Glossary · Who is regulatedOES

Operator of Essential Services

Definition

An Operator of Essential Services (OES) is an organisation that provides an essential service listed in Schedule 2 to the NIS Regulations 2018, such as electricity, transport, health care or drinking water, and meets that sector's threshold. It is regulated by its sector's competent authority and must manage cyber risk and report significant incidents.

How does an organisation become an OES?

There are two routes, both in regulation 8 of the NIS Regulations 2018. Under reg 8(1), a person that provides an essential service of a kind listed in Schedule 2, relies on network and information systems to do so, and meets the threshold for that subsector is deemed to be designated as an OES. It must then notify its designated competent authority in writing (reg 8(2)).

Under reg 8(3), a competent authority can also designate an organisation that falls below the threshold, if it concludes an incident affecting that service is likely to have significant disruptive effects. Reg 8(4) lists the factors it weighs, including the number of users, dependency of other sectors, market share and national security.

The thresholds sit in Schedule 2 to the NIS Regulations, not in the Bill. The Bill changes only the data centre and load control thresholds.

Which sectors contain OES?

Schedule 2 covers energy, transport, health, drinking water and digital infrastructure. After the Bill it also covers data infrastructure. Some examples of the unchanged 2018 thresholds:

  • Electricity supply: more than 250,000 final customers in Great Britain.
  • Air transport: aerodromes with more than 10 million annual terminal passengers.
  • Drinking water: supplying 200,000 or more people (see drinking water).
  • Health care: no numeric threshold; scope is by entity type, such as NHS Trusts and Health Boards (see NHS organisations).
  • Data centres: 1 MW rated IT load, or 10 MW on an enterprise basis (new in the Bill).

What must an OES do?

An OES must take appropriate and proportionate measures to manage risks to the network and information systems its essential service relies on (reg 10), which are the security duties that regulators usually assess against the NCSC Cyber Assessment Framework. It must report significant incidents to its competent authority and copy each notification to the NCSC as the CSIRT at the same time (new reg 11(8)).

Failures of the security duties, incident notification, directions and inspection requirements sit in the higher penalty band: the greater of £17m and 4% of turnover. Failing to notify designation or copy notifications to the CSIRT sits in the standard band: the greater of £10m and 2%.

How OES, RDSP and RMSP status compare after the Bill

OESRDSPRMSP
Legal testSchedule 2 service above threshold, or designatedCloud, online marketplace or search engineManaged service under contract
RegulatorSector competent authorityInformation CommissionInformation Commission
Size exemptionNo (threshold decides)Micro and small enterprises exemptMicro and small enterprises exempt
Security dutyReg 10Reg 12New reg 14B
Incident reportingReg 11 (11A for data centres)New reg 12ANew reg 14E

Common misconceptions

Myth: Telecoms operators are OES under the Bill.

Reality: No. New reg 8(1A) says the OES test does not apply to providing a public electronic communications network or service. Telecoms security is handled under the Communications Act 2003.

Myth: Ofgem alone regulates energy OES.

Reality: For electricity and most gas, the Secretary of State for Energy Security and Net Zero and GEMA (Ofgem) act jointly. Oil and several gas activities sit with the Secretary of State alone.

Where it appears in the Bill

  • cl.3, new reg 8(1ZA), 8(1A), 8(3A)Extraterritorial reach and the telecoms exclusion.
  • cl.4, NIS Sch 2 para 11Data centres become OES; Ofcom is the competent authority.
  • cl.6, NIS Sch 2 para 1(5A)-(5E)Large load controllers at 300 MW.
  • cl.15, new reg 11(2), (6), (8)24-hour and 72-hour notifications, copied to the CSIRT.
  • cl.12, new reg 14H(1)Competent authority may designate an OES's critical suppliers.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Does the Cyber Security and Resilience Bill create new OES?

Yes. It brings data centres with a rated IT load of 1 MW or more (10 MW for enterprise data centres) into a new data infrastructure subsector, and adds load controllers with 300 MW or more of potential electrical control to the electricity subsector. All other sector thresholds stay as they were in the NIS Regulations 2018.

Can a company based outside the UK be an OES?

Yes. The Bill inserts reg 8(1ZA) and 8(3A), which say the deemed designation rule and discretionary designation apply whether or not the person is established in the United Kingdom. What matters is that the essential service is provided in the UK and meets the relevant threshold or designation test.

When must an OES report an incident?

Under the rewritten reg 11, an OES must give its competent authority an initial notification within 24 hours and a full notification within 72 hours. Both periods start at the same moment: when the OES first became aware that the incident had occurred or was occurring. A copy must go to the NCSC at the same time.

When will the new OES rules apply?

Not yet. The Bill finished Lords Committee Stage on 9 September 2026 and Report Stage has no date. Royal Assent is expected between late 2026 and spring 2027, and most provisions commence later by regulations, with many duties expected towards 2028. Existing OES remain bound by the 2018 Regulations meanwhile.

Related guidance

Official sources

More in Who is regulated

Full glossary