Glossary · Enforcement and powers

Code of practice

Definition

A code of practice under clause 36 of the Cyber Security and Resilience Bill is a document the Secretary of State may issue describing measures recommended for complying with the NIS Regulations and future Part 3 regulations. Breaching it is not itself a breach of the law, but courts and regulators must take it into account.

How is the code made?

The Secretary of State must consult such persons as they consider appropriate before preparing or revising the code (cl.36(3)). The draft is then laid before Parliament. If either House resolves not to approve it within 40 days, it cannot be issued in that form. Otherwise it can be issued, and it comes into force on publication unless it says otherwise (cl.37(1)-(4)).

The code may make different provision for different descriptions of regulated person (cl.36(4)), so separate expectations for operators, cloud providers or managed service providers are possible. Clause 37(7) lets the Secretary of State change the procedure by regulations, a Henry VIII power the Lords have scrutinised. Withdrawal under cl.39 also requires consultation and a notice laid before Parliament.

What is the legal effect of the code?

Under cl.38(1), not following the code is not of itself evidence of a failure to comply with the underlying requirement, and does not of itself create liability. But the code is admissible in evidence (cl.38(2)). A court or tribunal must take a relevant provision into account (cl.38(3)), and a regulator deciding a compliance question under the NIS Regulations or Part 3 regulations must do the same (cl.38(4)).

In practice, an organisation that departs from the code should be able to explain why its own measures achieve the same outcome. The content of the code is not yet published. How it will relate to the Cyber Assessment Framework is not settled in the Bill.

Common misconceptions

Myth: The code of practice is the same as the Cyber Governance Code of Practice.

Reality: No. The Cyber Governance Code of Practice is a voluntary DSIT and NCSC code for boards. The cl.36 code is a statutory document tied to the NIS Regulations and Part 3.

Where it appears in the Bill

  • cl.36Power to issue, revise and reissue a code for regulated persons.
  • cl.37Parliamentary procedure (40-day period) and power to change it by regulations.
  • cl.38Legal effect of the code in proceedings and regulatory decisions.
  • cl.39Withdrawal of the code.
  • cl.19(3)-(5)Regulator guidance must have regard to any relevant code.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Is the code of practice legally binding?

Not directly. Clause 38 says failing to follow it is not of itself evidence of breaching a requirement and does not of itself create liability. However, courts, tribunals and regulators must take relevant provisions into account when deciding compliance questions, so in practice it will strongly influence how security duties are judged.

Has the code of practice been published?

No. The Bill has not yet received Royal Assent, and the code must first be consulted on and laid in draft before Parliament for 40 days. Chapter 4 of Part 3 commences by regulations under cl.60(3), not automatically on Royal Assent. Royal Assent is expected between late 2026 and spring 2027.

Who does the code of practice apply to?

Regulated persons as defined for Part 3 (cl.36(5) and cl.30(2)). That includes operators of essential services, relevant digital and managed service providers and critical suppliers, plus anyone brought in by future Part 3 regulations. The code may set different recommended measures for different descriptions of regulated person.

Related guidance

Official sources

More in Enforcement and powers

Full glossary