designate a Statement of Strategic Priorities setting out government priorities for cyber security and resilience. Section 27 requires regulatory authorities to have regard to this statement and seek to achieve relevant objectives.
  • Code of Practice - Section 36 enables the Secretary of State to issue a Code of Practice describing recommended measures for compliance. Section 38 makes codes admissible in evidence and requires courts and regulators to take them into account when determining compliance questions.
  • Regulatory Powers - Section 29 allows the Secretary of State to make regulations relating to security and resilience of network and information systems, with powers to impose requirements on regulated persons under Section 30.

6. Cost Recovery Powers

Section 17 introduces Regulations 20A-20C, allowing NIS enforcement authorities to:

  • Impose periodic charges on regulated persons through charging schemes
  • Recover costs of enforcement activities
  • Require payment of charges that need not relate to functions exercised in relation to the specific person charged

7. Information Sharing Enhancements

Section 18 significantly expands information sharing powers:

  • Regulation 6 allows NIS enforcement authorities to share information with other authorities, law enforcement, CSIRT, and UK public authorities for various purposes including national security, crime prevention, and regulatory functions.
  • Regulation 6A provides for onward disclosure with appropriate safeguards.
  • Regulation 6B allows the Information Commission to use information obtained under NIS Regulations for other functions if necessary and proportionate.
  • Regular sharing of registers and lists with GCHQ is mandated under Regulations 8ZA(6), 14(5), and 14C(6).

What to Expect Next: The Legislative Process

With the Bill now introduced to Parliament, organisations should understand the timeline ahead:

Parliamentary Stages

  1. First Reading - Completed on 12th November 2025. The Bill was formally introduced and ordered to be printed.
  2. Second Reading - Expected in the coming weeks. This is the main debate on the Bill's principles, where MPs will discuss the overall approach and key provisions.
  3. Committee Stage - Detailed examination of each clause, with potential amendments. This is where technical details may be refined.
  4. Report Stage - Further opportunity for amendments based on committee work.
  5. Third Reading - Final debate in the House of Commons before the Bill moves to the House of Lords.
  6. House of Lords - The Bill will go through similar stages in the Lords, where peers may propose amendments.
  7. Royal Assent - Once both Houses agree on the final text, the Bill receives Royal Assent and becomes an Act of Parliament.

Expected Timeline

Based on typical parliamentary processes for significant legislation:

  • Late 2025/Early 2026: Second Reading and Committee Stage
  • Early to Mid 2026: Report Stage, Third Reading, and House of Lords consideration
  • Mid to Late 2026: Royal Assent expected
  • Late 2026/Early 2027: Commencement regulations likely to bring most provisions into force

However, given the Bill's significance and the government's stated priorities, the process may be accelerated. Organisations should prepare for the possibility of earlier implementation.

What Will Happen After Royal Assent?

Section 60 provides for phased commencement, meaning different parts of the Bill will come into force at different times:

  1. Immediate (on Royal Assent):

    • Definitions and introductory provisions
    • Powers to make regulations
    • Reporting requirements framework
  2. Two Months After Royal Assent:

    • Information sharing provisions
    • Statement of Strategic Priorities framework
  3. Appointed Day (by regulations):

    • Expanded scope (MSPs, data centres, critical suppliers)
    • Mandatory incident reporting requirements
    • Enhanced enforcement powers
    • National security directions

The Secretary of State will make commencement regulations specifying exact dates. Organisations should expect guidance and consultation on implementation timelines.

Critical Action Items for Organisations

With the Bill now before Parliament, preparation is no longer theoretical. Here's what organisations should do immediately:

1. Determine Your Regulatory Status

Assess whether you fall into scope:

  • Managed Service Providers: Do you provide ongoing IT management services? Review Section 9 and Regulation 14B to understand RMSP duties.

  • Data Centres: Check your rated IT load. If 1MW+ (or 10MW+ for enterprise), you'll be an OES under Section 4.

  • Cloud/Digital Services: Review Section 7 to see if your services meet the "relevant digital service" definition.

  • Critical Suppliers: Even if not directly regulated, you may be designated as a critical supplier under Section 12 if your failure could impact essential services.

  • Existing OES/RDSP: Your duties are expanding. Review all new requirements.

2. Prepare for Mandatory Incident Reporting

The 24/72-hour timelines are strict. Prepare now:

  • Review incident detection capabilities - Can you identify reportable incidents within 24 hours?
  • Establish reporting workflows - Create clear processes for:
    • Initial notification (24 hours)
    • Full notification (72 hours)
    • Customer notification (as soon as reasonably practicable)
    • Dual reporting to regulator and CSIRT
  • Update incident response plans - Ensure they align with new legal requirements.
  • Train staff - Incident response teams must understand new thresholds and timelines.
  • Test processes - Run tabletop exercises simulating the new reporting requirements.

