{"id":15296,"date":"2026-09-14T15:14:56","date_gmt":"2026-09-14T09:44:56","guid":{"rendered":"https:\/\/threatcop.com\/blog\/?p=15296"},"modified":"2026-09-14T15:14:57","modified_gmt":"2026-09-14T09:44:57","slug":"cyber-security-resilience-bill","status":"publish","type":"post","link":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/","title":{"rendered":"UK Cyber Security and Resilience Bill: What Changes and When"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The Cyber Security and Resilience Bill overhauls the UK&#8217;s NIS Regulations 2018, pulling managed service providers, data centres, and designated critical suppliers into regulatory scope. It introduces a 24-hour incident notification duty, near-miss reporting, and penalties reaching \u00a317,000,000 or 4% of global turnover. Royal Assent is expected around the turn of 2027.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #414141;color:#414141\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #414141;color:#414141\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#What_the_Cyber_Security_and_Resilience_Bill_Changes_About_UK_Cyber_Law\" >What the Cyber Security and Resilience Bill Changes About UK Cyber Law<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#Where_the_Bill_Has_Reached_in_Parliament\" >Where the Bill Has Reached in Parliament<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#Who_Comes_Into_Scope_That_Was_Not_Before\" >Who Comes Into Scope That Was Not Before<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#What_the_24-Hour_Reporting_Clock_Actually_Demands\" >What the 24-Hour Reporting Clock Actually Demands<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#Why_Near-Miss_Reporting_Is_the_Hardest_New_Duty\" >Why Near-Miss Reporting Is the Hardest New Duty<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#What_Non-Compliance_Will_Cost\" >What Non-Compliance Will Cost<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#Why_the_Reporting_Clock_Is_a_Workforce_Problem_First\" >Why the Reporting Clock Is a Workforce Problem First<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#What_to_Do_Before_Royal_Assent\" >What to Do Before Royal Assent<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#Build_the_Reporting_Habit_While_You_Still_Have_Time\" >Build the Reporting Habit While You Still Have Time<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_the_Cyber_Security_and_Resilience_Bill_Changes_About_UK_Cyber_Law\"><\/span>What the Cyber Security and Resilience Bill Changes About UK Cyber Law<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Cyber Security and Resilience Bill, introduced as Bill 329, amends and substantially extends the Network and Information Systems Regulations 2018, which currently define which UK operators carry cyber incident duties. It is the largest reform of UK cyber regulation in more than a decade, announced in the July 2024 King&#8217;s Speech and introduced to the House of Commons on 12 November 2025.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Bill is structured in 5 Parts across 61 sections and 2 Schedules. Part 2 amends the NIS Regulations to bring new categories of organization into scope. Part 3 gives the Secretary of State powers to set strategic priorities and make further regulations, which matters because the operative detail of this regime will arrive in secondary legislation rather than in the Act itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Four things change in practice: who is regulated, how fast incidents must be reported, what counts as a reportable event, and what non-compliance costs. Each is covered below. Organizations that already map controls against a recognized framework will find the direction familiar, and comparisons with <a href=\"https:\/\/threatcop.com\/blog\/what-is-nist-cybersecurity-framework-csf\/\">the NIST Cybersecurity Framework<\/a> are a reasonable starting point for gap analysis.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_the_Bill_Has_Reached_in_Parliament\"><\/span>Where the Bill Has Reached in Parliament<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Coverage of the Cyber Security and Resilience Bill written at its introduction is now substantially out of date, because the Bill has moved through the entire Commons process and most of the Lords since November 2025.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Stage<\/th><th>Date<\/th><\/tr><\/thead><tbody><tr><td>Announced in the King&#8217;s Speech<\/td><td>July 2024<\/td><\/tr><tr><td>First reading, House of Commons (Bill 329)<\/td><td>12 November 2025<\/td><\/tr><tr><td>Second reading, Commons<\/td><td>6 January 2026<\/td><\/tr><tr><td>Committee stage, Commons<\/td><td>3 to 24 February 2026<\/td><\/tr><tr><td>Amended Bill published<\/td><td>25 February 2026<\/td><\/tr><tr><td>Report stage and third reading, Commons, passed without division<\/td><td>16 June 2026<\/td><\/tr><tr><td>Carried to the House of Lords as HL Bill 32<\/td><td>17 June 2026<\/td><\/tr><tr><td>Second reading, Lords, cross-party support in principle<\/td><td>14 July 2026<\/td><\/tr><tr><td>Committee stage, Lords, begins<\/td><td>1 September 2026<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Royal