Local Councils & Local Government

Local Councils and the Cyber Security and Resilience Bill

How the public authority exemption works, the narrow routes that can still bring a council into scope, and how regulation of your suppliers will change contracts and procurement.

Last updated: 14 September 2026

Local authorities are largely outside the direct scope of the Cyber Security and Resilience Bill. No clause names councils, and the managed and digital service provider duties exclude bodies under public authority oversight that earn half or less of their income commercially. A council is regulated directly only where it runs an essential service above a NIS threshold.

Does the Cyber Security and Resilience Bill apply to local councils?

For most councils, no. The Bill (HL Bill 32) amends the NIS Regulations 2018 and regulates five groups: operators of essential services (OES), relevant digital service providers (RDSPs), relevant managed service providers (RMSPs), data centres and large load controllers, plus suppliers designated as critical. Local government is not one of them.

The Local Government Association reached the same view: its policy briefing says the direct effects on councils are limited because they are largely excluded from the legislation.

That does not mean the Bill can be ignored. Three things still matter to a council: the specific services that can make a council an OES, the position of council-owned companies that sell IT services, and the new duties on the suppliers councils rely on. Those supplier duties are where most councils will feel the Bill.

Timing: Lords Committee Stage sat on 1, 3, 7 and 9 September 2026. Report Stage is next, with no date announced. Royal Assent is expected between late 2026 and spring 2027, and most duties will commence later through secondary legislation, towards 2028.

What is the public authority oversight test?

Clause 11 inserts a new regulation 1(3E) into the NIS Regulations. A person is subject to public authority oversight if it is subject to the management or control of one or more UK public authorities, or of a board more than half of whose members are appointed by UK public authorities. A UK public authority is any person exercising functions of a public nature in the UK.

The test is used in only two places: the definitions of an RDSP (clause 7(8), new reg 1(3)(e)) and an RMSP (clause 9(4), new reg 1(3)(ea)). Each requires, as limb (iv), that the provider either is not subject to public authority oversight, or is subject to it but derives more than half of its income from activities of a commercial nature.

Put the other way round: a body under public authority oversight that earns half or less of its income commercially cannot be an RDSP or RMSP. That is the exemption. It is separate from the micro and small enterprise exemption in limb (iii).

The oversight test does not apply to OES status. Nothing in regulation 8 or clause 3 excludes public bodies from being an operator of essential services. Clause 3 excludes only public electronic communications networks and services.

How could a council still be brought into scope?

The table sets out each route into the Bill and how realistic it is for local government.

Route into scopeHow a council could be caughtRegulatorThreshold or testLikelihood
Operator of essential services (reg 8, NIS Schedule 2)Harbour authority for a large port; owner or manager of a large aerodrome; metro operator; road authoritySecretary of State for Transport (water, rail, road); Secretary of State for Transport and the Civil Aviation Authority jointly (air)Port: over 10 million annual passengers or qualifying freight volumes. Aerodrome: over 10 million terminal passengers. Metro: over 50 million annual journeysNarrow but real. No public sector carve-out in the OES test
Relevant managed service provider (cl.9, reg 1(3)(ea))Council-owned IT company or shared service selling managed IT servicesInformation CommissionNot a micro or small enterprise, and either not under public authority oversight or earning more than half its income commerciallyPossible for commercially trading council companies
Relevant digital service provider (cl.7, reg 1(3)(e))Council body providing a cloud computing service, online marketplace or search engineInformation CommissionSame size and public authority oversight tests as managed service providersUnlikely
Critical supplier (reg 14H)Council that supplies goods or services directly to an OES, RDSP or RMSPDesignated competent authority or Information CommissionDisruption to the supply would have a significant impact on the economy or day-to-day functioning of societyUnlikely. No public authority carve-out in reg 14H or 14I
Part 3 essential activities (cl.24, cl.30)Only if future regulations specify council activitiesSet by the regulationsNone yet. No Part 3 regulations have been madeNot settled
Part 4 national security directions (cl.43)Only a council that is already a regulated person (OES, RDSP, RMSP, critical supplier or specified under Part 3)Secretary of StateDirection necessary and proportionate for national securityFollows from the routes above

Thresholds are from Schedule 2 to the NIS Regulations 2018, which the Bill leaves unchanged for these subsectors.

