Large Load Controllers and the Cyber Security and Resilience Bill
How clause 6 of HL Bill 32 makes load control of EV chargers, heat pumps, batteries and virtual power plants an essential service once a controller reaches 300 MW.
Last updated: 14 September 2026
Clause 6 of HL Bill 32 creates a new essential service of load control. Any organisation sending load control signals to EV chargers, electric vehicles, heat pumps, batteries or virtual power plants with a combined potential electrical control of 300 MW or more becomes an Operator of Essential Services, jointly regulated by DESNZ and Ofgem.
Why are load controllers being regulated?
Software platforms that switch thousands of EV chargers, heat pumps and home batteries on and off can move large blocks of demand in seconds. If one of those platforms were compromised when the grid is already stressed, an attacker could use it to destabilise the electricity system.
DESNZ says there are currently no legislative cyber security requirements for load controllers and that voluntary, industry-led codes are unlikely to deliver the resilience needed. The 300 MW threshold was developed with the National Energy System Operator as the point at which a controller's potential impact on the grid makes it an essential service.
How does the Bill define a load controller?
Clause 6 amends paragraph 1 of Schedule 2 to the NIS Regulations 2018 (the electricity subsector). It borrows its core terms from Part 9 of the Energy Act 2023. The four definitions that decide scope are:
“load controller” means a person which provides the service of load control
Load controller: new para 1(8)(ga), Schedule 2 NIS Regulations, inserted by cl.6(3)(c)
“Load control” means the sending of a load control signal to an energy smart appliance. A “load control signal” means a digital communication sent via a relevant electronic communications network to an energy smart appliance for the purpose of causing or otherwise facilitating such an adjustment.
Load control and load control signal: Energy Act 2023, s.238, applied by new para 1(8)(ga)
a load controller's potential electrical control, in relation to relevant ESAs managed by it, is the aggregate of (a) the maximum flow of electricity into all of those relevant ESAs (taken together), and (b) the maximum flow of electricity out of all of those relevant ESAs (taken together), which is capable of being achieved in response to load control signals sent by the load controller.
Potential electrical control: new para 1(5B), inserted by cl.6(2)
“relevant ESA” means an energy smart appliance (as defined by section 238(2) of the Energy Act 2023) which is any of the following: (i) an electric vehicle; (ii) a charge point (for electric vehicles); (iii) an electrical heating appliance; (iv) a battery energy storage system; (v) a virtual power plant
Relevant energy smart appliance: new para 1(5C)(a), inserted by cl.6(2)
Under the Energy Act 2023, an energy smart appliance is one “capable of adjusting the immediate or future flow of electricity into or out of itself or another appliance in response to a load control signal”. “Electrical heating appliance” means a hydronic heat pump, hot water heat pump, hybrid heat pump, direct electric hot water cylinder, electric storage heater or heat battery (new para 1(8)(cb)).
The Bill does not define battery energy storage system or virtual power plant. DESNZ consulted on draft definitions for both until 1 September 2026, so their exact boundaries are not yet settled.
How is the 300 MW threshold calculated?
New paragraph 1(5A) sets the threshold: a load controller whose potential electrical control over the relevant ESAs it manages is equal to or greater than 300 megawatts. The calculation has three features that often surprise operators.
- Nameplate, not usage. The maximum flow into or out of each device is set “by reference to the electrical capacity of the relevant ESA as stated by the manufacturer” (para 1(5C)(c)). Average or dispatched load is irrelevant.
- Import plus export. Para 1(5B) adds the maximum flow in to the maximum flow out. A bidirectional battery or vehicle-to-grid charger counts in both directions.
- Only managed devices. A device is “managed” if you control its electricity flow by load control signals you send (para 1(5C)(b)).
As a rough illustration, 300 MW is around 42,000 domestic 7 kW chargers, before any export capacity is counted. DESNZ also proposes that only devices on the Great Britain electricity system count, and that controllers monitor their total continuously and notify the competent authority when they reach 300 MW. Both points come from its consultation, not the Bill.
What about intermediaries and platform providers?
Load control often runs through a chain: a supplier or aggregator decides, and a platform provider sends the signal. Paragraphs 1(5D) and 1(5E) allocate the devices along that chain.
- Where an intermediary sends signals under the direction of or on behalf of a load controller, the devices count as managed by the load controller only.
- Where the intermediary is capable of adjusting or processing the signals and is authorised to do so, the devices count as managed by both, and the intermediary is also treated as a load controller.
- DESNZ says adjusting or processing includes creating a signal, changing it, or controlling when it is sent. Each party must reach 300 MW on its own count.
