Financial Services Cyber Security and Resilience Bill Compliance Guide
Complete guide to Cyber Security and Resilience Bill compliance for banks, fintech platforms, and digital payment services. Understand multi-regulatory obligations under HL Bill 32.
Sector Overview
The financial sector is the engine of the UK economy, increasingly powered by digital infrastructure. Banks, fintechs, and payment platforms process vast volumes of transactions and store sensitive financial data every day. Under the Cyber Security and Resilience Bill (HL Bill 32), financial institutions may be regulated in multiple ways depending on their activities.
Why Financial Services Are In Scope
Financial institutions may be in scope in several ways under HL Bill 32:
You're likely in scope if your organisation:
- Is an operator of essential services in the banking sector (meeting threshold requirements in Schedule 2)
- Provides cloud computing services, online marketplaces, or search engines (regulated as RDSP under Part 2, Section 7)
- Provides managed IT services (regulated as RMSP under Part 2, Section 9)
- Operates core banking or digital payment platforms
- Manages infrastructure used by regulated sectors (NHS, local government)
- Provides credit scoring, KYC/AML, or identity verification at scale
- Processes sensitive customer or business financial data
- Carries on essential activities or provides activity-critical supplies (subject to Part 3 regulations)
- May be subject to directions for national security purposes (Part 4)
Multi-Regulatory Environment:
Financial services must navigate FCA, PRA, ICO, and now Cyber Security and Resilience Bill requirements. The Cyber Security and Resilience Bill adds operational resilience and cyber incident response requirements alongside existing financial services regulation.
Banking Sector - Operators of Essential Services
Financial institutions providing essential services in the banking sector are listed as operators of essential services (OES) in Schedule 2 of the NIS Regulations, subject to threshold requirements.
As an OES in the banking sector, you must:
- Comply with security duties under Regulation 10
- Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 11
- Send a copy of incident notifications to CSIRT
- Comply with information requests and inspections under Regulations 15 and 16
- Have regard to guidance from your designated competent authority
Fintech as Relevant Digital Service Providers
Under Part 2, Section 7 of HL Bill 32, fintech providers offering cloud computing services, online marketplaces, or search engines may be regulated as Relevant Digital Service Providers (RDSPs):
- Register with the Information Commission within 3 months (Regulation 14)
- Comply with security duties under Regulation 12
- Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 12A
- Notify affected customers as soon as reasonably practicable under Regulation 12C
- Comply with information requests and inspections
Financial Services as Managed Service Providers
Under Part 2, Section 9 of HL Bill 32, financial services providing managed IT services may be regulated as Relevant Managed Service Providers (RMSPs):
- Register with the Information Commission within 3 months (Regulation 14C)
- Comply with security duties under Regulation 14B
- Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 14E
- Notify affected customers as soon as reasonably practicable under Regulation 14G
- Comply with information requests and inspections
Essential Activities & Activity-Critical Supplies
Under Part 3, Section 24 of HL Bill 32, financial institutions may carry on essential activities or provide activity-critical supplies, subjecting them to additional security and resilience requirements:
- May be subject to regulations under Section 29 relating to security and resilience of network and information systems
- May be subject to requirements imposed under Section 30
- May be subject to enforcement, sanctions, and appeals under Section 31
- May become subject to financial penalties under future Part 3 regulations, which Section 32(3) caps at the greater of £17,000,000 and 10% of turnover; no such regulations have been made yet
- Must have regard to codes of practice issued under Section 36
National Security Directions - Part 4
Under Part 4, Section 43 of HL Bill 32, financial institutions may be subject to directions for national security purposes:
- The Secretary of State may give directions if threats relating to network and information systems pose a risk to national security
- Directions may impose requirements relating to management of systems, provision of information, or prohibitions on use of goods/services
- You must comply with directions and may be subject to monitoring, information gathering, and inspections
- Penalties for contravening a direction: up to £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, with daily penalties of up to £100,000 while the contravention continues
- HL Bill 32, Part 4, Sections 43-52
Penalties for Non-Compliance
Financial services face penalties under multiple parts of HL Bill 32:
Part 2 Penalties (OES/RDSP/RMSP):
Higher Maximum: the greater of £17,000,000 and 4% of turnover for serious failures
Standard Maximum: the greater of £10,000,000 and 2% of turnover for administrative failures
Part 3 Penalties (Essential Activities):
Cap on future regulations: the greater of £17,000,000 and 10% of turnover. Part 3 penalties only come into being once regulations under Section 29(1) are made, and none have been.
