Cyber Security and Resilience Bill FAQ
Find answers to common questions about the Cyber Security and Resilience Bill (HL Bill 32). All answers reference specific sections and regulations from the legislation.
General Questions
The Cyber Security and Resilience (Network and Information Systems) Bill (Bill 329) was introduced to Parliament on 12th November 2025. As of June 2026 it has completed all of its House of Commons stages and is now before the House of Lords (introduced there on 17th June 2026 as HL Bill 32), with Royal Assent expected in late 2026. It's the UK's most comprehensive update to cyber legislation in over a decade, significantly expanding the scope of existing NIS Regulations 2018.
The Bill is structured in 5 Parts with 61 sections and 2 Schedules:
- Part 1: Introduction (Sections 1-2)
- Part 2: Amendments to NIS Regulations (Sections 3-23)
- Part 3: Security and Resilience Functions (Sections 24-42)
- Part 4: National Security Directions (Sections 43-58)
- Part 5: General provisions (Sections 59-61)
The Bill extends regulation to managed service providers, data centres, load controllers, and critical suppliers, while strengthening incident reporting, enforcement powers, and national security provisions.
The Bill is not yet law - it is still progressing through Parliament (in the House of Lords as of June 2026, with Royal Assent expected in late 2026). Its commencement provisions are staggered, and the Government has said it will consult during 2026 on the detailed implementation requirements before the main duties take effect. Once enacted, commencement is expected to follow this pattern:
Immediate commencement (when Act is passed):
- Part 1 (Introduction)
- Part 3, Chapters 1, 3, and 6 (Security and Resilience Functions)
- Section 40 (Reports on legislation)
- Part 5 (General)
2 months after passing:
- Section 18(3) and (4) (Information sharing)
- Part 3, Chapter 2 (Strategic Priorities)
- Schedule 2, paragraphs 3, 4, and 13
Appointed day (by Secretary of State regulations):
- Most other provisions, including Part 2 amendments
- Section 12 (Critical suppliers) must commence on the same day as first regulations under Section 29(1)
Organizations should begin preparing now, as registration requirements typically have a 3-month deadline from commencement.
References:
Enforcement is carried out by designated competent authorities and the Information Commission:
Designated Competent Authorities (Regulation 3):
- Regulate Operators of Essential Services (OES) in their respective sectors
- Examples: the Secretary of State for Energy Security and Net Zero and Ofgem acting jointly (electricity and most gas); the Secretary of State for Transport and the Civil Aviation Authority acting jointly (aviation); the Secretary of State for Health (health care in England); Ofcom (digital infrastructure and data centres)
Information Commission:
- Regulates Relevant Digital Service Providers (RDSPs) - Section 7
- Regulates Relevant Managed Service Providers (RMSPs) - Section 9
- Can designate critical suppliers under Regulation 14H
GCHQ (Government Communications Headquarters):
- Receives registration information for national security purposes (Section 18(1))
- Receives incident notifications via CSIRT
CSIRT (Computer Security Incident Response Team):
- Receives copies of all incident notifications (Regulations 11(8), 12A(7), 14E(7))
Each regulator has powers to issue enforcement notices, impose penalties, and conduct inspections under Schedule 1.
References:
Who is Affected?
Yes, Managed Service Providers are now regulated as Relevant Managed Service Providers (RMSPs) under Section 9.
Definition (Regulation 3B): An RMSP provides ongoing management of IT systems including support, maintenance, monitoring, or active administration, where the provider connects to or accesses the customer's network and information systems.
Requirements:
- Must register with Information Commission within 3 months (Regulation 14C)
- Must identify and manage risks to network and information systems (Regulation 14B)
- Must report incidents within 24 hours (Regulation 14E)
- Must notify affected customers (Regulation 14G)
Exemptions:
- Micro or small enterprises (as defined by Commission Recommendation 2003/361/EC)
- Providers of data centre services (covered separately)
- Public electronic communications networks/services
UK Representative: If your principal office is outside the UK, you must nominate a UK representative within 3 months (Regulation 14D).
Yes, data centres are now regulated as essential services under Section 4.
Thresholds:
- General data centres: 1 megawatt (MW) or more rated IT load
- Enterprise-only data centres: 10MW or more rated IT load (where the data centre is owned/managed by a person solely for their own undertaking)
Definition (Schedule 2, paragraph 11): A data centre service provides a physical structure containing IT equipment with supporting infrastructure (electricity, environmental control, security, resilience).
