How this links to the Cyber Security and Resilience Bill
The Cyber Governance Code is voluntary and sits outside the Cyber Security and Resilience Bill. It should not be confused with the statutory code of practice the Secretary of State may issue under clause 36, which will describe measures for complying with the NIS Regulations and Part 3 regulations and must be laid before Parliament.
- The Bill places no personal liability on directors; peers raised executive liability during Lords scrutiny, but it is not in HL Bill 32.
- Regulated organisations face a higher penalty band of the greater of £17m and 4% of turnover, which makes cyber risk a board matter.
- The code’s incident planning principle supports readiness for the 24-hour and 72-hour reporting clocks.
- The clause 36 code is a separate document that has not yet been published.
What does the Cyber Governance Code ask boards to do?
The code sets out the governance actions directors are responsible for, grouped under five principles. It is aimed mainly at medium and large organisations, and is supported by NCSC Cyber Governance Training and the Cyber Security Toolkit for Boards. It does not prescribe technical controls; it asks boards to own the risk and check that management is handling it.
- Risk management: understand critical assets and set risk appetite.
- Strategy: align cyber strategy with business strategy and fund it.
- People: build a cyber security culture and board-level skills.
- Incident planning and response: make sure a tested plan exists.
- Assurance and oversight: get regular, independent assurance.
How does it help with the Cyber Security and Resilience Bill?
The Bill places duties on the organisation, not individual directors, but those duties need board sponsorship. Registration with the Information Commission, security duties and incident reporting all require budget and clear decision rights.
Following the code gives boards a documented way to show they understand and oversee cyber risk. That will matter if a regulator investigates after an incident, even though the code itself carries no legal weight under the Bill. Its assurance principle also fits well with the Cyber Assessment Framework, whose governance outcomes regulators already assess.
Common misconceptions
Myth: The Cyber Governance Code is the code of practice created by the Bill.
Reality: It is not. The Bill’s clause 36 code is a separate statutory document, subject to Parliamentary procedure, about compliance measures rather than board governance.
Where it appears in the Bill
- Clause 36Statutory code of practice for regulated persons, distinct from the voluntary governance code.
- Clause 37Draft statutory code must be laid before Parliament; either House can reject it within 40 days.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Is the Cyber Governance Code of Practice mandatory?
No. DSIT and the NCSC published it on 8 April 2025 as voluntary guidance for boards and directors. The Cyber Security and Resilience Bill does not make it binding. It is still a useful way for boards of regulated organisations to show they oversee cyber risk, particularly if a regulator later asks how decisions were made.
Does the Cyber Security and Resilience Bill make directors personally liable?
Not as currently drafted. Duties and penalties fall on the regulated organisation. Peers raised executive liability during Lords scrutiny, but it is not in HL Bill 32. Report Stage has not yet been scheduled, so the position could still change before Royal Assent, expected between late 2026 and spring 2027.
Which organisations should use the code?
Any organisation whose board is responsible for digital risk, whether or not it is regulated. It is aimed at medium and large organisations and is especially relevant to boards of operators of essential services, managed service providers and data centres, which will face new statutory duties once the Bill is commenced.