Universities Cyber Security and Resilience Bill Compliance Guide
Complete guide to Cyber Security and Resilience Bill compliance for universities and research institutions. Understand multi-faceted regulatory obligations under HL Bill 32.
Sector Overview
Universities and research institutions are hubs of innovation, managing vast amounts of sensitive research data, student information, and critical computing infrastructure. Under the Cyber Security and Resilience Bill (HL Bill 32), universities may be regulated in multiple ways depending on their activities.
Why Universities Are In Scope
Universities may be in scope under HL Bill 32 in several ways:
You're likely in scope if your organisation:
- Is an operator of essential services in sectors like health, energy, or transport (meeting threshold requirements in Schedule 2)
- Provides cloud computing services, online marketplaces, or search engines (regulated as RDSP under Part 2, Section 7)
- Provides managed IT services (regulated as RMSP under Part 2, Section 9)
- Carries on essential activities or provides activity-critical supplies (subject to Part 3 regulations)
- May be subject to directions for national security purposes (Part 4)
- Is subject to public authority oversight and relies on network and information systems
- Manages research with implications for national resilience or security
- Operates or supports high-performance computing (HPC) environments
- Processes sensitive student, staff, or partner data at scale
- Provides infrastructure to regulated sectors through collaboration
Public Authority Oversight:
Under Part 2, Section 11 of HL Bill 32, universities subject to public authority oversight may be regulated even if they derive more than half their income from commercial activities, if they provide essential services or digital/managed services.
As Operators of Essential Services (OES)
Universities providing essential services in sectors like health, energy, or transport are listed as operators of essential services (OES) in Schedule 2, subject to threshold requirements.
As an OES, you must:
- Comply with security duties under Regulation 10
- Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 11
- Send a copy of incident notifications to CSIRT
- Provide information to designated competent authority within 3 months under Regulation 8ZA (if providing data centre services)
- Comply with information requests and inspections under Regulations 15 and 16
- Have regard to guidance from your designated competent authority
As Relevant Digital Service Providers (RDSP)
Under Part 2, Section 7 of HL Bill 32, universities providing cloud computing services, online marketplaces, or search engines may be regulated as Relevant Digital Service Providers (RDSPs):
- Register with the Information Commission within 3 months (Regulation 14)
- Comply with security duties under Regulation 12
- Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 12A
- Notify affected customers as soon as reasonably practicable under Regulation 12C
- Comply with information requests and inspections
As Relevant Managed Service Providers (RMSP)
Under Part 2, Section 9 of HL Bill 32, universities providing managed IT services may be regulated as Relevant Managed Service Providers (RMSPs):
- Register with the Information Commission within 3 months (Regulation 14C)
- Comply with security duties under Regulation 14B
- Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 14E
- Notify affected customers as soon as reasonably practicable under Regulation 14G
- Comply with information requests and inspections
Essential Activities & Activity-Critical Supplies
Under Part 3, Section 24 of HL Bill 32, universities may carry on essential activities or provide activity-critical supplies, subjecting them to additional security and resilience requirements:
- May be subject to regulations under Section 29 relating to security and resilience of network and information systems
- May be subject to requirements imposed under Section 30
- May be subject to enforcement, sanctions, and appeals under Section 31
- May become subject to financial penalties under future Part 3 regulations, which Section 32(3) caps at the greater of £17,000,000 and 10% of turnover; no such regulations have been made yet
- Must have regard to codes of practice issued under Section 36
National Security Directions - Part 4
Under Part 4, Section 43 of HL Bill 32, universities may be subject to directions for national security purposes:
- The Secretary of State may give directions if threats relating to network and information systems pose a risk to national security
- Directions may impose requirements relating to management of systems, provision of information, or prohibitions on use of goods/services
- You must comply with directions and may be subject to monitoring, information gathering, and inspections under Sections 45-47
- Penalties for contravening a direction: up to £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, with daily penalties of up to £100,000 while the contravention continues
- HL Bill 32, Part 4, Sections 43-52
Penalties for Non-Compliance
Universities face penalties depending on how they're regulated:
Part 2 Penalties (OES/RDSP/RMSP):
Higher Maximum: the greater of £17,000,000 and 4% of turnover for serious failures
Standard Maximum: the greater of £10,000,000 and 2% of turnover for administrative failures
Part 3 Penalties (Essential Activities):
Cap on future regulations: the greater of £17,000,000 and 10% of turnover. Part 3 penalties only come into being once regulations under Section 29(1) are made, and none have been.
