Frequently Asked Questions

Cyber Security and Resilience Bill FAQ

Find answers to common questions about the Cyber Security and Resilience Bill (HL Bill 32). All answers reference specific sections and regulations from the legislation.

General Questions

The Cyber Security and Resilience (Network and Information Systems) Bill (Bill 329) was introduced to Parliament on 12th November 2025. As of June 2026 it has completed all of its House of Commons stages and is now before the House of Lords (introduced there on 17th June 2026 as HL Bill 32), with Royal Assent expected in late 2026. It's the UK's most comprehensive update to cyber legislation in over a decade, significantly expanding the scope of existing NIS Regulations 2018.

The Bill is structured in 5 Parts with 61 sections and 2 Schedules:

  • Part 1: Introduction (Sections 1-2)
  • Part 2: Amendments to NIS Regulations (Sections 3-23)
  • Part 3: Security and Resilience Functions (Sections 24-42)
  • Part 4: National Security Directions (Sections 43-58)
  • Part 5: General provisions (Sections 59-61)

The Bill extends regulation to managed service providers, data centres, load controllers, and critical suppliers, while strengthening incident reporting, enforcement powers, and national security provisions.

The Bill is not yet law - it is still progressing through Parliament (in the House of Lords as of June 2026, with Royal Assent expected in late 2026). Its commencement provisions are staggered, and the Government has said it will consult during 2026 on the detailed implementation requirements before the main duties take effect. Once enacted, commencement is expected to follow this pattern:

Immediate commencement (when Act is passed):

  • Part 1 (Introduction)
  • Part 3, Chapters 1, 3, and 6 (Security and Resilience Functions)
  • Section 40 (Reports on legislation)
  • Part 5 (General)

2 months after passing:

  • Section 18(3) and (4) (Information sharing)
  • Part 3, Chapter 2 (Strategic Priorities)
  • Schedule 2, paragraphs 3, 4, and 13

Appointed day (by Secretary of State regulations):

  • Most other provisions, including Part 2 amendments
  • Section 12 (Critical suppliers) must commence on the same day as first regulations under Section 29(1)

Organizations should begin preparing now, as registration requirements typically have a 3-month deadline from commencement.

Enforcement is carried out by designated competent authorities and the Information Commission:

Designated Competent Authorities (Regulation 3):

  • Regulate Operators of Essential Services (OES) in their respective sectors
  • Examples: the Secretary of State for Energy Security and Net Zero and Ofgem acting jointly (electricity and most gas); the Secretary of State for Transport and the Civil Aviation Authority acting jointly (aviation); the Secretary of State for Health (health care in England); Ofcom (digital infrastructure and data centres)

Information Commission:

  • Regulates Relevant Digital Service Providers (RDSPs) - Section 7
  • Regulates Relevant Managed Service Providers (RMSPs) - Section 9
  • Can designate critical suppliers under Regulation 14H

GCHQ (Government Communications Headquarters):

  • Receives registration information for national security purposes (Section 18(1))
  • Receives incident notifications via CSIRT

CSIRT (Computer Security Incident Response Team):

  • Receives copies of all incident notifications (Regulations 11(8), 12A(7), 14E(7))

Each regulator has powers to issue enforcement notices, impose penalties, and conduct inspections under Schedule 1.

Who is Affected?

Yes, Managed Service Providers are now regulated as Relevant Managed Service Providers (RMSPs) under Section 9.

Definition (Regulation 3B): An RMSP provides ongoing management of IT systems including support, maintenance, monitoring, or active administration, where the provider connects to or accesses the customer's network and information systems.

Requirements:

  • Must register with Information Commission within 3 months (Regulation 14C)
  • Must identify and manage risks to network and information systems (Regulation 14B)
  • Must report incidents within 24 hours (Regulation 14E)
  • Must notify affected customers (Regulation 14G)

Exemptions:

  • Micro or small enterprises (as defined by Commission Recommendation 2003/361/EC)
  • Providers of data centre services (covered separately)
  • Public electronic communications networks/services

UK Representative: If your principal office is outside the UK, you must nominate a UK representative within 3 months (Regulation 14D).

Yes, data centres are now regulated as essential services under Section 4.

Thresholds:

  • General data centres: 1 megawatt (MW) or more rated IT load
  • Enterprise-only data centres: 10MW or more rated IT load (where the data centre is owned/managed by a person solely for their own undertaking)

Definition (Schedule 2, paragraph 11): A data centre service provides a physical structure containing IT equipment with supporting infrastructure (electricity, environmental control, security, resilience).

