How this links to the Cyber Security and Resilience Bill
The Cyber Security and Resilience Bill gives regulators a new power to pull key suppliers into the NIS regime by designation, instead of relying only on the regulated organisation to manage its supply chain. The power is narrow and procedural, and it cannot be switched on at Royal Assent. What a designated supplier must actually do will be set by later regulations under Part 3, not by the Bill itself.
- Cl.12(2) defines a critical supplier in reg 1(2) as a person for the time being designated under reg 14H.
- New reg 14H(1) lets a designated competent authority designate direct suppliers to an OES it regulates; reg 14H(2) gives the Information Commission the same power for suppliers to an RDSP or RMSP.
- New reg 14I prevents designation for a service by virtue of which the person is already an OES, RDSP or RMSP.
- New regs 14J and 14K require consultation, written reasons and a chance to make representations, and allow revocation.
- Cl.60(5)-(6) stop section 12 commencing on any day other than the day the first Part 3 regulations imposing requirements on providers of activity-critical supplies come into force.
What is the test for designating a critical supplier?
Under new reg 14H, a regulator may designate a person (P) only if all of these are met:
- P supplies goods or services directly to an OES, RDSP or RMSP that the regulator oversees.
- P relies on network and information systems for that supply.
- The regulator considers an incident affecting those systems has the potential to disrupt the customer’s service, or services of others P supplies.
- That disruption is likely to have a significant impact on the economy or the day-to-day functioning of society in the whole or any part of the UK.
- Designation is not prevented by reg 14I.
What must the regulator consider before designating?
Reg 14H(3) requires the regulator to consider whether the customer could obtain the goods or services from an alternative source. Reg 14H(4) requires it to weigh the likely nature, scale and duration of the disruption. Reg 14H(6) asks whether the risk could be adequately managed through the customer’s own duties, and whether another regulator already covers P.
Before designating, the regulator must consult other designated competent authorities or the Information Commission where they have a relevant connection, give P written reasons, and allow a reasonable period for representations (reg 14J). A supplier can be designated by more than one regulator, and suppliers based outside the UK can be designated. Reg 14L requires the regulators to co-ordinate.
What happens once a supplier is designated?
A designated critical supplier is not automatically subject to the same duties as an OES, RDSP or RMSP. Its requirements come from the Part 3 regulations on activity-critical supply, which cl.30(5) treats critical suppliers as regulated persons for. Those regulations have not yet been drafted or consulted on.
Some parts of the NIS regime do reach critical suppliers directly: they are persons "regulated by" the designating authority for information notices under reg 15, and a designated supplier that believes it no longer meets the test must tell the regulator (reg 14K(3) and (5)).
Common misconceptions
Myth: Critical suppliers will be designated as soon as the Bill becomes law.
Reality: No. Cl.60(5)-(6) tie commencement of section 12 to the first Part 3 activity-critical supply regulations, which do not yet exist.
Myth: A designated critical supplier takes on full OES duties.
Reality: Its requirements come from future Part 3 regulations. The Bill does not copy OES, RDSP or RMSP duties onto critical suppliers.
Where it appears in the Bill
- cl.12(2), reg 1(2)Definition of critical supplier.
- cl.12(3), new reg 14HDesignation test for competent authorities and the Information Commission.
- cl.12(3), new regs 14I-14LRestrictions, procedure, revocation and co-ordination.
- cl.30(5)(d)Critical suppliers treated as regulated persons for Part 3 regulations.
- cl.60(5)-(6)Commencement tied to first Part 3 activity-critical supply regulations.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Who can designate a critical supplier?
The designated competent authority for the OES that the supplier serves, or the Information Commission where the supplier serves an RDSP or RMSP. A supplier can be designated by several authorities at once, and those authorities must co-ordinate their functions under new reg 14L. The Secretary of State does not designate directly under reg 14H.
Can a supplier challenge a proposed designation?
Yes. Reg 14J requires the regulator to give written reasons and a reasonable period for written representations, and to have regard to them. After designation, if the supplier believes it no longer meets the test it must notify the regulator with evidence, and the regulator must consider revoking the designation under reg 14K.
Can an OES be a critical supplier to another OES?
Not for the same service. Reg 14I prevents designation in relation to an essential service for which the person is already an OES, or a relevant digital or managed service by virtue of which it is an RDSP or RMSP. It could be designated for a different supply that falls outside its existing regulated status.
When could the first designations happen?
Only after the first Part 3 regulations imposing requirements on providers of activity-critical supplies come into force, because cl.60(5)-(6) tie section 12 to them. No draft of those regulations has been published. Royal Assent itself is expected between late 2026 and spring 2027, so designations are some way off.