Assent timing is the one point where sources genuinely disagree, and it is worth stating rather than papering over. Most commentary through 2026 has expected Royal Assent in late 2026. A government consultation published in June 2026 put it at spring 2027, subject to parliamentary progress. Either way, the gap that matters is the one after assent: substantive obligations are expected to take effect around 2028, delivered through secondary legislation following a government implementation consultation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Peers have tabled 65 amendments to the Cyber Security and Resilience Bill at Lords stages, ranging from personal liability for company directors to an AI shutdown provision. Amendments of that kind rarely survive intact, but they indicate where enforcement expectations are drifting, and board-level accountability is the recurring theme.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Who_Comes_Into_Scope_That_Was_Not_Before\"><\/span>Who Comes Into Scope That Was Not Before<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The scope expansion is the provision most organizations will be caught by, because it reaches intermediaries that have never been regulated as infrastructure.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Category<\/th><th>Bill provision<\/th><th>What it captures<\/th><\/tr><\/thead><tbody><tr><td>Regulated managed service providers<\/td><td>Section 9<\/td><td>MSPs and IT service providers supplying organizations in scope, including incident reporting and recovery plan duties<\/td><\/tr><tr><td>Data centres<\/td><td>Section 4<\/td><td>Facilities meeting capacity thresholds set at 1MW and 10MW, with Ofcom made the sole regulator by a committee amendment<\/td><\/tr><tr><td>Load controllers<\/td><td>Section 6<\/td><td>Operators controlling 300MW or more of electrical load<\/td><\/tr><tr><td>Critical suppliers<\/td><td>Section 12<\/td><td>Suppliers a regulator designates as critical to an essential service, forced to meet minimum security standards<\/td><\/tr><tr><td>Statement of Strategic Priorities<\/td><td>Section 25<\/td><td>Ministerial direction of regulator focus<\/td><\/tr><tr><td>Codes of Practice<\/td><td>Section 36<\/td><td>The mechanism through which detailed expectations will be set<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The critical supplier designation deserves particular attention from organizations that do not consider themselves infrastructure. A company can be brought into scope by a regulator&#8217;s decision about its customer rather than by anything about its own sector, which means supply chain position, not industry classification, determines exposure. The wider pattern is set out in <a href=\"https:\/\/threatcop.com\/blog\/third-party-data-breaches\/\">third-party data breaches<\/a> and in this account of <a href=\"https:\/\/threatcop.com\/blog\/adidas-got-breached-through-a-vendor\/\">a breach reaching a brand through its vendor<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_the_24-Hour_Reporting_Clock_Actually_Demands\"><\/span>What the 24-Hour Reporting Clock Actually Demands<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Bill introduces a two-stage notification duty: an initial report within 24 hours of becoming aware of a significant incident, followed by a full report within 72 hours. The 72-hour element will be familiar to anyone who has handled a GDPR notification. The 24-hour element is new to most UK organizations, and it is the harder of the two.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Twenty-four hours is shorter than most organizations&#8217; internal escalation path. The clock starts on awareness, not on confirmation, which removes the option of waiting for forensic certainty before telling a regulator. An organization that discovers an incident at 4pm on a Friday has until Saturday afternoon, and an escalation chain that depends on someone reading email on Monday has already failed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Meeting it requires three things decided in advance: who is authorized to declare an incident reportable, what the minimum viable initial report contains, and how that decision gets made outside working hours. Organizations that have rehearsed against a defined process handle it; those treating notification as a legal step after technical resolution do not. Structuring that work is covered in <a href=\"https:\/\/threatcop.com\/blog\/nist-incident-response\/\">NIST incident response<\/a> and in <a href=\"https:\/\/threatcop.com\/blog\/integrating-people-security-into-incident-response-playbooks\/\">people security and incident response<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Near-Miss_Reporting_Is_the_Hardest_New_Duty\"><\/span>Why Near-Miss Reporting Is the Hardest New Duty<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Near-miss reporting duties extend notification beyond incidents that caused harm to events that could have. The policy logic is borrowed from aviation and industrial safety, where recording what nearly happened is the main source of preventive data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The difficulty is cultural rather than technical. A near miss is, by definition, something that did not go wrong, which means nobody is forced to notice it and somebody usually has to admit they nearly made a mistake. Organizations that respond to reported errors with blame receive no near-miss reports at all, and then record a clean compliance position that reflects silence rather than safety.