Can a council-run harbour, airport or transport network be an operator of essential services?

Yes. The OES test looks at the service, not at who owns it. A council that is the statutory harbour authority for a port with more than 10 million annual passengers, or with qualifying roll-on roll-off, lift-on lift-off, liquid bulk or biomass freight volumes, meets the water transport threshold. The owner or manager of an aerodrome with more than 10 million annual terminal passengers meets the air transport threshold.

Local government transport bodies can also qualify. The metro threshold is more than 50 million annual passenger journeys, and Transport for London, a functional body of the Greater London Authority, runs the London Underground well above that level.

Most council ports and regional airports fall below these thresholds, and many council-linked airports are run by separate companies rather than the council itself. Each council should check its own figures. Where a council is an OES, it must meet the security duties in regulation 10 and report incidents under regulation 11: an initial notification within 24 hours and a full notification within 72 hours, both from first awareness. Part 2 penalties have two bands: a standard maximum of the greater of £10,000,000 and 2% of turnover, and a higher maximum of the greater of £17,000,000 and 4% of turnover.

Are council-owned IT companies and shared services regulated?

Possibly. A company wholly owned by one or more councils is under public authority oversight, so the question becomes how much of its income comes from activities of a commercial nature.

  • An in-house ICT department or a shared service run between councils on a cost-recovery basis is unlikely to be an RMSP.
  • A council-owned company that earns most of its income selling managed IT services, and is not a micro or small enterprise, may be an RMSP and have to register with the Information Commission.
  • The Bill does not define "activities of a commercial nature". Whether fees charged to other councils count as commercial income is not yet settled.

DSIT's managed service provider factsheet confirms that entities subject to public authority oversight and deriving less than half their income from commercial activities are exempt. Councils with trading companies should take advice on their income mix before the duties commence.

How will the Cyber Security and Resilience Bill affect councils through their suppliers?

This is where most councils will feel the Bill. Many council IT outsourcers, managed security providers and cloud platforms will be RMSPs or RDSPs, and some data centres they use will be regulated too.

  • Incident reporting: an RMSP must notify the Information Commission within 24 hours and give a full notification within 72 hours, both from first awareness (regulation 14E).
  • Customer notification: after its full notification, an RMSP must identify UK customers likely to be adversely affected and notify them (regulation 14G). RDSPs have the same duty under regulation 12C.
  • Critical suppliers: regulators can designate a supplier to an OES, RDSP or RMSP as a critical supplier under regulation 14H, bringing duties further down the chain.
  • Small suppliers: micro and small enterprises are exempt from RMSP and RDSP status, so a small local IT provider may not be regulated at all.

The statutory customer notice is a floor, not a service level. It is sent "as soon as reasonably practicable" after the full notification. Councils that need faster warning should write it into contracts.

What is the LGA's position on the Cyber Security and Resilience Bill?

The Local Government Association's policy briefing welcomes the Government's proposals to strengthen supply chain resilience, enhance incident reporting and improve threat intelligence, which it says address longstanding weaknesses in local government cyber security. It also welcomes local authorities being included in the Bill's ambitions for better information sharing.

The LGA says the direct effects on councils are limited because they are largely excluded. It warns that the Bill may introduce new supplier-related risks and requirements, and that it signals new expectations around cyber assurance in procurement and commissioning. Because the Bill widens what counts as a reportable incident, council suppliers may face stronger assurance expectations and more reporting.

Why is the public sector exempt, and what did the Lords say?

The Government has chosen to regulate the private operators and suppliers behind essential services by statute, and to secure government itself through policy. On 6 January 2026, alongside Commons Second Reading, it published the Government Cyber Action Plan. It is backed by more than £210 million and sets up a Government Cyber Unit to coordinate cyber risk management and incident response across departments and the wider public sector.

Critics say this leaves the public sector without legal obligations. At Lords Second Reading on 14 July 2026, Lord Clement-Jones called the Bill "not nearly ambitious enough", and peers raised the near-total public sector exemption again at Committee Stage in September.

