What every business needs to know
Cyber security legislation in the UK is undergoing its biggest transformation since the introduction of the Network and Information Systems (NIS) Regulations in 2018.
The Cyber Security and Resilience (Network and Information Systems) Bill represents a significant evolution of the UK’s approach to protecting critical infrastructure and essential digital services from an increasingly sophisticated cyber threat landscape.
For many organisations, this legislation is far more than a regulatory update. It signals a shift from cyber security being viewed as an IT issue to becoming a board-level business responsibility with stronger regulatory oversight, increased reporting obligations, and significantly tougher enforcement powers.
Why is a new law needed?
The UK’s existing Network and Information Systems (NIS) Regulations 2018 were introduced following the EU’s original NIS Directive. At the time, they focused primarily on organisations delivering essential services, such as:
- Energy
- Water
- Transport
- Healthcare
- Digital infrastructure
- Certain digital service providers
While the regulations were appropriate in 2018, the cyber threat landscape has changed dramatically.
Today organisations face a must broader, ever-evolving threat landscape:
- Large-scale ransomware attacks
- Supply chain compromises
- State-sponsored cyber operations
- Cloud-first infrastructure
- Managed Service Provider (MSP) attacks
- Increasing reliance on third-party suppliers
Incidents such as the SolarWinds compromise, MOVEit attacks, attacks against NHS suppliers, and ransomware campaigns targeting critical infrastructure have demonstrated that attackers often exploit trusted suppliers rather than attacking their final targets directly.
The Government concluded that the existing legislation no longer provided sufficient protection for the UK’s increasingly interconnected digital economy. The new Bill therefore modernises the existing NIS framework while giving regulators much stronger powers to respond to emerging threats.
What is the cyber security and resilience bill?
The new Bill is legislation designed to strengthen the UK’s cyber resilience by expanding and modernising the existing NIS Regulations.
Rather than replacing the 2018 Regulations entirely, the Bill amends and significantly extends them.
The new objectives are to:
- Protect critical national infrastructure
- Improve cyber resilience across essential services
- Increase visibility of cyber incidents
- Strengthen supply chain security
- Improve government oversight
- Enable regulators to respond more quickly to emerging threats
- Increase accountability for organisations responsible for critical services
The legislation is intended to create a more proactive regulatory framework that focuses not simply on responding to cyber incidents, but on preventing them from occurring in the first place.
Which organisations will be affected?
One of the most significant changes brought about with the new regulation is the expansion of organisations that fall within scope.
The current NIS Regulations apply to a relatively limited number of operators of essential services and digital service providers. The new Bill significantly widens this scope.
Examples include:
- Managed Service Providers (MSPs)
- Data centre operators
- Critical suppliers supporting regulated organisations
- Additional digital infrastructure providers
- Organisations designated as critical to national resilience
This is particularly important because many cyber attacks now target suppliers rather than the organisations they ultimately intend to compromise.
This means that If your business provides outsourced IT, cloud services, managed security, hosting, networking, or infrastructure services to regulated organisations, there is a strong possibility that you could become subject to these new requirements.
The biggest changes introduced by the Bill
1. Stronger Incident Reporting
One of the headline changes is enhanced cyber incident reporting. Organisations will be expected to notify regulators much sooner following significant cyber incidents.
The intention is not simply regulatory compliance, but to improve national awareness of cyber threats so that intelligence can be shared across sectors before attacks spread further.
Businesses will therefore need:
- Clearly defined incident response procedures
- Well-practised reporting processes
- Accurate asset inventories
- Effective security monitoring
- The ability to rapidly assess the impact of an incident
Delayed reporting could itself become a regulatory breach.
Whilst the Bill does not prescribe a fixed fine specifically for late reporting, delayed reporting is treated as a failure to comply with a statutory reporting requirement, and the regulator has discretion to impose a penalty that is appropriate and proportionate, up to the applicable statutory maximum.
Under the new Bill:
- A significant cyber incident must be notified to the regulator and the NCSC with an initial notification within 24 hours of becoming aware of it.
- A full incident report must follow within 72 hours.
If an organisation fails to meet these reporting obligations, the regulator will consider factors such as:
- How late the report was.
- Whether the delay hindered the response to the incident.
- The seriousness of the underlying cyber incident.
- Whether the organisation has a history of non-compliance.
- Whether the organisation took prompt action to remedy the failure.
- Whether there were any reasonable mitigating circumstances
For breaches of information-gathering, reporting, or inspection requirements, the Bill provides for penalties of up to £10 million.
If, after being directed by the regulator to comply, an organisation continues not to meet its obligations, additional continuing penalties of up to £50,000 per day can apply for failures relating to information or inspection requirements.
