Glossary · Enforcement and powers

Vendor-related direction

Definition

A vendor-related direction is a proposed ministerial power to require regulated organisations to stop buying from, restrict or remove products supplied by a vendor judged a national security risk. The Government tabled it as an amendment to the Cyber Security and Resilience Bill for Lords Committee. It is not in the printed Bill.

How would a vendor-related direction differ from a national security direction?

A clause 43 direction is tied to a particular regulated person and a specific risk from a security or operational compromise. As reported, a vendor-related direction would be framed around a supplier: its purpose is to stop regulated organisations relying on a vendor whose products could pose a critical national security risk, for example because of ties to a hostile state.

That moves supplier risk from something organisations are expected to manage under their security duties into something the state can compel. It also differs from critical supplier designation under cl.12, which places duties on the supplier rather than restricting its customers.

What is still unknown?

The clause numbers, the exact test the minister must apply, the consultation and appeal arrangements, and how directions interact with the Part 4 penalty regime are not settled while the amendments are at Committee. Lords raised the breadth of delegated powers at Second Reading, and reduced transparency compared with the 2021 telecoms regime is likely to be contested at Report Stage, for which no date has been set.

Royal Assent is expected between late 2026 and spring 2027, with most duties commencing later through secondary legislation, towards 2028. Organisations should not treat any reported detail as final.

  • Map where each significant supplier’s technology sits in your estate, including embedded and fourth-party components.
  • Check that contracts give you exit, substitution and data portability rights.
  • Agree internally how you would receive and act on a confidential direction.

Where it appears in the Bill

  • Not in HL Bill 32The printed Bill (17 June 2026) contains no vendor-direction power; it exists only as tabled Government amendments.
  • cl.43(3)(d)-(f)Existing Part 4 power to prohibit use or installation of goods and services, or require removal or modification.
  • cl.12Critical supplier designation, a separate supplier-focused regime.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Is the vendor-related direction power law?

No. It is a Government amendment tabled for Lords Committee Stage of the Cyber Security and Resilience Bill. It is not in HL Bill 32 as printed, and even the Bill as a whole has not yet received Royal Assent. The detail can change at Committee or Report Stage, so check the amendment papers before relying on specific wording.

How does it compare with the Huawei telecoms powers?

It is reported to adapt the designated vendor direction regime in the Telecommunications (Security) Act 2021, which was used to remove Huawei equipment from UK 5G networks. The reported differences are wider reach across regulated sectors and fewer transparency safeguards: no prior public designation of the vendor and no duty to notify it.

Can the Government already order us to remove a supplier’s kit?

Under the printed Bill, yes in limited circumstances. Clause 43 allows a national security direction to prohibit the use or installation of goods and services, or to require their removal or modification, where a cyber threat creates a national security risk. Part 4 has not yet commenced, and commencement depends on Royal Assent and regulations under cl.60(3).

Related guidance

Official sources

More in Enforcement and powers

Full glossary