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An organization cannot build that reporting habit in the months before a duty commences. It takes sustained work to establish that reporting is rewarded, which is why the implementation gap running to 2028 is better understood as preparation time than as delay. The mechanics are set out in <a href=\"https:\/\/threatcop.com\/blog\/how-incident-reporting-culture-prevents-greater-damage\/\">incident reporting culture<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Non-Compliance_Will_Cost\"><\/span>What Non-Compliance Will Cost<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Bill introduces a two-tier penalty regime with turnover-linked maximums, reaching \u00a317,000,000 or 4% of global turnover, whichever is higher. Turnover linkage is the significant design choice, because it scales the deterrent to the organization rather than capping it at a figure a large company can absorb.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regulatory penalties are rarely the largest cost, and UK incidents have made that concrete. The 2024 Qilin ransomware attack on pathology provider Synnovis cost roughly \u00a332,700,000 against company profits of \u00a34,300,000 for 2023, disrupted services across London, and in June 2025 King&#8217;s College Hospital NHS Trust confirmed it contributed to a patient death. Sector-specific exposure of this kind is examined in <a href=\"https:\/\/threatcop.com\/blog\/cybersecurity-in-healthcare\/\">cybersecurity in healthcare<\/a>. Marks and Spencer&#8217;s 2025 incident carried estimated costs above \u00a3300,000,000, and the Co-op breach saw data on all 6,500,000 members stolen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Those figures are the argument for treating the Bill as a resilience deadline rather than a compliance one. Human error remains the most common route in, as <a href=\"https:\/\/threatcop.com\/blog\/ransomware-breaches-caused-by-human-error\/\">ransomware breaches caused by human error<\/a> sets out.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_the_Reporting_Clock_Is_a_Workforce_Problem_First\"><\/span>Why the Reporting Clock Is a Workforce Problem First<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A 24-hour statutory clock changes what an organization needs from its people, and this is the part legal summaries of the Bill consistently skip. The clock starts when the organization becomes aware. In most incidents, the organization becomes aware because a person noticed something and said so.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.ncsc.gov.uk\/files\/ncsc-annual-review-2025.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">NCSC&#8217;s Annual Review 2025<\/a>, covering September 2024 to August 2025, recorded 1,727 tips resolved into 429 incidents, of which 204 were nationally significant, up from 89 the year before. Eighteen were categorized as highly significant, a rise of roughly 50% and the third consecutive annual increase. The NCSC&#8217;s own framing is that it now handles four nationally significant incidents a week. Detection at that volume is not achieved by a security operations centre alone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The practical consequence is that the interval between an employee seeing something wrong and a responder receiving it becomes a regulated quantity. Threatcop&#8217;s TPIR compresses that interval: one-click reporting from email or WhatsApp delivers the message to an analyst with threat-level scoring attached, and its who-else insight shows immediately how many others received the same thing, which is often what turns a single report into a declared incident inside the first hour. Measuring the value of that capability is covered in <a href=\"https:\/\/threatcop.com\/blog\/incident-response-training-roi\/\">incident response training ROI<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_Do_Before_Royal_Assent\"><\/span>What to Do Before Royal Assent<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Cyber Security and Resilience Bill&#8217;s framework is settled even where its detail is not, and its obligations take longer to build than the notice period will allow. Mapping current controls against <a href=\"https:\/\/threatcop.com\/blog\/nist-csf-2-0\/\">NIST CSF 2.0<\/a> is a reasonable way to find the gaps that incident reporting duties will expose.