How this links to the Cyber Security and Resilience Bill
Clause 60 decides when each part of the Cyber Security and Resilience Bill actually bites. Royal Assent brings only the framework and regulation-making powers into force. The duties most organisations care about, such as managed service provider regulation, incident reporting and the new penalties, wait for commencement regulations. Those are expected to be phased towards 2028.
- Clause 60(1): Part 1, Chapters 1, 3 and 6 of Part 3, clause 40 and Part 5 commence on Royal Assent.
- Clause 60(2): clause 18(3) and (4), Chapter 2 of Part 3, and paragraphs 3, 4 and 14 of Schedule 2 commence two months later.
- Clause 60(3)-(4): everything else commences on days appointed by regulations, which can differ by purpose.
- Clause 60(5)-(6): clause 12 (critical supplier designation) commences with the first Part 3 activity-critical supply regulations.
- Clause 60(7): the Secretary of State can make transitional and saving provision.
What comes into force when?
The table sets out the three stages in clause 60. "The day on which this Act is passed" means the day of Royal Assent. Part 2, which contains almost all of the amendments to the NIS Regulations, does not appear in clause 60(1) or (2), except for clause 18(3) and (4) on information sharing. So Part 2 falls under clause 60(3) and needs commencement regulations.
Part 4, on national security directions, and the code of practice in Chapter 4 of Part 3 also commence by regulations.
Why is critical supplier designation locked to Part 3?
Clause 60(5) says commencement regulations may not appoint a day for clause 12 that differs from the day on which the first regulations under clause 29(1) imposing requirements on providers of activity-critical supplies come into force. Clause 60(6) defines those as provisions amending the NIS Regulations to impose such requirements.
In practice, no organisation can be designated as a critical supplier until the Government has made, consulted on and won Parliamentary approval for those Part 3 regulations. A designated critical supplier’s requirements will come from them. It is not automatically subject to the same duties as an OES, RDSP or RMSP.
How do deadlines run from commencement?
Several new NIS deadlines run from the day a particular section commences, not from Royal Assent. For example, registration with the Information Commission and nomination of a UK representative are due within three months of section 14 coming into force. Because clause 60(4) allows different days for different purposes, organisations should track each commencement instrument, not just the date of Royal Assent.
Clause 18(1) works the same way for regulators: competent authorities must send their lists of operators to GCHQ within four months of section 18(1) coming into force, and annually after that.
Commencement under clause 60 of the Cyber Security and Resilience Bill
| When | What commences | Clause |
|---|---|---|
| On Royal Assent | Part 1 (meaning of the NIS Regulations; overview) | 60(1)(a) |
| On Royal Assent | Part 3 Chapter 1 (key definitions, including essential activity), Chapter 3 (clause 29 regulation-making powers) and Chapter 6 (procedure for Part 3 regulations) | 60(1)(b) |
| On Royal Assent | Clause 40 (five-yearly report on NIS legislation) | 60(1)(c) |
| On Royal Assent | Part 5 (extent, commencement, short title) | 60(1)(d) |
| Two months after Royal Assent | Clause 18(3) and (4) (information sharing, new NIS regs 6, 6A, 6B and reg 7) | 60(2)(a) |
| Two months after Royal Assent | Part 3 Chapter 2 (statement of strategic priorities) | 60(2)(b) |
| Two months after Royal Assent | Schedule 2 paras 3, 4 and 14 (NIS national strategy provisions omitted, but kept until the first statement is designated) | 60(2)(c) |
| By regulations | Everything else, including Part 2 (NIS amendments), the code of practice and Part 4 directions | 60(3)-(4) |
| By regulations, on a fixed day | Clause 12 (critical suppliers), on the day the first Part 3 activity-critical supply regulations come into force | 60(5)-(6) |
Common misconceptions
Myth: The new duties apply from Royal Assent.
Reality: Royal Assent commences the framework and powers only. The Part 2 duties, such as RMSP regulation, the 24-hour and 72-hour incident reporting clocks and the new penalty bands, commence on days appointed by regulations.
Myth: Critical suppliers can be designated as soon as the Act is passed.
Reality: Clause 60(5) prevents clause 12 commencing before the first Part 3 activity-critical supply regulations are in force.
Where it appears in the Bill
- Clause 60(1)Provisions commencing on Royal Assent.
- Clause 60(2)Provisions commencing two months after Royal Assent.
- Clause 60(3)-(4)All other provisions commence by regulations; different days for different purposes.
- Clause 60(5)-(6)Critical supplier clause 12 tied to the first activity-critical supply regulations.
- Clause 60(7)-(9)Transitional and saving provision; regulations made by statutory instrument.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
When will the Cyber Security and Resilience Bill come into force?
In stages. As of September 2026 the Bill has completed Lords Committee Stage, with Report Stage next and no date set. Royal Assent is expected between late 2026 and spring 2027. Some framework provisions commence on Royal Assent and some two months later. Most duties then commence through regulations, phased towards 2028.
Do the new incident reporting rules start on Royal Assent?
No. The 24-hour initial notification and 72-hour full report are Part 2 amendments to the NIS Regulations, and Part 2 is not listed in clause 60(1) or (2). They commence on a day appointed by regulations under clause 60(3). When they do, both clocks run from the moment the organisation first becomes aware of the incident.
Can different parts of the Bill commence on different days?
Yes. Clause 60(4) lets commencement regulations appoint different days for different purposes, and clause 60(7) allows transitional and saving provision. The Government can therefore phase in, for example, managed service provider registration separately from other duties. Organisations should track each commencement instrument rather than rely on a single start date.