Skip to main content
Regulation

Cyber Security and Resilience Bill: what UK organisations need to know

By Goldline Consultancy

11 min read

Contents

    The Cyber Security and Resilience Bill received its first reading in Parliament on 12 November 2025. By the time it receives Royal Assent and the secondary legislation takes effect, it will substantially expand the scope of UK cyber security regulation and bring new categories of organisation under formal cyber regulation for the first time.

    This article sets out what the Bill changes, who comes into scope, and how it intersects with ISO 27001 readiness work that organisations are already doing or should be doing now.

    Why the Bill exists

    The UK's existing cyber regulation, the Network and Information Systems Regulations 2018, was the UK's pre-Brexit transposition of the original EU NIS Directive. The EU has since replaced NIS with NIS2, which most member states transposed into national law during 2024 and 2025. The UK was no longer obliged to follow NIS2 after Brexit and chose not to.

    The decision to update UK regulation has been driven by a sustained increase in attack volume against UK essential services. The NCSC's Annual Report published in October 2025 documented 204 nationally significant cyber attacks in the year to September 2025, up from 89 the previous year. High-profile incidents at Marks and Spencer, Jaguar Land Rover, the NHS, and others made the inadequacy of the 2018 regime evident.

    The Bill is the UK's response. It is not a transposition of NIS2 and is not designed to mirror it exactly. It is a calibrated update to the 2018 regime that addresses the most acute supply chain and incident reporting gaps while leaving the core NIS structure in place.

    Who comes into scope

    The 2018 regulations cover Operators of Essential Services in five sectors: transport, energy, drinking water, health, and digital infrastructure. They also cover Relevant Digital Service Providers including online marketplaces, search engines, and cloud computing services.

    The Bill expands the scope in three principal directions.

    Managed Service Providers come into scope as a new category of operator with similar obligations to existing Digital Service Providers. The definition is more specific than the equivalent in NIS2 and captures organisations providing ongoing management support, active administration, or monitoring of IT systems, infrastructure, applications, or networks. The Information Commission, replacing the existing Information Commissioner's Office, will be the competent authority for MSPs.

    Data centre service providers come into scope where they offer rated IT load above 10 megawatts on an enterprise basis. The Secretary of State for Science, Innovation and Technology, along with Ofcom, will be the competent authority.

    Large load operators in the electricity sector come into scope as Operators of Essential Services.

    Beyond these named categories, the Bill introduces a critical supplier designation power. Regulators will be able to designate specific businesses supplying goods or services directly to in-scope organisations as critical suppliers, bringing them directly under the NIS regime even if they would not otherwise have been caught by it. This is a meaningful expansion. It captures organisations that supply essential services without themselves operating essential services.

    What the Bill requires

    Unlike NIS2 Article 21, which lists specific minimum technical and organisational measures, the Bill does not prescribe a detailed control set. It maintains the principle of appropriate technical and organisational measures while reserving the power for the Secretary of State to issue codes of practice that would set more specific requirements. The expectation across cyber legal and regulatory commentary is that codes of practice will follow Royal Assent and will draw on NCSC's Cyber Assessment Framework for Operators of Essential Services and on more specific requirements for digital service providers.

    Incident reporting is tightened. Where the 2018 regulations require reporting within 72 hours of an incident with significant impact, the Bill aligns partially with NIS2 by introducing an initial 24-hour notification followed by a fuller 72-hour follow-up. The scope of reportable incidents is also expanded with the Government's stated intention to capture ransomware attacks specifically.

    Customer notification obligations shift. Under the existing regime, the regulator decides whether the public or customers should be notified. The Bill places this obligation directly on the provider.

    Penalties broadly mirror the GDPR structure. Serious breaches face the higher of £17 million or 4% of worldwide annual turnover. Less severe violations face the higher of £10 million or 2%. Continuing non-compliance can attract daily fines up to £100,000.

    When this takes effect

    The Bill received its first reading on 12 November 2025 and is progressing through Parliament. As of mid-2026, no implementation date has been confirmed. Many of the substantive reforms require secondary legislation to take effect after Royal Assent, which means in-scope organisations have some preparation time, but the direction is set.

    Organisations that wait for the implementation date to begin preparation will be working under time pressure. Organisations that prepare now using the substantive direction in the published policy statement and the Bill text will be in good position when the secondary legislation lands.

    How the Bill intersects with ISO 27001

    ISO 27001 is not a substitute for compliance with the Bill, and certification does not exempt an organisation from the regulatory obligations. But the substantive overlap is significant, and an organisation with a mature ISO 27001 ISMS will satisfy most of the Bill's likely requirements through evidence reuse.

    The clearest overlap is in Annex A.5.19 to A.5.23 covering supplier and supply chain security. The Bill's critical supplier designation power and broader supply chain emphasis map directly onto these controls. An organisation that has implemented Annex A.5 supplier security properly is in much better position to respond to a critical supplier designation than one that has not.

    Annex A.5.24 to A.5.28 covering incident management aligns with the Bill's tightened incident reporting requirements. An organisation with a tested incident response capability and documented reporting procedures can adapt to the new 24-hour and 72-hour windows without rebuilding its incident response operating model.

    The management system clauses 4 through 10 align with the Bill's likely codes of practice. Context analysis, risk management, leadership commitment, internal audit, and management review are the structural backbone that codes of practice will probably require, regardless of how detailed the eventual technical requirements are.

    For organisations that already hold ISO 27001 certification, preparation for the Bill is mostly about scope review and gap analysis against the published policy direction. For organisations that do not yet hold ISO 27001 but expect to come into scope of the Bill, getting the certification work moving now positions them well for both.

    Closing thought

    The Cyber Security and Resilience Bill is real, is moving, and will substantially expand the scope of UK cyber regulation. Organisations that come into scope, and many will for the first time, need to start preparing now.

    ISO 27001 is not a compliance shortcut, but it is the strongest single piece of preparation an organisation can do. The management system structure carries across most of the Bill's likely requirements with minimal additional work.

    Goldline Consultancy is led by an ISO 27001 Lead Implementer (PECB) and ISO 42001 Lead Implementer and Lead Auditor (PECB), SC-cleared, and delivers ISO 27001 implementation as a fixed-scope engagement for UK defence supply chain and regulated organisations. Take our free ISMS maturity self-assessment or book an ISO 27001 diagnostic call.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.