Drinking Water Supply and Distribution

Drinking Water Suppliers and the Cyber Security and Resilience Bill

What HL Bill 32 changes for water undertakers, water supply licensees, Scottish Water and NI Water: thresholds, regulators, incident reporting, suppliers and penalties.

Last updated: 14 September 2026

Yes. Water companies supplying drinking water to 200,000 or more people are already Operators of Essential Services under the NIS Regulations 2018, and the Cyber Security and Resilience Bill keeps that threshold. It tightens their duties: 24-hour and 72-hour incident reports, a wider incident definition, critical supplier designation, regulator charging and higher penalties.

Which water suppliers are in scope?

The drinking water supply and distribution subsector is set out in paragraph 9 of Schedule 2 to the NIS Regulations 2018. The essential service is the supply of potable water, and the threshold is the supply of water to 200,000 or more people. The Cyber Security and Resilience Bill does not change this threshold. It changes only three thresholds, all for data centres and electricity load control.

The test turns on the number of people supplied, not on the type of company. Schedule 2 does not list water undertakers or licensees by name. In practice it catches the large regional water and water-and-sewerage undertakers in England and Wales, Scottish Water and NI Water. A water supply licensee, or a smaller water-only company, is in scope only if it meets the 200,000-person test itself.

Already regulated: water is not a new sector. Operators that met the threshold have been NIS operators since 2018. The Bill amends their existing obligations rather than creating new ones from scratch.

Who regulates water companies under the NIS Regulations?

Schedule 1 to the NIS Regulations names a different competent authority for each UK nation. The Bill keeps these arrangements.

NationCompetent authority (NIS Schedule 1)Who does the work
EnglandSecretary of State for Environment, Food and Rural AffairsDrinking Water Inspectorate (DWI)
WalesThe Welsh MinistersDrinking Water Inspectorate (DWI)
ScotlandThe Drinking Water Quality Regulator for ScotlandDWQR
Northern IrelandThe Department of FinanceDepartment of Finance

The DWI states that it has been transferred the operational competent authority duties to regulate operators on behalf of the Secretary of State for England and the Welsh Government for Wales. The National Cyber Security Centre is the single point of contact and CSIRT for incidents and acts as technical authority.

Is Ofwat the NIS regulator for water?

No. This is one of the most common points of confusion in the sector. Ofwat is the economic regulator for water and sewerage companies in England and Wales. It sets price controls and licenses water supply and sewerage licensees, but it is not a competent authority under the NIS Regulations 2018.

Ofwat does not appear in Schedule 1 to the NIS Regulations, and the Cyber Security and Resilience Bill does not mention it. Cyber security oversight of water operators under NIS sits with Defra and the Welsh Ministers, exercised through the DWI, and with the DWQR and the Department of Finance in Scotland and Northern Ireland.

The two can still meet in practice. Water companies have put cyber and physical security investment cases into their business plans for price reviews, which Ofwat determines, but compliance with the NIS duties is assessed by the NIS competent authority, not Ofwat.

What does the Cyber Security and Resilience Bill change for water companies?

ChangeBill provisionWhat it means for a water operator
Incident reportingClause 15, new regulation 11Initial notification within 24 hours and full notification within 72 hours, both from first awareness, with a copy to the NCSC
Wider incident definitionClause 15(2), regulation 1(2)Covers events capable of having an adverse effect, and effects on the operation of systems, not only their security
Critical suppliersClause 12, new regulations 14H to 14JThe competent authority can designate key suppliers of an operator and bring them into regulation
Cost recoveryClause 17, new regulation 20ARegulators may charge regulated persons under a published charging scheme
PenaltiesClause 21, regulation 18(7) to (11)Two bands: the greater of £10,000,000 and 2% of turnover, or the greater of £17,000,000 and 4%
National security directionsPart 4, clause 43The Secretary of State can direct regulated persons where a threat to systems poses a risk to national security

The threshold, the competent authorities and the core security duty in regulation 10 all stay in place. The changes are about speed, breadth and consequences.

How does incident reporting change for water operators?

Clause 15 substitutes a new regulation 11. If an operator is aware that an incident has occurred or is occurring, it must give its competent authority an initial notification with its name, the essential service affected and brief details, followed by a full notification covering timing, nature, impact and any link to an incident at another regulated person.

