The Cyber Security and Resilience Bill overhauls the UK’s NIS Regulations 2018, pulling managed service providers, data centres, and designated critical suppliers into regulatory scope. It introduces a 24-hour incident notification duty, near-miss reporting, and penalties reaching £17,000,000 or 4% of global turnover. Royal Assent is expected around the turn of 2027.
Table of Contents
ToggleWhat the Cyber Security and Resilience Bill Changes About UK Cyber Law
The Cyber Security and Resilience Bill, introduced as Bill 329, amends and substantially extends the Network and Information Systems Regulations 2018, which currently define which UK operators carry cyber incident duties. It is the largest reform of UK cyber regulation in more than a decade, announced in the July 2024 King’s Speech and introduced to the House of Commons on 12 November 2025.
The Bill is structured in 5 Parts across 61 sections and 2 Schedules. Part 2 amends the NIS Regulations to bring new categories of organization into scope. Part 3 gives the Secretary of State powers to set strategic priorities and make further regulations, which matters because the operative detail of this regime will arrive in secondary legislation rather than in the Act itself.
Four things change in practice: who is regulated, how fast incidents must be reported, what counts as a reportable event, and what non-compliance costs. Each is covered below. Organizations that already map controls against a recognized framework will find the direction familiar, and comparisons with the NIST Cybersecurity Framework are a reasonable starting point for gap analysis.
Where the Bill Has Reached in Parliament
Coverage of the Cyber Security and Resilience Bill written at its introduction is now substantially out of date, because the Bill has moved through the entire Commons process and most of the Lords since November 2025.
| Stage | Date |
|---|---|
| Announced in the King’s Speech | July 2024 |
| First reading, House of Commons (Bill 329) | 12 November 2025 |
| Second reading, Commons | 6 January 2026 |
| Committee stage, Commons | 3 to 24 February 2026 |
| Amended Bill published | 25 February 2026 |
| Report stage and third reading, Commons, passed without division | 16 June 2026 |
| Carried to the House of Lords as HL Bill 32 | 17 June 2026 |
| Second reading, Lords, cross-party support in principle | 14 July 2026 |
| Committee stage, Lords, begins | 1 September 2026 |
Royal Assent timing is the one point where sources genuinely disagree, and it is worth stating rather than papering over. Most commentary through 2026 has expected Royal Assent in late 2026. A government consultation published in June 2026 put it at spring 2027, subject to parliamentary progress. Either way, the gap that matters is the one after assent: substantive obligations are expected to take effect around 2028, delivered through secondary legislation following a government implementation consultation.
Peers have tabled 65 amendments to the Cyber Security and Resilience Bill at Lords stages, ranging from personal liability for company directors to an AI shutdown provision. Amendments of that kind rarely survive intact, but they indicate where enforcement expectations are drifting, and board-level accountability is the recurring theme.
Who Comes Into Scope That Was Not Before
The scope expansion is the provision most organizations will be caught by, because it reaches intermediaries that have never been regulated as infrastructure.
| Category | Bill provision | What it captures |
|---|---|---|
| Regulated managed service providers | Section 9 | MSPs and IT service providers supplying organizations in scope, including incident reporting and recovery plan duties |
| Data centres | Section 4 | Facilities meeting capacity thresholds set at 1MW and 10MW, with Ofcom made the sole regulator by a committee amendment |
| Load controllers | Section 6 | Operators controlling 300MW or more of electrical load |
| Critical suppliers | Section 12 | Suppliers a regulator designates as critical to an essential service, forced to meet minimum security standards |
| Statement of Strategic Priorities | Section 25 | Ministerial direction of regulator focus |
| Codes of Practice | Section 36 | The mechanism through which detailed expectations will be set |
The critical supplier designation deserves particular attention from organizations that do not consider themselves infrastructure. A company can be brought into scope by a regulator’s decision about its customer rather than by anything about its own sector, which means supply chain position, not industry classification, determines exposure. The wider pattern is set out in third-party data breaches and in this account of a breach reaching a brand through its vendor.
What the 24-Hour Reporting Clock Actually Demands
The Bill introduces a two-stage notification duty: an initial report within 24 hours of becoming aware of a significant incident, followed by a full report within 72 hours. The 72-hour element will be familiar to anyone who has handled a GDPR notification. The 24-hour element is new to most UK organizations, and it is the harder of the two.
Twenty-four hours is shorter than most organizations’ internal escalation path. The clock starts on awareness, not on confirmation, which removes the option of waiting for forensic certainty before telling a regulator. An organization that discovers an incident at 4pm on a Friday has until Saturday afternoon, and an escalation chain that depends on someone reading email on Monday has already failed.
Meeting it requires three things decided in advance: who is authorized to declare an incident reportable, what the minimum viable initial report contains, and how that decision gets made outside working hours. Organizations that have rehearsed against a defined process handle it; those treating notification as a legal step after technical resolution do not. Structuring that work is covered in NIST incident response and in people security and incident response.
Why Near-Miss Reporting Is the Hardest New Duty
Near-miss reporting duties extend notification beyond incidents that caused harm to events that could have. The policy logic is borrowed from aviation and industrial safety, where recording what nearly happened is the main source of preventive data.
The difficulty is cultural rather than technical. A near miss is, by definition, something that did not go wrong, which means nobody is forced to notice it and somebody usually has to admit they nearly made a mistake. Organizations that respond to reported errors with blame receive no near-miss reports at all, and then record a clean compliance position that reflects silence rather than safety.