Requirements:
- Must provide information to designated competent authority within 3 months (Regulation 8ZA)
- Must report incidents with lower threshold - any significant impact (Regulation 11A)
- Must notify affected customers (Regulation 11C)
- Must update information within 7 days of changes (Regulation 8ZA(6))
Crown Application: Government data centres are regulated except for Security Service, Secret Intelligence Service, GCHQ, or services classified as "secret" or "top secret" (Section 5).
Large load controllers are regulated under Section 6 if they manage 300 megawatts (MW) or more of potential electrical control.
Calculation (Schedule 2, paragraph 1(5B)): A load controller's potential electrical control is the aggregate of:
- Maximum flow of electricity INTO all relevant Energy Smart Appliances (ESAs)
- Maximum flow of electricity OUT of all relevant ESAs
Relevant ESAs include:
- Electric vehicles
- Charge points (for electric vehicles)
- Electrical heating appliances (heat pumps, storage heaters, etc.)
- Battery energy storage systems
- Virtual power plants
Intermediaries: If load control signals are sent through an intermediary who can adjust or process them, both the load controller AND intermediary may be treated as load controllers (Schedule 2, paragraph 1(5E)).
Requirements: Load controllers meeting the threshold are Operators of Essential Services (OES) and must comply with all OES requirements including security duties, incident reporting, and registration.
References:
Yes, even small businesses can be designated as critical suppliers under Section 12 (Regulation 14H) if they meet the criteria.
Designation Criteria: A person can be designated if they:
- Supply goods or services directly to an OES, RDSP, or RMSP
- Rely on network and information systems for that supply
- An incident affecting their systems could cause significant disruption to:
- The essential service/digital service/managed service they supply to, OR
- Essential services, digital services, or managed services more generally
- The disruption would likely have significant impact on the economy or day-to-day functioning of society
Key Points:
- Size doesn't matter - impact does (Regulation 14H(3) considers alternative sources)
- Can be designated whether or not established in UK (Regulation 14H(7))
- Can be designated by multiple regulators (Regulation 14H(5))
- Must comply with same requirements as OES/RDSP/RMSP once designated
Consultation Process: Before designation, you'll receive written notice with reasons and have opportunity to make representations (Regulation 14J).
References:
Yes, cloud computing services are regulated as Relevant Digital Services (RDSPs) under Section 7.
Definition (Regulation 1(2), as amended by Section 7): A cloud computing service enables access to a scalable, elastic pool of shareable computing resources (networks, servers, software, storage) with:
- Broad remote access
- On-demand, self-service capability
- Distributed across multiple locations
- Not solely for the provider's own use
- NOT a managed service
Requirements:
- Must register with Information Commission within 3 months (Regulation 14)
- Must take appropriate security measures (Regulation 12)
- Must report incidents within 24 hours (Regulation 12A)
- Must notify affected customers (Regulation 12C)
Exclusions:
- Managed services (covered separately as RMSPs)
- Public electronic communications networks/services
- Micro or small enterprises
UK Representative: If principal office is outside UK, must nominate UK representative within 3 months (Regulation 14A).
Incident Reporting
The Bill requires strict incident reporting deadlines under Section 15:
Initial Notification: 24 hours
- Must be given within 24 hours of becoming aware of an incident
- Must include: name, service affected, brief details
- Must be sent to both your designated competent authority AND CSIRT simultaneously
Full Notification: 72 hours
- Must be given within 72 hours of becoming aware
- Must include comprehensive details:
- Time, duration, whether ongoing
- Nature of incident
- Impact (including cross-border)
- Details of any related incidents affecting other regulated persons
- Other relevant information
Customer Notification: After full notification, must notify affected UK customers "as soon as reasonably practicable" (Section 16, Regulations 11C, 12C, 14G).
Data Centres: Data centre operators have a lower reporting threshold - any incident with significant impact must be reported (Regulation 11A(3)).
The definition of "incident" has been expanded under Section 15(2) to include potential impacts, not just actual damage.
Definition (Regulation 1(2), as amended): An incident is anything that has, or is capable of having, an adverse effect on the operation or security of network and information systems.
For OES (other than data centres): An incident is reportable if it:
- Has affected or is affecting operation/security of systems
- Impact in UK has been, is, or is likely to be significant, considering:
- Extent of disruption to essential service
- Number of users affected
- Duration
- Geographical area affected
- Compromise of data confidentiality, authenticity, integrity, or availability
For Data Centres: Any incident which could have had, has had, is having, or is likely to have:
- Significant impact on operation/security of systems
- Significant impact on continuity of service
- Any other significant impact in UK
For RDSPs/RMSPs: Similar criteria plus impact on users' systems and impact on economy/society.
