Cyber Security and Resilience (Network and Information Systems) Bill
Before the second chamber, dated , as of .
A sector security regimes rule binding public and private bodies.
- Obligation class
- Security, Reporting, Licensing
As of .
Where it has got to
The text described here is HL Bill 49 (as amended in Grand Committee). That print is HL Bill 49, published .
Locally, this stage is House of Lords committee stage, sittings on 1, 3 and , before report stage on .
The stage above is recorded at bills-api.parliament.uk.
The bill had its first reading in the House of Commons on in the 2024-26 session and had a carry-over motion on . It was reintroduced in the Commons on in the 2026-27 session, had its third reading there on and was brought to the House of Lords on as HL Bill 32. The Lords second reading was on , and the print reflects the amendments made in Grand Committee, which sat on 1, 3 and . Report stage in the Lords has a sitting date of and has not yet taken place.
What it requires
- This bill is before the House of Lords and has not been enacted, so it asks nothing of an app or organization yet; what follows is what it would require if enacted in this form.
- It would reach you if you operate an essential service in the United Kingdom, whether or not you are established there, a class the bill extends to a data center service of 1 megawatt or more of rated IT load (10 megawatts or more where the data center serves only the undertaking that owns or manages it) and to a load controller of 300 megawatts or more of potential electrical control that carries on activities for system-balancing purposes.
- It would also reach you where you provide a managed service, or an online marketplace, an online search engine or a cloud computing service, in the United Kingdom, whether or not you are established there, unless you are a micro or small enterprise, are designated a critical supplier for that service, or are subject to public authority oversight and do not derive more than half your income from activities of a commercial nature; providing a public electronic communications network or service does not by itself make you a digital or managed service provider.
- If you operate an essential service other than a data center, give your designated competent authority an initial notification of an incident that has affected or is affecting the operation or security of the systems you rely on, and whose impact in the United Kingdom has been, is or is likely to be significant, within 24 hours of first being aware of it, and a full notification within 72 hours of that time, in writing and in the form and manner the authority determines, sending a copy to the computer security incident response team (the CSIRT) at the same time (new regulation 11).
- If you operate a data center service, give the same 24-hour and 72-hour notifications of an incident that could have had, has had, is having or is likely to have a significant impact on the operation or security of the systems you rely on, on the continuity of the service, or any other significant impact in the United Kingdom (new regulation 11A); as soon as reasonably practicable after the full notification, take reasonable steps to establish which of your United Kingdom customers are likely to be adversely affected and notify them of the nature of the incident and why you consider them likely to be adversely affected (new regulation 11C).
- If you operate a data center service, give the designated competent authority your name, proper address, the names of your directors or partners and up-to-date contact details within three months of being deemed designated or of notice of your designation, and tell it of any change within seven days of the change taking effect (new regulation 8ZA).
- If you provide a relevant digital service, give the Information Commission an initial notification within 24 hours, and a full notification within 72 hours, of first being aware of an incident affecting the service whose impact in the United Kingdom has been, is or is likely to be significant, with a copy to the CSIRT; then, as soon as reasonably practicable after the full notification, notify your United Kingdom customers likely to be adversely affected (new regulations 12A and 12C).
- If you provide a relevant digital service, have regard to any relevant guidance from the Information Commission when carrying out your duties under regulation 12(1) (new regulation 12(2A)); notify the Information Commission of any change to your registered details within seven days of the change taking effect, those details now including the names of your directors or partners and which relevant digital services you provide (regulation 14, as amended); and, if your principal office is outside the United Kingdom, nominate a representative in the United Kingdom within three months (regulation 14A, as amended).
- If you provide a managed service, identify and take appropriate and proportionate measures to manage the risks to the network and information systems you rely on to provide managed services within the United Kingdom, ensuring (having regard to the state of the art) a level of security appropriate to the risk and preventing and minimizing the impact of incidents, and have regard to any relevant guidance from the Information Commission (new regulation 14B).
- If you provide a managed service, give the Information Commission an initial notification within 24 hours, and a full notification within 72 hours, of first being aware of an incident affecting the service whose impact in the United Kingdom has been, is or is likely to be significant, with a copy to the CSIRT; then, as soon as reasonably practicable after the full notification, notify your United Kingdom customers likely to be adversely affected (new regulations 14E and 14G).
