The existing Network and Information Systems (NIS) Regulations 2018 (‘NIS Regulations’) apply to certain operators of essential services in energy, transport, health, drinking water and digital infrastructure. They also apply to qualifying providers of online marketplaces, online search engines and cloud computing services.
The Cyber Security and Resilience (Network and Information Systems) Bill (‘the Bill’) will reform and add to the existing NIS Regulations. It will bring additional organisations within scope, strengthen the effectiveness of regulators, and enable the government to make changes to the regime in response to evolving or imminent threats.
At the time of writing, the Bill has completed its House of Commons stages and is progressing through the House of Lords. It is not yet law and may still be amended.
Why are the NIS Regulations being updated?
Essential and digital services increasingly depend on interconnected technology, outsourced services and infrastructure, and third-party providers. An incident affecting one provider can disrupt several customers and the services they deliver.
For example, the 2020 SolarWinds compromise was a sophisticated supply chain attack in which malicious code was distributed through a legitimate software update, giving attackers access to some customers’ systems before the activity was detected.
In 2021, attackers exploited vulnerabilities in Kaseya software used by managed service providers to manage customers’ computers remotely. This enabled ransomware to reach customers downstream, with an estimated 800 to 1,500 organisations compromised. The incident illustrates the potential “one-to-many” impact of an attack involving a managed service provider.
A June 2024 ransomware attack on Synnovis, a company providing blood-testing and other laboratory services to NHS organisations in London, significantly reduced the number of tests it could process and report. More than 11,000 outpatient appointments and planned procedures were postponed. As affected hospitals could not match patients’ blood as frequently as usual, they needed more O-positive and O-negative blood, prompting an urgent appeal for donors.
These incidents show how the compromise of one provider or product can affect multiple organisations and essential services. The Bill is intended to address gaps in the existing NIS Regulations and enable the regulatory regime to respond more readily as technologies, dependencies and cyber threats change.
How did we get here and what happens next?
The NIS Regulations came into force in 2018. Following a government review in 2020, some amendments were made to improve how the Regulations operated. Further review and public consultation followed, and in 2022 the government confirmed that it intended to pursue broader reforms to the Regulations.
The Cyber Security and Resilience Bill was subsequently announced in the July 2024 King’s Speech and introduced to Parliament on 12 November 2025. It has completed its House of Commons stages and received its second reading in the House of Lords on 14 July 2026. The Bill is scheduled to begin its House of Lords committee stage on 01 September 2026, when it will be examined line by line and amendments may be proposed.
The Bill must complete its remaining parliamentary stages before it can receive Royal Assent and become an Act of Parliament. A June 2026 government consultation states that Royal Assent is expected in spring 2027, subject to parliamentary progress.
Not every provision would take effect as soon as the Bill became law. Under the Bill’s current wording, some would commence on Royal Assent, others two months later, and the remaining provisions would come into force on dates appointed by the government through regulations. Further consultation and secondary legislation will also be needed for some aspects of the new regime. There is therefore no single confirmed implementation date for all the proposed changes.
The latest position can be checked on the UK Parliament Bill page.
Who is currently in scope and who could be added?
The NIS Regulations currently apply to:
- certain operators of essential services in energy, transport, health, drinking water and digital infrastructure; and
- qualifying providers of online marketplaces, online search engines and cloud computing services.
The Bill would update the requirements applying to existing regulated categories and extend the Regulations to relevant managed service providers, operators of data centres meeting specified thresholds, and load controllers with the potential to control at least 300 MW of electrical load. Regulators would also be able to designate certain direct suppliers to regulated organisations as critical where an incident affecting the supplier’s network and information systems could cause disruption likely to have a significant effect on the economy or the day-to-day functioning of society.
Managed service providers
Medium and large providers meeting the proposed definition of a relevant managed service provider would be brought within scope of the NIS Regulations. Managed service providers often have trusted access to customers’ IT systems, meaning an incident affecting one provider can affect multiple customers.
The definition covers services provided under contract that involve the ongoing management of a customer’s IT systems. The service must be provided by the provider, or someone acting on its behalf, connecting to or otherwise obtaining access to network and information systems relied on by the customer. This could include ongoing IT support, infrastructure or application management, managed security services and the management of cloud environments.