2. Greater Supply Chain Accountability
Supply chain security becomes a much larger focus.
Organisations cannot simply secure their own networks – they must also understand the cyber risks introduced by suppliers and service providers.
This means businesses should expect to:
- Assess supplier cyber maturity
- Include cyber security requirements within contracts
- Monitor supplier security posture
- Review third-party risk regularly
- Ensure critical suppliers meet acceptable security standards
Cyber security questionnaires alone are unlikely to be considered sufficient in higher-risk environments.
The Cyber Security and Resilience Bill does not require organisations to obtain a SOC 2 or SOC 3 report. However, these reports are likely to become considerably more valuable as evidence that an organisation has appropriate cyber security controls in place.
One of the key requirements of the Bill is that organisations must demonstrate they have “appropriate and proportionate” security measures. As such, regulators may ask questions such as:
- How do you manage access to systems?
- How do you detect and respond to incidents?
- How do you manage third-party risk?
- How do you ensure systems remain available?
- What evidence do you have that your controls are operating effectively?
A SOC 2 Type II report provides independent assurance over many of these areas.
It evaluates controls against the Trust Services Criteria, including:
- Security
- Availability
- Processing Integrity
- Confidentiality
- Privacy
Unlike a certification, a Type II report assesses whether controls operated effectively over a period of time (typically 6–12 months), making it particularly useful as evidence of ongoing compliance.
If you’re an MSP providing services to regulated organisations, customers are increasingly likely to ask:
- Do you have Cyber Essentials Plus?
- Are you ISO 27001 certified?
- Can you provide a SOC 2 Type II report?
A SOC 2 report can significantly reduce the need for lengthy customer security questionnaires because an independent auditor has already assessed your control environment.
3. Increased regulatory powers
Regulators will receive considerably stronger powers.
These include greater authority to:
- Request information
- Investigate security practices
- Conduct inspections
- Require evidence of compliance
- Direct organisations to address identified weaknesses
The emphasis shifts from reactive enforcement after an incident towards proactive oversight.
Organisations should therefore expect increased scrutiny and more frequent engagement with regulators.
Who are the regulators?
The Bill retains the sector-based regulatory model established by the NIS Regulations rather than creating a single “Cyber Security Regulator”.
There are 12 competent authorities (regulators) responsible for supervising different sectors. The Bill strengthens their powers but does not replace them with a central regulator.
The main regulators include:
| Sector | Primary Regulator(s) |
| Energy | Department for Energy Security and Net Zero (DESNZ) and Ofgem |
| Drinking Water | Drinking Water Inspectorate |
| Health (England) | Department of Health and Social Care |
| Health (Scotland) | Scottish Government |
| Health (Wales) | Welsh Government |
| Transport (Aviation) | Civil Aviation Authority (CAA) |
| Transport (Maritime) | Maritime and Coastguard Agency (MCA) |
| Transport (Road) | Department for Transport |
| Transport (Rail) | Office of Rail and Road (ORR) |
| Digital Infrastructure | Ofcom |
| Digital Service Providers | Information Commissioner’s Office (ICO) |
| Northern Ireland sectors | Relevant Northern Ireland departments for devolved functions |
Remember that one of the biggest changes introduced by the Bill is that Managed Service Providers (MSPs) will now come into scope.
The Bill doesn’t create a brand-new MSP regulator. Instead, MSPs will become subject to the regulatory framework under the NIS regime, with the Secretary of State designating the appropriate regulatory authority through secondary legislation.
At present, the Government has not confirmed which regulator will oversee MSPs, although this is expected to be decided before the relevant provisions come into force
4. Improved government flexibility
As we know, technology changes rapidly – Far more rapidly than regulations do.
Rather than requiring entirely new legislation whenever the threat landscape evolves, the Bill gives government greater flexibility to update regulatory requirements through secondary legislation.
This means organisations should expect cyber security obligations to continue evolving over time rather than remaining static for another decade.
5. Stronger executive accountability
Although technical teams will still implement security controls, responsibility increasingly sits with an organisations senior leadership.
Company boards will need confidence that:
- Cyber risks are understood
- Appropriate investment has been made
- Security governance is effective
- Incident response plans are tested
- Supply chain risks are managed
Cyber security becomes an enterprise risk management issue rather than simply an IT responsibility.
What does this mean for businesses?
Many organisations already have security controls in place.
However, compliance will increasingly require businesses to demonstrate – not simply claim – that those controls are effective.
Businesses should expect increased emphasis on:
- Governance
- Risk management
- Security monitoring
- Incident response
- Business continuity
- Disaster recovery
- Supply chain management
- Documentation
- Evidence gathering
The ability to prove compliance will become almost as important as implementing the controls themselves.