- If you provide a managed service, register with the Information Commission your name, proper address, the names of your directors or partners and up-to-date contact details before the registration date, which is three months after section 14 of the Act comes into force or, if you first meet the definition later, three months after you first meet it; notify any change within seven days of it taking effect; and, if your principal office is outside the United Kingdom, nominate a representative in the United Kingdom within three months (new regulations 14C and 14D).
- If a designated competent authority or the Information Commission designates you as a critical supplier, notify it as soon as practicable, in writing and with supporting evidence, if you have reasonable grounds to believe it could not designate you (new regulation 14K).
- If a designated competent authority or the Information Commission gives you a written information notice, comply with it: the notice may be given to a person it regulates or to any other person, other than the single point of contact or the CSIRT, that appears to it likely to have the information or documents sought, whether or not that person is established in the United Kingdom, and, for a person it does not regulate, it may be a general request published for a category of persons; the power reaches information stored outside the United Kingdom (new regulations 15 and 15A).
- If a designated competent authority or the Information Commission regulates you, allow an inspection under regulation 16, which the bill extends to managed service providers, and pay any charge it imposes under its charging scheme and any invoice for its costs of exercising a function in relation to you (new regulations 20A and 20C).
- Comply with a direction the Secretary of State gives you under section 43 to do, or not to do, a particular thing specified in it, for example a restriction on the use of goods, services or facilities, the removal or modification of goods or facilities, or the appointment of a skilled person whose appointment the Secretary of State has approved in writing, and keep its existence and contents confidential where the Secretary of State so requires.
If you get it wrong
Private right of actionNo
Penalty structure
Clause 21(7) of the bill inserts regulation 18(8) and (9) into the NIS Regulations: the standard maximum amount is the greater of 10,000,000 pounds sterling and 2% of an undertaking's turnover inside and outside the United Kingdom (10,000,000 pounds sterling for any other person), and the higher maximum amount is the greater of 17,000,000 pounds sterling and 4% (17,000,000 pounds sterling for any other person). Regulation 18(11) places a failure to fulfil the security duties, to notify an incident, to notify customers, to comply with a direction, or to comply with an information notice on the higher maximum, and regulation 18(10) places failures to register, to provide contact details or nominate a representative, and to copy a notification to the CSIRT on the standard maximum. The higher maximum is the structure recorded here. A penalty provided for by regulations under section 29(1) could not exceed, for an undertaking, the greater of 17,000,000 pounds sterling and 10% of turnover (section 32(3)). A penalty for contravening a Part 4 direction would be capped at 17,000,000 pounds sterling or, once regulations on turnover are in force, for an undertaking at the greater of that sum and 10% of turnover, and a penalty set at a daily rate for a continuing contravention could be up to 100,000 pounds sterling a day; a penalty for failing to give information or allow an inspection under Part 4 would be capped at 10,000,000 pounds sterling, or 50,000 pounds sterling a day, and a penalty for breaching a non-disclosure requirement is capped in the same amounts (sections 49 and 52).
- Rule
- Higher of
- As of
- Currency
- GBP
- Fixed cap
- 17,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
The designated competent authorities for operators of essential services (the Office of Communications for the new data infrastructure subsector), the Information Commission for relevant digital service providers and relevant managed service providers, and the Secretary of State for Part 4 directions.
What this law does
This bill has not been enacted and binds no one. Its long title is 'A Bill to Make provision, including provision amending the Network and Information Systems Regulations 2018, about the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities'.
It was introduced in the House of Commons on . A carry-over motion for the bill was held in the House of Commons on . The bill was reintroduced in the House of Commons on . It was brought from the House of Commons to the House of Lords on . The House of Lords gave it a second reading on . The Lords sat in committee on 1, 3 and , and report stage in the Lords is set for .
The bill would amend the Network and Information Systems Regulations 2018 (the NIS Regulations) to add the provision of a data center service to the essential services in Schedule 2, with a threshold of 1 megawatt of rated IT load, or 10 megawatts where the data center is provided on an enterprise basis, solely for its owner's or manager's own undertaking. The Office of Communications would be the designated competent authority for the new data infrastructure subsector.
