Don’t do SECURITY. Do business SECURELY.

Cyber Security and Resilience Bill passes the House of Commons

The Bill expanding the UK NIS regime has completed its Commons stages and moves to the House of Lords.

The Cyber Security and Resilience (Network and Information Systems) Bill completed its third reading in the House of Commons today and now moves to the House of Lords.

Reminder of what the Bill will do

  • Extend the NIS regime to relevant managed service providers and data centres.
  • Allow regulators to designate critical suppliers.
  • Require initial incident reports within 24 hours and full reports within 72 hours.
  • Increase maximum penalties, with turnover-based fines.

Royal Assent is expected later in 2026, with most of the detailed duties to follow in secondary legislation. IT and security consultancies and managed service providers with privileged access to client systems should begin scoping their obligations now, using the NCSC CAF as a guide.

Source: Cyber Security and Resilience (Network and Information Systems) Bill (UK Parliament)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights