How this links to the Cyber Security and Resilience Bill
The OES category already exists under the NIS Regulations 2018. The Cyber Security and Resilience Bill keeps the core test but adds two new kinds of OES, reaches operators based outside the UK, and replaces the current incident reporting rule with a two-stage 24-hour and 72-hour regime. It also lets regulators designate the suppliers an OES depends on, once the relevant secondary legislation exists.
- Cl.3 makes reg 8 apply whether or not the operator is established in the UK, and restates the exclusion for public electronic communications networks and services (new reg 8(1A)).
- Cl.4 adds a data infrastructure subsector: data centres with a rated IT load of 1 MW or more, or 10 MW or more for enterprise data centres, regulated by Ofcom.
- Cl.6 adds load control to the electricity subsector, catching load controllers with 300 MW or more of potential electrical control.
- Cl.15 rewrites reg 11: an initial notification within 24 hours and a full notification within 72 hours, both counted from when the OES first became aware of the incident.
- Cl.12 lets the OES's competent authority designate its key suppliers as critical suppliers, but only once Part 3 activity-critical supply regulations are in force (cl.60(5)-(6)).
How does an organisation become an OES?
There are two routes, both in regulation 8 of the NIS Regulations 2018. Under reg 8(1), a person that provides an essential service of a kind listed in Schedule 2, relies on network and information systems to do so, and meets the threshold for that subsector is deemed to be designated as an OES. It must then notify its designated competent authority in writing (reg 8(2)).
Under reg 8(3), a competent authority can also designate an organisation that falls below the threshold, if it concludes an incident affecting that service is likely to have significant disruptive effects. Reg 8(4) lists the factors it weighs, including the number of users, dependency of other sectors, market share and national security.
The thresholds sit in Schedule 2 to the NIS Regulations, not in the Bill. The Bill changes only the data centre and load control thresholds.
Which sectors contain OES?
Schedule 2 covers energy, transport, health, drinking water and digital infrastructure. After the Bill it also covers data infrastructure. Some examples of the unchanged 2018 thresholds:
- Electricity supply: more than 250,000 final customers in Great Britain.
- Air transport: aerodromes with more than 10 million annual terminal passengers.
- Drinking water: supplying 200,000 or more people (see drinking water).
- Health care: no numeric threshold; scope is by entity type, such as NHS Trusts and Health Boards (see NHS organisations).
- Data centres: 1 MW rated IT load, or 10 MW on an enterprise basis (new in the Bill).
What must an OES do?
An OES must take appropriate and proportionate measures to manage risks to the network and information systems its essential service relies on (reg 10), which are the security duties that regulators usually assess against the NCSC Cyber Assessment Framework. It must report significant incidents to its competent authority and copy each notification to the NCSC as the CSIRT at the same time (new reg 11(8)).
Failures of the security duties, incident notification, directions and inspection requirements sit in the higher penalty band: the greater of £17m and 4% of turnover. Failing to notify designation or copy notifications to the CSIRT sits in the standard band: the greater of £10m and 2%.
How OES, RDSP and RMSP status compare after the Bill
| OES | RDSP | RMSP | |
|---|---|---|---|
| Legal test | Schedule 2 service above threshold, or designated | Cloud, online marketplace or search engine | Managed service under contract |
| Regulator | Sector competent authority | Information Commission | Information Commission |
| Size exemption | No (threshold decides) | Micro and small enterprises exempt | Micro and small enterprises exempt |
| Security duty | Reg 10 | Reg 12 | New reg 14B |
| Incident reporting | Reg 11 (11A for data centres) | New reg 12A | New reg 14E |
Common misconceptions
Myth: Telecoms operators are OES under the Bill.
Reality: No. New reg 8(1A) says the OES test does not apply to providing a public electronic communications network or service. Telecoms security is handled under the Communications Act 2003.
Myth: Ofgem alone regulates energy OES.
Reality: For electricity and most gas, the Secretary of State for Energy Security and Net Zero and GEMA (Ofgem) act jointly. Oil and several gas activities sit with the Secretary of State alone.
Where it appears in the Bill
- cl.3, new reg 8(1ZA), 8(1A), 8(3A)Extraterritorial reach and the telecoms exclusion.
- cl.4, NIS Sch 2 para 11Data centres become OES; Ofcom is the competent authority.
- cl.6, NIS Sch 2 para 1(5A)-(5E)Large load controllers at 300 MW.
- cl.15, new reg 11(2), (6), (8)24-hour and 72-hour notifications, copied to the CSIRT.
- cl.12, new reg 14H(1)Competent authority may designate an OES's critical suppliers.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Does the Cyber Security and Resilience Bill create new OES?
Yes. It brings data centres with a rated IT load of 1 MW or more (10 MW for enterprise data centres) into a new data infrastructure subsector, and adds load controllers with 300 MW or more of potential electrical control to the electricity subsector. All other sector thresholds stay as they were in the NIS Regulations 2018.
Can a company based outside the UK be an OES?
Yes. The Bill inserts reg 8(1ZA) and 8(3A), which say the deemed designation rule and discretionary designation apply whether or not the person is established in the United Kingdom. What matters is that the essential service is provided in the UK and meets the relevant threshold or designation test.
When must an OES report an incident?
Under the rewritten reg 11, an OES must give its competent authority an initial notification within 24 hours and a full notification within 72 hours. Both periods start at the same moment: when the OES first became aware that the incident had occurred or was occurring. A copy must go to the NCSC at the same time.
When will the new OES rules apply?
Not yet. The Bill finished Lords Committee Stage on 9 September 2026 and Report Stage has no date. Royal Assent is expected between late 2026 and spring 2027, and most provisions commence later by regulations, with many duties expected towards 2028. Existing OES remain bound by the 2018 Regulations meanwhile.
Related guidance
Who's affected
Every sector and category in scope.
Utilities and energy
Energy OES and the joint DESNZ and Ofgem role.
Transport infrastructure
Aviation, rail, maritime and road operators.
Drinking water
Water suppliers above the 200,000 people threshold.
What the Bill changes
Side-by-side view of the NIS Regulations before and after.