Skip to content

UK Cyber Security and Resilience Bill

Proposed United Kingdom ยท next deadline Oct 26, 2026 (in 30 days)

Deadlines

DateWhat happens
Coming up
Oct 26, 2026in 4 weeksLords report stage scheduledtentative
Earlier
Jun 16, 20263 months agoPasses House of Commons
Nov 12, 202510 months agoIntroduced (Commons first reading)

Summaries for reference, not legal advice. Check the official text.

What it does

Updates the NIS Regulations 2018: brings managed service providers and data centres into scope, lets regulators designate critical suppliers, tightens incident reporting (initial notice within 24 hours, full report within 72 hours) and strengthens regulator powers. Substantive duties will follow via secondary legislation after Royal Assent.

Who it applies to
Operators of essential services and relevant digital service providers under NIS, plus (proposed) managed service providers, data centres above capacity thresholds, and designated critical suppliers.
Penalties
Proposed higher maximum penalties aligned with turnover-based fines; final figures depend on the enacted text (not verified).
Enforced by
Sector NIS competent authorities and the ICO (for digital services); DSIT policy lead
Official name
Cyber Security and Resilience (Network and Information Systems) Bill
Citation
Bill 4035 (HL Bill, 2026 session)
Topics
cybersecurity, breach-notification
Verified 2026-09-22 bills-api.parliament.uk compliancehub.wiki
Research notes

Not yet law as of 2026-09-22 (in House of Lords). Royal Assent expected late 2026 or early 2027; substantive obligations expected around 2028 via secondary legislation. 24h/72h reporting timeline is from the government's published policy, not the final text.

Related

Questions about UK Cyber Security and Resilience Bill
What are the UK Cyber Security and Resilience Bill compliance deadlines?
Nov 12, 2025: Introduced (Commons first reading). Jun 16, 2026: Passes House of Commons. Oct 26, 2026: Lords report stage scheduled (tentative).
Who does UK Cyber Security and Resilience Bill apply to?
Operators of essential services and relevant digital service providers under NIS, plus (proposed) managed service providers, data centres above capacity thresholds, and designated critical suppliers.
What are the penalties under UK Cyber Security and Resilience Bill?
Proposed higher maximum penalties aligned with turnover-based fines; final figures depend on the enacted text (not verified).

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.