Key Point: You must report potential threats that could cause harm, not just actual damage.
Yes, customer notification is mandatory under Section 16 after you've given your full notification to regulators.
Who Must Notify:
- Data centre operators (Regulation 11C)
- Relevant Digital Service Providers (Regulation 12C)
- Relevant Managed Service Providers (Regulation 14G)
Timing:
- Must take reasonable steps to identify affected UK customers
- Must notify them "as soon as reasonably practicable" after full notification
Content Requirements: Notification must include:
- Details of the nature of the incident
- Explanation of why the customer is likely to be adversely affected
Considerations: When determining if a customer is affected, you must consider:
- Extent of disruption to service provided to customer
- Whether data confidentiality, authenticity, integrity, or availability is compromised
- Any other impact on customer's network and information systems
Penalties: Failure to notify customers can result in penalties up to the greater of £17 million and 4% of turnover (Section 21, Regulation 17).
Registration & Information
Registration requirements vary by entity type:
Data Centre Operators (Regulation 8ZA):
- Name, proper address
- Names of directors (if body corporate) or partners (if partnership)
- Up-to-date contact details (email, telephone)
- Must be provided within 3 months of designation
- Must update within 7 days of any changes
RDSPs (Regulation 14):
- Name, proper address
- Names of directors or partners
- Which relevant digital services you provide
- Up-to-date contact details
- Must register before registration date (3 months from becoming RDSP)
RMSPs (Regulation 14C):
- Name, proper address
- Names of directors or partners
- Up-to-date contact details
- Must register before registration date (3 months from becoming RMSP)
Important:
- Registration information is shared with GCHQ for national security purposes (Section 18(1))
- Must update within 7 days of any changes (Regulations 8ZA(6), 14(3), 14C(5))
- If outside UK, must also nominate UK representative (Regulations 8A, 14A, 14D)
Yes, if your principal office is outside the UK, you must nominate a UK representative under:
OES (Regulation 8A):
- Must nominate within 3 months of becoming OES
- Must notify designated competent authority of representative's name and contact details
- Must update within 7 days of changes
RDSPs (Regulation 14A):
- Must nominate within 3 months
- Must notify Information Commission
- Must include email address and telephone number
RMSPs (Regulation 14D):
- Must nominate within 3 months
- Must notify Information Commission
- Must include email address and telephone number
Representative's Role:
- Can be contacted by Information Commission or GCHQ instead of or in addition to you
- Acts as your point of contact in UK
- Nomination doesn't affect legal liability - you remain responsible
Penalties: Failure to nominate or notify changes can result in enforcement notices and penalties.
References:
Yes, regulators have extensive information gathering powers under Section 20 (Regulation 15).
Who Can Request:
- Designated competent authorities (from OES and others)
- Information Commission (from RDSPs, RMSPs, and others)
What Can Be Requested:
- Information or documents reasonably required for exercising functions
- Can require you to obtain, generate, collect, or retain information you wouldn't otherwise have (Regulation 15A(1))
- Can relate to information stored outside UK (Regulation 15A(3))
Purposes Include:
- Establishing if you meet designation criteria
- Deciding whether to designate or revoke designation
- Determining penalty amounts
- Determining charge amounts
- Monitoring compliance
Information Notice Requirements: Must specify:
- Information/documents sought
- Why they're being sought
- Manner and form
- Time period
- Consequences of non-compliance
Penalties: Failure to comply with an information notice falls in the higher band: the greater of £17 million and 4% of turnover (Regulation 18(11)(d), applying to Regulation 17(2ZB)).
Penalties & Enforcement
Penalties are tiered based on the severity of the violation under Section 21:
Standard Maximum Amount:
- For undertakings: Greater of £10,000,000 OR 2% of global turnover
- For others: £10,000,000
Applies to failures such as:
- Registration and information-provision failures (Regulation 8ZA)
- Some incident reporting failures (copying CSIRT, etc.)
Note: failing to comply with an information notice (Regulation 17(2ZB)) is not in this band - Regulation 18(11)(d) places it in the higher band below.
