The UK Cyber Security and Resilience Bill (CSRB) is one of the most significant updates to UK cyber legislation in years. With UK organisations operating in an increasingly hostile digital landscape, this bill has been introduced in response to the sharp rise in ransomware, data breaches and supply chain attacks, with the aim to raise the bar for how businesses prevent, detect and respond to cyber threats.
With more sectors under scrutiny, the CSRB signals a clear shift: cyber security is no longer just IT issue - it is a legal and operational priority. If your organisation delivers digital services or plays a role in essential operations, preparing now is non-negotiable - it’s essential.
What is the Cyber Security and Resilience Bill?
The Cyber Security and Resilience (Network and Information Systems) Bill (Bill 329) was introduced to Parliament on 12th November 2025. Announced in the 2024 King's Speech and backed by a formal policy paper in April 2025, CSRB is the UK's response to a rapidly evolving cyber ecosystem and the need for stronger regulatory oversight for organisations.
The Bill is structured in 5 Parts with 61 sections and 2 Schedules. Rather than overhauling the current frameworks entirely, Part 2 of CSRB builds upon the existing NIS Regulations 2018 - but with tougher requirements, broader scope and clearer responsibilities for both digital and essential service providers.
Part 2, Chapter 1 extends legal duties to a wider range of sectors:
- Section 9: Managed Service Providers (MSPs) as 'Relevant Managed Service Providers' (RMSPs)
- Section 4: Data centres as essential services (1MW/10MW thresholds)
- Section 6: Large load controllers (300MW+)
- Section 12: Critical supplier designation powers
- Section 7: Cloud computing services redefined as 'relevant digital services'
These changes reflect the government's focus on elevating baseline cyber hygiene and strengthening national resilience.
The end goal for this legislation is to ensure that essential and digital services and maintain operational resilience, even in the face of growing and more sophisticated cyber threats. Organisations will be expected to take a more proactive stance on cyber security governance, which includes board-level accountability, risk assessments and coordinated incident response.
Who does the Cyber Security and Resilience Bill (CSRB) apply to?
The CSRB will bring a much broader range of UK organisations into scope. If your business delivers digital services, supports critical infrastructure or operates within a regulated sector, it’s highly likely that you will be affected.
Organisations which fall under the Cyber Security and Resilience Bill include, but are not limited to:
- Managed Service Providers (MSPs)
- Cloud infrastructure and hosting Platforms
- SaaS vendors and software providers
- Data centres
- Public sectors bodies and local authorities
- Operators of essential services (e.g. energy, transport, healthcare, water, education, telecommunications).
- Vendors and suppliers in critical national infrastructure supply chains.
Even if your organisation hasn’t previously fell into scope of other similar legislation, the broader scope of CSRB introduces new legal duties for a wide array of businesses, meaning even indirect links to critical infrastructure could bring your organisation under regulatory scrutiny for the first time.
For a more comprehensive deep dive into how the CSRB applies to your sector, including tailored breakdowns by industry, readiness checklists, and guidance on whether your organisation is in scope, click here.
What Are the Key Changes?
To address the ever-evolving threat landscape, the UK Government has overhauled existing legislation and has introduced sweeping changes which put pressure on organisations to strengthen their defences and take cyber security seriously.
Expanded Scope of Regulation
Thousands of organisations not previously covered by legislation will now fall under the CSRB.
Mandatory Incident Reporting (with 24-72 hour deadlines)
Section 15 mandates strict reporting timelines. Regulation 11 (OES), Regulation 12A (RDSP), and Regulation 14E (RMSP) require initial notification within 24 hours and full report within 72 hours to both the regulator and CSIRT. Section 16 requires customer notification 'as soon as reasonably practicable' after full notification. The definition of 'incident' is expanded in Section 15(2) to include incidents 'capable of having' an impact, not just actual impacts.
Strategic Priorities & Codes of Practice (Part 3)
Section 25 allows the Secretary of State to designate a Statement of Strategic Priorities, which regulatory authorities must have regard to (Section 27). Section 36 enables Codes of Practice describing recommended measures for compliance. Section 38 makes codes admissible in evidence and requires courts and regulators to take them into account. Section 29 allows the Secretary of State to make regulations relating to security and resilience.
Legal Duties for Supply Chain Security
Section 12 introduces Regulation 14H allowing designation of critical suppliers whose failure could impact national infrastructure. Section 30(3) enables regulations to impose requirements on providers of 'activity-critical supplies'. Even small suppliers can be designated if their failure impacts essential services, and they face the same regulatory duties as larger providers.
