Public Services Cyber Security and Resilience Bill Compliance Guide
Complete guide to Cyber Security and Resilience Bill compliance for local authorities, councils, and government departments. Understand essential service obligations under HL Bill 32.
Sector Overview
Public services - including local authorities, government departments, and public agencies - are fundamental to the UK's national infrastructure. They deliver vital services like housing, education, social care, and emergency response. Under the Cyber Security and Resilience Bill (HL Bill 32), public sector organisations providing essential services are regulated as Operators of Essential Services (OES).
Why Public Services Are In Scope
Under Part 2, Section 3 of HL Bill 32, Regulation 8 identifies operators of essential services. Local authorities, councils, and government departments that provide essential services are directly in scope. Even if you generate more than half your income from commercial activities, you may still be regulated if you're subject to public authority oversight under Part 2, Section 11.
You may be affected if you:
- Are an operator of essential services providing services like healthcare, transport, energy, or water (meeting threshold requirements in Schedule 2)
- Deliver essential public-facing services via digital platforms (housing, education, social care, benefits)
- Manage critical data or infrastructure that supports day-to-day functioning of society
- Work with third-party providers that fall under Cyber Security and Resilience Bill scope (cloud services, MSPs)
- Support national resilience or emergency response functions
- Are subject to public authority oversight and rely on network and information systems
- Provide cloud computing services, online marketplaces, or managed services (may be regulated as RDSP or RMSP)
Public Authority Oversight:
Under Part 2, Section 11 of HL Bill 32, a person is subject to public authority oversight if they are subject to the management or control of one or more UK public authorities, or a board more than half of whose members are appointed by UK public authorities. Even if you derive more than half your income from commercial activities, you may still be regulated if you're subject to public authority oversight.
Security Duties - Regulation 10
As an Operator of Essential Services (OES), you must comply with security duties under Regulation 10 of the NIS Regulations:
- Take appropriate and proportionate technical and organisational measures to manage risks posed to the security of network and information systems on which you rely for the provision of the essential service
- Take appropriate and proportionate measures to prevent and minimise the impact of incidents affecting the security of those network and information systems
- Have regard to any relevant guidance issued by your designated competent authority
Incident Reporting Requirements - Regulation 11
Under Part 2, Section 15 of HL Bill 32, Regulation 11 sets out strict incident reporting requirements:
⚠️ Critical Timeline:
Required Information in Full Notification:
- Your name and the essential service to which the incident relates
- The time the incident occurred, its duration and whether it is ongoing
- Information concerning the nature of the incident
- Where the incident was caused by a separate incident affecting another regulated person: details of that separate incident and of the regulated person
- Information concerning the impact (including any cross-border impact) which the incident has had, is having or is likely to have
- Such other information as you consider may assist the designated competent authority
Reporting Requirements:
Notifications must be in writing, provided in such form and manner as the designated competent authority determines. You must send a copy of the notification to CSIRT (Computer Security Incident Response Team) at the same time as sending it to the designated competent authority.
- HL Bill 32, Part 2, Section 15, Regulation 11
Information Requests & Inspections
Under Part 2, Section 20 of HL Bill 32, Regulation 15 gives designated competent authorities powers to:
- Require you to give such information or documents as it reasonably requires for exercising its functions
- Require you to obtain or generate information or documents
- Require you to collect or retain information that you would not otherwise collect or retain
- Send information notices whether or not you're established in the UK
- Request information or documents stored within or outside the United Kingdom
⚠️ Important:
Failure to comply with an information notice is a breach that can result in penalties. Under Schedule 1, Regulation 16, regulators can inspect your premises, examine documents, test your systems, and interview your staff.
- HL Bill 32, Part 2, Section 20, Regulation 15; Schedule 1, Regulation 16
Penalties for Non-Compliance
Under Part 2, Section 21 of HL Bill 32, Regulation 18 sets out financial penalties:
Higher Maximum Amount (Serious Failures):
Maximum: the greater of £17,000,000 and 4% of global turnover for failures including security duties and incident reporting
Standard Maximum Amount (Administrative Failures):
Maximum: the greater of £10,000,000 and 2% of global turnover for failures including information provision and notification timing
- HL Bill 32, Part 2, Section 21, Regulation 18
Benefits of Cyber Security and Resilience Bill Compliance
Service Continuity
- Reduces risk of service outages and data loss affecting residents
- Improves cyber maturity across departments
- Builds trust with residents and supports continued funding
Governance & Strategy
- Demonstrates responsible digital governance to auditors and central government
- Access to guidance from designated competent authorities
- Better positioning for future digital transformation initiatives
Direct References from HL Bill 32
Part 2, Section 3 - Identification of Operators of Essential Services
Regulation 8 identifies local authorities, councils, and government departments as operators of essential services where they provide essential services in sectors like transport, energy, water, or health, meeting threshold requirements in Schedule 2.
HL Bill 32, Part 2, Section 3, Regulation 8
Part 2, Section 11 - Subject to Public Authority Oversight
Regulation 1(3E) defines public authority oversight. Public services subject to public authority oversight may be regulated even if they derive more than half their income from commercial activities, if they provide essential services or digital/managed services.
HL Bill 32, Part 2, Section 11, Regulation 1(3E)
Frequently Asked Questions
Are local authorities regulated under the CSRB?
Local authorities, councils and government departments are regulated under the Cyber Security and Resilience Bill as Operators of Essential Services where they provide essential services in sectors such as transport, energy, water or health and meet the threshold requirements in Schedule 2. Public sector organisations may also be regulated as Relevant Digital Service Providers or Relevant Managed Service Providers where they provide cloud computing services, online marketplaces or managed services.
What is public authority oversight under the CSRB?
A person is subject to public authority oversight under the Cyber Security and Resilience Bill if they are subject to the management or control of one or more UK public authorities, or of a board more than half of whose members are appointed by UK public authorities. This matters because an organisation subject to public authority oversight may still be regulated even if it derives more than half its income from commercial activities. Public authority oversight is defined by Regulation 1(3E), inserted by Part 2, Section 11 of HL Bill 32.
How quickly must a council report a cyber incident under the CSRB?
A local authority regulated as an Operator of Essential Services must give an initial notification within 24 hours of first becoming aware of an OES incident and a full notification within 72 hours, under Regulation 11. Notifications must be in writing and in the form and manner the designated competent authority determines, and a copy must be sent to CSIRT at the same time.
What powers do regulators have over public sector bodies?
Designated competent authorities can require public sector bodies to give, obtain, generate, collect or retain information and documents under Regulation 15, whether or not the body is established in the UK and whether the material is stored inside or outside the UK. Under Schedule 1, Regulation 16, regulators can also inspect premises, examine documents, test systems and interview staff. Failure to comply with an information notice is a breach that can result in penalties, although privileged legal advice does not have to be given.
What penalties can local authorities face under the CSRB?
Local authorities face a higher maximum penalty of the greater of £17,000,000 and 4% of global turnover, for serious failures including breaches of security duties and incident reporting. Administrative failures such as information provision and notification timing carry a standard maximum of the greater of £10,000,000 and 2% of global turnover under Regulation 18.
Need Help with Public Services Cyber Security and Resilience Bill Compliance?
Our expert team helps local authorities and government departments implement and prove compliance with Cyber Security and Resilience Bill requirements.