Part 4 Penalties (National Security Directions):
Maximum: £17,000,000 for contravening a direction, becoming the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues
- HL Bill 32, Part 2, Section 21; Part 3, Section 32; Part 4, Section 49
Benefits of Cyber Security and Resilience Bill Compliance
Research Protection
- Protects data and research environments from cyber threats
- Supports funding, collaboration, and government trust
- Strengthens cyber maturity across academic networks
Strategic Benefits
- Futureproofs institutions in a security-driven digital landscape
- Access to guidance from regulatory authorities
- Better positioning for government-backed research programmes
Direct References from HL Bill 32
Schedule 2 - Essential Services
Universities providing essential services in sectors like health, energy, or transport are listed as operators of essential services (OES) in Schedule 2, subject to threshold requirements.
HL Bill 32, Schedule 2
Part 2, Section 11 - Subject to Public Authority Oversight
Regulation 1(3E) defines public authority oversight. Universities subject to public authority oversight may be regulated even if they derive more than half their income from commercial activities, if they provide essential services or digital/managed services.
HL Bill 32, Part 2, Section 11, Regulation 1(3E)
Part 3, Section 24 - Essential Activities
Universities may carry on essential activities or provide activity-critical supplies, subjecting them to additional security and resilience requirements under Part 3.
HL Bill 32, Part 3, Section 24
Part 4, Section 43 - Directions for National Security
Universities may be subject to directions for national security purposes if threats relating to network and information systems pose a risk to national security.
HL Bill 32, Part 4, Section 43
Frequently Asked Questions
Are universities regulated under the CSRB?
Universities are regulated under the Cyber Security and Resilience Bill where they are operators of essential services in sectors such as health, energy or transport, provide cloud computing services, online marketplaces or search engines, or provide managed IT services. They may also carry on essential activities under Part 3 or be subject to directions for national security purposes under Part 4.
Are universities regulated if most of their income is commercial?
Universities subject to public authority oversight may be regulated under the Cyber Security and Resilience Bill even if they derive more than half their income from commercial activities, provided they supply essential services or digital or managed services. Public authority oversight is defined by Regulation 1(3E), inserted by Part 2, Section 11 of HL Bill 32.
What must a university do if it is an Operator of Essential Services?
A university regulated as an Operator of Essential Services must comply with the security duties in Regulation 10, report incidents within 24 hours and 72 hours under Regulation 11, and send a copy of each notification to CSIRT. Where it provides data centre services it must also give information to its designated competent authority within 3 months under Regulation 8ZA. It must comply with information requests and inspections under Regulations 15 and 16 and have regard to guidance from its designated competent authority.
Does high-performance computing bring a university into CSRB scope?
Universities that operate or support high-performance computing (HPC) environments are among those most likely to fall within scope of the Cyber Security and Resilience Bill. Other indicators include managing research with implications for national resilience or security, processing sensitive student, staff or partner data at scale, and providing infrastructure to regulated sectors through collaboration.
What penalties do universities face under the CSRB?
Universities face a higher maximum penalty of the greater of £17,000,000 and 4% of turnover for serious Part 2 failures as an OES, RDSP or RMSP, and a standard maximum of the greater of £10,000,000 and 2% of turnover for administrative failures. Part 3 penalties do not exist yet; when regulations are made, Section 32(3) caps them at the greater of £17,000,000 and 10% of turnover. Contravening a Part 4 national security direction carries a maximum of £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues.
Need Help with University Cyber Security and Resilience Bill Compliance?
Our expert team helps universities and research institutions navigate multi-faceted Cyber Security and Resilience Bill requirements.