Requirements:

  • Must provide information to designated competent authority within 3 months (Regulation 8ZA)
  • Must report incidents with lower threshold - any significant impact (Regulation 11A)
  • Must notify affected customers (Regulation 11C)
  • Must update information within 7 days of changes (Regulation 8ZA(6))

Crown Application: Government data centres are regulated except for Security Service, Secret Intelligence Service, GCHQ, or services classified as "secret" or "top secret" (Section 5).

Large load controllers are regulated under Section 6 if they manage 300 megawatts (MW) or more of potential electrical control.

Calculation (Schedule 2, paragraph 1(5B)): A load controller's potential electrical control is the aggregate of:

  • Maximum flow of electricity INTO all relevant Energy Smart Appliances (ESAs)
  • Maximum flow of electricity OUT of all relevant ESAs

Relevant ESAs include:

  • Electric vehicles
  • Charge points (for electric vehicles)
  • Electrical heating appliances (heat pumps, storage heaters, etc.)
  • Battery energy storage systems
  • Virtual power plants

Intermediaries: If load control signals are sent through an intermediary who can adjust or process them, both the load controller AND intermediary may be treated as load controllers (Schedule 2, paragraph 1(5E)).

Requirements: Load controllers meeting the threshold are Operators of Essential Services (OES) and must comply with all OES requirements including security duties, incident reporting, and registration.

Yes, even small businesses can be designated as critical suppliers under Section 12 (Regulation 14H) if they meet the criteria.

Designation Criteria: A person can be designated if they:

  1. Supply goods or services directly to an OES, RDSP, or RMSP
  2. Rely on network and information systems for that supply
  3. An incident affecting their systems could cause significant disruption to:
    • The essential service/digital service/managed service they supply to, OR
    • Essential services, digital services, or managed services more generally
  4. The disruption would likely have significant impact on the economy or day-to-day functioning of society

Key Points:

  • Size doesn't matter - impact does (Regulation 14H(3) considers alternative sources)
  • Can be designated whether or not established in UK (Regulation 14H(7))
  • Can be designated by multiple regulators (Regulation 14H(5))
  • Must comply with same requirements as OES/RDSP/RMSP once designated

Consultation Process: Before designation, you'll receive written notice with reasons and have opportunity to make representations (Regulation 14J).

Yes, cloud computing services are regulated as Relevant Digital Services (RDSPs) under Section 7.

Definition (Regulation 1(2), as amended by Section 7): A cloud computing service enables access to a scalable, elastic pool of shareable computing resources (networks, servers, software, storage) with:

  • Broad remote access
  • On-demand, self-service capability
  • Distributed across multiple locations
  • Not solely for the provider's own use
  • NOT a managed service

Requirements:

  • Must register with Information Commission within 3 months (Regulation 14)
  • Must take appropriate security measures (Regulation 12)
  • Must report incidents within 24 hours (Regulation 12A)
  • Must notify affected customers (Regulation 12C)

Exclusions:

  • Managed services (covered separately as RMSPs)
  • Public electronic communications networks/services
  • Micro or small enterprises

UK Representative: If principal office is outside UK, must nominate UK representative within 3 months (Regulation 14A).

Incident Reporting

The Bill requires strict incident reporting deadlines under Section 15:

Initial Notification: 24 hours

  • Must be given within 24 hours of becoming aware of an incident
  • Must include: name, service affected, brief details
  • Must be sent to both your designated competent authority AND CSIRT simultaneously

Full Notification: 72 hours

  • Must be given within 72 hours of becoming aware
  • Must include comprehensive details:
    • Time, duration, whether ongoing
    • Nature of incident
    • Impact (including cross-border)
    • Details of any related incidents affecting other regulated persons
    • Other relevant information

Customer Notification: After full notification, must notify affected UK customers "as soon as reasonably practicable" (Section 16, Regulations 11C, 12C, 14G).

Data Centres: Data centre operators have a lower reporting threshold - any incident with significant impact must be reported (Regulation 11A(3)).

The definition of "incident" has been expanded under Section 15(2) to include potential impacts, not just actual damage.

Definition (Regulation 1(2), as amended): An incident is anything that has, or is capable of having, an adverse effect on the operation or security of network and information systems.

For OES (other than data centres): An incident is reportable if it:

  • Has affected or is affecting operation/security of systems
  • Impact in UK has been, is, or is likely to be significant, considering:
    • Extent of disruption to essential service
    • Number of users affected
    • Duration
    • Geographical area affected
    • Compromise of data confidentiality, authenticity, integrity, or availability

For Data Centres: Any incident which could have had, has had, is having, or is likely to have:

  • Significant impact on operation/security of systems
  • Significant impact on continuity of service
  • Any other significant impact in UK

For RDSPs/RMSPs: Similar criteria plus impact on users' systems and impact on economy/society.

