Cyber Governance6-minute read·Marcin Pajdzik·September 2026

The Cyber Security and Resilience Bill Puts UK Boards on Notice

The Cyber Security and Resilience Bill is the UK's answer to many of the same cyber resilience problems addressed by the EU's NIS2 Directive. It updates the Network and Information Systems Regulations 2018, the UK's own cyber regime since NIS2 itself does not apply here after Brexit, and it is moving through its final stages in Parliament. It brings managed service providers, data centres and large electricity load controllers into UK cyber regulation for the first time, with penalties reaching 4% of global turnover for the most serious breaches.

For a board that has never answered to a cyber regulator, that combination changes what an oversight failure costs. The Bill, as drafted, creates no personal board duty to approve these measures, unlike Article 20 of NIS2, which expressly requires management bodies to approve cybersecurity risk management measures and oversee their implementation.

Where the Bill stands and what it changes

The Bill was introduced in the House of Commons in November 2025, completed its Commons stages in June 2026, and had its second reading in the House of Lords in July 2026. It is now working through Lords committee stage, with Royal Assent expected in spring 2027 and its provisions entering into force later that year.

The amendments reach categories the 2018 Regulations never covered, mainly digital infrastructure and energy operators that support essential services without being classed as essential services themselves. What falls into scope, who regulates it, and what it costs to get wrong are set out below.

What the new regime requires

Four areas define what changes for an organisation newly caught by the amended Regulations.

Scope
Data centres with a rated IT load of at least 1 megawatt, and enterprise data centres, meaning those operated solely for their owner's IT needs, with a rated IT load of at least 10 megawatts, medium and large managed service providers, electricity load controllers managing 300 megawatts or more of aggregate capacity, and suppliers a regulator designates as critical to an entity already in scope.
Regulator
Oversight is split across several bodies rather than one. The Information Commission is expected to cover managed service providers, the Secretary of State and Ofcom the data centre sector, and the Department for Energy Security and Net Zero with Ofgem the load controllers, alongside the competent authorities already responsible for the sectors the 2018 Regulations covered.
Reporting timeline
An initial notification is required within 24 hours of an incident and a full report within 72 hours, tightened from the current standard of reporting without undue delay. The duty extends to significant near misses as well as incidents that cause actual disruption.
Penalties
Standard breaches carry fines of up to £10 million or 2% of global turnover, serious breaches up to £17 million or 4%, and continuing non-compliance a daily penalty of up to £100,000.

What a board should ask while the standard is still being set

A board does not need to wait for Royal Assent to engage with what the Bill will require. The National Cyber Security Centre's proposed Cyber Assessment Framework profile for large load controllers closed for public consultation on 1 September 2026, with a finalised version due later that year, a proposed compliance deadline of the end of 2029, and formal assurance beginning in 2030. For large load controllers, the pattern is already visible. The technical standard an organisation will be judged against is being fixed years before the legislation that creates the duty to meet it, and well before Royal Assent itself.

Has anyone assessed whether the organisation's data centre capacity, managed service offering or role in the electricity system meets one of these thresholds. Which of the several regulators would have jurisdiction if it does. Would the current incident response process meet a 24-hour initial notification, including for a near miss that caused no actual disruption.

Where the organisation reports under the EU's NIS2 Directive elsewhere in the group, the further question is whether that governance structure, its reporting lines and its evidence trail extend to the UK regime or need a parallel structure of their own. A structure built for one regulator does not automatically satisfy a different one with its own thresholds and its own reporting clock.

How this affects your organisation

For boards inside the expanded scope, whether newly caught by it or already managing an equivalent structure under NIS2 elsewhere in the group, the penalty for getting oversight wrong now sits with a UK regulator empowered to fine your own balance sheet directly.

Board-level oversight is already a practical expectation. The government's voluntary Cyber Resilience Pledge, launched in July 2026, commits signatory boards to NCSC cyber governance training within three months of signing, well ahead of anything the Bill itself will require. The test for your board is whether it already meets that standard, or would need to, before your sector's technical standard is finalised without your input.

If you are working out whether the Cyber Security and Resilience Bill brings your organisation into scope for the first time, an advisory call is a useful starting point.

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.