How this links to the Cyber Security and Resilience Bill
The Cyber Security and Resilience Bill keeps the sector-by-sector model of the NIS Regulations 2018 but gives competent authorities new work: a new data infrastructure entry, the power to designate critical suppliers, cost recovery, and guidance duties tied to the new code of practice. The regime remains heavily Whitehall-run, with the Secretary of State as sole or joint authority for energy, transport, and health and drinking water in England.
- Cl.4(2) adds Ofcom to Schedule 1 as competent authority for data infrastructure across the UK.
- Cl.12 lets a competent authority designate critical suppliers to the OES it regulates (new reg 14H(1)).
- Cl.15 makes the competent authority the recipient of 24-hour and 72-hour OES incident notifications.
- Cl.19 requires competent authorities to have regard to any relevant code of practice when preparing guidance, and to co-ordinate critical supplier guidance with each other and the Information Commission.
Who is the competent authority for each sector?
Reg 3(1) designates the person in column 3 of Schedule 1 for each subsector and territory, so the answer depends on both the service and where in the UK it is provided. Several sectors have different authorities in England, Wales, Scotland and Northern Ireland, and in Northern Ireland the Department of Finance covers every subsector. The Bill adds only the data infrastructure row. Load control falls under electricity; it has no Schedule 1 row of its own, and the joint energy role is confirmed in the DSIT large load controllers factsheet.
What does a competent authority do?
Under reg 3(3), each competent authority reviews how the Regulations apply in its sector, publishes guidance, keeps a list of the operators of essential services it has designated and shares it with GCHQ, and co-operates with the NCSC, law enforcement and other authorities. It can issue information notices, inspect, issue enforcement notices and impose penalties.
After the Bill, a competent authority can also designate critical suppliers, and can recover its costs through charges. Where a data centre, energy or water operator reports an incident, the competent authority receives the notification and the NCSC receives a copy.
Competent authorities under NIS Schedule 1, as amended by the Bill
| Sector | Competent authority |
|---|---|
| Electricity and most gas | Secretary of State for Energy Security and Net Zero and GEMA (Ofgem), jointly |
| Oil; gas storage, LNG, gas processing, petroleum production | Secretary of State for Energy Security and Net Zero alone |
| Air transport | Secretary of State for Transport and the Civil Aviation Authority, jointly |
| Rail, water transport, road | Secretary of State for Transport (devolved variations apply) |
| Health care | Secretary of State for Health (England); Welsh Ministers; Scottish Ministers; Department of Finance (NI) |
| Drinking water | Secretary of State for Environment (England); Welsh Ministers; DWQR (Scotland); Department of Finance (NI) |
| Digital infrastructure (TLD, DNS, IXP) | Ofcom, UK-wide |
| Data infrastructure (data centres) | Ofcom, UK-wide (added by cl.4(2)) |
| RDSPs and RMSPs (not a Schedule 1 entry) | Information Commission, UK-wide (reg 3(2)) |
Common misconceptions
Myth: Ofcom is the competent authority for telecoms under the Bill.
Reality: Telecoms is excluded from the regime. Ofcom’s role here is for digital infrastructure and data centres.
Myth: NHS England regulates health care under NIS.
Reality: NHS England does not appear in Schedule 1. The authority for health care in England is the Secretary of State for Health.
Where it appears in the Bill
- NIS reg 3(1) and Sch 1Designation of competent authorities by subsector and territory.
- cl.4(2), NIS Sch 1Ofcom added for data infrastructure.
- cl.9(7), reg 3(2)Information Commission for RDSPs and RMSPs.
- cl.12, new reg 14H(1)Power to designate critical suppliers.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Who regulates data centres under the Bill?
Ofcom, across the whole of the United Kingdom. Clause 4(2) of the Cyber Security and Resilience Bill adds a data infrastructure entry to Schedule 1 of the NIS Regulations naming the Office of Communications. Data centres at or above 1 MW rated IT load, or 10 MW for enterprise data centres, become operators of essential services.
Is the Information Commission a designated competent authority?
Not in the Schedule 1 sense. The Schedule 1 authorities regulate operators of essential services by subsector. The Information Commission is designated separately by reg 3(2) as the competent authority for RDSPs and, after the Bill, RMSPs. The Bill refers to "a designated competent authority or the Information Commission" when it means both.
Can one organisation have more than one competent authority?
Yes. An organisation designated as an OES in two subsectors answers to the authority for each. A critical supplier can be designated by several competent authorities and the Information Commission, which must then co-ordinate under new reg 14L. Joint authorities, such as DESNZ and Ofgem for electricity, act together for one subsector.