  • Initial notification: within 24 hours of first becoming aware (regulation 11(6)(a))
  • Full notification: within 72 hours of that same moment, not 72 hours after the initial report (regulation 11(6)(b))
  • Notifications must be in writing, in the form the competent authority sets (regulation 11(7))
  • A copy must be sent to the CSIRT (the NCSC) at the same time (regulation 11(8))
Tighter than today: the DWI currently asks for NIS incidents without undue delay and no later than 72 hours after awareness. The new 24-hour initial notification is a real change for water incident playbooks.

What counts as a reportable incident now?

Clause 15(2) widens the definition of "incident" in regulation 1(2) in two ways. It now covers events having, or capable of having, an adverse effect, and effects on the operation as well as the security of network and information systems.

An incident must be notified where it has affected or is affecting the operation or security of the systems relied on to supply water, and its impact in the UK has been, is or is likely to be significant. Regulation 11(4) lists the factors: extent of disruption, number of users affected, duration, geographical area, and whether the confidentiality, authenticity, integrity or availability of user data is compromised.

For water, this means a ransomware attack that forces a treatment works into manual operation as a precaution may be reportable even if no customer loses supply.

Why do OT and SCADA systems matter here?

The network and information systems a water company relies on to supply potable water are largely operational technology: SCADA, telemetry, programmable logic controllers at pumping stations and treatment works, and the remote access that links them. The NIS security duty covers all of them, not just corporate IT.

Adding "operation" to the incident definition matters most in this environment. An intrusion that degrades control or visibility of a process, without any data being stolen, falls squarely within scope. Precautionary shutdowns and loss of telemetry both need to be assessed against the significance factors quickly enough to meet the 24-hour clock.

The DWI already asks water companies for an annual Cyber Assessment Framework return and has audited companies against it. Expect that CAF evidence, especially for OT asset inventory, segmentation and remote access, to underpin how the DWI judges compliance with the amended regulations.

Will suppliers to water companies be regulated?

Possibly. Clause 12 inserts a new Part 4B into the NIS Regulations. Under regulation 14H(1), a competent authority may designate a person as a critical supplier if that person supplies goods or services directly to an operator it regulates, relies on network and information systems for that supply, and an incident at the supplier could cause disruption with a significant impact on the economy or the day-to-day functioning of society.

  • Likely candidates include SCADA and telemetry vendors, OT integrators, billing and customer platforms, and outsourced security operations
  • The authority must consider whether the operator could get the supply elsewhere (regulation 14H(3))
  • It must also consider whether the risk is already managed through the operator's own duties or another regulator (regulation 14H(6))
  • Designation requires consultation first (regulation 14J), and suppliers outside the UK can be designated (regulation 14H(7))
  • Managed IT and security providers may separately be regulated as managed service providers under clause 9

Even without designation, water companies will push the new reporting and security expectations down to suppliers through contract.

How do SEMD and the Water Industry Act fit with the Bill?

Water companies in England and Wales already have a second security regime. The Security and Emergency Measures Direction (SEMD) is issued by the Secretary of State and Welsh Ministers under section 208 of the Water Industry Act 1991, which lets them direct undertakers and licensees in the interests of national security or to mitigate the effects of a civil emergency. The current version is the 2022 Direction, amended in 2024.

The DWI regulates SEMD on behalf of the Secretary of State and Welsh Ministers, including reviewing companies' annual self-assessments and national infrastructure audits, and taking enforcement action.

The Cyber Security and Resilience Bill does not amend the Water Industry Act 1991 or SEMD. The two regimes run in parallel, overseen largely by the same inspectorate, so one evidence base serving both is the efficient approach. How the DWI will align SEMD and NIS enforcement after the Bill is not yet settled.

Will water companies pay for NIS regulation?

Very likely. Clause 17 inserts a new Part 5A into the NIS Regulations. Under new regulation 20A, a NIS enforcement authority may charge a person it regulates for its relevant costs, but only under a charging scheme it has made and published, and only for a chargeable period in that scheme.

Relevant costs are the authority's costs of exercising its functions under the NIS Regulations or Parts 3 and 4 of the Bill once enacted. The government says this is intended to let regulators recover the full costs of their NIS duties with more transparency. No water sector charging scheme has been published, and the amounts are not yet known.

What penalties can water companies face?

Clause 21 replaces the penalty caps in regulation 18 with two bands. Both are the greater of a fixed sum and a share of turnover, including turnover outside the UK, so the fixed sum is a floor for large undertakings, not a ceiling.

Higher maximum: the greater of £17,000,000 and 4% of turnover

Applies to failures of the security duties in regulation 10(1) and (2), and failures to notify an incident or meet the notification deadlines (regulation 18(11)).

