WAJD Learning

Module 3 of 3 · 50 minutes

The UK Cyber Security and Resilience Bill, and what to do now

By the end of this module you will be able to

  • State the Bill's status and why it is not yet law
  • Say who the Bill would bring into scope
  • State the Bill's incident reporting timeline and who is told
  • Explain what will be decided later in secondary legislation
  • Set out five steps worth taking now under either regime

Work through it

1 interactive for this module, built on the WAJD Teach engine. Nothing moves until you ask it to, and every one has a written version if you would rather read it.

Watch: Emma and George talk it through

4 minutes. Captions are on, and the same conversation is written out in full below. The voices are computer generated.

Emma George, so NIS2 is the EU's. What has the UK actually done?

George It has a Bill, and it isn't law yet. That's the headline. The UK already has the Network and Information Systems Regulations from 2018. The Cyber Security and Resilience Bill amends and widens them.

Emma How far has it got?

George Introduced in November 2025. Through the Commons in June 2026. Lords second reading in July, committee stage finished in September, report stage scheduled for 26 October 2026. Royal Assent has been expected late in 2026 or in spring 2027.

Emma So today, what applies?

George The 2018 Regulations as they stand. Until the Bill passes and the regulations under it are made. Check the current position before you rely on anything I'm about to say.

Emma Fair. Who would it bring in?

George Four groups, according to the government's factsheets. Medium and large managed service providers, the firms that run IT for other organisations. Data centres above set thresholds. Large load controllers, which manage power for things like vehicle chargers. And designated critical suppliers.

Emma Designated by whom?

George By regulators. If a supplier's failure would disrupt an essential service, they could be designated and brought under duties.

Emma Why that power?

George June 2024. An attack on a pathology supplier to the NHS led to more than eleven thousand postponed appointments and procedures. The supplier wasn't itself regulated. That's the gap.

Emma And reporting? Is it the same 24 hours as Europe?

George Similar shape. An initial notification within 24 hours and a full report within 72, to the regulator, with the National Cyber Security Centre told at the same time. More incidents become reportable, including ones capable of significant impact, like ransomware.

Emma What about customers?

George Managed service providers, digital service providers and data centres would have to tell customers likely to be affected.

Emma And the fines?

George Maximum penalties go up, to align with things like data protection law. Regulators can recover their costs. And the Secretary of State can set priorities and give directions for national security. I won't quote figures, because a lot is left to secondary legislation, including what counts as significant.

Emma So what do I do while Parliament finishes?

George Five things, and none needs the Bill to pass. Work out where you stand. Brief the people who run the business and record it. Check your critical suppliers and your incident clauses. Write down who decides and who reports, and test it out of hours.

Emma And the fifth?

George Fix the three basics. Multi-factor authentication, backups you've tested, and staff training. They've been the advice for years, and they're what every one of these regimes checks first.

The written material

Where the Bill stands

The United Kingdom already has the Network and Information Systems Regulations 2018, which cover operators of essential services and some digital service providers. The Cyber Security and Resilience (Network and Information Systems) Bill amends and widens them.

The Bill was introduced on 12 November 2025. It completed its stages in the House of Commons on 10 June 2026, had its second reading in the House of Lords on 14 July 2026 and finished Lords committee stage on 7 September 2026. Report stage is scheduled for 26 October 2026. Royal Assent has been expected in late 2026 or spring 2027.

Who it would bring in

The government's factsheets describe four additions. Medium and large managed service providers, meaning firms that manage IT systems for other organisations, with the information regulator overseeing them. Data centres above set thresholds, as an essential service, with Ofcom as regulator. Large load controllers, which manage electrical load for smart appliances such as vehicle chargers. And designated critical suppliers: regulators would be able to designate a supplier whose failure would disrupt an essential or digital service.

That last power exists because of what happened in June 2024, when an attack on a pathology supplier to the NHS led to more than 11,000 postponed appointments and procedures. The supplier was not itself regulated.

Reporting, penalties and what is still to come

The Bill moves the United Kingdom to a two stage report: an initial notification within 24 hours and a full report within 72 hours, to the regulator, with the National Cyber Security Centre told at the same time. More incidents would be reportable, including those capable of significant impact, such as ransomware. Managed service providers, digital service providers and data centres would also have to tell the customers likely to be affected.

Maximum penalties are being raised to align with comparable legislation such as data protection law, regulators would be able to recover their costs from those they regulate, and the Secretary of State would be able to set strategic priorities and give directions where national security is at risk.

A great deal is left to secondary legislation after Royal Assent, including the thresholds for what counts as a significant incident and the duties on critical suppliers. The government has said it will consult first.

Five things worth doing now

Whether your duty comes from NIS2, from the UK Bill, from a customer's contract or from none of them, the same five steps make you safer and make every later conversation easier.

  • Work out where you stand: covered directly, covered through a customer, or neither
  • Brief the people who run the business and record that you did
  • Check your critical suppliers and what your contracts say about incidents
  • Write down who decides and who reports, and test it out of hours
  • Fix the three basics: multi-factor authentication, tested backups, staff training

Knowledge check

The knowledge check and your certificate need a free account, so that your progress and results can be saved as evidence.

Create a free account Sign in

The learning itself stays free and open. You are reading all of it right now without an account.