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Establish whether you are in scope<\/strong>, including as a designated critical supplier to a customer who is, rather than assuming sector exclusion applies<\/li>\n\n\n\n<li><strong>Map your supply chain in the other direction<\/strong>, identifying which of your providers would carry duties, since their failure becomes your incident<\/li>\n\n\n\n<li><strong>Define the 24-hour decision<\/strong>, naming who declares an incident reportable and what the initial notification must contain<\/li>\n\n\n\n<li><strong>Rehearse out-of-hours escalation<\/strong>, because the clock does not pause at weekends<\/li>\n\n\n\n<li><strong>Start collecting near misses now<\/strong>, under an explicitly blameless process, so the duty commences against an existing habit<\/li>\n\n\n\n<li><strong>Measure time from first human observation to analyst triage<\/strong>, which is the metric the reporting clock actually constrains<\/li>\n\n\n\n<li><strong>Take the implementation consultation seriously<\/strong>, since the Codes of Practice under Section 36 will carry the operative expectations<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Waiting for the final text of the Cyber Security and Resilience Bill is not a defensible position, and it is not a practical one either. Organizations that begin when the regulations land will have roughly a year of notice on obligations that take longer than a year to implement.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Build_the_Reporting_Habit_While_You_Still_Have_Time\"><\/span>Build the Reporting Habit While You Still Have Time<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Bill gives UK organizations something unusual: a clearly signalled obligation with years of notice. The duties that are hardest to retrofit are the human ones, because a 24-hour clock and a near-miss duty both depend on people choosing to speak up quickly, and that choice is shaped over years rather than configured in a quarter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/threatcop.com\/threatcop-phishing-incident-response\">Give your workforce a one-click reporting path<\/a> and start measuring how long it takes a report to reach an analyst. That number is the one the statute will eventually be testing.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\t\t<div class=\"sp-easy-accordion-block sp-eab-regular-accordion alignwide\"\n\t\t\t\t>\n\t\t\t<div class=\"sp-eab-wrapper sp-eab-vertical-accordion sp-eab-f1ace71dc447\">\n\t\t\t\t\t\t\t\t<div class='sp-eab-accordion sp-eab-mode-vertical sp-eab-vertical-one sp-d-flex' data-accordion-settings=\"{&quot;mode&quot;:&quot;vertical&quot;,&quot;activeEvent&quot;:&quot;click&quot;,&quot;defaultAccordionOpen&quot;:&quot;first-item&quot;,&quot;selectedItemOpen&quot;:0,&quot;openMultiItemAtaTime&quot;:false,&quot;scrollToTopOnLoad&quot;:false,&quot;scrollToTopOnClick&quot;:false,&quot;accordionItemToUrl&quot;:false,&quot;animationEffect&quot;:false,&quot;applyAccessibility&quot;:true}\">\n        \t    \t\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-1794a07b3e17\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-1dc447\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-1dc447'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat is the Cyber Security and Resilience Bill?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-1dc447'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">The Cyber Security and Resilience Bill is UK legislation amending the Network and Information Systems Regulations 2018, introduced to Parliament as Bill 329 on 12 November 2025. It expands regulatory scope to managed service providers, data centres, load controllers, and designated critical suppliers, introduces 24-hour incident notification and near-miss reporting, and creates turnover-linked penalties. It is the most significant reform of UK cyber regulation since 2018.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-4c17510e3f1b\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-1dc447\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-1dc447'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhen will the Cyber Security and Resilience Bill become law?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-1dc447'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">The Bill cleared all Commons stages on 16 June 2026 and entered the House of Lords as HL Bill 32, with second reading on 14 July 2026 and committee stage beginning 1 September 2026. Royal Assent has been widely expected in late 2026, though a June 2026 government consultation indicated spring 2027 subject to parliamentary progress. Substantive obligations are expected to apply around 2028 through secondary legislation.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-87f216008188\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-1dc447\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-1dc447'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWho is in scope of the Cyber Security and Resilience Bill?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-1dc447'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Existing operators of essential services and digital service providers remain in scope, joined by regulated managed service providers, data centres meeting capacity thresholds, load controllers at 300MW or higher, and suppliers designated critical by a regulator. The critical supplier route means an organization can be regulated because of who it supplies rather than what sector it operates in.