ILaw Logo blue text, transparent background
AboutpeopleexpertiseNewsTestimonialsCareersContact

Cyber Security and Resilience Bill

13 August 2026

The Cyber Security and Resilience Bill represents the most significant reform of UK cyber security legislation since the introduction of the Network and Information Systems Regulations 2018 (NIS Regulations). While the legislation introduces new regulatory obligations for organisations operating critical infrastructure and digital services, its commercial impact extends much further. Businesses throughout the supply chain will increasingly be expected to demonstrate robust cyber security measures as customers seek to meet their own compliance obligations.

Why is the law changing?

The existing NIS Regulations were introduced at a time when cloud computing, managed IT services and interconnected digital supply chains were far less prevalent than they are today. As cyber threats have evolved, so too has the UK's reliance on digital infrastructure, exposing weaknesses in the current regulatory framework.

Recent cyber-attacks affecting organisations including the NHS, the Ministry of Defence, Marks & Spencer and Jaguar Land Rover have demonstrated the widespread disruption that can result from a single security breach. At the same time, the National Cyber Security Centre has reported a significant increase in nationally significant cyber incidents, highlighting the growing sophistication and frequency of attacks.

The Cyber Security and Resilience Bill seeks to modernise UK cyber security law and strengthen the resilience of critical services. It also brings the UK more closely into line with the European Union's NIS2 Directive, ensuring that the UK's regulatory framework keeps pace with international standards.

Perhaps most notably, the Bill focuses on preventing attacks before they cause widespread disruption. Rather than responding only after systems have been compromised, regulators will have greater powers to identify and manage risks at an earlier stage.

Who will be affected?

One of the most significant changes is the expansion of organisations falling within the regulatory regime.

In addition to operators of essential services and existing digital service providers, the Bill introduces obligations for several new categories of business, including:

  • Qualifying Data Centres
  • Medium and large managed service providers (MSPs)
  • Large Load Controllers responsible for significant electricity demand, such as operators of extensive electric vehicle charging networks; and
  • Organisations designated as critical suppliers where disruption could have a wider economic impact

Different sector regulators will oversee compliance depending on the nature of the organisation, with bodies including Ofcom and Ofgem taking on enhanced supervisory roles.

Tougher reporting obligations:

The Bill also introduces substantially stricter incident reporting requirements.

Organisations within scope will generally be required to notify their regulator within 24 hours of becoming aware of a significant incident, followed by a more detailed report within 72 hours. where appropriate, affected customers must be informed.

Importantly, the reporting threshold has been widened. Businesses will be expected to report incidents that have the potential to cause serious disruption, rather than waiting until substantial harm has already occurred. This reflects a broader shift towards proactive cyber risk management.

Stronger enforcement powers

Financial penalties for non-compliance will increase substantially, with the most serious breaches attracting fines of up to £17 million or 4% of global annual turnover, together with continuing daily penalties where failures remain unresolved. Regulators will also have expanded powers to require information, inspect systems, recover enforcement costs and, in certain circumstances, direct organisations to take specific action where national security is at risk.

The Bill also places the National Cyber Security Centre's Cyber Assessment Framework on a firmer statutory footing, providing a clearer benchmark against which organisations' cyber resilience may be assessed.

Why it’s important for Businesses

Although the legislation directly regulates only certain sectors, its commercial impact will be felt much more widely.

The Bill recognises that cyber security risks rarely exist in isolation. A vulnerability within a managed service provider, software supplier or data centre can rapidly affect hundreds of connected organisations. As a result, businesses subject to the new regime will be expected to manage cyber risks throughout their supply chains.

This is likely to result in more rigorous procurement processes, enhanced contractual obligations and increased scrutiny of suppliers' cyber security arrangements. Organisations providing software, cloud services, IT support or digital infrastructure should therefore expect customers to request greater assurance, including security questionnaires, audit rights and evidence of recognised cyber security standards.

Businesses operating outside the UK should also be aware that the Bill has extraterritorial effect in certain circumstances, meaning overseas organisations providing services into the UK may also fall within scope.

Preparing for the new regime

The Cyber Security and Resilience Bill should not be viewed simply as another regulatory burden. Increasingly, strong cyber resilience is becoming a commercial differentiator.

Organisations that can demonstrate effective cyber governance, resilient systems and robust incident response procedures are likely to be viewed as lower-risk suppliers, strengthening their position when bidding for contracts, particularly within regulated sectors such as healthcare, energy, financial services and critical infrastructure.

Conversely, businesses that fail to meet evolving cyber security expectations may find themselves excluded from procurement opportunities or subject to increased contractual obligations imposed by customers seeking to manage their own regulatory exposure.

With the Bill expected to become law later this year, now is the time for businesses to assess their cyber security arrangements, review supplier relationships and ensure governance frameworks are fit for purpose. Taking proactive steps today will not only support future compliance but also strengthen customer confidence and improve long-term commercial resilience.

Need Advice on the Cyber Security and Resilience Bill?

The Cyber Security and Resilience Bill represent a significant shift in the UK's cyber security landscape. Whether your organisation falls directly within the scope of the new legislation or forms part of the supply chain supporting regulated businesses, now is the time to review your cyber security governance, contractual arrangements and incident response procedures.

Preparing early will not only help minimise regulatory risk but also strengthen your commercial position, enhance customer confidence and demonstrate your commitment to cyber resilience. If you would like advice on how the Bill may affect your business, or assistance in reviewing your contractual and compliance obligations, the team at Culbert Ellis is here to help.

Accurate at the time of writing. This information is provided for general information purposes only and should not be relied upon as legal advice.

About the author(s)

Share

Latest News