As printed, HL Bill 32 does not bring local authorities into scope. How far the Action Plan's standards bind councils, as opposed to central government departments, is not something we have been able to confirm from the published plan. Report Stage is the next chance for amendments.

What should councils do now to prepare?

  • Confirm your direct position: check any harbour, aerodrome or transport function against the NIS Schedule 2 thresholds, and record the result.
  • Review council-owned companies and shared services against the RMSP definition, including their share of commercial income.
  • Map critical ICT suppliers and identify which are likely to be RMSPs, RDSPs, data centres or critical suppliers.
  • Add contract clauses requiring suppliers to notify the council of incidents within set hours, and to share their regulatory notifications.
  • Add procurement questions on regulatory status, Cyber Assessment Framework alignment and incident response.
  • Plan for suppliers you rely on that sit outside the Bill, such as small providers under the micro and small exemption.
  • Test incident response plans against a supplier-originated incident, not only an attack on your own network.
  • Track Report Stage and the secondary legislation that will set commencement dates.

Frequently Asked Questions

Are local councils covered by the Cyber Security and Resilience Bill?

Mostly not directly. The Bill regulates operators of essential services, digital and managed service providers, data centres, large load controllers and designated critical suppliers. Councils are not a category in their own right. The digital and managed service provider duties exclude bodies under public authority oversight that earn half or less of their income commercially. A council is caught only where it runs an essential service above a NIS Schedule 2 threshold.

What does public authority oversight mean in the Cyber Security and Resilience Bill?

Clause 11 inserts regulation 1(3E) into the NIS Regulations 2018. A person is subject to public authority oversight if it is managed or controlled by one or more UK public authorities, or by a board more than half of whose members they appoint. The test matters only for digital and managed service provider status, where it combines with a test of how much income is commercial.

Is a council-owned IT company regulated as a managed service provider?

It can be. A council-owned company is almost certainly under public authority oversight, so it avoids managed service provider status only if half or less of its income comes from activities of a commercial nature. A company earning most of its income from selling IT services, and not a micro or small enterprise, may be a relevant managed service provider. The Bill does not define commercial activity.

Can a council be an operator of essential services under the NIS Regulations?

Yes, if it provides an essential service above a threshold in Schedule 2 to the NIS Regulations 2018. The OES test has no public sector carve-out. Examples include a harbour authority for a port with more than 10 million annual passengers or qualifying freight volumes, an aerodrome with more than 10 million terminal passengers, or a metro operator with more than 50 million annual journeys.

Will council suppliers have to tell councils about cyber incidents?

Regulated suppliers will. A relevant managed service provider must give the Information Commission an initial notification within 24 hours and a full notification within 72 hours, both running from first awareness. After the full notification it must identify UK customers likely to be adversely affected and notify them under regulation 14G. Relevant digital service providers have an equivalent duty under regulation 12C.

Why is the public sector exempt from the Cyber Security and Resilience Bill?

The Government has chosen to secure government through policy rather than new statutory duties. It points to the Government Cyber Action Plan, published on 6 January 2026 with more than £210 million of funding and a new Government Cyber Unit. Peers criticised the near-total public sector exemption at Second Reading and Committee Stage, but HL Bill 32 does not bring councils into scope.

What does the LGA say about the Cyber Security and Resilience Bill?

The Local Government Association's policy briefing welcomes the Bill's measures on supply chain resilience, incident reporting and threat intelligence. It says the direct effects on councils are limited because they are largely excluded, but that the Bill signals new expectations around cyber assurance in procurement and commissioning, and may bring new supplier-related risks and more incident reporting.

When will the Cyber Security and Resilience Bill affect councils?

Lords Committee Stage sat on 1, 3, 7 and 9 September 2026 and Report Stage is next, with no date announced. Royal Assent is expected between late 2026 and spring 2027. Most duties, including those on managed service providers, will commence later through secondary legislation, expected towards 2028. Councils can use that window to update supplier contracts and procurement questions.

Official sources

Related guidance

Need help assuring your council's suppliers?

We help councils test their exposure to supplier incidents, review contract and procurement clauses, and confirm whether any council service or company falls within the Cyber Security and Resilience Bill.

This page explains the Bill as brought from the Commons (HL Bill 32). It is not legal advice, and the text may change at Report Stage.