- Passive intermediaries, such as telecoms networks that carry signals they cannot change or are not authorised to change, are not intended to be caught.
DESNZ intends control through a home energy management system to count the same as direct control. It is still gathering evidence on platform providers that could be both a load controller and a relevant managed service provider for the same service.
Which organisations does this catch?
The test is functional: what matters is whether you send load control signals to relevant devices, not what you call your business. Organisations likely to need a threshold calculation include:
| Organisation type | Relevant ESAs | Likely position |
|---|---|---|
| EV charge point operators and smart charging platforms | Charge points, electric vehicles | In scope at 300 MW or more of managed capacity |
| Aggregators and virtual power plant operators | Virtual power plants, batteries, mixed portfolios | In scope at 300 MW; active intermediaries counted separately |
| Heat pump and home battery platforms | Electrical heating appliances, battery energy storage systems | In scope if they carry out load control for grid balancing |
| Energy suppliers running demand-side response or smart tariffs with device control | Any listed ESA under their control | In scope at 300 MW, in addition to any existing OES status as a supplier |
| Fleet and depot charging operators (industrial or commercial) | Charge points, electric vehicles | NIS applies at 300 MW in any setting, even without a licence |
| Device manufacturers | Their own products | Generally out of scope unless they actively carry out load control for grid balancing |
Sending firmware updates, safety signals, or tariff, weather or carbon intensity data without configuring the device's load response is intended to be out of scope.
Who is the regulator for large load controllers?
Load control sits in the electricity subsector, so the existing Schedule 1 entry applies: the Secretary of State for Energy Security and Net Zero and the Gas and Electricity Markets Authority (Ofgem) act jointly as designated competent authority. The DSIT large load controllers factsheet confirms that DESNZ and Ofgem “will be joint competent authorities”.
DESNZ's consultation divides the work: DESNZ sets policy, Ofgem assesses compliance, enforces and issues penalties, and both receive incident notifications. Operators are expected to demonstrate compliance against a new Tier 1 Cyber Assessment Framework profile for large load controllers, built with Ofgem and the NCSC. DESNZ proposes full alignment with that profile by the end of 2029, while keeping the right to enforce the core security duties from designation.
What must a large load controller do as an OES?
A designated load controller takes on the same duties as any other Operator of Essential Services under the amended NIS Regulations:
- Notify the competent authority that it meets the threshold. The factsheet says within 3 months of falling within scope; failure to notify under regulation 8(2) is a standard-band penalty.
- Take appropriate and proportionate technical and organisational measures to manage risks to its network and information systems, and to prevent and minimise the impact of incidents (regulation 10(1) and (2)).
- Have regard to competent authority guidance, including the Tier 1 CAF profile (regulation 10(3)).
- Report incidents: an initial notification within 24 hours and a full notification within 72 hours, both running from first awareness (new regulation 11(6)), with a copy to the CSIRT at the same time (regulation 11(8)).
- Respond to information notices and inspections, and manage supply chain risk, including any critical suppliers designated under new regulation 14H.
Designation also applies to controllers established outside the United Kingdom (new regulation 8(1ZA)), which matters for overseas platforms controlling British devices.
What are the penalties for load controllers?
New regulation 18 sets two bands. Turnover means turnover both inside and outside the United Kingdom.
Higher maximum: the greater of £17,000,000 and 4% of turnover
For failing the security duties in regulation 10(1) and (2), failing to notify an incident, or missing the 24 or 72 hour deadlines (regulation 18(9) and (11)).
Standard maximum: the greater of £10,000,000 and 2% of turnover
For failures such as not notifying designation under regulation 8(2) or not copying an incident notification to the CSIRT (regulation 18(8) and (10)).
Separately, Part 4 lets the Secretary of State give national security directions, with their own penalties. DESNZ has also said Ofgem could revoke a load control licence for NIS non-compliance as a last resort.
How does this fit with smart appliance and charge point rules?
Three regimes now touch the same devices, each aimed at a different party:
- Electric Vehicles (Smart Charge Points) Regulations 2021: product rules for private charge points sold in Great Britain since 30 June 2022, with Schedule 1 security requirements since 30 December 2022, enforced by the Office for Product Safety and Standards. They cover devices, not controllers, and exclude public and rapid (50 kW and above) charge points.
- Load control licensing under the Energy Act 2023: Ofgem's licence for controllers of domestic and small non-domestic devices. Ofgem published its decision on 7 August 2026. DESNZ expects the licence requirement to apply after a 12-month application window. Below 300 MW, cyber requirements come from licence Condition 9.
