Skip to content

UK Cyber Security and Resilience Bill

Proposed United Kingdom ยท next deadline Oct 26, 2026 (in 32 days)

Deadlines

DateWhat happens
Nov 12, 2025Introduced (Commons first reading)10 months ago
Jun 16, 2026Passes House of Commons3 months ago
Oct 26, 2026Lords report stage scheduledtentativein 32 days

Summaries for reference, not legal advice. Check the official text.

What it does

Updates the NIS Regulations 2018: brings managed service providers and data centres into scope, lets regulators designate critical suppliers, tightens incident reporting (initial notice within 24 hours, full report within 72 hours) and strengthens regulator powers. Substantive duties will follow via secondary legislation after Royal Assent.

Who it applies to
Operators of essential services and relevant digital service providers under NIS, plus (proposed) managed service providers, data centres above capacity thresholds, and designated critical suppliers.
Penalties
Proposed higher maximum penalties aligned with turnover-based fines; final figures depend on the enacted text (not verified).
Enforced by
Sector NIS competent authorities and the ICO (for digital services); DSIT policy lead
Official name
Cyber Security and Resilience (Network and Information Systems) Bill
Citation
Bill 4035 (HL Bill, 2026 session)
Topics
cybersecurity, breach-notification
Verified 2026-09-22 bills-api.parliament.uk compliancehub.wiki
Research notes

Not yet law as of 2026-09-22 (in House of Lords). Royal Assent expected late 2026 or early 2027; substantive obligations expected around 2028 via secondary legislation. 24h/72h reporting timeline is from the government's published policy, not the final text.

Related

Questions about UK Cyber Security and Resilience Bill
What are the UK Cyber Security and Resilience Bill compliance deadlines?
Nov 12, 2025: Introduced (Commons first reading). Jun 16, 2026: Passes House of Commons. Oct 26, 2026: Lords report stage scheduled (tentative).
Who does UK Cyber Security and Resilience Bill apply to?
Operators of essential services and relevant digital service providers under NIS, plus (proposed) managed service providers, data centres above capacity thresholds, and designated critical suppliers.
What are the penalties under UK Cyber Security and Resilience Bill?
Proposed higher maximum penalties aligned with turnover-based fines; final figures depend on the enacted text (not verified).

When the rules change: new data, privacy and AI laws and deadlines, the next morning.