Cyber GovernanceCSRB6-minute read·Marcin Pajdzik·August 2026

The Cyber Security and Resilience Bill Puts UK Boards on Notice

The Cyber Security and Resilience Bill is the UK's answer to many of the same cyber resilience problems addressed by the EU's NIS2 Directive, which does not apply in the UK after Brexit. It updates the Network and Information Systems Regulations 2018 and is moving through its final stages in Parliament. It brings managed service providers, data centres and large electricity load controllers into UK cyber regulation for the first time, with penalties reaching 4% of worldwide turnover for the most serious breaches.

For boards of organisations newly brought into cyber regulation, decisions about cyber governance, resilience and incident response that were previously matters of internal risk management will become subject to regulatory scrutiny and enforcement. Yet the Bill stops short of NIS2 by not imposing Article 20's explicit duty on management bodies to approve cybersecurity risk management measures and oversee their implementation.

Where the Bill stands and what it changes

The Bill completed its Commons stages in June 2026 and is now progressing through the House of Lords, with Royal Assent expected in spring 2027. Implementation will follow in stages through commencement provisions, secondary legislation and guidance.

The amendments reach categories the 2018 Regulations never covered, mainly digital infrastructure and energy operators that support essential services without being classed as essential services themselves. What falls into scope, who regulates it, and what it costs to get wrong are set out below.

What the new regime requires

Four areas define what changes for an organisation newly caught by the amended Regulations.

Scope
The expanded regime captures medium and large managed service providers; data centres with a rated IT load of at least 1 megawatt; enterprise data centres, operated solely for their owner's IT needs, with a rated IT load of at least 10 megawatts; and electricity load controllers managing at least 300 megawatts of aggregate capacity. Regulators will also be able to designate suppliers as critical where their services are sufficiently important to an entity already within scope.
Regulator
Oversight sits with several different bodies, with the regulator depending on the type of organisation. The Information Commission is expected to cover managed service providers, the Secretary of State and Ofcom the data centre sector, and the Department for Energy Security and Net Zero with Ofgem the load controllers, alongside the competent authorities already responsible for the sectors the 2018 Regulations covered.
Reporting timeline
An initial notification is required within 24 hours of an incident and a full report within 72 hours, tightened from the current standard of reporting without undue delay. The duty covers incidents that have had, are having, or are likely to have a significant impact.
Penalties
Standard breaches carry fines of up to £10 million or 2% of worldwide turnover, serious breaches up to £17 million or 4%, and continuing non-compliance a daily penalty of up to £100,000.

What a board should ask while the assurance framework is still being set

A board does not need to wait for Royal Assent to engage with what the Bill will require. The National Cyber Security Centre's proposed Cyber Assessment Framework profile for large load controllers closed for consultation on 1 September 2026, with a final version expected later this year and full compliance proposed by the end of 2029. The assurance framework is being developed before the Bill receives Royal Assent, giving affected organisations several years to build the capability against which they will eventually be assessed.

Has anyone assessed whether the organisation's data centre operations, managed service offering or role in the electricity system now meets one of these thresholds? Which regulator would have jurisdiction if it does? Would the current incident response process support an initial notification within 24 hours, including where an incident is likely to have a significant impact but has not yet caused disruption?

Where the organisation reports under the EU's NIS2 Directive elsewhere in the group, the further question is whether that governance structure, its reporting lines and its evidence trail extend to the UK regime or need a parallel structure of their own. A structure built for one regulator does not automatically satisfy a different one with its own thresholds and its own reporting clock.

How this affects your organisation

For boards inside the expanded scope, whether newly caught by it or already managing equivalent obligations under NIS2 elsewhere in the group, cyber governance is now judged against a standard the regulator sets and enforces. It may enforce against the entity, but whether it meets that standard will depend substantially on decisions made at board level.

The direction of travel is nevertheless clear. Government expects cyber resilience to receive board level ownership, even where the Bill itself stops short of imposing the explicit management body duties found in NIS2. Its voluntary Cyber Resilience Pledge, formally launched in July 2026, explicitly asks organisations to 'make cyber a Board responsibility', implement the Cyber Governance Code of Practice and ensure all board members complete NCSC cyber governance training within three months and annually thereafter. The practical question for your board is whether the governance, evidence and assurance needed to meet the new regulatory requirements are already being built, regardless of when those requirements formally take effect.

If you are assessing whether the Bill brings your organisation into scope for the first time, start by establishing applicability, identifying the competent regulator, and testing whether your existing cyber governance and incident reporting arrangements meet the new regime. An advisory call is a useful way to work through that assessment.

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.