Digital Infrastructure Operators

Digital Infrastructure Cyber Security and Resilience Bill Compliance Guide

Complete guide to Cyber Security and Resilience Bill compliance for DNS providers, IXPs, and domain registrars. Understand essential service obligations under HL Bill 32.

Sector Overview

Digital infrastructure operators are the silent enablers of the UK's online ecosystem. From Domain Name System (DNS) services and internet exchange points (IXPs) to domain registrars and root zone maintainers, these providers ensure the smooth and secure functioning of internet traffic. Under the Cyber Security and Resilience Bill (HL Bill 32), these foundational services are recognised as essential to national digital resilience.

Essential Recognition: Under the Cyber Security and Resilience Bill (CSRB), these foundational services are recognised as essential to national digital resilience, bringing them into direct regulatory scope for the first time.

Why Digital Infrastructure Operators Are In Scope

Digital infrastructure operators may be in scope under HL Bill 32 in several ways:

You're in scope if you operate:
  • Are an operator of essential services in the digital infrastructure sector (meeting threshold requirements in Schedule 2)
  • Provide cloud computing services, online marketplaces, or search engines (regulated as RDSP under Part 2, Section 7)
  • Provide managed services - ongoing IT management for digital infrastructure (regulated as RMSP under Part 2, Section 9)
  • Authoritative DNS or recursive DNS services used by essential entities or regulated sectors
  • Internet exchange points (IXPs) critical to UK routing or peering that support essential services
  • Domain registrars managing .uk domains or infrastructure-critical namespaces
  • Any infrastructure service underpinning national internet stability
  • Carry on essential activities or provide activity-critical supplies (subject to Part 3 regulations)
  • May be subject to directions for national security purposes (Part 4)

As Operators of Essential Services (OES)

Digital infrastructure operators providing essential services in the digital infrastructure sector are listed as operators of essential services (OES) in Schedule 2, subject to threshold requirements.

As an OES, you must:
  • Comply with security duties under Regulation 10
  • Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 11
  • Send a copy of incident notifications to CSIRT
  • Comply with information requests and inspections under Regulations 15 and 16
  • Have regard to guidance from your designated competent authority

As Relevant Digital Service Providers (RDSP)

Under Part 2, Section 7 of HL Bill 32, digital infrastructure operators offering cloud computing services, online marketplaces, or search engines may be regulated as Relevant Digital Service Providers (RDSPs):

  • Register with the Information Commission within 3 months (Regulation 14)
  • Comply with security duties under Regulation 12
  • Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 12A
  • Notify affected customers as soon as reasonably practicable under Regulation 12C
  • Comply with information requests and inspections

As Relevant Managed Service Providers (RMSP)

Under Part 2, Section 9 of HL Bill 32, digital infrastructure operators offering managed services (ongoing IT management for digital infrastructure) may be regulated as Relevant Managed Service Providers (RMSPs):

  • Register with the Information Commission within 3 months (Regulation 14C)
  • Comply with security duties under Regulation 14B
  • Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 14E
  • Notify affected customers as soon as reasonably practicable under Regulation 14G
  • Comply with information requests and inspections

National Security Directions - Part 4

Under Part 4, Section 43 of HL Bill 32, digital infrastructure operators may be subject to directions for national security purposes:

  • The Secretary of State may give directions if threats relating to network and information systems pose a risk to national security
  • Directions may impose requirements relating to management of systems, provision of information, or prohibitions on use of goods/services
  • You must comply with directions and may be subject to monitoring, information gathering, and inspections under Sections 45-47
  • Penalties for contravening a direction: up to £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, with daily penalties of up to £100,000 while the contravention continues

- HL Bill 32, Part 4, Sections 43-52

Penalties for Non-Compliance

Digital infrastructure operators face penalties depending on how they're regulated:

Part 2 Penalties (OES/RDSP/RMSP):

Higher Maximum: the greater of £17,000,000 and 4% of turnover for serious failures

Standard Maximum: the greater of £10,000,000 and 2% of turnover for administrative failures

Part 4 Penalties (National Security Directions):

Maximum: £17,000,000 for contravening a direction, becoming the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues

- HL Bill 32, Part 2, Section 21; Part 4, Section 49

Benefits of Cyber Security and Resilience Bill Compliance

National Connectivity
  • Protects stability and availability of UK's internet backbone
  • Demonstrates resilience to clients, regulators, and stakeholders
  • Supports safe routing, trusted DNS operations, and secure domain management
Strategic Benefits
  • Access to guidance from regulatory authorities
  • Better positioning for government and critical infrastructure contracts
  • Reduces cyber risk and incident costs

Direct References from HL Bill 32

Schedule 2 - Digital Infrastructure Subsector

Digital infrastructure operators providing essential services in the digital infrastructure sector are listed as operators of essential services (OES) in Schedule 2, subject to threshold requirements.

HL Bill 32, Schedule 2

Part 4, Section 43 - Directions for National Security

Digital infrastructure operators may be subject to directions for national security purposes if threats relating to network and information systems pose a risk to national security.

HL Bill 32, Part 4, Section 43

Frequently Asked Questions

Are DNS providers and IXPs regulated under the CSRB?

DNS providers, internet exchange points and domain registrars are regulated under the Cyber Security and Resilience Bill where they are operators of essential services in the digital infrastructure sector and meet the threshold requirements in Schedule 2. They may alternatively be in scope as Relevant Digital Service Providers if they offer cloud computing services, online marketplaces or search engines, or as Relevant Managed Service Providers if they offer ongoing IT management. Digital infrastructure operators may also carry on essential activities under Part 3 or be subject to national security directions under Part 4.

What must digital infrastructure operators do as Operators of Essential Services?

Digital infrastructure operators regulated as Operators of Essential Services must comply with the security duties in Regulation 10, report incidents within 24 hours and 72 hours under Regulation 11, and send a copy of each incident notification to CSIRT. They must also comply with information requests and inspections under Regulations 15 and 16 and have regard to guidance issued by their designated competent authority.

Do DNS providers and registrars have to register with the Information Commission?

Digital infrastructure operators must register with the Information Commission within 3 months where they are regulated as Relevant Digital Service Providers under Regulation 14, or as Relevant Managed Service Providers under Regulation 14C. RDSPs comply with security duties under Regulation 12 and report incidents under Regulation 12A; RMSPs comply with security duties under Regulation 14B and report incidents under Regulation 14E. Both must notify affected customers as soon as reasonably practicable, under Regulation 12C and Regulation 14G respectively.

Can digital infrastructure operators be given national security directions?

The Secretary of State may give digital infrastructure operators directions for national security purposes under Part 4, Section 43 of HL Bill 32 where threats relating to network and information systems pose a risk to national security. Directions may impose requirements about the management of systems, require the provision of information, or prohibit the use of particular goods or services. Operators subject to a direction may also face monitoring, information gathering and inspections under Sections 45 to 47.

What penalties do digital infrastructure operators face under the CSRB?

Digital infrastructure operators face a higher maximum penalty of the greater of £17,000,000 and 4% of turnover for serious Part 2 failures and a standard maximum of the greater of £10,000,000 and 2% of turnover for administrative failures. Contravening a national security direction under Part 4 carries a maximum of £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues. Neither applies under the NIS Regulations.

Need Help with Digital Infrastructure Cyber Security and Resilience Bill Compliance?

Our expert team helps DNS providers, IXPs, and domain registrars implement and prove compliance with Cyber Security and Resilience Bill requirements.