Where the Bill stands and what it changes
The Bill completed its Commons stages in June 2026 and is now progressing through the House of Lords, with Royal Assent expected in spring 2027. Implementation will follow in stages through commencement provisions, secondary legislation and guidance.
The amendments reach categories the 2018 Regulations never covered, mainly digital infrastructure and energy operators that support essential services without being classed as essential services themselves. What falls into scope, who regulates it, and what it costs to get wrong are set out below.
What the new regime requires
Four areas define what changes for an organisation newly caught by the amended Regulations.
- Scope
- The expanded regime captures medium and large managed service providers; data centres with a rated IT load of at least 1 megawatt; enterprise data centres, operated solely for their owner's IT needs, with a rated IT load of at least 10 megawatts; and electricity load controllers managing at least 300 megawatts of aggregate capacity. Regulators will also be able to designate suppliers as critical where their services are sufficiently important to an entity already within scope.
- Regulator
- Oversight sits with several different bodies, with the regulator depending on the type of organisation. The Information Commission is expected to cover managed service providers, the Secretary of State and Ofcom the data centre sector, and the Department for Energy Security and Net Zero with Ofgem the load controllers, alongside the competent authorities already responsible for the sectors the 2018 Regulations covered.
- Reporting timeline
- An initial notification is required within 24 hours of an incident and a full report within 72 hours, tightened from the current standard of reporting without undue delay. The duty covers incidents that have had, are having, or are likely to have a significant impact.
- Penalties
- Standard breaches carry fines of up to £10 million or 2% of worldwide turnover, serious breaches up to £17 million or 4%, and continuing non-compliance a daily penalty of up to £100,000.
What a board should ask while the assurance framework is still being set
A board does not need to wait for Royal Assent to engage with what the Bill will require. The National Cyber Security Centre's proposed Cyber Assessment Framework profile for large load controllers closed for consultation on 1 September 2026, with a final version expected later this year and full compliance proposed by the end of 2029. The assurance framework is being developed before the Bill receives Royal Assent, giving affected organisations several years to build the capability against which they will eventually be assessed.
Has anyone assessed whether the organisation's data centre operations, managed service offering or role in the electricity system now meets one of these thresholds? Which regulator would have jurisdiction if it does? Would the current incident response process support an initial notification within 24 hours, including where an incident is likely to have a significant impact but has not yet caused disruption?
Where the organisation reports under the EU's NIS2 Directive elsewhere in the group, the further question is whether that governance structure, its reporting lines and its evidence trail extend to the UK regime or need a parallel structure of their own. A structure built for one regulator does not automatically satisfy a different one with its own thresholds and its own reporting clock.