An organization cannot build that reporting habit in the months before a duty commences. It takes sustained work to establish that reporting is rewarded, which is why the implementation gap running to 2028 is better understood as preparation time than as delay. The mechanics are set out in incident reporting culture.
What Non-Compliance Will Cost
The Bill introduces a two-tier penalty regime with turnover-linked maximums, reaching £17,000,000 or 4% of global turnover, whichever is higher. Turnover linkage is the significant design choice, because it scales the deterrent to the organization rather than capping it at a figure a large company can absorb.
Regulatory penalties are rarely the largest cost, and UK incidents have made that concrete. The 2024 Qilin ransomware attack on pathology provider Synnovis cost roughly £32,700,000 against company profits of £4,300,000 for 2023, disrupted services across London, and in June 2025 King’s College Hospital NHS Trust confirmed it contributed to a patient death. Sector-specific exposure of this kind is examined in cybersecurity in healthcare. Marks and Spencer’s 2025 incident carried estimated costs above £300,000,000, and the Co-op breach saw data on all 6,500,000 members stolen.
Those figures are the argument for treating the Bill as a resilience deadline rather than a compliance one. Human error remains the most common route in, as ransomware breaches caused by human error sets out.
Why the Reporting Clock Is a Workforce Problem First
A 24-hour statutory clock changes what an organization needs from its people, and this is the part legal summaries of the Bill consistently skip. The clock starts when the organization becomes aware. In most incidents, the organization becomes aware because a person noticed something and said so.
The NCSC’s Annual Review 2025, covering September 2024 to August 2025, recorded 1,727 tips resolved into 429 incidents, of which 204 were nationally significant, up from 89 the year before. Eighteen were categorized as highly significant, a rise of roughly 50% and the third consecutive annual increase. The NCSC’s own framing is that it now handles four nationally significant incidents a week. Detection at that volume is not achieved by a security operations centre alone.
The practical consequence is that the interval between an employee seeing something wrong and a responder receiving it becomes a regulated quantity. Threatcop’s TPIR compresses that interval: one-click reporting from email or WhatsApp delivers the message to an analyst with threat-level scoring attached, and its who-else insight shows immediately how many others received the same thing, which is often what turns a single report into a declared incident inside the first hour. Measuring the value of that capability is covered in incident response training ROI.
What to Do Before Royal Assent
The Cyber Security and Resilience Bill’s framework is settled even where its detail is not, and its obligations take longer to build than the notice period will allow. Mapping current controls against NIST CSF 2.0 is a reasonable way to find the gaps that incident reporting duties will expose.
- Establish whether you are in scope, including as a designated critical supplier to a customer who is, rather than assuming sector exclusion applies
- Map your supply chain in the other direction, identifying which of your providers would carry duties, since their failure becomes your incident
- Define the 24-hour decision, naming who declares an incident reportable and what the initial notification must contain
- Rehearse out-of-hours escalation, because the clock does not pause at weekends
- Start collecting near misses now, under an explicitly blameless process, so the duty commences against an existing habit
- Measure time from first human observation to analyst triage, which is the metric the reporting clock actually constrains
- Take the implementation consultation seriously, since the Codes of Practice under Section 36 will carry the operative expectations
Waiting for the final text of the Cyber Security and Resilience Bill is not a defensible position, and it is not a practical one either. Organizations that begin when the regulations land will have roughly a year of notice on obligations that take longer than a year to implement.
Build the Reporting Habit While You Still Have Time
The Bill gives UK organizations something unusual: a clearly signalled obligation with years of notice. The duties that are hardest to retrofit are the human ones, because a 24-hour clock and a near-miss duty both depend on people choosing to speak up quickly, and that choice is shaped over years rather than configured in a quarter.
Give your workforce a one-click reporting path and start measuring how long it takes a report to reach an analyst. That number is the one the statute will eventually be testing.
Frequently Asked Questions
What is the Cyber Security and Resilience Bill?
The Cyber Security and Resilience Bill is UK legislation amending the Network and Information Systems Regulations 2018, introduced to Parliament as Bill 329 on 12 November 2025. It expands regulatory scope to managed service providers, data centres, load controllers, and designated critical suppliers, introduces 24-hour incident notification and near-miss reporting, and creates turnover-linked penalties. It is the most significant reform of UK cyber regulation since 2018.
When will the Cyber Security and Resilience Bill become law?
The Bill cleared all Commons stages on 16 June 2026 and entered the House of Lords as HL Bill 32, with second reading on 14 July 2026 and committee stage beginning 1 September 2026. Royal Assent has been widely expected in late 2026, though a June 2026 government consultation indicated spring 2027 subject to parliamentary progress. Substantive obligations are expected to apply around 2028 through secondary legislation.
Who is in scope of the Cyber Security and Resilience Bill?
Existing operators of essential services and digital service providers remain in scope, joined by regulated managed service providers, data centres meeting capacity thresholds, load controllers at 300MW or higher, and suppliers designated critical by a regulator. The critical supplier route means an organization can be regulated because of who it supplies rather than what sector it operates in.
What are the penalties under the Cyber Security and Resilience Bill?
The Bill establishes a two-tier penalty regime with maximums reaching £17,000,000 or 4% of global turnover, whichever is higher. Turnover linkage means the ceiling scales with organization size rather than sitting at a fixed figure. Detailed enforcement mechanics are expected to be set through secondary legislation and Codes of Practice after Royal Assent.

Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