Key Point: You must report potential threats that could cause harm, not just actual damage.

Yes, customer notification is mandatory under Section 16 after you've given your full notification to regulators.

Who Must Notify:

  • Data centre operators (Regulation 11C)
  • Relevant Digital Service Providers (Regulation 12C)
  • Relevant Managed Service Providers (Regulation 14G)

Timing:

  • Must take reasonable steps to identify affected UK customers
  • Must notify them "as soon as reasonably practicable" after full notification

Content Requirements: Notification must include:

  • Details of the nature of the incident
  • Explanation of why the customer is likely to be adversely affected

Considerations: When determining if a customer is affected, you must consider:

  • Extent of disruption to service provided to customer
  • Whether data confidentiality, authenticity, integrity, or availability is compromised
  • Any other impact on customer's network and information systems

Penalties: Failure to notify customers can result in penalties up to the greater of £17 million and 4% of turnover (Section 21, Regulation 17).

Registration & Information

Registration requirements vary by entity type:

Data Centre Operators (Regulation 8ZA):

  • Name, proper address
  • Names of directors (if body corporate) or partners (if partnership)
  • Up-to-date contact details (email, telephone)
  • Must be provided within 3 months of designation
  • Must update within 7 days of any changes

RDSPs (Regulation 14):

  • Name, proper address
  • Names of directors or partners
  • Which relevant digital services you provide
  • Up-to-date contact details
  • Must register before registration date (3 months from becoming RDSP)

RMSPs (Regulation 14C):

  • Name, proper address
  • Names of directors or partners
  • Up-to-date contact details
  • Must register before registration date (3 months from becoming RMSP)

Important:

  • Registration information is shared with GCHQ for national security purposes (Section 18(1))
  • Must update within 7 days of any changes (Regulations 8ZA(6), 14(3), 14C(5))
  • If outside UK, must also nominate UK representative (Regulations 8A, 14A, 14D)

Yes, if your principal office is outside the UK, you must nominate a UK representative under:

OES (Regulation 8A):

  • Must nominate within 3 months of becoming OES
  • Must notify designated competent authority of representative's name and contact details
  • Must update within 7 days of changes

RDSPs (Regulation 14A):

  • Must nominate within 3 months
  • Must notify Information Commission
  • Must include email address and telephone number

RMSPs (Regulation 14D):

  • Must nominate within 3 months
  • Must notify Information Commission
  • Must include email address and telephone number

Representative's Role:

  • Can be contacted by Information Commission or GCHQ instead of or in addition to you
  • Acts as your point of contact in UK
  • Nomination doesn't affect legal liability - you remain responsible

Penalties: Failure to nominate or notify changes can result in enforcement notices and penalties.

Yes, regulators have extensive information gathering powers under Section 20 (Regulation 15).

Who Can Request:

  • Designated competent authorities (from OES and others)
  • Information Commission (from RDSPs, RMSPs, and others)

What Can Be Requested:

  • Information or documents reasonably required for exercising functions
  • Can require you to obtain, generate, collect, or retain information you wouldn't otherwise have (Regulation 15A(1))
  • Can relate to information stored outside UK (Regulation 15A(3))

Purposes Include:

  • Establishing if you meet designation criteria
  • Deciding whether to designate or revoke designation
  • Determining penalty amounts
  • Determining charge amounts
  • Monitoring compliance

Information Notice Requirements: Must specify:

  • Information/documents sought
  • Why they're being sought
  • Manner and form
  • Time period
  • Consequences of non-compliance

Penalties: Failure to comply with an information notice falls in the higher band: the greater of £17 million and 4% of turnover (Regulation 18(11)(d), applying to Regulation 17(2ZB)).

Penalties & Enforcement

Penalties are tiered based on the severity of the violation under Section 21:

Standard Maximum Amount:

  • For undertakings: Greater of £10,000,000 OR 2% of global turnover
  • For others: £10,000,000

Applies to failures such as:

  • Registration and information-provision failures (Regulation 8ZA)
  • Some incident reporting failures (copying CSIRT, etc.)

Note: failing to comply with an information notice (Regulation 17(2ZB)) is not in this band - Regulation 18(11)(d) places it in the higher band below.