Small and micro managed service providers would be excluded from this category. However, they could potentially be designated as critical suppliers if they supplied a regulated organisation directly and met the conditions for designation.
The Information Commission would regulate relevant managed service providers. Further information is available in the government’s managed service provider factsheet.
Data centres
The Bill would bring operators of data centres meeting specified capacity thresholds within the NIS Regulations by treating data centre services as essential services. Data centres host systems and information used by public services and businesses, meaning an outage or security incident can affect multiple organisations and services.
Different thresholds would apply depending on how the data centre is used. A data centre serving other organisations would be in scope where the maximum power available to operate its IT equipment was at least 1 MW. A data centre used solely for the IT needs of the organisation that owns or manages it would be in scope at 10 MW or above.
Ofcom will serve as the operational regulator. The proposed arrangements are explained in the data centre factsheet.
Large load controllers
Large load controllers use digital systems to coordinate electricity use across networks of connected equipment, such as electric vehicle chargers and battery storage systems. By sending control signals to this equipment, they can change when electricity is drawn from or supplied to the grid, helping to manage demand across the electricity network.
The Bill would treat load control as an essential service and bring organisations within scope where they have the potential to control at least 300 MW of electrical load to and from relevant energy smart appliances. The requirements are aimed at organisations exercising large-scale control.
The Department for Energy Security and Net Zero and Ofgem would act as joint regulators. Further information is available in the large load controller factsheet.
Designated critical suppliers
A regulator could designate a supplier that provides goods or services directly to a regulated organisation where an incident affecting the supplier’s network and information systems could disrupt essential, digital or managed services and significantly affect the economy or the day-to-day functioning of society.
The regulator would need to assess the risks and formally designate the supplier. In making that decision, it would consider whether the goods or services could realistically be obtained from another source and whether the risks could be managed adequately through duties placed on the regulated customer or through other regulatory oversight.
The supplier would be consulted before designation. The proposed process is explained in the government’s critical supplier factsheet.
What would being within scope mean?
The Bill would amend the existing NIS Regulations rather than create a separate regulatory regime. Newly regulated organisations would need to comply with the requirements applying to their category when the relevant provisions came into force. Organisations already regulated would need to adapt to the amended requirements as they came into force.
Depending on the organisation, requirements could include identifying and taking appropriate and proportionate measures to manage risks posed to the security of the network and information systems relied on to provide the regulated service, registering or providing information to the regulator, and reporting significant incidents.
The government also intends to clarify, through consultation and secondary legislation, how regulated organisations should manage cyber risks arising through their supply chains. Measures could include contractual security requirements, security checks and continuity plans, as explained in the government’s futureproofing factsheet.
The Bill would introduce a two-stage reporting process for operators of essential services and relevant digital and managed service providers. An initial notification would be required within 24 hours of becoming aware that a reportable incident had occurred or was occurring, followed by a fuller notification within 72 hours of that awareness. The National Cyber Security Centre (NCSC) would receive the notifications at the same time as the regulator.
For operators of essential services other than data centres, and for relevant digital and managed service providers, reporting would extend to incidents that had adversely affected the operation or security of relevant systems where the impact was, or was likely to be, significant, even if significant disruption to the service had not yet occurred. Separate reporting criteria would apply to data centres.
After submitting a full report, data centre operators and relevant digital and managed service providers would need to notify customers likely to have been adversely affected. Further details are available in the government’s incident reporting factsheet.
Some technical requirements, including further detail on security measures and incident reporting thresholds, would be developed through consultation, secondary legislation and regulatory guidance. Until the relevant provisions come into force, organisations already within scope must continue to comply with the current NIS Regulations.
How would oversight and enforcement change?
The NIS regime would continue to use different regulators for different sectors. Under the proposed expansion, Ofcom would regulate qualifying data centres, the Information Commission would regulate relevant managed service providers, and the Department for Energy Security and Net Zero and Ofgem would jointly regulate large load controllers.
Regulators would have clearer powers to obtain and share information, investigate potential non-compliance, conduct inspections and require corrective action. The Secretary of State would also be able to publish a statement of strategic priorities that regulators would have a duty to seek to achieve, supporting greater consistency across the regime.