It would also add load control to the electricity subsector, with a threshold of a load controller that carries on activities for system-balancing purposes and has potential electrical control of 300 megawatts or more over the appliances it manages. The appliances counted are electric vehicles, charge points, electrical heating appliances, battery energy storage systems and virtual power plants.
A managed service would be a service provided under a contract for the ongoing management of a customer's information technology systems, by connecting to or otherwise obtaining access to network and information systems the customer relies on in connection with a business or other activity the customer carries on.
A person would be a relevant managed service provider only if it provides a managed service in the United Kingdom, whether or not it is established there, is not designated as a critical supplier for that service, is not a micro or small enterprise, and either is not subject to public authority oversight or derives more than half its income from activities of a commercial nature.
A relevant managed service provider would have to identify and take appropriate and proportionate measures to manage the risks posed to the security of the network and information systems it relies on to provide managed services within the United Kingdom. A relevant digital service would be an online marketplace, an online search engine or a cloud computing service.
A designated competent authority could designate a person as a critical supplier if the person supplies goods or services directly to an operator of essential services for which the authority is the designated competent authority and relies on network and information systems for that supply, and if the authority considers that an incident affecting those systems has the potential to cause disruption that is likely to have a significant impact on the economy or the day-to-day functioning of society in the whole or any part of the United Kingdom, unless new regulation 14I prevents the designation.
The Information Commission could designate a person as a critical supplier on the same conditions if the person supplies goods or services directly to a relevant digital service provider or a relevant managed service provider.
An operator of essential services other than a data center would have to give its designated competent authority an initial notification within 24 hours, and a full notification within 72 hours, of first being aware of a notifiable incident. A data center operator would have to notify a data center incident, which includes an incident that could have had a significant impact on the operation or security of the network and information systems it relies on.
A data center operator would have the same 24-hour and 72-hour deadlines. A relevant digital service provider would have to give the Information Commission an initial notification within 24 hours, and a full notification within 72 hours, of first being aware of a notifiable incident. A relevant managed service provider would have to give the Information Commission an initial notification within 24 hours, and a full notification within 72 hours, of first being aware of a notifiable incident.
The higher maximum penalty under the NIS Regulations would be the greater of 17,000,000 pounds sterling and 4% of an undertaking's turnover inside and outside the United Kingdom, or 17,000,000 pounds sterling for any other person. The higher maximum would apply to a failure to fulfil the security duties or to notify an incident.
The standard maximum penalty would be the greater of 10,000,000 pounds sterling and 2% of an undertaking's turnover inside and outside the United Kingdom, or 10,000,000 pounds sterling for any other person.
For the purposes of the information-gathering power, a person would be regulated by a designated competent authority if it is an operator of essential services in the authority's subsector or a critical supplier the authority designated, and by the Information Commission if it is a relevant digital service provider, a relevant managed service provider or a critical supplier the Commission designated.
Part 3 would let the Secretary of State make regulations imposing on regulated persons requirements to take specified action, to refrain from specified action and to report specified matters, and operators of essential services, relevant digital service providers, relevant managed service providers and critical suppliers would be treated as regulated persons.
A financial penalty provided for by regulations under Part 3 could not exceed, for an undertaking, the greater of 17,000,000 pounds sterling and 10% of its turnover inside and outside the United Kingdom.
Part 4 would let the Secretary of State give a regulated person a direction requiring it to do, or not to do, a particular thing where the Secretary of State considers that a security or operational compromise of a relevant network and information system, or the threat of one, gives rise to a risk to national security and that the direction is necessary and proportionate in the interests of national security.
A penalty for contravening such a direction would be capped at 17,000,000 pounds sterling for an undertaking, or at the greater of 17,000,000 pounds sterling and 10% of its turnover once regulations on turnover are in force.
Part 1, Chapters 1, 3 and 6 of Part 3, section 40 and Part 5 would come into force on the day the Act is passed, section 18(3) and (4), Chapter 2 of Part 3 and paragraphs 3, 4 and 14 of Schedule 2 two months later, and the other provisions, including the new duties in Part 2, on a day the Secretary of State appoints by regulations.
Section 12 on critical suppliers could come into force only on the day the first regulations under section 29(1) that amend the NIS Regulations to impose requirements on providers of activity-critical supplies come into force.
When LexLint raises it
When your app profile says your app runs an essential service or operates an app store.