How this links to the Cyber Security and Resilience Bill
Data centres are not regulated under the NIS Regulations 2018 at all today. Clause 4 creates a new data infrastructure subsector, defines a data centre service, sets rated IT load thresholds and names Ofcom as the competent authority. Operators that meet a threshold become Operators of Essential Services, with security duties, 24 and 72-hour incident reporting and a new duty to tell affected customers.
- cl.4(2) adds a Schedule 1 entry making the Office of Communications (Ofcom) the designated competent authority for data infrastructure across the UK.
- cl.4(3) inserts NIS Sch 2 para 11: 1 MW rated IT load for most data centre services, 10 MW where the service is provided on an enterprise basis.
- cl.13 inserts reg 8ZA: within 3 months of designation, give Ofcom your name, proper address, directors or partners and contact details, and report changes within 7 days.
- cl.15 inserts reg 11A: initial notification within 24 hours and full notification within 72 hours, both running from first awareness of a data centre incident.
- cl.16 inserts reg 11C: after the full notification, identify UK customers likely to be adversely affected and notify them as soon as reasonably practicable.
How does the Bill define a data centre service?
New paragraph 11(4) of Schedule 2 to the NIS Regulations defines a data centre service as “a service consisting of the provision of a physical structure (a “data centre”)” which contains an area for the housing, connection and operation of relevant IT equipment and provides supporting infrastructure for that equipment. Relevant IT equipment is equipment used to provide information technology services.
A “structure” includes a building, part of a building or a group of structures, so a single hall inside a larger building can be a data centre, and a campus can be treated as one. How far separate buildings on one site will be grouped in practice is not yet settled by guidance.
- Supporting infrastructure means one or more of: electricity supply, environmental control (heating, ventilation, air conditioning, dust, humidity and flame control), security of the data centre and its IT equipment, and resilience of both.
- Rated IT load is the maximum electrical power available for the operation of relevant IT equipment housed in the data centre (para 11(8)(b)). It is a capacity figure, not average draw.
Which data centre services are in scope?
Colocation and multi-tenant operators are the main target. A service provided to third parties is in scope at 1 MW of rated IT load. A data centre run solely for the owner’s own undertaking is an enterprise data centre and is only in scope at 10 MW. Operators that meet a threshold are deemed designated as an OES, and Ofcom can also designate under reg 8(3).
Two carve-outs matter. Providing a data centre service does not make a business a relevant managed service provider (new reg 1(3D)(a)). And under new reg 8(7ZA)-(7ZB) the Crown is caught when it provides a data centre service, except the Security Service, the Secret Intelligence Service and GCHQ, and commercial provision on behalf of the Government for information classified secret or top secret.
The data centre itself is regulated separately from the cloud services running on it. A hyperscaler may be an OES for its data halls and an RDSP for its cloud computing service. See the data centres sector guide and AI companies for how this plays out.
What must a data centre OES do?
A designated operator takes on the standard OES security duties under reg 10 and the data centre reporting regime in regs 11A and 11C. A data centre incident is one with a significant impact on the systems relied on to provide the service in the UK, on continuity of the service, or any other significant UK impact (reg 11A(3)).
Penalties sit in two bands under new reg 18. Failing to comply with reg 8ZA or to copy notifications to the CSIRT (reg 11A(7)) attracts the standard maximum: the greater of £10m and 2% of turnover. Security duty failures, late or incomplete incident notifications (reg 11A(2), (5)-(6)) and customer notification failures (reg 11C(2)(b) and (4)) attract the higher maximum: the greater of £17m and 4% of turnover.
Data infrastructure thresholds in new NIS Sch 2 para 11
| Kind of data centre service | Threshold (rated IT load) | Source |
|---|---|---|
| Provided otherwise than on an enterprise basis (colocation, multi-tenant, third-party) | 1 MW or more | para 11(2) |
| Provided on an enterprise basis (sole purpose is the owner’s own IT) | 10 MW or more | para 11(3), (7) |
Common misconceptions
Myth: Only hyperscale sites will be regulated.
Reality: The general threshold is 1 MW of rated IT load, which catches many regional colocation facilities. Only enterprise sites get the higher 10 MW threshold.
Myth: Cloud and data centre regulation are the same thing.
Reality: Data centres are OES regulated by Ofcom. Cloud computing services are relevant digital services regulated by the Information Commission. One company can be both.
Where it appears in the Bill
- cl.4(2)Adds Ofcom to NIS Sch 1 as competent authority for the data infrastructure subsector.
- cl.4(3), NIS Sch 2 para 11(2)-(8)Definition of data centre service, supporting infrastructure, rated IT load and the 1 MW and 10 MW thresholds.
- cl.5, new reg 8(7ZA)-(7ZB)Crown application and the intelligence agency and classified-information carve-outs.
- cl.13, new reg 8ZAInformation to be given to Ofcom within 3 months of designation.
- cl.15, new reg 11A24-hour and 72-hour data centre incident notifications, both from first awareness.
- cl.16, new reg 11CDuty to notify UK customers likely to be adversely affected.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
What is the threshold for a data centre under the Cyber Security and Resilience Bill?
A data centre service provided in the UK is an essential service if the data centre’s rated IT load is 1 megawatt or more. Where the service is provided on an enterprise basis, meaning the owner runs it solely for its own undertaking’s IT, the threshold is 10 megawatts. Rated IT load is the maximum electrical power available to the IT equipment housed there.
Who regulates data centres under the Bill?
Ofcom. Clause 4(2) adds a data infrastructure entry to Schedule 1 of the NIS Regulations naming the Office of Communications as the designated competent authority for the whole United Kingdom. Ofcom receives the reg 8ZA information, incident notifications under reg 11A and exercises the enforcement powers, while copies of incident notifications also go to the CSIRT.
Does a data centre operator have to tell its customers about incidents?
Yes. New regulation 11C requires a data centre OES, after giving its full incident notification, to take reasonable steps as soon as reasonably practicable to identify UK customers likely to be adversely affected, then notify them. The notice must describe the incident and explain why the customer is likely to be affected. Failure sits in the higher penalty band.
When will data centre regulation start?
Not yet. The Bill finished Lords Committee Stage on 9 September 2026 and Report Stage has no date. Royal Assent is expected between late 2026 and spring 2027. Clause 4 is not listed for automatic commencement in clause 60, so it will start on a day appointed by regulations, with most duties expected towards 2028.