Higher Maximum Amount:

  • For undertakings: Greater of £17,000,000 OR 4% of global turnover
  • For others: £17,000,000

Applies to serious failures such as:

  • Security duty failures
  • Incident reporting failures (initial/full notifications)
  • Customer notification failures
  • Direction compliance failures

Daily Penalties (Part 4 - National Security):

  • Up to £100,000 per day while a contravention of a national security direction continues (Section 49(3))
  • Up to £50,000 per day for Part 4 information/inspection failures
  • These daily penalties belong to Part 4 only. There is no daily penalty in the NIS Regulations regime.

Penalty Determination: Regulators must consider:

  • Impact of the failure
  • Steps taken to remedy or mitigate
  • Previous compliance history

Penalties are recoverable as civil debt (Regulation 18(3C)).

Failure to comply with an enforcement notice can lead to severe consequences:

Enforcement Notices (Regulation 17):

  • Can be served for various failures (security duties, incident reporting, registration, etc.)
  • Must specify steps to be taken
  • Must be complied with regardless of whether penalty is paid (Regulation 17(3A))

Consequences of Non-Compliance:

  1. Civil Proceedings (Regulation A20):

    • Regulator can commence civil proceedings for injunction or specific performance
    • Can seek any appropriate remedy or relief
  2. Additional Penalties:

    • Can result in further penalty notices
    • Daily penalties may apply for continuing violations
  3. Inspection Powers:

    • Regulator can conduct inspections to verify compliance (Schedule 1, Regulation 16)
    • You must pay reasonable costs of inspections
  4. Information Gathering:

    • Regulator can require extensive information (Section 20)

Appeals: You can appeal enforcement notices to First-tier Tribunal (Schedule 1, Regulation 19A), but must still comply pending appeal unless Tribunal orders otherwise.

Yes, regulators have extensive inspection powers under Schedule 1 (Regulation 16).

Who Can Inspect:

  • Designated competent authorities
  • Information Commission
  • Inspectors appointed by them

What Inspectors Can Do:

  • Enter premises at reasonable times (except private dwellings)
  • Examine, print, copy, or remove documents/information
  • Examine or remove material/equipment
  • Interview any person
  • Carry out or direct security tests on systems
  • Require you to maintain materials without alteration

Your Obligations:

  • Must cooperate with inspector
  • Must provide access to premises
  • Must allow examination/removal of documents, information, material, equipment
  • Must allow access to persons for interviews
  • Must not intentionally obstruct
  • Must comply with inspector's requests
  • Must pay reasonable costs of inspection

Protections:

  • Cannot be required to produce privileged communications (Regulation 16(8A))
  • Powers not exercisable outside UK for premises/material/equipment/individuals (Regulation 16(8B))
  • Can exercise powers in relation to documents/information stored outside UK

Notice: Inspector must give notice of consequences before conducting inspection (Regulation 16(4A)).

National Security

National security directions are emergency powers under Part 4 (Section 43) that allow the Secretary of State to require immediate action when national security is at risk.

When Can Directions Be Given:

  • When security or operational compromise (or threat) gives rise to risk to national security
  • Must be necessary and proportionate in interests of national security

What Can Be Required:

  • Management of network/information systems
  • Risk reduction or impact mitigation
  • Information provision
  • Prohibition/restriction on use of goods/services/facilities
  • Prohibition on installation
  • Removal, disabling, or modification of goods/facilities
  • Appointment of skilled persons (with approval)
  • Actions in UK, relevant UK waters, or outside UK

Priority: Compliance with directions takes priority over conflicting regulatory requirements (Section 44).

Penalties:

  • Up to £17 million for contravening a direction, rising to the greater of £17 million and 10% of turnover only where regulations under Section 49(5) are in force (none have been made yet)
  • Up to £100,000 per day while a contravention of a direction continues, and up to £50,000 per day for information or inspection failures (Section 49)
  • These Part 4 sanctions are separate from the NIS Regulations regime, which has no daily penalty

Non-Disclosure: Secretary of State can require you not to disclose existence or contents of directions (Section 43(11)).

Information sharing with GCHQ is mandatory under Section 18(1):

What Is Shared:

  • Lists of OES maintained by competent authorities (Regulation 3(3)(e))
  • Register of RDSPs (Regulation 14(5))
  • Register of RMSPs (Regulation 14C(6))
  • Copies of incident notifications (via CSIRT)

Timing:

  • Initial sharing: Within 4 months of Section 18(1) coming into force
  • Ongoing: Annually thereafter

Purpose: To facilitate exercise of GCHQ's functions under NIS Regulations or any other enactment.