New On-Site Inspection & Enforcement Powers (Part 2, Chapter 3)
Section 20 grants powers to require information and documents from regulated persons and others. Schedule 1 strengthens inspection powers (Regulation 16) allowing on-site inspections, document examination, and system testing. Section 21 sets financial penalties: up to the greater of £17,000,000 and 4% of global turnover for serious failures; the greater of £10,000,000 and 2% of turnover for standard failures. Schedule 1 (Regulation 17) enables enforcement notices requiring immediate action.
Delegated Powers for Rapid Legal Change
The Secretary of State now has powers to amend CSRB requirements quickly in response to emerging threats - so compliance must be dynamic, not static.
Transparency & Customer Notification Duties
You may be required to notify affected customers directly in the event of a significant incident, placing pressure on PR and breach communications planning.
Why Should You Care?
Because the cost of not caring is too high.
The Cyber Security and Resilience Bill isn’t just another piece of regulation - it carries real financial, legal and reputational consequences for non-compliance.
Part 2, Chapter 3 sets maximum penalties under Section 21: up to the greater of £17,000,000 and 4% of global turnover for serious failures (security duties, incident reporting); up to the greater of £10,000,000 and 2% of turnover for standard failures (registration, notification timing).
Part 4 introduces national security directions with even higher penalties. Section 43 allows the Secretary of State to give directions to regulated persons when threats pose a risk to national security. Section 49 sets a maximum penalty of £17,000,000 for contravening a direction, rising to the greater of £17,000,000 and 10% of global turnover only where regulations under Section 49(5) are in force, and none have yet been made. Daily penalties of up to £100,000 apply while a contravention of a direction continues, or up to £50,000 per day for information and inspection failures. None of these Part 4 sanctions apply under the NIS Regulations.
In addition to this, The National Cyber Security Centre (NCSC) will be provided with stronger powers with regulators, making it easier to investigate breaches and enforce compliance.
This isn’t just about avoiding fines. It’s about protecting your organisation’s ability to operate, serve customers, and maintain trust in a high-risk landscape.
What Should Businesses Do Now?
The Bill was introduced to Parliament on 12th November 2025. Section 60 provides for phased commencement - some provisions come into force immediately on Royal Assent, others require regulations. Preparation is key. With all of these changes on the horizon, here's how your organisation can begin getting ready now:
Assess Your Exposure
Firstly, identify whether your organisation falls under the new scope of the Cyber Security and Resilience Bill - especially if you're a digital service provider, MSP, or part of a critical supply chain. You should understand your obligations and which teams need to be involved.
Strengthen Incident Response and Governance
Make sure your incident response processes are fit for purpose and aligned with the new legal reporting timelines (24 to 72 hours). This includes reviewing your escalation paths, running tabletop exercises, and assigning board-level accountability.
Secure Your Supply Chain
Under the CSRB, you’re not just responsible for your own systems. You are also legally accountable for the security of key suppliers and third parties. It’s a good time to review contracts, assess supplier risk, and ensure that basic security controls are being implemented across the chain.
How can Precursor Security help?
At Precursor Security, we understand that navigating new legislation can be overwhelming- especially when it demands countless technical, procedural and organisational changes.
That’s why we are helping client prepare for the Cyber Security and Resilience Bill before it comes into effect.
Our team has real-world experience delivering compliance services across a range of industries. We can support you with:
- Cyber Security and Resilience Bill (CSRB) compliance gap assessments.
- Cyber Essentials and Cyber Essentials Plus certification
- ISO 27001 readiness assessments and audit support.
- Penetration testing and vulnerability assessments.
- Cloud configuration reviews.
- 24/7 CREST-accredited Security Operations Centre.
You can explore all of our compliance services by clicking here.
In addition to this, you’re already in the right place. This website is your dedicated hub for understanding and preparing for the CSRB. Here you’ll find:
- A clear overview of the Bill with an at-a-glance timeline.
- An interactive CSRB Readiness Assessment to benchmark your posture and receive tailored recommendations.
- Curated guidance, articles and useful links.
- Sector-specific obligations with practical next steps.
This Bill isn’t just a government tick box - it’s your opportunity to make resilience your competitive edge.
Final Thoughts: Stay Ahead of the Curve
The Cyber Security and Resilience Bill (CSRB) will impact a wide range of organisations - but it’s also an opportunity to harden defences, protect your customers, and build a reputation for resilience.
By preparing early and building CSRB compliance into your wider cyber strategy, you don’t just reduce risk - you get ahead.
Cyber security is no longer just an IT concern - it’s now a legal obligation that boards and leadership teams must understand and actively manage.
Start preparing now by:
- Assessing your organisation’s current security posture
- Reviewing supplier dependencies
- Updating response plans
- Raising board-level awareness