Glossary

Cyber Security and Resilience Bill Glossary

The Cyber Security and Resilience Bill uses precise legal terms to decide who is regulated and what they must do. This glossary defines 53 of them in plain English, shows where each appears in the Bill, and explains how it affects your organisation.

Who is regulated

The categories of organisation the Bill brings into scope, and the definitions that decide whether you are one.

Cloud computing service

A cloud computing service is a digital service giving broad remote, on-demand, self-service access to a scalable and elastic pool of shareable computing resources, such as servers, software and storage, that is not a managed service. The Cyber Security and Resilience Bill substitutes this definition into reg 1(2) of the NIS Regulations 2018.

Critical supplier

A critical supplier is a person designated under new regulation 14H of the NIS Regulations because it supplies goods or services directly to an OES, RDSP or RMSP, and an incident affecting its systems could cause disruption with a significant impact on the UK economy or society. Designation cannot begin until Part 3 regulations exist.

Data centre service

A data centre service is the provision of a physical structure that houses, connects and operates IT equipment and supplies supporting infrastructure such as power, cooling, security and resilience. Under the Cyber Security and Resilience Bill, a UK data centre service with a rated IT load of 1 MW or more (10 MW for enterprise sites) becomes an essential service.

Designated competent authority

A designated competent authority is the regulator named in Schedule 1 to the NIS Regulations 2018 for a particular subsector and territory, such as Ofcom for data centres. It oversees operators of essential services, issues guidance, receives incident reports and enforces. Relevant digital and managed service providers are regulated separately by the Information Commission.

Enterprise data centre

An enterprise data centre is one owned or managed by a business solely to provide IT services for that business. Under the Cyber Security and Resilience Bill, it is regulated as an essential service only if its rated IT load is 10 MW or more, against 1 MW for data centres serving third parties.

Information Commission

The Information Commission is the UK regulator that replaced the Information Commissioner under the Data (Use and Access) Act 2025. Under the Cyber Security and Resilience Bill it is the competent authority for relevant digital service providers and relevant managed service providers across the UK, and it can designate their critical suppliers.

Large load controller

A large load controller is a load controller whose potential electrical control over relevant energy smart appliances it manages is 300 MW or more. Clause 6 of the Cyber Security and Resilience Bill makes load control an essential service, so large load controllers become Operators of Essential Services regulated jointly by DESNZ and Ofgem.

Load controller

A load controller is a person that provides the service of load control: sending load control signals that adjust the flow of electricity into or out of energy smart appliances such as EV chargers, heat pumps and batteries. The Cyber Security and Resilience Bill takes this definition from the Energy Act 2023 into the NIS Regulations.

Managed service

Under the Cyber Security and Resilience Bill, a managed service is a service provided under contract for the ongoing management of a customer’s IT systems, such as support, maintenance, monitoring or active administration, delivered by connecting to or accessing the customer’s network and information systems, whether on site or remotely. It is defined in new NIS reg 1(3B).

Online marketplace

An online marketplace is a digital service that allows consumers or traders to conclude online sales or service contracts with traders. Under the NIS Regulations 2018, as amended by the Cyber Security and Resilience Bill, it is a relevant digital service, so most providers serving the UK are Relevant Digital Service Providers regulated by the Information Commission.

Online search engine

An online search engine is a digital service that lets users search, in principle, all websites or all websites in a particular language, using a query on any subject. Under the NIS Regulations 2018, as amended by the Cyber Security and Resilience Bill, it is a relevant digital service regulated by the Information Commission.

Operator of Essential Services

OES

An Operator of Essential Services (OES) is an organisation that provides an essential service listed in Schedule 2 to the NIS Regulations 2018, such as electricity, transport, health care or drinking water, and meets that sector's threshold. It is regulated by its sector's competent authority and must manage cyber risk and report significant incidents.

Potential electrical control

Potential electrical control is the measure used to test whether a load controller is regulated. It is the maximum electricity flow into all relevant energy smart appliances a controller manages, plus the maximum flow out, based on manufacturer-stated capacity. Under the Cyber Security and Resilience Bill, 300 MW or more makes a load controller an essential service.

Relevant Digital Service Provider

RDSP

A Relevant Digital Service Provider (RDSP) is a person that provides an online marketplace, online search engine or cloud computing service in the UK, is not a micro or small enterprise, and is not exempt through public authority oversight. RDSPs are regulated by the Information Commission under the NIS Regulations 2018.

Relevant energy smart appliance

ESA

A relevant energy smart appliance is an energy smart appliance, as defined by the Energy Act 2023, that is an electric vehicle, EV charge point, listed electrical heating appliance, battery energy storage system or virtual power plant. Only these devices count towards the 300 MW threshold for large load controllers in the Cyber Security and Resilience Bill.

