Where the Bill stands and what it changes
The Bill was introduced in the House of Commons in November 2025, completed its Commons stages in June 2026, and had its second reading in the House of Lords in July 2026. It is now working through Lords committee stage, with Royal Assent expected in spring 2027 and its provisions entering into force later that year.
The amendments reach categories the 2018 Regulations never covered, mainly digital infrastructure and energy operators that support essential services without being classed as essential services themselves. What falls into scope, who regulates it, and what it costs to get wrong are set out below.
What the new regime requires
Four areas define what changes for an organisation newly caught by the amended Regulations.
- Scope
- Data centres with a rated IT load of at least 1 megawatt, and enterprise data centres, meaning those operated solely for their owner's IT needs, with a rated IT load of at least 10 megawatts, medium and large managed service providers, electricity load controllers managing 300 megawatts or more of aggregate capacity, and suppliers a regulator designates as critical to an entity already in scope.
- Regulator
- Oversight is split across several bodies rather than one. The Information Commission is expected to cover managed service providers, the Secretary of State and Ofcom the data centre sector, and the Department for Energy Security and Net Zero with Ofgem the load controllers, alongside the competent authorities already responsible for the sectors the 2018 Regulations covered.
- Reporting timeline
- An initial notification is required within 24 hours of an incident and a full report within 72 hours, tightened from the current standard of reporting without undue delay. The duty extends to significant near misses as well as incidents that cause actual disruption.
- Penalties
- Standard breaches carry fines of up to £10 million or 2% of global turnover, serious breaches up to £17 million or 4%, and continuing non-compliance a daily penalty of up to £100,000.
What a board should ask while the standard is still being set
A board does not need to wait for Royal Assent to engage with what the Bill will require. The National Cyber Security Centre's proposed Cyber Assessment Framework profile for large load controllers closed for public consultation on 1 September 2026, with a finalised version due later that year, a proposed compliance deadline of the end of 2029, and formal assurance beginning in 2030. For large load controllers, the pattern is already visible. The technical standard an organisation will be judged against is being fixed years before the legislation that creates the duty to meet it, and well before Royal Assent itself.
Has anyone assessed whether the organisation's data centre capacity, managed service offering or role in the electricity system meets one of these thresholds. Which of the several regulators would have jurisdiction if it does. Would the current incident response process meet a 24-hour initial notification, including for a near miss that caused no actual disruption.
Where the organisation reports under the EU's NIS2 Directive elsewhere in the group, the further question is whether that governance structure, its reporting lines and its evidence trail extend to the UK regime or need a parallel structure of their own. A structure built for one regulator does not automatically satisfy a different one with its own thresholds and its own reporting clock.