How this links to the Cyber Security and Resilience Bill
The Cyber Security and Resilience Bill is mostly an amending Bill. Clause 1 defines "the NIS Regulations" as SI 2018/506, and Part 2 rewrites parts of them in place, so the 2018 Regulations remain the legal home of the duties. What changes is who is caught, how fast incidents must be reported, and how hard regulators can enforce.
- Stays: the sector-by-sector model, the designated competent authorities, the NCSC as CSIRT and most Schedule 2 thresholds.
- Changes: data centres, relevant managed service providers, large load controllers and designated critical suppliers are brought in (clauses 4, 6, 9 and 12).
- Changes: incident reporting becomes a 24-hour initial notification and a 72-hour full report, both running from first awareness (clause 15).
- Changes: penalties move to two bands, the greater of £10m and 2% of turnover, or the greater of £17m and 4% (clause 21, new reg 18).
- Clause 40 requires a report on how the NIS Regulations are working at least once every 5 years.
What do the NIS Regulations 2018 require?
The Regulations implemented the EU NIS Directive (2016/1148) in UK law and stayed on the statute book after Brexit. They apply to two groups: operators of essential services in energy, transport, health, drinking water and digital infrastructure, and relevant digital service providers such as cloud computing services, online marketplaces and online search engines.
Each regulated organisation must take appropriate and proportionate measures to manage risks to its network and information systems, and must notify significant incidents. Enforcement sits with sector regulators, the designated competent authorities, and with the Information Commission for digital services.
What does the Cyber Security and Resilience Bill change?
The Bill widens the definition of "incident" to cover events capable of having an adverse effect, which is the basis of near-miss reporting. It also rewrites regulation 11 so that operators give an initial notification and a full incident report. Thresholds are mostly untouched: the Bill changes only the data centre and load control entries in Schedule 2.
Telecoms stays outside scope. Public electronic communications networks and services are excluded from essential service, digital service and managed service status. Most new duties will only bite once commencement regulations and secondary legislation are made, which is expected towards 2028.
NIS Regulations 2018 compared with the Regulations as amended by the Bill
| Area | NIS Regulations 2018 today | As amended by the Bill |
|---|---|---|
| Who is regulated | Operators of essential services and relevant digital service providers | Adds data centres, managed service providers, large load controllers and designated critical suppliers |
| Incident definition | Events with an actual adverse effect | Also events capable of having an adverse effect |
| Reporting deadline | Without undue delay, no later than 72 hours | 24-hour initial notification and 72-hour full report, both from first awareness |
| Maximum penalty | Tiered, with an overall cap of £17m | The greater of £10m and 2% of turnover, or the greater of £17m and 4% |
| Customer notification | No general duty | Duty to tell likely affected customers in defined cases |
Common misconceptions
Myth: The Bill repeals the NIS Regulations and starts again.
Reality: It amends them. Existing operators keep their current duties and regulators while the new provisions are phased in.
Myth: The maximum fine is capped at £17m.
Reality: The higher band is the greater of £17m and 4% of turnover, so for large undertakings the percentage sets the ceiling.
Where it appears in the Bill
- Clause 1Defines "the NIS Regulations" as SI 2018/506.
- Clause 15Widens the incident definition and substitutes regulation 11 (24-hour and 72-hour reporting).
- Clause 21Substitutes the penalty provisions in regulation 18 with two bands.
- Clause 40Report on the operation of the NIS Regulations at least every 5 years.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Are the NIS Regulations 2018 still in force?
Yes. The NIS Regulations 2018 apply today to operators of essential services and relevant digital service providers. The Cyber Security and Resilience Bill amends them rather than repealing them, and most of its changes will only take effect after Royal Assent, expected between late 2026 and spring 2027, and later commencement regulations.
Do I need to do anything under the NIS Regulations before the Bill passes?
If you are already an operator of essential services or a relevant digital service provider, your current duties continue unchanged, including security measures and incident notification. Organisations newly brought into scope, such as managed service providers and data centres, have no NIS duties until the relevant provisions commence, but preparing now shortens the gap.
What are the penalties under the amended NIS Regulations?
The Bill creates two bands in regulation 18. The standard maximum is the greater of £10m and 2% of turnover. The higher maximum, which covers security duty and incident notification failures, is the greater of £17m and 4% of turnover. For large undertakings the percentage figure sets the ceiling.