Digital Infrastructure Cyber Security and Resilience Bill Compliance Guide
Complete guide to Cyber Security and Resilience Bill compliance for DNS providers, IXPs, and domain registrars. Understand essential service obligations under HL Bill 32.
Sector Overview
Digital infrastructure operators are the silent enablers of the UK's online ecosystem. From Domain Name System (DNS) services and internet exchange points (IXPs) to domain registrars and root zone maintainers, these providers ensure the smooth and secure functioning of internet traffic. Under the Cyber Security and Resilience Bill (HL Bill 32), these foundational services are recognised as essential to national digital resilience.
Why Digital Infrastructure Operators Are In Scope
Digital infrastructure operators may be in scope under HL Bill 32 in several ways:
You're in scope if you operate:
- Are an operator of essential services in the digital infrastructure sector (meeting threshold requirements in Schedule 2)
- Provide cloud computing services, online marketplaces, or search engines (regulated as RDSP under Part 2, Section 7)
- Provide managed services - ongoing IT management for digital infrastructure (regulated as RMSP under Part 2, Section 9)
- Authoritative DNS or recursive DNS services used by essential entities or regulated sectors
- Internet exchange points (IXPs) critical to UK routing or peering that support essential services
- Domain registrars managing .uk domains or infrastructure-critical namespaces
- Any infrastructure service underpinning national internet stability
- Carry on essential activities or provide activity-critical supplies (subject to Part 3 regulations)
- May be subject to directions for national security purposes (Part 4)
As Operators of Essential Services (OES)
Digital infrastructure operators providing essential services in the digital infrastructure sector are listed as operators of essential services (OES) in Schedule 2, subject to threshold requirements.
As an OES, you must:
- Comply with security duties under Regulation 10
- Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 11
- Send a copy of incident notifications to CSIRT
- Comply with information requests and inspections under Regulations 15 and 16
- Have regard to guidance from your designated competent authority
As Relevant Digital Service Providers (RDSP)
Under Part 2, Section 7 of HL Bill 32, digital infrastructure operators offering cloud computing services, online marketplaces, or search engines may be regulated as Relevant Digital Service Providers (RDSPs):
- Register with the Information Commission within 3 months (Regulation 14)
- Comply with security duties under Regulation 12
- Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 12A
- Notify affected customers as soon as reasonably practicable under Regulation 12C
- Comply with information requests and inspections
As Relevant Managed Service Providers (RMSP)
Under Part 2, Section 9 of HL Bill 32, digital infrastructure operators offering managed services (ongoing IT management for digital infrastructure) may be regulated as Relevant Managed Service Providers (RMSPs):
- Register with the Information Commission within 3 months (Regulation 14C)
- Comply with security duties under Regulation 14B
- Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 14E
- Notify affected customers as soon as reasonably practicable under Regulation 14G
- Comply with information requests and inspections
National Security Directions - Part 4
Under Part 4, Section 43 of HL Bill 32, digital infrastructure operators may be subject to directions for national security purposes:
- The Secretary of State may give directions if threats relating to network and information systems pose a risk to national security
- Directions may impose requirements relating to management of systems, provision of information, or prohibitions on use of goods/services
- You must comply with directions and may be subject to monitoring, information gathering, and inspections under Sections 45-47
- Penalties for contravening a direction: up to £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, with daily penalties of up to £100,000 while the contravention continues
- HL Bill 32, Part 4, Sections 43-52
Penalties for Non-Compliance
Digital infrastructure operators face penalties depending on how they're regulated:
Part 2 Penalties (OES/RDSP/RMSP):
Higher Maximum: the greater of £17,000,000 and 4% of turnover for serious failures
Standard Maximum: the greater of £10,000,000 and 2% of turnover for administrative failures
Part 4 Penalties (National Security Directions):
Maximum: £17,000,000 for contravening a direction, becoming the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues
- HL Bill 32, Part 2, Section 21; Part 4, Section 49
Benefits of Cyber Security and Resilience Bill Compliance
National Connectivity
- Protects stability and availability of UK's internet backbone
- Demonstrates resilience to clients, regulators, and stakeholders
- Supports safe routing, trusted DNS operations, and secure domain management
Strategic Benefits
- Access to guidance from regulatory authorities
- Better positioning for government and critical infrastructure contracts
- Reduces cyber risk and incident costs
Direct References from HL Bill 32
Schedule 2 - Digital Infrastructure Subsector
Digital infrastructure operators providing essential services in the digital infrastructure sector are listed as operators of essential services (OES) in Schedule 2, subject to threshold requirements.
HL Bill 32, Schedule 2
Part 4, Section 43 - Directions for National Security
Digital infrastructure operators may be subject to directions for national security purposes if threats relating to network and information systems pose a risk to national security.
HL Bill 32, Part 4, Section 43
Frequently Asked Questions
Are DNS providers and IXPs regulated under the CSRB?
DNS providers, internet exchange points and domain registrars are regulated under the Cyber Security and Resilience Bill where they are operators of essential services in the digital infrastructure sector and meet the threshold requirements in Schedule 2. They may alternatively be in scope as Relevant Digital Service Providers if they offer cloud computing services, online marketplaces or search engines, or as Relevant Managed Service Providers if they offer ongoing IT management. Digital infrastructure operators may also carry on essential activities under Part 3 or be subject to national security directions under Part 4.
What must digital infrastructure operators do as Operators of Essential Services?
Digital infrastructure operators regulated as Operators of Essential Services must comply with the security duties in Regulation 10, report incidents within 24 hours and 72 hours under Regulation 11, and send a copy of each incident notification to CSIRT. They must also comply with information requests and inspections under Regulations 15 and 16 and have regard to guidance issued by their designated competent authority.
Do DNS providers and registrars have to register with the Information Commission?
Digital infrastructure operators must register with the Information Commission within 3 months where they are regulated as Relevant Digital Service Providers under Regulation 14, or as Relevant Managed Service Providers under Regulation 14C. RDSPs comply with security duties under Regulation 12 and report incidents under Regulation 12A; RMSPs comply with security duties under Regulation 14B and report incidents under Regulation 14E. Both must notify affected customers as soon as reasonably practicable, under Regulation 12C and Regulation 14G respectively.
Can digital infrastructure operators be given national security directions?
The Secretary of State may give digital infrastructure operators directions for national security purposes under Part 4, Section 43 of HL Bill 32 where threats relating to network and information systems pose a risk to national security. Directions may impose requirements about the management of systems, require the provision of information, or prohibit the use of particular goods or services. Operators subject to a direction may also face monitoring, information gathering and inspections under Sections 45 to 47.
What penalties do digital infrastructure operators face under the CSRB?
Digital infrastructure operators face a higher maximum penalty of the greater of £17,000,000 and 4% of turnover for serious Part 2 failures and a standard maximum of the greater of £10,000,000 and 2% of turnover for administrative failures. Contravening a national security direction under Part 4 carries a maximum of £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues. Neither applies under the NIS Regulations.
Need Help with Digital Infrastructure Cyber Security and Resilience Bill Compliance?
Our expert team helps DNS providers, IXPs, and domain registrars implement and prove compliance with Cyber Security and Resilience Bill requirements.