The UK Cyber Security and Resilience Bill: what it means for your business

The UK is updating its cybersecurity law. The Cyber Security and Resilience Bill, progressing through Parliament, will replace and strengthen the ageing Network and Information Systems Regulations and bring the UK regime closer to the EU’s NIS2. It is not yet in force, and full implementation is expected to be phased over the following years, but the direction is set — and for businesses that operate critical services or sit in digital supply chains, the time to understand it is before it lands, not after.

What the Bill does

The Bill reforms the UK’s existing cybersecurity framework for critical national infrastructure and essential services, which was built on the 2018 NIS Regulations and is widely seen as no longer fit for the current threat level. It modernises and broadens that framework — extending oversight, strengthening incident reporting, and notably bringing managed service providers and other digital intermediaries more firmly into scope. It also gives government greater powers to direct regulated organisations and to update the rules through secondary legislation, which means the regime can evolve faster than primary law usually allows. In short, it is the UK’s answer to the same pressures that produced NIS2 across the EU.

Where it stands and when it bites

The Bill is actively moving through Parliament and is expected to receive Royal Assent in 2026, but it is important to be realistic about timing: implementation is expected to be phased, with full effect potentially not arriving until around 2028. That lead time is not an excuse to wait. The obligations it introduces — particularly around governance, incident reporting and supply-chain oversight — take time to build, and businesses that begin scoping and preparing early will find the transition far smoother than those that wait for the rules to be fully in force.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

The convergence that actually matters

For any business operating on both sides of the Channel, the most useful way to read this Bill is alongside the EU’s NIS2. The two regimes are converging deliberately, which is good news: a business that builds its cybersecurity governance to meet one is doing most of the work for the other. There is also overlap with the operational-resilience expectations of DORA for financial firms, and with the technical controls a cyber insurance questionnaire demands. Rather than treating each as a separate project, the sensible approach is to build one coherent cybersecurity posture that satisfies the common core of all of them — and there is real duplication of effort to be avoided by doing so.

The Bill also reinforces a wider point: incident reporting now sits alongside data-protection obligations, so a single incident can trigger reporting duties under more than one regime at once. Incident response plans need to be built and tested against those dual-track timelines, not designed for one rule in isolation.

What to do now

Three steps make sense ahead of the Bill taking full effect. Run a preliminary scoping exercise to understand whether, and how, your business is likely to be in scope — bearing in mind that the expansion to managed service providers and digital supply chains catches businesses that the old regime did not. Assess your cybersecurity governance, incident response and supplier oversight against where the regime is heading. And, if you also operate in the EU, build your programme to the common standard across NIS2 and the UK regime, so you are not solving the same problem twice. Preparing now turns a future obligation into a manageable transition rather than a deadline scramble.

The UK’s cybersecurity regime is being strengthened, and the businesses that prepare early will absorb it far more easily than those that wait. We will work out whether you are likely to be in scope and what to start doing now.

Start a Conversation

This is general information about a Bill still progressing through Parliament, not legal advice, and the detail may change before it becomes law. For a formal view, take advice from a qualified legal adviser.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming