Glossary · Who is regulated

Designated competent authority

Definition

A designated competent authority is the regulator named in Schedule 1 to the NIS Regulations 2018 for a particular subsector and territory, such as Ofcom for data centres. It oversees operators of essential services, issues guidance, receives incident reports and enforces. Relevant digital and managed service providers are regulated separately by the Information Commission.

Who is the competent authority for each sector?

Reg 3(1) designates the person in column 3 of Schedule 1 for each subsector and territory, so the answer depends on both the service and where in the UK it is provided. Several sectors have different authorities in England, Wales, Scotland and Northern Ireland, and in Northern Ireland the Department of Finance covers every subsector. The Bill adds only the data infrastructure row. Load control falls under electricity; it has no Schedule 1 row of its own, and the joint energy role is confirmed in the DSIT large load controllers factsheet.

What does a competent authority do?

Under reg 3(3), each competent authority reviews how the Regulations apply in its sector, publishes guidance, keeps a list of the operators of essential services it has designated and shares it with GCHQ, and co-operates with the NCSC, law enforcement and other authorities. It can issue information notices, inspect, issue enforcement notices and impose penalties.

After the Bill, a competent authority can also designate critical suppliers, and can recover its costs through charges. Where a data centre, energy or water operator reports an incident, the competent authority receives the notification and the NCSC receives a copy.

Competent authorities under NIS Schedule 1, as amended by the Bill

SectorCompetent authority
Electricity and most gasSecretary of State for Energy Security and Net Zero and GEMA (Ofgem), jointly
Oil; gas storage, LNG, gas processing, petroleum productionSecretary of State for Energy Security and Net Zero alone
Air transportSecretary of State for Transport and the Civil Aviation Authority, jointly
Rail, water transport, roadSecretary of State for Transport (devolved variations apply)
Health careSecretary of State for Health (England); Welsh Ministers; Scottish Ministers; Department of Finance (NI)
Drinking waterSecretary of State for Environment (England); Welsh Ministers; DWQR (Scotland); Department of Finance (NI)
Digital infrastructure (TLD, DNS, IXP)Ofcom, UK-wide
Data infrastructure (data centres)Ofcom, UK-wide (added by cl.4(2))
RDSPs and RMSPs (not a Schedule 1 entry)Information Commission, UK-wide (reg 3(2))

Common misconceptions

Myth: Ofcom is the competent authority for telecoms under the Bill.

Reality: Telecoms is excluded from the regime. Ofcom’s role here is for digital infrastructure and data centres.

Myth: NHS England regulates health care under NIS.

Reality: NHS England does not appear in Schedule 1. The authority for health care in England is the Secretary of State for Health.

Where it appears in the Bill

  • NIS reg 3(1) and Sch 1Designation of competent authorities by subsector and territory.
  • cl.4(2), NIS Sch 1Ofcom added for data infrastructure.
  • cl.9(7), reg 3(2)Information Commission for RDSPs and RMSPs.
  • cl.12, new reg 14H(1)Power to designate critical suppliers.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Who regulates data centres under the Bill?

Ofcom, across the whole of the United Kingdom. Clause 4(2) of the Cyber Security and Resilience Bill adds a data infrastructure entry to Schedule 1 of the NIS Regulations naming the Office of Communications. Data centres at or above 1 MW rated IT load, or 10 MW for enterprise data centres, become operators of essential services.

Is the Information Commission a designated competent authority?

Not in the Schedule 1 sense. The Schedule 1 authorities regulate operators of essential services by subsector. The Information Commission is designated separately by reg 3(2) as the competent authority for RDSPs and, after the Bill, RMSPs. The Bill refers to "a designated competent authority or the Information Commission" when it means both.

Can one organisation have more than one competent authority?

Yes. An organisation designated as an OES in two subsectors answers to the authority for each. A critical supplier can be designated by several competent authorities and the Information Commission, which must then co-ordinate under new reg 14L. Joint authorities, such as DESNZ and Ofgem for electricity, act together for one subsector.

Related guidance

Official sources

More in Who is regulated

Full glossary