The Cyber Security and Resilience Bill 2026: A Definitive Analysis
The Cyber Security and Resilience Bill (CSRB), which replaces the NIS Regulations 2018, is now through Second Reading, and its four shifts - expanded scope, two-stage reporting, cost recovery and direct supply chain intervention - land on organisations that have never been regulated before. A full analysis of the RMSP and critical supplier definitions, the near miss clause, the 14 principles of the Software Security Code of Practice, and the penalty tiers.