How should businesses prepare?
At the time of writing (04/08/26) The Bill has not yet become law. It is progressing through Parliament and has not yet received Royal Assent. The Bill was introduced in November 2025 and has completed its Second Reading, with further Parliamentary scrutiny continuing.
Based on the current progress, the expectation is:
- Royal Assent: likely during the latter part of 2026, assuming there are no significant parliamentary delays.
- Commencement: the new requirements are not expected to take effect immediately. Instead, the Government has indicated that implementation will be phased, with different provisions being brought into force through secondary legislation over time. Some obligations may not be fully in force until 2027 or even 2028, depending on the area of the legislation
Although many implementation dates will be introduced through secondary legislation after Royal Assent, organisations should begin preparing now rather than waiting for legal deadlines.
Practical preparation should include:
Conduct a gap analysis
Compare your existing security programme against recognised frameworks such as:
- ISO/IEC 27001
- NIST Cybersecurity Framework
- Cyber Essentials Plus (where appropriate)
Identify areas requiring improvement before the regulators do.
Improve asset visibility
You cannot protect systems you do not know exist. Knowing what assets you have, what their criticality to the business is, and the risks associated with them are crucial to good cyber security.
Maintain an accurate inventory covering:
- Servers
- Cloud services
- User devices
- Network equipment
- Third-party services
- Critical applications
Review incident response plans
Businesses should ask themselves:
- Who declares an incident?
- Who contacts regulators?
- Who communicates with customers?
- How quickly can evidence be collected?
- Has the plan been tested?
Tabletop exercises (TTX) are becoming increasingly important. The NCSC have for a long time provided good examples of TTX’s via their Exercise in a box programme
Strengthen supply chain management
Organisations should conduct in-depth reviews of their supply chains:
- Supplier contracts
- Security requirements
- Right-to-audit clauses
- Incident notification requirements
- Business continuity expectations
Remember that a supplier’s security weaknesses can quickly become your own.
Improve logging and monitoring
Organisations should ensure they have sufficient visibility across their environment.
This may include:
- Security Information and Event Management (SIEM)
- Endpoint Detection and Response (EDR)
- Identity monitoring
- Vulnerability management
- Centralised logging
- Threat intelligence integration
Without appropriate monitoring, organisations may struggle to detect incidents quickly enough to satisfy reporting obligations.
Board-level engagement
Company executives should receive regular cyber risk reporting which covers:
- The current threat landscape
- Significant vulnerabilities
- Security maturity
- Compliance status
- Incident trends
- Third-party risks
Cyber resilience should become a standing board agenda item.
What happens if businesses fail to comply?
One of the most widely discussed aspects of the Bill is enforcement. The legislation strengthens regulators’ ability to investigate organisations and require improvements.
Where organisations fail to meet their legal obligations, regulators will have broader enforcement powers, including financial penalties.
As mentioned above, breaches of information-gathering, reporting, or inspection requirements, the Bill provides for penalties of up to £10 million.
If, after being directed by the regulator to comply, an organisation continues not to meet its obligations, additional continuing penalties of up to £50,000 per day can apply for failures relating to information or inspection requirements.
Government policy has also proposed penalties of up to £100,000 per day for failures to address regulatory requirements in certain circumstances, although the precise enforcement framework will depend on the final legislation and associated regulations.
Importantly, penalties are unlikely to be imposed simply because an organisation has suffered a cyber attack, as mentioned, many factors will be examined to determine if a penalty will be applicable
In other words, organisations are more likely to face regulatory action where poor governance, inadequate security practices or failures to comply have contributed to the incident.
Final thoughts
The Cyber Security and Resilience (Network and Information Systems) Bill represents one of the most significant changes to UK cyber security regulation in nearly a decade.
Its focus extends beyond preventing cyber attacks, and aims to improve the resilience of the UK’s critical services, strengthen national visibility of cyber threats, improve supply chain security and ensure organisations can continue delivering essential services even when incidents occur.
For businesses though, the message is clear: cyber security is no longer just a technical discipline – It is a legal, operational and governance requirement.
Organisations that invest early in robust security controls, effective governance, comprehensive incident response capabilities and supply chain assurance will be well positioned not only to meet the new regulatory requirements but also to reduce their exposure to an increasingly hostile cyber threat landscape.
Ultimately, compliance should not be viewed as a box-ticking exercise. The organisations that embrace the principles behind the legislation, such as building resilience, understanding risk, and preparing for inevitable cyber incidents – will be better equipped to protect their customers, maintain trust and ensure business continuity in an era where cyber attacks are no longer a question of if, but when.