Relevant Managed Service Provider

RMSP

A Relevant Managed Service Provider (RMSP) is a person that provides a managed service in the UK, meaning ongoing management of a customer’s IT systems under contract with access to those systems, and is not a micro or small enterprise. The Cyber Security and Resilience Bill creates the category and makes the Information Commission its regulator.

Scope tests and exemptions

The thresholds, size tests and carve-outs that take organisations in or out of scope.

Micro or small enterprise

A micro or small enterprise is a business below the size ceilings in Commission Recommendation 2003/361/EC: fewer than 50 staff and annual turnover or balance sheet total of no more than €10 million. Under the Cyber Security and Resilience Bill, such businesses cannot be relevant digital service providers or relevant managed service providers.

Public authority oversight

Public authority oversight is a test inserted into the NIS Regulations 2018 by clause 11 of the Cyber Security and Resilience Bill. A body is under oversight if UK public authorities manage or control it, or appoint most of its board. Such a body earning half or less of its income commercially cannot be an RDSP or RMSP.

Public electronic communications network

A public electronic communications network is a network provided wholly or mainly for making electronic communications services available to the public, as defined in section 151(1) of the Communications Act 2003. The Cyber Security and Resilience Bill excludes these networks, and public electronic communications services, from OES, RDSP and RMSP status.

Schedule 2 thresholds

Schedule 2 thresholds are the sector limits in Schedule 2 to the NIS Regulations 2018 that decide who is an operator of essential services. They are not the Bill’s own Schedule 2. The Cyber Security and Resilience Bill adds thresholds only for data centres and electricity load control, and leaves the rest unchanged.

UK representative

A UK representative is a person in the United Kingdom that a regulated provider headquartered abroad must nominate in writing. Under regulation 14A of the NIS Regulations, as amended by the Cyber Security and Resilience Bill, RDSPs must nominate one and notify the Information Commission within three months. New regulation 14D does the same for RMSPs.

Duties and incidents

What regulated organisations must do, from security duties to the 24-hour and 72-hour reporting clocks.

Computer Security Incident Response Team

CSIRT

The CSIRT is the UK's Computer Security Incident Response Team under the NIS Regulations 2018. Regulation 5 designates GCHQ, and the function is carried out by the National Cyber Security Centre (NCSC), part of GCHQ. Under the Cyber Security and Resilience Bill, every incident notification must be copied to the CSIRT.

Customer notification

Customer notification is a new duty in the Cyber Security and Resilience Bill requiring data centre operators, relevant digital service providers and relevant managed service providers to tell UK customers likely to be adversely affected by a reportable incident. It applies as soon as reasonably practicable after the 72-hour full notification, under regs 11C, 12C and 14G.

Full incident report

A full incident report, called a "full notification" in the Cyber Security and Resilience Bill, is the detailed second report of a reportable incident. It is due within 72 hours of first becoming aware of the incident, the same starting point as the 24-hour initial notification, not 72 hours after it.

Incident

Under the NIS Regulations 2018 as amended by the Cyber Security and Resilience Bill, an incident is any event having, or capable of having, an adverse effect on the operation or security of network and information systems. The Bill adds events that merely could cause harm, and harm to how systems operate, not only their security.

Initial notification

An initial notification is the first report of a reportable incident under the Cyber Security and Resilience Bill. It must reach the regulator within 24 hours of first becoming aware of the incident, give your name, the affected service and brief details, and be copied to the CSIRT at the same time.

Near miss

A near miss is an event that could have caused harm but did not. The Cyber Security and Resilience Bill does not use the term, but it amends the NIS definition of incident to cover events "capable of having" an adverse effect. Only the data centre test expressly makes such events reportable.

Network and information systems

Network and information systems are defined in regulation 1(2) of the NIS Regulations 2018 as electronic communications networks, devices that automatically process digital data, and the data those networks and devices store, process, retrieve or transmit. The Cyber Security and Resilience Bill keeps this definition for Part 2 and uses a similar one for Part 3.

Registration with the Information Commission

Registration is the duty on relevant digital service providers (NIS reg 14) and relevant managed service providers (new reg 14C) to give the Information Commission their name, address, directors and contact details. Under the Cyber Security and Resilience Bill it is due within three months of coming into scope, with changes notified within seven days.

Security duties

Security duties are the legal requirements under the NIS Regulations 2018 to take appropriate and proportionate measures to manage risks to network and information systems and to prevent and minimise incident impact. The Cyber Security and Resilience Bill extends them to managed service providers (reg 14B) and refocuses them on security, not only continuity.