For breaches of duties under the NIS Regulations, the proposed maximum penalties would be:
- £17 million or 4% of relevant worldwide turnover, whichever was higher, for more serious breaches; and
- £10 million or 2% of relevant worldwide turnover, whichever was higher, for less serious breaches.
The precise definition of turnover would be set through secondary legislation. These would be maximum penalties rather than automatic fines. Regulators would be required to act proportionately and consider the circumstances of each case, including the severity of the breach, the organisation’s history of noncompliance and any action taken to mitigate the impact or remedy the breach. Further detail is set out in the enforcement factsheet.
The Bill would also give the government powers to update aspects of the regime through secondary legislation as technologies and threats change. Separately, the Secretary of State would be able to direct regulated organisations to take necessary and proportionate action where an imminent or live threat presented a risk to UK national security. The national-security direction powers would have their own enforcement and penalty arrangements.
How can organisations prepare?
The Bill is not yet law and does not create new legal obligations. If it is enacted, requirements would apply when the relevant provisions were brought into force. Organisations that may be affected can nevertheless assess whether they could fall within scope, identify the services and dependencies that may be relevant, and review their governance, security and incident arrangements.
Boards and committees
Boards and senior leaders should seek assurance that the organisation understands whether it may fall within scope, has identified its important services and the systems and suppliers on which they depend, and has assigned clear responsibility for cyber risk, resilience and incident reporting.
Audit and risk committees can scrutinise whether cyber and supply-chain risks are represented accurately, improvement plans are progressing and assurance shows that key arrangements are working as intended. This is consistent with the government’s Cyber Governance Code of Practice.
Internal audit
Internal audit can provide independent assurance over:
- governance and monitoring of regulatory developments;
- identification of relevant services, systems and suppliers;
- cyber and supply-chain risk management;
- incident detection, escalation and reporting;
- continuity and recovery arrangements; and
- information provided to boards, committees and regulators.
Reviews should distinguish between current legal obligations, proposed requirements and preparatory good practice.
Procurement and supplier management
The Bill does not prescribe a due-diligence checklist. However, procurement and supplier-management teams can:
- understand the systems and information that suppliers can access;
- assess the effect of supplier disruption and whether alternative providers are available;
- establish proportionate security and incident-notification requirements;
- consider relevant subcontractors and include appropriate assurance or audit rights; and
- plan how services would continue, transfer to another provider or be brought to an orderly end if a supplier became unavailable.
Due diligence should continue throughout the relationship because suppliers’ services, access and risks can change.
Other teams
Cyber security and IT teams can assess technical risks, while operational owners identify how disruption would affect the services they deliver. Risk and business continuity teams can connect cyber scenarios with continuity and recovery planning.
Legal, compliance and data protection teams can help interpret applicable requirements and coordinate any overlapping notification duties. Communications and customer teams may also be needed during an incident.
The proposed 24-hour initial reporting period would leave little time to clarify responsibilities or address untested escalation arrangements once a reportable incident had been identified. Organisations that may be affected should therefore establish reporting responsibilities and test escalation arrangements before the proposed requirements come into force.
Standards and frameworks
Recognised standards and frameworks can provide a strong foundation for cyber resilience and regulatory readiness. The NCSC Cyber Assessment Framework provides a systematic approach to assessing how cyber risks to important functions are being managed. Its objectives cover managing security risk, protecting against cyber attacks, detecting cyber security events and minimising the impact of incidents.
An information security management system aligned with ISO/IEC 27001 can support effective governance, risk management, security controls, incident management and continual improvement. Independent certification can also strengthen customer confidence and support supplier due diligence and tender requirements.
The Cyber Assessment Framework and ISO/IEC 27001 can support NIS readiness and provide evidence that security arrangements are established and reviewed. Organisations would still need to compare their arrangements with the specific NIS duties and regulatory guidance applying to them, ensuring all relevant services and systems are covered.
Looking ahead
The Bill may still be amended, and further detail is expected to follow through consultation, secondary legislation and regulatory guidance. Organisations already regulated must continue to comply with the current NIS Regulations, while those that may be brought within scope should not treat the proposed requirements as though they are already law.
Organisations can use this period to examine the services, systems and suppliers on which they depend, consider the consequences of disruption and assess whether their response and recovery arrangements have been tested and shown to work. As further detail emerges, they can compare their existing arrangements with the requirements that would apply to them and address any gaps.


