The UK’s Cyber Security and Resilience Bill: what it means for your organisation
Cyber threats are evolving faster than ever.
In the year to September 2025, the National Cyber Security Centre (NCSC) managed 429 cyber incidents, almost half of which were classified as nationally significant. That’s more than double the previous year. Meanwhile, cyber attacks are estimated to cost UK businesses£14.7 billion annually.
The UK remains one of Europe’s most targeted countries for cyber crime. In response, the government is introducing the Cyber Security and Resilience (Network and Information Systems) Bill, the most significant update to UK cyber regulation in nearly a decade.
The Bill passed through the House of Commons in June 2026 and is currently progressing through the House of Lords, with Royal Assent expected later this year.
For many organisations, this isn’t just another compliance exercise. It represents a shift in how cyber resilience is managed, governed and enforced across the UK economy.
Why is the law changing?
The current Network and Information Systems (NIS) Regulations 2018 provided an important foundation for cyber resilience. However, the threat landscape has changed significantly since then.
Attackers increasingly target managed service providers (MSPs), technology partners and supply chains as a route into larger organisations and critical services. As a result, cyber resilience can no longer be viewed solely through the lens of your own systems.
The new Bill reflects this reality. It expands the range of organisations covered by regulation, introduces tougher reporting requirements and gives regulators stronger enforcement powers.
In short, organisations will be expected to identify cyber risks earlier, respond faster and take greater responsibility for risks throughout their supplier ecosystem.
Could your organisation be affected?
If your organisation relies on critical digital infrastructure, provides technology services or supplies regulated businesses, there is a strong chance the new requirements will affect you in some way.
Organisations already in scope
- Essential service operators, including organisations in energy transport, health, drinking water and digital infrastructure.
- Digital service providers, including cloud computing providers, online marketplaces and search engines.
Organisations newly coming into scope
- Managed service providers (MSPs). Medium and large MSPs will be regulated for the first time. This includes organisations delivering services such as ongoing IT support, helpdesk services and managed security services. The Information Commissioner’s Office (ICO) is expected to act as the regulator.
- Data centres. Data centres with a capacity of 1MW or above will be classified as essential services and regulated by Ofcom.
- Large load controllers. Organisations managing electrical demand at scale, including those supporting smart technologies such as electric vehicle charging infrastructure.
- Designated critical suppliers. Organisations can be brought into scope regardless of sector or size where government determines that disruption could have significant national impact.
Not directly regulated, but still affected
Even if your organisation is not directly regulated, the Bill could still have significant consequences.
- SMEs supplying regulated organisations. Expect increased customer scrutiny. Demonstrating cyber resilience is likely to become a commercial requirement, with customers seeking evidence through certification, assessments and contractual obligations.
- UK organisations operating in the EU. While the Bill broadly aligns with the EU’s NIS2 Directive, there are important differences. Organisations operating across both jurisdictions should prepare for dual compliance requirements.
What are the biggest changes?
Faster incident reporting
Organisations will be required to:
- Submit an initial notification within 24 hours
- Submit a fuller report within 72 hours
- Share incident information with the NCSC
Importantly, reporting obligations extend beyond incidents that have already caused disruption. Significant cyber intrusions and ransomware events may also need to be reported.
Greater transparency for customers
Data centres, digital service providers and MSPs will be required to notify affected customers following significant cyber incidents.
Supply chain accountability
Organisations will be expected to understand, assess and manage cyber risks across their supplier networks, not just within their own operations.
Stronger enforcement powers
The Bill introduces a two-tier penalty framework:
- Up to £10 million or 2 per cent of global annual turnover for less serious breaches
- Up to £17 million or 4 per cent of global annual turnover for more serious failures, including failures to report incidents or meet security obligations
- Ongoing penalties of up to £100,000 per day for continued non-compliance
For larger organisations, turnover-based fines could significantly exceed the headline figures.
Phased implementation
Some measures are expected to take effect shortly after Royal Assent. Others, including new requirements for MSPs, data centres and designated critical suppliers, will be introduced through secondary legislation.
Five practical steps to take now
Waiting for final implementation dates could leave you on the back foot. Taking action now will make future compliance significantly easier.
1. Confirm whether you’re in scope
The scope of regulation is expanding. MSPs, data centres and organisations supporting regulated sectors should assess their position now.
2. Review your supply chain
Map critical suppliers and understand where cyber dependencies exist. Equally, consider what evidence of resilience your customers may soon expect from you.
3. Test your incident response capability
Could you identify, assess and report a material cyber incident within 24 hours?
Many organisations struggle to meet that timeframe. Tabletop exercises can help expose weaknesses before a real incident occurs.
4. Strengthen your cyber credentials
Frameworks such as Cyber Essentials and ISO 27001 provide a strong foundation. They can also help demonstrate diligence to regulators, customers and business partners.
5. Put cyber resilience on the board agenda
Cyber risk is no longer solely an IT concern.
The Bill reinforces expectations around governance, oversight and accountability. Boards should be confident they understand their organisation’s cyber risk exposure and response arrangements.
Don’t wait for the legislation to take effect
Although implementation will be phased, the direction of travel is already clear.
Organisations that start preparing now will be in a much stronger position than those waiting for regulatory deadlines to arrive.
A practical gap analysis can help identify areas requiring attention, whether that’s governance, reporting processes, supplier oversight or incident response capability. Addressing these issues incrementally is typically more effective, less disruptive and less costly than a last-minute compliance programme.
Just as importantly, improving cyber resilience is about more than avoiding regulatory penalties. It’s about protecting operations, supporting customers and building confidence in an increasingly complex threat landscape.