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-9a267aeffe6e\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-1dc447\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-1dc447'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat are the penalties under the Cyber Security and Resilience Bill?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-1dc447'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">The Bill establishes a two-tier penalty regime with maximums reaching \u00a317,000,000 or 4% of global turnover, whichever is higher. Turnover linkage means the ceiling scales with organization size rather than sitting at a fixed figure. Detailed enforcement mechanics are expected to be set through secondary legislation and Codes of Practice after Royal Assent.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>The Cyber Security and Resilience Bill overhauls the UK&#8217;s NIS Regulations 2018, pulling managed service providers, data centres, and designated critical suppliers into regulatory scope. It introduces a 24-hour incident notification duty, near-miss reporting, and penalties reaching \u00a317,000,000 or 4% of global turnover. Royal Assent is expected around the turn of 2027. What the Cyber [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":15306,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[42],"tags":[],"class_list":["post-15296","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-awareness"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cyber Security and Resilience Bill: What Changes and When<\/title>\n<meta name=\"description\" content=\"The Cyber Security and Resilience Bill reaches Lords committee stage. See who comes into scope, the 24-hour reporting clock, penalties, and what to do now.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyber Security and Resilience Bill: What Changes and When\" \/>\n<meta property=\"og:description\" content=\"The Cyber Security and Resilience Bill reaches Lords committee stage. See who comes into scope, the 24-hour reporting clock, penalties, and what to do now.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/\" \/>\n<meta property=\"og:site_name\" content=\"Threatcop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-14T09:44:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-14T09:44:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Blog-Banner-1.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Nikunj Rakesh\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatcop\" \/>\n<meta name=\"twitter:site\" content=\"@threatcop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nikunj Rakesh\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/\"},\"author\":{\"name\":\"Nikunj Rakesh\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/d931534f0bd46db3dcf54b9313f587db\"},\"headline\":\"UK Cyber Security and Resilience Bill: What Changes and When\",\"datePublished\":\"2026-09-14T09:44:56+00:00\",\"dateModified\":\"2026-09-14T09:44:57+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/\"},\"wordCount\":1956,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Blog-Banner-1.webp\",\"articleSection\":[\"Cybersecurity Awareness\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/\",\"name\":\"Cyber Security and Resilience Bill: What Changes and When\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Blog-Banner-1.webp\",\"datePublished\":\"2026-09-14T09:44:56+00:00\",\"dateModified\":\"2026-09-14T09:44:57+00:00\",\"description\":\"The Cyber Security and Resilience Bill reaches Lords committee stage. See who comes into scope, the 24-hour reporting clock, penalties, and what to do now.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/#primaryimage\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Blog-Banner-1.webp\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Blog-Banner-1.webp\",\"width\":1280,\"height\":720,\"caption\":\"UK Cyber Security and Resilience Bill\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/cyber-security-resilience-bill\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"UK Cyber Security and Resilience Bill: What Changes and When\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"name\":\"Threatcop\",\"description\":\"Cybersecurity Blogs, News, Updates, and Articles\",\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\",\"name\":\"Threatcop\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"width\":432,\"height\":102,\"caption\":\"Threatcop\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/Threatcop\\\/100083109892339\\\/\",\"https:\\\/\\\/x.com\\\/threatcop\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/threatcop\\\/\",\"https:\\\/\\\/www.instagram.com\\\/threatcop_official\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/d931534f0bd46db3dcf54b9313f587db\",\"name\":\"Nikunj Rakesh\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/litespeed\\\/avatar\\\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789018822\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/litespeed\\\/avatar\\\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789018822\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/litespeed\\\/avatar\\\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789018822\",\"caption\":\"Nikunj Rakesh\"},\"description\":\"Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.