Part 4 Penalties (National Security Directions):
Maximum: £17,000,000 for contravening a direction, becoming the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues
- HL Bill 32, Part 2, Section 21; Part 3, Section 32; Part 4, Section 49
Benefits of Cyber Security and Resilience Bill Compliance
Operational Resilience
- Ensures continuity of financial services during incidents
- Strengthens security across fast-scaling fintech operations
- Builds confidence with institutional clients and partners
Regulatory Alignment
- Prepares for future legislation like DORA and NIS2
- Better alignment with existing FCA and PRA requirements
- Access to guidance from regulatory authorities
Direct References from HL Bill 32
Schedule 2 - Banking Subsector
Financial institutions providing essential services in the banking sector are listed as operators of essential services (OES) in Schedule 2, subject to threshold requirements.
HL Bill 32, Schedule 2
Part 2, Section 7 - Digital Services
Fintech providers offering cloud computing services, online marketplaces, or search engines may be regulated as relevant digital service providers (RDSPs).
HL Bill 32, Part 2, Section 7
Part 3, Section 24 - Essential Activities
Financial institutions may carry on essential activities or provide activity-critical supplies, subjecting them to additional security and resilience requirements under Part 3.
HL Bill 32, Part 3, Section 24
Part 4, Section 43 - Directions for National Security
Financial institutions may be subject to directions for national security purposes if threats relating to network and information systems pose a risk to national security.
HL Bill 32, Part 4, Section 43
Frequently Asked Questions
Are banks regulated under the CSRB?
Banks are regulated under the Cyber Security and Resilience Bill as Operators of Essential Services where they provide essential services in the banking sector and meet the threshold requirements in Schedule 2. Fintech providers may instead be in scope as Relevant Digital Service Providers if they offer cloud computing services, online marketplaces or search engines, or as Relevant Managed Service Providers if they offer managed IT services.
How does the CSRB interact with FCA and PRA regulation?
The Cyber Security and Resilience Bill adds operational resilience and cyber incident response requirements alongside existing financial services regulation rather than replacing it. Financial services firms must navigate FCA, PRA, ICO and now Cyber Security and Resilience Bill requirements together, with the Bill specifically targeting operational resilience and cyber incident response for organisations of systemic importance.
How quickly must a bank report a cyber incident under the CSRB?
A bank regulated as an Operator of Essential Services must give an initial notification within 24 hours and a full notification within 72 hours under Regulation 11, sending a copy to CSIRT at the same time. Fintechs regulated as Relevant Digital Service Providers report on the same 24-hour and 72-hour timetable under Regulation 12A, and those regulated as Relevant Managed Service Providers under Regulation 14E, in each case to the Information Commission.
Are fintech platforms in scope of the CSRB?
Fintech platforms are in scope of the Cyber Security and Resilience Bill where they provide cloud computing services, online marketplaces or search engines as Relevant Digital Service Providers under Part 2, Section 7, or provide managed IT services as Relevant Managed Service Providers under Part 2, Section 9. RDSPs must register with the Information Commission within 3 months under Regulation 14 and RMSPs within 3 months under Regulation 14C, and both must notify affected customers as soon as reasonably practicable after a full incident notification.
What penalties can financial services firms face under the CSRB?
Financial services firms face a higher maximum penalty of the greater of £17,000,000 and 4% of turnover for serious Part 2 failures as an OES, RDSP or RMSP, and a standard maximum of the greater of £10,000,000 and 2% of turnover for administrative failures. Part 3 penalties do not exist yet; when regulations are made, Section 32(3) caps them at the greater of £17,000,000 and 10% of turnover. Contravening a Part 4 national security direction carries a maximum of £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues.
Need Help with Financial Services Cyber Security and Resilience Bill Compliance?
Our expert team helps banks and fintech platforms navigate multi-regulatory requirements and implement Cyber Security and Resilience Bill compliance.