Additional Sharing:

  • Information Commission can share information with GCHQ for facilitating functions (Regulation 6)
  • CSIRT receives all incident notifications
  • Information can be shared for national security purposes (Section 56)

Your Rights:

  • You're notified that information will be shared
  • Sharing is for national security and regulatory purposes
  • Subject to data protection laws

Costs & Charges

Yes, regulators can impose charges under Section 17:

Periodic Charges (Regulation 20A):

  • Regulators can make charging schemes for periodic charges
  • Charges relate to regulator's costs in exercising functions
  • Can make different provision for different purposes
  • Must be published and consulted on
  • Charges may not relate to functions exercised in relation to you specifically

Enforcement Charges (Regulation 20C):

  • Can require charges for costs of specific enforcement actions
  • Excludes costs relating to appeals or proceedings
  • Must provide invoice stating costs

Inspection Costs:

  • You must pay reasonable costs of inspections (Schedule 1, Regulation 16(3)(a))
  • Can be significant for complex systems

Cost Recovery Statements: Regulators must publish statements showing:

  • Aggregate charges received
  • Outstanding charges
  • Costs of functions

Budget Planning: You should budget for:

  • Annual or periodic regulatory charges
  • Potential inspection costs
  • Enforcement action costs
  • Compliance implementation costs

Appeals & Disputes

Yes, you can appeal to the First-tier Tribunal under Schedule 1 (Regulation 19A):

What Can Be Appealed:

  • Enforcement notices (Regulation 17)
  • Penalty notices (Regulation 18(3B))
  • Critical supplier designations (Regulation 14H)
  • Critical supplier revocations (Regulation 14K)
  • Information notice failures (Regulation 17(2ZB))

Appeal Grounds:

  • Decision was based on error of fact
  • Decision was wrong in law
  • Decision was unreasonable
  • Decision was procedurally unfair

Tribunal Powers: First-tier Tribunal can (Regulation 19B):

  • Confirm the decision
  • Vary the decision
  • Withdraw the decision
  • Award costs

Process:

  • Must appeal within specified time period
  • Decision may be suspended pending appeal (depending on circumstances)
  • May require legal representation
  • Can be costly

Important: You must still comply with enforcement notices pending appeal unless Tribunal orders otherwise.

Implementation & Compliance

Security requirements vary by entity type:

OES (Regulation 10):

  • Must identify and take appropriate and proportionate measures to manage risks
  • Must ensure level of security appropriate to risk (having regard to state of art)
  • Must prevent and minimize impact of incidents
  • Must ensure continuity of services

RDSPs (Regulation 12):

  • Must identify and take appropriate and proportionate measures to manage risks
  • Must ensure security of network and information systems
  • Must have regard to Information Commission guidance

RMSPs (Regulation 14B):

  • Must identify and take appropriate and proportionate measures to manage risks
  • Must ensure level of security appropriate to risk (having regard to state of art)
  • Must prevent and minimize impact of incidents
  • Must have regard to Information Commission guidance

Codes of Practice:

  • Secretary of State can issue Codes of Practice (Section 36)
  • Codes describe recommended measures
  • Courts and regulators must take codes into account (Section 38)
  • Failure to follow codes may be evidence of non-compliance

Strategic Priorities:

  • Regulatory authorities must have regard to Statement of Strategic Priorities (Section 27)
  • Will guide enforcement decisions

Here's a practical compliance roadmap:

Phase 1: Assessment (Immediate)

  • Determine if you're in scope (check thresholds, entity types)
  • Assess whether you might be designated as critical supplier
  • Review your current security measures
  • Identify gaps

Phase 2: Registration (Within 3 months of commencement)

  • Gather required information (company details, directors, contacts)
  • Register with appropriate regulator
  • Nominate UK representative if outside UK
  • Set up processes to update within 7 days of changes

Phase 3: Security Implementation (Ongoing)

  • Implement appropriate security measures
  • Align with Codes of Practice when issued
  • Establish risk management processes
  • Prepare for inspections

Phase 4: Incident Response (Ongoing)

  • Set up 24/7 monitoring
  • Create incident response procedures
  • Prepare notification templates
  • Establish customer notification processes
  • Train staff on incident identification

Phase 5: Ongoing Compliance

  • Monitor for regulatory updates
  • Participate in consultations
  • Maintain compliance documentation
  • Conduct regular reviews
  • Budget for regulatory charges

Resources:

  • Take our readiness assessment: /assessment
  • Consult regulatory guidance (Section 19)
  • Monitor for Codes of Practice (Section 36)
  • Review Strategic Priorities (Section 25)

Still Have Questions?

Our cybersecurity compliance experts can help you understand how the Cyber Security and Resilience Bill affects your organisation and develop a roadmap for compliance.