- NIS Regulations, as amended by the Cyber Security and Resilience Bill: at 300 MW or more, in any setting, cyber requirements come from NIS and the Tier 1 CAF profile. A domestic-focused controller that size still needs the licence for its other conditions.
Further Energy Smart Appliance product regulations are still in development, so their final content is not yet settled.
What should load controllers do now?
- Build an inventory of every relevant device you send load control signals to, with the manufacturer's stated import and export capacity.
- Calculate your potential electrical control under para 1(5B), and forecast when growth will take you past 300 MW.
- Map your signal chain. Identify intermediaries that create, change or time signals, and agree in writing who is the load controller.
- Run a gap assessment against the NCSC Cyber Assessment Framework now, then against the Tier 1 profile once DESNZ finalises it, expected late 2026.
- Test the control plane: commissioning, device authentication, signal integrity and platform access. Penetration testing of the platform and its APIs gives evidence of CAF outcomes.
- Build a 24-hour incident notification process, including how you will know an incident has started and who decides it is notifiable.
- Review suppliers, especially cloud, device and platform providers, and add security and notification terms to contracts.
Frequently Asked Questions
Does the Cyber Security and Resilience Bill apply to EV charge point operators?
Yes, if the operator sends load control signals to charge points or electric vehicles whose manufacturer-stated capacity adds up to 300 MW or more. Clause 6 of HL Bill 32 makes that controller an Operator of Essential Services in the electricity subsector. A charge point operator below 300 MW is not caught by this route, although it may need an Ofgem load control licence instead.
How is the 300 MW load controller threshold calculated?
Add the maximum flow of electricity into all the relevant energy smart appliances you manage to the maximum flow out of them, using each device's electrical capacity as stated by its manufacturer. It is a nameplate figure, not average or actual dispatched load. DESNZ proposes counting only devices on the Great Britain electricity system and expects controllers to monitor the total continuously.
Who regulates large load controllers under the Cyber Security and Resilience Bill?
The Department for Energy Security and Net Zero and Ofgem, acting jointly as competent authority. This follows the existing Schedule 1 entry for electricity in the NIS Regulations 2018 and is confirmed in the government's large load controllers factsheet. DESNZ's consultation says Ofgem will carry out day-to-day compliance assessment, enforcement and penalties, while both bodies receive incident notifications.
Are aggregators and virtual power plant operators in scope?
They can be. A virtual power plant is itself a listed relevant energy smart appliance, and an aggregator that sends load control signals is a load controller. Where an aggregator acts for another controller but can adjust or process the signals and is authorised to do so, both are treated as load controllers. Each must still reach 300 MW on its own count.
Are smart appliance manufacturers caught by the load controller rules?
Not simply for making the device. DESNZ says manufacturers are in scope only where they actively carry out load control for grid operation and balancing. Local device optimisation, firmware updates, safety signals and passing on tariff or carbon intensity data are intended to be out of scope. A manufacturer's cloud platform may still be a critical supplier to an in-scope controller.
What is the incident reporting deadline for large load controllers?
As Operators of Essential Services, large load controllers must send an initial notification within 24 hours and a full notification within 72 hours. Under new regulation 11(6) both periods start when the operator is first aware that the incident has occurred or is occurring, so the 72 hours do not follow the 24. A copy must go to the CSIRT at the same time.
What fines can a large load controller face?
Part 2 of the Cyber Security and Resilience Bill sets two bands. The standard maximum, for failures such as not notifying designation, is the greater of £10,000,000 and 2% of turnover. The higher maximum, for security duty and incident reporting failures, is the greater of £17,000,000 and 4% of turnover. Turnover includes activity inside and outside the United Kingdom.
How does NIS regulation relate to the Ofgem load control licence?
They are separate regimes that meet at 300 MW. Controllers of domestic and small non-domestic devices below 300 MW take an Ofgem load control licence with cyber requirements in the licence conditions. At 300 MW or more, in any setting, cyber requirements come from the NIS Regulations instead, although a domestic-focused controller that size still needs the licence for its other conditions.
Official sources
- Cyber Security and Resilience (Network and Information Systems) Bill: UK Parliament bill page
- Read the Bill text (HL Bill 32), clause 6
- DSIT factsheet: large load controllers
- DESNZ: Large Load Controllers Tier 1 Cyber Assessment Framework consultation (PDF)
- Ofgem: implementing the load control licensing regime
- Energy Act 2023, section 238
- The Network and Information Systems Regulations 2018
- The Electric Vehicles (Smart Charge Points) Regulations 2021
Related guidance
Approaching 300 MW?
We help load controllers test their control platforms and prepare CAF evidence before designation under the Cyber Security and Resilience Bill.