Higher Maximum Amount:
- For undertakings: Greater of £17,000,000 OR 4% of global turnover
- For others: £17,000,000
Applies to serious failures such as:
- Security duty failures
- Incident reporting failures (initial/full notifications)
- Customer notification failures
- Direction compliance failures
Daily Penalties (Part 4 - National Security):
- Up to £100,000 per day while a contravention of a national security direction continues (Section 49(3))
- Up to £50,000 per day for Part 4 information/inspection failures
- These daily penalties belong to Part 4 only. There is no daily penalty in the NIS Regulations regime.
Penalty Determination: Regulators must consider:
- Impact of the failure
- Steps taken to remedy or mitigate
- Previous compliance history
Penalties are recoverable as civil debt (Regulation 18(3C)).
References:
Failure to comply with an enforcement notice can lead to severe consequences:
Enforcement Notices (Regulation 17):
- Can be served for various failures (security duties, incident reporting, registration, etc.)
- Must specify steps to be taken
- Must be complied with regardless of whether penalty is paid (Regulation 17(3A))
Consequences of Non-Compliance:
-
Civil Proceedings (Regulation A20):
- Regulator can commence civil proceedings for injunction or specific performance
- Can seek any appropriate remedy or relief
-
Additional Penalties:
- Can result in further penalty notices
- Daily penalties may apply for continuing violations
-
Inspection Powers:
- Regulator can conduct inspections to verify compliance (Schedule 1, Regulation 16)
- You must pay reasonable costs of inspections
-
Information Gathering:
- Regulator can require extensive information (Section 20)
Appeals: You can appeal enforcement notices to First-tier Tribunal (Schedule 1, Regulation 19A), but must still comply pending appeal unless Tribunal orders otherwise.
Yes, regulators have extensive inspection powers under Schedule 1 (Regulation 16).
Who Can Inspect:
- Designated competent authorities
- Information Commission
- Inspectors appointed by them
What Inspectors Can Do:
- Enter premises at reasonable times (except private dwellings)
- Examine, print, copy, or remove documents/information
- Examine or remove material/equipment
- Interview any person
- Carry out or direct security tests on systems
- Require you to maintain materials without alteration
Your Obligations:
- Must cooperate with inspector
- Must provide access to premises
- Must allow examination/removal of documents, information, material, equipment
- Must allow access to persons for interviews
- Must not intentionally obstruct
- Must comply with inspector's requests
- Must pay reasonable costs of inspection
Protections:
- Cannot be required to produce privileged communications (Regulation 16(8A))
- Powers not exercisable outside UK for premises/material/equipment/individuals (Regulation 16(8B))
- Can exercise powers in relation to documents/information stored outside UK
Notice: Inspector must give notice of consequences before conducting inspection (Regulation 16(4A)).
References:
National Security
National security directions are emergency powers under Part 4 (Section 43) that allow the Secretary of State to require immediate action when national security is at risk.
When Can Directions Be Given:
- When security or operational compromise (or threat) gives rise to risk to national security
- Must be necessary and proportionate in interests of national security
What Can Be Required:
- Management of network/information systems
- Risk reduction or impact mitigation
- Information provision
- Prohibition/restriction on use of goods/services/facilities
- Prohibition on installation
- Removal, disabling, or modification of goods/facilities
- Appointment of skilled persons (with approval)
- Actions in UK, relevant UK waters, or outside UK
Priority: Compliance with directions takes priority over conflicting regulatory requirements (Section 44).
Penalties:
- Up to £17 million for contravening a direction, rising to the greater of £17 million and 10% of turnover only where regulations under Section 49(5) are in force (none have been made yet)
- Up to £100,000 per day while a contravention of a direction continues, and up to £50,000 per day for information or inspection failures (Section 49)
- These Part 4 sanctions are separate from the NIS Regulations regime, which has no daily penalty
Non-Disclosure: Secretary of State can require you not to disclose existence or contents of directions (Section 43(11)).
References:
Information sharing with GCHQ is mandatory under Section 18(1):
What Is Shared:
- Lists of OES maintained by competent authorities (Regulation 3(3)(e))
- Register of RDSPs (Regulation 14(5))
- Register of RMSPs (Regulation 14C(6))
- Copies of incident notifications (via CSIRT)
Timing:
- Initial sharing: Within 4 months of Section 18(1) coming into force
- Ongoing: Annually thereafter
Purpose: To facilitate exercise of GCHQ's functions under NIS Regulations or any other enactment.
