View Cyber Security and Resilience Bill
The complete Cyber Security and Resilience (Network and Information Systems) Bill. Introduced to the Commons as Bill 329 on 12th November 2025, the document below is the current version - HL Bill 32, as brought from the Commons to the House of Lords on 17th June 2026. For live status, see the UK Parliament Bill page.
Cyber Security and Resilience (Network and Information Systems) Bill
Loading PDF document...
Bill Structure
- Part 1:Introduction (Sections 1-2)
- Part 2:The NIS Regulations (Sections 3-23)
- Part 3:Security and Resilience Functions (Sections 24-42)
- Part 4:National Security Directions (Sections 43-58)
- Part 5:General (Sections 59-61)
- Schedules:Schedule 1 (Enforcement), Schedule 2 (Amendments)
Key Information
- Bill Number: Bill 329 (now HL Bill 32)
- Introduced: 12th November 2025
- Presented by: Secretary Liz Kendall
- Status: House of Lords (passed Commons 16 June 2026)
- Total Sections: 61
- Schedules: 2
Quick Actions
Copyright and Licensing Information
This document contains Parliamentary information licensed under the Open Parliament Licence.
Parliamentary material is reproduced with the permission of the Controller of HMSO on behalf of Parliament. You may use and re-use the information featured on this page (not including logos) free of charge in any format or medium, under the terms of the Open Parliament Licence.
Under the Open Parliament Licence you are free to:
- Copy, publish, distribute and transmit the information
- Adapt the information
- Exploit the information commercially and non-commercially
You must, where you do any of the above:
- Acknowledge the source of the information by including the following attribution statement: "Contains Parliamentary information licensed under the Open Parliament Licence"
- Include a link to the Open Parliament Licence
What Is in the Bill, Part by Part
HL Bill 32 runs to 5 Parts, 61 sections and 2 Schedules. Use this to find the provision you need before opening the PDF.
Part 1: Introduction
Sections 1 to 2Defines "the NIS Regulations" as SI 2018/506 and gives an overview of the Act.
- s.1Meaning of "the NIS Regulations"
- s.2Overview of Act
Part 2: The NIS Regulations
Sections 3 to 23The operative part for most organisations. It amends the 2018 Regulations to bring new entities into scope and to change duties, reporting and enforcement.
Chapter 1 - Persons regulated
- s.3Identification of operators of essential services
- s.4Data centres to be regulated as essential services
- s.5Operators of data centre services: Crown application
- s.6Designation of large load controllers
- s.7Digital services
- s.8Duties of relevant digital service providers
- s.9Managed service providers
- s.10Duties of managed service providers to manage risks
- s.11Meaning of "subject to public authority oversight"
- s.12Critical suppliers
Chapter 2 - Information and incident reporting
- s.13Provision of information by operators of data centre services
- s.14Provision of information by digital or managed service providers
- s.15Reporting of incidents by regulated persons
- s.16Notification of incidents to customers
Chapter 3 - Other amendments
- s.17Powers to impose charges (cost recovery)
- s.18Sharing and use of information
- s.19Guidance
- s.20Powers to require information
- s.21Financial penalties
- s.22Enforcement and appeals
- s.23Minor and consequential amendments
Part 3: Functions of the Secretary of State
Sections 24 to 42Creates powers to set strategic priorities, make further security regulations and issue a code of practice. This is where most of the delegated-powers criticism is directed.
Chapters 1 to 2 - Definitions and strategic priorities
- s.24Key definitions in Part 3
- s.25Statement of strategic priorities
- s.26Consultation and procedure
- s.27Duties of regulatory authorities in relation to statement
- s.28Report by Secretary of State
Chapter 3 - Regulations about security and resilience
- s.29Regulations relating to security and resilience
- s.30Imposition of requirements on regulated persons
- s.31Enforcement, sanctions and appeals
- s.32Provision about financial penalties
- s.33Information, guidance and other functions
- s.34Recovery of costs of regulatory authorities
- s.35Supplementary provision and interpretation
Chapters 4 to 6 - Code of practice, report and regulations
- s.36-39Code of practice: issue, effect and withdrawal
- s.40Report on network and information systems legislation
- s.41-42Regulations under Part 3, consultation and procedure
Part 4: Directions for national security purposes
Sections 43 to 58A separate regime from the NIS Regulations. It lets the Secretary of State direct regulated persons and regulators, with its own penalties including daily amounts.
- s.43Directions to regulated persons
- s.44Compliance with directions to take priority
- s.45Monitoring by regulatory authorities
- s.46-47Information gathering and inspections
- s.48-52Notification of contravention, penalty amounts and enforcement
- s.53Power to direct regulatory authorities
- s.54-58Review and revocation, laying before Parliament, information sharing, interpretation
Part 5: General
Sections 59 to 61Extent, commencement and short title. Commencement matters: most duties begin through later regulations, not on Royal Assent.
- s.59Extent
- s.60Commencement
- s.61Short title
The two Schedules
- Schedule 1 - Enforcement and appeals. Further amendments to the NIS Regulations covering how enforcement decisions are made and challenged.
- Schedule 2 - Minor and consequential amendments. Worth knowing because it is a common source of confusion: this is not the sector threshold table. Those thresholds are in Schedule 2 to the NIS Regulations 2018, which this Bill amends but does not reproduce.
Section numbers are from the HL Bill 32 print of 17 June 2026. If the Bill is reprinted after Lords Committee Stage, check the arrangement of clauses before relying on them.