How this links to the Cyber Security and Resilience Bill
The 2018 Regulations left the detail of "appropriate and proportionate" security measures to regulator guidance. Clause 36 lets the Government set out recommended measures in a single statutory code, which regulators must reflect in their guidance and must weigh when judging compliance. It will shape what good security duties compliance looks like.
- cl.36(1): the code describes measures recommended for compliance with requirements under the NIS Regulations or regulations under cl.29(1).
- cl.37: a draft must be laid before Parliament; if neither House resolves against it within 40 days, it can be issued.
- cl.38: failure to follow the code is not of itself evidence of a breach, but courts, tribunals and regulators must take relevant provisions into account.
- cl.19(3)-(5): regulator guidance must have regard to any relevant code with a view to consistency (new reg 3(3ZB) and (4B)).
How is the code made?
The Secretary of State must consult such persons as they consider appropriate before preparing or revising the code (cl.36(3)). The draft is then laid before Parliament. If either House resolves not to approve it within 40 days, it cannot be issued in that form. Otherwise it can be issued, and it comes into force on publication unless it says otherwise (cl.37(1)-(4)).
The code may make different provision for different descriptions of regulated person (cl.36(4)), so separate expectations for operators, cloud providers or managed service providers are possible. Clause 37(7) lets the Secretary of State change the procedure by regulations, a Henry VIII power the Lords have scrutinised. Withdrawal under cl.39 also requires consultation and a notice laid before Parliament.
What is the legal effect of the code?
Under cl.38(1), not following the code is not of itself evidence of a failure to comply with the underlying requirement, and does not of itself create liability. But the code is admissible in evidence (cl.38(2)). A court or tribunal must take a relevant provision into account (cl.38(3)), and a regulator deciding a compliance question under the NIS Regulations or Part 3 regulations must do the same (cl.38(4)).
In practice, an organisation that departs from the code should be able to explain why its own measures achieve the same outcome. The content of the code is not yet published. How it will relate to the Cyber Assessment Framework is not settled in the Bill.
Common misconceptions
Myth: The code of practice is the same as the Cyber Governance Code of Practice.
Reality: No. The Cyber Governance Code of Practice is a voluntary DSIT and NCSC code for boards. The cl.36 code is a statutory document tied to the NIS Regulations and Part 3.
Where it appears in the Bill
- cl.36Power to issue, revise and reissue a code for regulated persons.
- cl.37Parliamentary procedure (40-day period) and power to change it by regulations.
- cl.38Legal effect of the code in proceedings and regulatory decisions.
- cl.39Withdrawal of the code.
- cl.19(3)-(5)Regulator guidance must have regard to any relevant code.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Is the code of practice legally binding?
Not directly. Clause 38 says failing to follow it is not of itself evidence of breaching a requirement and does not of itself create liability. However, courts, tribunals and regulators must take relevant provisions into account when deciding compliance questions, so in practice it will strongly influence how security duties are judged.
Has the code of practice been published?
No. The Bill has not yet received Royal Assent, and the code must first be consulted on and laid in draft before Parliament for 40 days. Chapter 4 of Part 3 commences by regulations under cl.60(3), not automatically on Royal Assent. Royal Assent is expected between late 2026 and spring 2027.
Who does the code of practice apply to?
Regulated persons as defined for Part 3 (cl.36(5) and cl.30(2)). That includes operators of essential services, relevant digital and managed service providers and critical suppliers, plus anyone brought in by future Part 3 regulations. The code may set different recommended measures for different descriptions of regulated person.