Significant incident

A significant incident is an incident that must be notified to a regulator under the Cyber Security and Resilience Bill. The test differs by category: operators of essential services (reg 11), data centres (reg 11A), digital service providers (reg 12A) and managed service providers (reg 14E). Each asks whether impact is or is likely to be significant.

Enforcement and powers

Penalties, information and inspection powers, and the Government’s national security directions.

Code of practice

A code of practice under clause 36 of the Cyber Security and Resilience Bill is a document the Secretary of State may issue describing measures recommended for complying with the NIS Regulations and future Part 3 regulations. Breaching it is not itself a breach of the law, but courts and regulators must take it into account.

Cost recovery

Cost recovery is the power for NIS regulators to charge regulated organisations for the cost of regulating them. Clause 17 of the Cyber Security and Resilience Bill inserts new regulations 20A to 20C into the NIS Regulations 2018, allowing periodic charges under a published charging scheme and case-specific charges backed by an invoice.

Enforcement notice

An enforcement notice is a written notice under regulation 17 of the NIS Regulations 2018 requiring a regulated person to put right a failure to comply with its duties. The Cyber Security and Resilience Bill (Schedule 1) extends it to managed service providers and information notices, and allows remedial steps outside the UK.

Higher maximum penalty

The higher maximum penalty is the top fine ceiling under new regulation 18(9) of the NIS Regulations, inserted by the Cyber Security and Resilience Bill. For an undertaking it is the greater of £17 million and 4% of worldwide turnover. It covers security duty, incident notification, direction, inspection and information notice failures.

Information notice

An information notice is a written notice requiring a person to give a regulator information or documents. Clause 20 of the Cyber Security and Resilience Bill substitutes a wider regulation 15 into the NIS Regulations 2018. Failing to comply can lead to an enforcement notice and a higher band penalty.

Inspection

An inspection is a regulator’s examination of whether a regulated organisation is meeting its duties, under regulation 16 of the NIS Regulations 2018. The Cyber Security and Resilience Bill (Schedule 1) extends it to managed service providers, adds a notice requirement and territorial limits, and puts inspection failures in the higher penalty band.

National security direction

A national security direction is a binding instruction the Secretary of State can give a regulated person under clause 43 of the Cyber Security and Resilience Bill. It can require the person to do, or stop doing, something specific where a cyber threat creates a risk to national security and the direction is necessary and proportionate.

Standard maximum penalty

The standard maximum penalty is the lower of the two fine ceilings in new regulation 18(8) of the NIS Regulations 2018, inserted by clause 21 of the Cyber Security and Resilience Bill. For an undertaking it is the greater of £10 million and 2% of worldwide turnover. It covers registration, representative and notification-copying failures.

Statement of Strategic Priorities

The Statement of Strategic Priorities is a Government statement under clause 25 of the Cyber Security and Resilience Bill setting out its priorities for the security of systems behind essential activities, regulators’ roles and objectives for regulators. Once designated, regulators must have regard to it and seek to achieve its objectives.

Vendor-related direction

A vendor-related direction is a proposed ministerial power to require regulated organisations to stop buying from, restrict or remove products supplied by a vendor judged a national security risk. The Government tabled it as an amendment to the Cyber Security and Resilience Bill for Lords Committee. It is not in the printed Bill.

Parts of the new regime

Part 3 essential activities, secondary legislation and how the Bill comes into force.

Activity-critical supply

An activity-critical supply is a supply of goods or services without which carrying on an essential activity would be at risk of disruption. The Cyber Security and Resilience Bill defines it in clause 29(6). Part 3 regulations can impose requirements on its providers, and critical supplier designation cannot start until they do.

Commencement

Commencement is when a provision of an Act comes into legal force. Under clause 60 of the Cyber Security and Resilience Bill, some provisions commence on Royal Assent and some two months later. Everything else, including most new NIS duties, commences on days the Secretary of State appoints by regulations.

Essential activity

An essential activity is an activity the Secretary of State specifies in regulations under clause 24(3) of the Cyber Security and Resilience Bill because it is essential to the UK economy or the day-to-day functioning of society. Existing NIS essential services, relevant digital services and managed services are treated as essential activities automatically.

Henry VIII power

A Henry VIII power is a power in an Act that lets ministers amend or repeal primary legislation, sometimes the Act itself, by secondary legislation. The Cyber Security and Resilience Bill contains several, including clause 37(7), which lets the Secretary of State change the code of practice procedure by regulations.

Secondary legislation

Secondary legislation is law made by ministers under powers in an Act, usually as statutory instruments, rather than passed as a Bill. The NIS Regulations 2018 are secondary legislation, and the Cyber Security and Resilience Bill relies on it to commence most of its provisions, add essential activities and impose Part 3 requirements.