Additional Sharing:
- Information Commission can share information with GCHQ for facilitating functions (Regulation 6)
- CSIRT receives all incident notifications
- Information can be shared for national security purposes (Section 56)
Your Rights:
- You're notified that information will be shared
- Sharing is for national security and regulatory purposes
- Subject to data protection laws
Costs & Charges
Yes, regulators can impose charges under Section 17:
Periodic Charges (Regulation 20A):
- Regulators can make charging schemes for periodic charges
- Charges relate to regulator's costs in exercising functions
- Can make different provision for different purposes
- Must be published and consulted on
- Charges may not relate to functions exercised in relation to you specifically
Enforcement Charges (Regulation 20C):
- Can require charges for costs of specific enforcement actions
- Excludes costs relating to appeals or proceedings
- Must provide invoice stating costs
Inspection Costs:
- You must pay reasonable costs of inspections (Schedule 1, Regulation 16(3)(a))
- Can be significant for complex systems
Cost Recovery Statements: Regulators must publish statements showing:
- Aggregate charges received
- Outstanding charges
- Costs of functions
Budget Planning: You should budget for:
- Annual or periodic regulatory charges
- Potential inspection costs
- Enforcement action costs
- Compliance implementation costs
Appeals & Disputes
Yes, you can appeal to the First-tier Tribunal under Schedule 1 (Regulation 19A):
What Can Be Appealed:
- Enforcement notices (Regulation 17)
- Penalty notices (Regulation 18(3B))
- Critical supplier designations (Regulation 14H)
- Critical supplier revocations (Regulation 14K)
- Information notice failures (Regulation 17(2ZB))
Appeal Grounds:
- Decision was based on error of fact
- Decision was wrong in law
- Decision was unreasonable
- Decision was procedurally unfair
Tribunal Powers: First-tier Tribunal can (Regulation 19B):
- Confirm the decision
- Vary the decision
- Withdraw the decision
- Award costs
Process:
- Must appeal within specified time period
- Decision may be suspended pending appeal (depending on circumstances)
- May require legal representation
- Can be costly
Important: You must still comply with enforcement notices pending appeal unless Tribunal orders otherwise.
References:
Implementation & Compliance
Security requirements vary by entity type:
OES (Regulation 10):
- Must identify and take appropriate and proportionate measures to manage risks
- Must ensure level of security appropriate to risk (having regard to state of art)
- Must prevent and minimize impact of incidents
- Must ensure continuity of services
RDSPs (Regulation 12):
- Must identify and take appropriate and proportionate measures to manage risks
- Must ensure security of network and information systems
- Must have regard to Information Commission guidance
RMSPs (Regulation 14B):
- Must identify and take appropriate and proportionate measures to manage risks
- Must ensure level of security appropriate to risk (having regard to state of art)
- Must prevent and minimize impact of incidents
- Must have regard to Information Commission guidance
Codes of Practice:
- Secretary of State can issue Codes of Practice (Section 36)
- Codes describe recommended measures
- Courts and regulators must take codes into account (Section 38)
- Failure to follow codes may be evidence of non-compliance
Strategic Priorities:
- Regulatory authorities must have regard to Statement of Strategic Priorities (Section 27)
- Will guide enforcement decisions
Here's a practical compliance roadmap:
Phase 1: Assessment (Immediate)
- Determine if you're in scope (check thresholds, entity types)
- Assess whether you might be designated as critical supplier
- Review your current security measures
- Identify gaps
Phase 2: Registration (Within 3 months of commencement)
- Gather required information (company details, directors, contacts)
- Register with appropriate regulator
- Nominate UK representative if outside UK
- Set up processes to update within 7 days of changes
Phase 3: Security Implementation (Ongoing)
- Implement appropriate security measures
- Align with Codes of Practice when issued
- Establish risk management processes
- Prepare for inspections
Phase 4: Incident Response (Ongoing)
- Set up 24/7 monitoring
- Create incident response procedures
- Prepare notification templates
- Establish customer notification processes
- Train staff on incident identification
Phase 5: Ongoing Compliance
- Monitor for regulatory updates
- Participate in consultations
- Maintain compliance documentation
- Conduct regular reviews
- Budget for regulatory charges
Resources:
- Take our readiness assessment: /assessment
- Consult regulatory guidance (Section 19)
- Monitor for Codes of Practice (Section 36)
- Review Strategic Priorities (Section 25)
Still Have Questions?
Our cybersecurity compliance experts can help you understand how the Cyber Security and Resilience Bill affects your organisation and develop a roadmap for compliance.