Glossary · Related frameworks

Computer Misuse Act 1990

Definition

The Computer Misuse Act 1990 is the UK’s main hacking law, making unauthorised access to computer material a criminal offence. It has no defence for good-faith security research. The Cyber Security and Resilience Bill does not amend it: a Lords amendment requiring a review of a statutory defence was withdrawn at Committee Stage in September 2026.

Why does the Computer Misuse Act matter to security teams?

Section 1 makes it an offence to cause a computer to perform any function with intent to secure unauthorised access. There is no public interest or research defence, so scanning or probing a system without permission can be criminal even when the intent is to report a flaw.

Penetration testing is lawful because the system owner authorises it. That is why scoping documents and written authority matter, and why independent vulnerability research and threat intelligence work sit in a grey area.

The issue links to the Bill because its security duties and the Cyber Assessment Framework both expect regulated organisations to test their defences and understand attacker behaviour. Researchers who find flaws in managed service providers or operators of essential services without permission still carry legal risk.

What happened at Lords Committee?

Reform of the Act was one of the themes peers raised at Second Reading and pressed again at Committee Stage, which sat on 1, 3, 7 and 9 September 2026. The proposed clause would only have required a review and report to Parliament, not a defence itself.

The minister, Baroness Lloyd of Effra, rejected it, pointing to separate reform work. No Government bill amending the Act has a published timetable, so the timing of reform is not settled. Report Stage, which has no date yet, is the next chance for peers to return to it; watch the amendment papers rather than assume the issue is closed.

Common misconceptions

Myth: The Cyber Security and Resilience Bill protects ethical hackers.

Reality: It does not. The Bill regulates organisations’ security and reporting; it leaves the criminal law on unauthorised access untouched.

Where it appears in the Bill

  • NoneHL Bill 32 contains no provision amending the Computer Misuse Act 1990.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Does the Cyber Security and Resilience Bill change the Computer Misuse Act?

No. HL Bill 32 does not amend the Computer Misuse Act 1990. An amendment requiring a 12-month review of a statutory defence for security researchers was withdrawn at Lords Committee after the Government declined it. Peers could raise it again at Report Stage, but for now the Act is unchanged.

Is penetration testing legal under the Computer Misuse Act?

Yes, when the system owner has authorised it. The section 1 offence turns on unauthorised access, so a clearly scoped engagement with written permission is lawful. Testing outside that scope, or probing third-party systems without consent, can still be an offence, because the Act contains no defence for good-faith research.

When will the Computer Misuse Act be reformed?

There is no firm date. Computer Weekly reported the minister saying changes would come "as soon as parliamentary time allows", and the Government has pointed to separate reform work rather than the Cyber Security and Resilience Bill. Until legislation is introduced, organisations should rely on written authorisation and published vulnerability disclosure policies.

Related guidance

Official sources

More in Related frameworks

Full glossary