How this links to the Cyber Security and Resilience Bill
Under the NIS Regulations 2018 the Information Commissioner regulated only digital service providers. The Cyber Security and Resilience Bill widens the role considerably, making the Information Commission the regulator for the new managed service provider category as well, and giving it a register, incident reporting, customer notification and critical supplier powers. The Bill uses "the Information Commission" throughout and never "Information Commissioner".
- Cl.9(7) amends reg 3(2) so the Information Commission is competent authority for RMSPs as well as RDSPs.
- Cl.14 requires it to keep registers of RDSPs (reg 14) and RMSPs (reg 14C) and send them to GCHQ within 4 months of commencement, then annually.
- Cl.15 makes it the recipient of 24-hour and 72-hour incident notifications from RDSPs (reg 12A) and RMSPs (reg 14E).
- Cl.12 gives it power to designate critical suppliers to RDSPs and RMSPs (new reg 14H(2)).
- Cl.19 requires its guidance to cover RDSP and RMSP security measures, registration, incident reporting and customer notification (new reg 3(4A)).
What does the Information Commission do under the Bill?
It is the single UK-wide regulator for relevant digital service providers and relevant managed service providers. It maintains the registers, publishes guidance that RDSPs and RMSPs must have regard to, receives incident notifications, can direct providers to inform customers or the public, and enforces through information notices, inspections, enforcement notices and penalties.
It can also designate critical suppliers to RDSPs and RMSPs, although that power cannot commence until the first Part 3 activity-critical supply regulations are in force.
Why does the name matter?
The Data (Use and Access) Act 2025 replaced the Information Commissioner, a single office holder, with a body corporate called the Information Commission. The Bill reflects that change, so references to the "ICO" or "Information Commissioner" in older guidance about the NIS Regulations now mean the Information Commission. The same body also regulates data protection, which matters where a cyber incident is also a personal data breach.
In practice, an RDSP or RMSP may deal with the same regulator twice over for one incident: once under the NIS Regulations, with the 24-hour and 72-hour clocks, and once under UK GDPR if personal data is involved. Those are separate legal duties with separate deadlines, so incident plans should treat them as two workstreams.
Where it appears in the Bill
- cl.9(7), reg 3(2)Competent authority for RDSPs and RMSPs.
- cl.14, regs 14 and 14CRegisters of RDSPs and RMSPs.
- cl.15, new regs 12A and 14EReceives incident notifications.
- cl.12, new reg 14H(2)Critical supplier designation for RDSP and RMSP supply chains.
- cl.19, new reg 3(4A)Minimum content of its guidance.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Is the Information Commission the same as the ICO?
It is the successor body. The Data (Use and Access) Act 2025 replaced the Information Commissioner with the Information Commission, a body corporate. It carries on the same data protection and NIS functions, and the Cyber Security and Resilience Bill adds new responsibilities for managed service providers and critical suppliers on top.
Do RMSPs register with the Information Commission?
Yes. New reg 14C requires an RMSP to submit its name, address, directors or partners and contact details before the registration date: 3 months after section 14 commences, or 3 months after it first meets the RMSP test. Changes must be notified within 7 days. The Commission shares the register with GCHQ.
Does the Information Commission regulate operators of essential services?
No. Operators of essential services are regulated by the competent authority for their subsector in Schedule 1 of the NIS Regulations, such as Ofcom for data centres. The Information Commission may be consulted, for example on critical supplier designations or where an incident involves personal data.