Standard maximum: the greater of £10,000,000 and 2% of turnover

Applies to other listed failures, such as not sending a copy of a notification to the CSIRT under regulation 11(8) (regulation 18(10)).

Part 4 national security directions

Contravening a direction carries up to £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under clause 49(5) are in force, plus up to £100,000 per day while the contravention continues. These figures do not apply to ordinary NIS failures.

When will the changes apply, and what should water companies do now?

Lords Committee Stage on HL Bill 32 sat on 1, 3, 7 and 9 September 2026. Report Stage is next, with no date announced, and Royal Assent is expected between late 2026 and spring 2027. Most duties then commence through secondary legislation, towards 2028. Until then the NIS Regulations 2018 apply unchanged.

  • Rework incident playbooks for a 24-hour initial notification, with clear rules on when the awareness clock starts
  • Map OT and SCADA assets that support potable water supply, and test detection for operational impact, not only data loss
  • Identify suppliers likely to be designated critical suppliers and review contract clauses on reporting and security
  • Align CAF and SEMD evidence so one control set supports both regimes
  • Budget for regulator charges and brief the board on the new penalty bands

Frequently asked questions

Does the Cyber Security and Resilience Bill apply to water companies?

Yes, where a company supplies potable water to 200,000 or more people. That threshold, in paragraph 9 of Schedule 2 to the NIS Regulations 2018, makes the supplier an Operator of Essential Services. The Bill does not change the threshold, but it amends the duties those operators already have, including faster incident reporting, a wider incident definition and a new two-band penalty regime.

Who is the NIS regulator for water companies in England?

The competent authority named in Schedule 1 to the NIS Regulations is the Secretary of State for Environment, Food and Rural Affairs. In practice the Drinking Water Inspectorate carries out the operational competent authority duties on behalf of the Secretary of State for England and the Welsh Government for Wales. The NCSC acts as the CSIRT that receives copies of incident notifications.

Is Ofwat the cyber security regulator for water under NIS?

No. Ofwat is the economic regulator for water and sewerage companies in England and Wales, but it is not a competent authority under the NIS Regulations 2018 and the Cyber Security and Resilience Bill does not mention it. NIS oversight sits with Defra and the Welsh Ministers, exercised through the Drinking Water Inspectorate, with separate authorities in Scotland and Northern Ireland.

How quickly must a water company report a cyber incident under the Bill?

An initial notification must reach the competent authority within 24 hours, and a full notification within 72 hours. Both periods begin when the operator first becomes aware that an incident has occurred or is occurring, under new regulation 11(6) inserted by clause 15. The 72 hours is not added after the 24 hours. A copy must go to the NCSC at the same time.

Are water sector OT and SCADA suppliers caught by the Bill?

Not automatically. A supplier can be designated a critical supplier under new regulation 14H if it supplies an operator directly, relies on network and information systems to do so, and disruption would have a significant impact on the economy or daily life. Suppliers providing managed IT services may separately be regulated as managed service providers. Designation follows consultation under regulation 14J.

What fines can a water company face under the Cyber Security and Resilience Bill?

Under new regulation 18, inserted by clause 21, failures to meet security duties or notify incidents carry a higher maximum of the greater of £17,000,000 and 4% of turnover. Other failures, such as not copying a notification to the NCSC, carry a standard maximum of the greater of £10,000,000 and 2% of turnover. Turnover includes activity inside and outside the United Kingdom.

Does the Bill replace SEMD for water companies?

No. The Security and Emergency Measures Direction is issued under section 208 of the Water Industry Act 1991 by the Secretary of State and Welsh Ministers, and the Drinking Water Inspectorate regulates it. The Cyber Security and Resilience Bill does not amend the Water Industry Act or the Direction, so water companies in England and Wales should expect both regimes to continue side by side.

When will the Bill's changes apply to water suppliers?

Not yet. As of 14 September 2026 Lords Committee Stage has sat on 1, 3, 7 and 9 September and Report Stage has no date. Royal Assent is expected between late 2026 and spring 2027. Many provisions, including incident reporting details, critical supplier designation and cost recovery, depend on secondary legislation, with most duties expected to commence towards 2028. The existing NIS Regulations 2018 continue to apply meanwhile.

Need help preparing your water operation for the Cyber Security and Resilience Bill?

Precursor Security helps water operators test OT and IT defences, evidence CAF outcomes and build incident response that meets the 24-hour clock.