\",\"sameAs\":[\"https:\\\/\\\/threatcop.com\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nikunj-rakesh-579a87129\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cyber Security and Resilience Bill: What Changes and When","description":"The Cyber Security and Resilience Bill reaches Lords committee stage. See who comes into scope, the 24-hour reporting clock, penalties, and what to do now.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/","og_locale":"en_US","og_type":"article","og_title":"Cyber Security and Resilience Bill: What Changes and When","og_description":"The Cyber Security and Resilience Bill reaches Lords committee stage. See who comes into scope, the 24-hour reporting clock, penalties, and what to do now.","og_url":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/","og_site_name":"Threatcop","article_publisher":"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","article_published_time":"2026-09-14T09:44:56+00:00","article_modified_time":"2026-09-14T09:44:57+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Blog-Banner-1.webp","type":"image\/webp"}],"author":"Nikunj Rakesh","twitter_card":"summary_large_image","twitter_creator":"@threatcop","twitter_site":"@threatcop","twitter_misc":{"Written by":"Nikunj Rakesh","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#article","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/"},"author":{"name":"Nikunj Rakesh","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/d931534f0bd46db3dcf54b9313f587db"},"headline":"UK Cyber Security and Resilience Bill: What Changes and When","datePublished":"2026-09-14T09:44:56+00:00","dateModified":"2026-09-14T09:44:57+00:00","mainEntityOfPage":{"@id":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/"},"wordCount":1956,"commentCount":0,"publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"image":{"@id":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Blog-Banner-1.webp","articleSection":["Cybersecurity Awareness"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/","url":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/","name":"Cyber Security and Resilience Bill: What Changes and When","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#primaryimage"},"image":{"@id":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Blog-Banner-1.webp","datePublished":"2026-09-14T09:44:56+00:00","dateModified":"2026-09-14T09:44:57+00:00","description":"The Cyber Security and Resilience Bill reaches Lords committee stage. See who comes into scope, the 24-hour reporting clock, penalties, and what to do now.","breadcrumb":{"@id":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#primaryimage","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Blog-Banner-1.webp","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Blog-Banner-1.webp","width":1280,"height":720,"caption":"UK Cyber Security and Resilience Bill"},{"@type":"BreadcrumbList","@id":"https:\/\/threatcop.com\/blog\/cyber-security-resilience-bill\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatcop.com\/blog\/"},{"@type":"ListItem","position":2,"name":"UK Cyber Security and Resilience Bill: What Changes and When"}]},{"@type":"WebSite","@id":"https:\/\/threatcop.com\/blog\/#website","url":"https:\/\/threatcop.com\/blog\/","name":"Threatcop","description":"Cybersecurity Blogs, News, Updates, and Articles","publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatcop.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/threatcop.com\/blog\/#organization","name":"Threatcop","url":"https:\/\/threatcop.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","width":432,"height":102,"caption":"Threatcop"},"image":{"@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","https:\/\/x.com\/threatcop","https:\/\/www.linkedin.com\/company\/threatcop\/","https:\/\/www.instagram.com\/threatcop_official\/"]},{"@type":"Person","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/d931534f0bd46db3dcf54b9313f587db","name":"Nikunj Rakesh","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/wp-content\/litespeed\/avatar\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789018822","url":"https:\/\/threatcop.com\/blog\/wp-content\/litespeed\/avatar\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789018822","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/litespeed\/avatar\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789018822","caption":"Nikunj Rakesh"},"description":"Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.","sameAs":["https:\/\/threatcop.com\/","https:\/\/www.linkedin.com\/in\/nikunj-rakesh-579a87129"]}]}},"_links":{"self":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/comments?post=15296"}],"version-history":[{"count":1,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15296\/revisions"}],"predecessor-version":[{"id":15304,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15296\/revisions\/15304"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media\/15306"}],"wp:attachment":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media?parent=15296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/categories?post=15296"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/tags?post=15296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}