3. Strengthen Security Posture

Enhanced enforcement means higher stakes:

  • Conduct gap assessments - Identify where current security measures fall short of expected standards.
  • Review security governance - Ensure board-level accountability and clear ownership.
  • Assess supply chain risks - Understand dependencies and prepare for potential critical supplier designation.
  • Review contracts - Ensure supplier agreements support compliance with new requirements.
  • Consider certifications - Cyber Essentials, ISO 27001, and other frameworks can demonstrate due diligence.

4. Understand Information Gathering Powers

Regulators will have extensive information powers:

  • Document your security measures - Be ready to demonstrate compliance through documentation.
  • Review data retention policies - Regulators can require collection of data you wouldn't normally retain.
  • Prepare for inspections - Understand what inspectors can access and require.
  • Legal privilege considerations - Know what information is protected from disclosure.

5. Plan for Cost Recovery

Regulators can recover costs through charges:

  • Budget for compliance costs - Periodic charges may be imposed regardless of whether functions are exercised in relation to your organisation.
  • Monitor charging scheme consultations - Regulators must consult before making or revising schemes.
  • Understand charge structures - Review how charges are calculated (may be based on turnover).

6. Monitor Parliamentary Progress

Stay informed as the Bill progresses:

  • Track amendments that may affect your obligations.
  • Participate in consultations on guidance and codes of practice.
  • Review draft regulations as they're published.
  • Engage with industry bodies and trade associations.

The Bottom Line: Why This Matters Now

The introduction of the Cyber Security and Resilience Bill to Parliament is a clear signal that the UK is serious about raising cyber security standards across the economy.

For organisations in scope, the message is clear:

  1. Compliance is becoming mandatory, not optional - More organisations will face legal duties.
  2. The cost of non-compliance is high - Penalties of up to the greater of £17 million and 4% of turnover for serious failures, and the greater of £10 million and 2% for standard ones.
  3. Preparation takes time - Incident response and governance improvements cannot be rushed.
  4. Supply chain risks are real - Critical supplier designation increases exposure.
  5. The window for preparation is closing - Royal Assent could come as early as mid-2026.

How Precursor Security Can Help

At Precursor Security, we are helping organisations prepare for the Cyber Security and Resilience Bill through:

  • CSRB Compliance Gap Assessments
  • Incident Response Readiness (24/72-hour reporting)
  • Security Posture Reviews
  • Supply Chain Risk Assessments
  • Regulatory Engagement Support
  • Certification Support (Cyber Essentials, ISO 27001, etc.)

Our team combines deep technical expertise with regulatory knowledge to help integrate compliance into your security strategy.

Conclusion: The Time to Act is Now

The Cyber Security and Resilience Bill's introduction to Parliament on 12 November 2025 marks a major shift in UK cyber regulation. Expanded scope, stricter requirements, and enhanced enforcement powers mean organisations cannot wait.

The most successful organisations will treat CSRB compliance as an opportunity to strengthen security and build trust.

Start preparing now. Assess your exposure, strengthen your capabilities, and build the governance structures needed to meet these requirements.

For organisations needing deeper guidance, we’ve published a comprehensive CSRB Readiness Assessment on the Cyber Security and Resilience Bill website, featuring detailed explanations, sector-specific implications, and practical preparation steps tailored to different types of organisations. Visit cybersecurityandresiliencebill.com to explore more.

For tailored support, explore the resources on this site or contact Precursor Security to discuss your specific needs.

Tags:
CSRBcyber securityUK legislationcomplianceresilienceregulationsNISParliamentBill 329incident reportingenforcement
Last updated: 3 August 2026
Share:

You Might Also Like

Explore more insights and guidance on the Cyber Security and Resilience Bill.

Precursor Security
21 Jun 2026

Cyber Security and Resilience Bill Clears the Commons: Where It Stands in 2026

The Cyber Security and Resilience Bill (CSRB) has cleared every House of Commons stage and passed to the Lords as HL Bill 32. The core architecture survived intact - expanded scope, 24/72-hour reporting, £17m penalties - with one headline change: Ofcom is now the sole regulator for data centres. Here is the confirmed timeline and what to do before Royal Assent, expected late 2026.

CSRBcyber security+12 more
Read Article
Precursor Security
29 Aug 2025

What is the UK Cyber Security and Resilience Bill (CSRB) and Why Should You Care?

The UK Cyber Security and Resilience Bill (CSRB) is the biggest shake-up of UK cyber legislation in years: 5 Parts, 61 sections, and a shift that turns resilience from good practice into a legal obligation. This is the plain-English starting point - who it catches, what it demands, what non-compliance costs, and the three things to do about it now.

CSRBcyber security+6 more
Read Article
Precursor Security
22 Jul 2026

Lords Complete Cyber Security and Resilience Bill Second Reading: Key Themes and Committee Stage on 1 September

The Lords gave the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, cross-party support at Second Reading on 14 July 2026 without calling a division - but they put five pointed themes on the record, from the public sector exemption to the Bill's total silence on AI. Committee Stage begins on 1 September, and those themes are the working agenda. Here is what each one means for in-scope organisations.

CSRBcyber security+19 more
Read Article