Join Our Mailing List

Be the first to hear about updates

Be the first to hear about updates on the Cyber Security and Resilience Bill. Stay informed about compliance requirements, key changes, and important announcements.

ComplianceBack to Blog

Lords Complete CSRB Second Reading: Key Themes and Committee Stage on 1 September

The Lords gave HL Bill 32 cross-party support at Second Reading on 14 July 2026 without calling a division - but they put five pointed themes on the record, from the public sector exemption to the Bill's total silence on AI. Committee Stage begins on 1 September, and those themes are the working agenda. Here is what each one means for in-scope organisations.

Precursor Security
22 July 2026
8 min read
1,380 words

Precursor Security

Precursor Security is a UK-based penetration testing and offensive security testing company with 24/7 security operations centres. We are CREST certified in both penetration testing and security operations, providing comprehensive cyber security services to help organisations achieve regulatory compliance and enhance their security posture.

Share:

Lords Complete CSRB Second Reading: Key Themes and Committee Stage on 1 September

The House of Lords completed its Second Reading of HL Bill 32 on 14 July 2026, with Baroness Lloyd of Effra, the Government's Minister for Digital Economy, opening and closing for the Government. No division was called - the Lords gave the legislation cross-party support in principle - but the debate placed five clear themes on the record that will drive amendment activity when Committee Stage begins on 1 September 2026.

This article covers what was said, what the two new Lords committee reports mean, and what organisations in scope should be doing before scrutiny intensifies in the autumn.

What Second Reading Is - and Why the Debate Matters

Second Reading in the House of Lords is a general debate on the principles of a Bill. No amendments are moved at this stage. Its function is to allow Lords to express support for, or reservations about, the legislation's overall approach and to signal the areas they intend to pursue once Committee Stage begins.

Because the Bill arrived from the Commons having passed its Third Reading without a division, the Lords were never likely to reject it. What matters is what they chose to put on the record. Those statements now form the working agenda for Committee Stage, which unlike the Commons process is taken on the floor of the chamber, allowing all Lords to participate and to move amendments.

As our earlier post on the Second Reading anticipated, several themes were already predictable from the Commons passage. The 14 July debate confirmed which of those will be actively pursued.

Theme 1: The Bill Is "Not Nearly Ambitious Enough"

The most prominent criticism came from Lord Clement-Jones, the Liberal Democrat digital spokesperson, who reflected what he described as a cross-bench consensus: the Bill is "not nearly ambitious enough." In a summary published on 17 July, he identified two specific shortcomings.

First, scope. The statutory duties in the Bill apply to a comparatively small population of regulated entities - operators of essential services, qualifying managed service providers, data centres, large load controllers and designated critical suppliers. Central government, public administrations and local authorities are "almost entirely exempt from the Bill's direct statutory duties." Given the volume of sensitive data and critical systems operated by public bodies, Lords are likely to press the Government on why the public sector sits largely outside the main statutory framework.

Second, EU alignment. Lord Clement-Jones argued the Bill represents a missed opportunity to align more closely with the NIS2 Directive, from which the UK diverged after leaving the EU. Organisations operating across both UK and EU jurisdictions would benefit from harmonisation; the divergence is a compliance overhead with no obvious policy rationale.

Theme 2: AI and Cyber-Enabled Fraud Are Absent

Lords raised two significant omissions from the Bill's text.

The Bill does not mention artificial intelligence anywhere in its provisions. The NCSC and Five Eyes partners have already published joint advisories warning that AI is compressing cyber threat timelines, and that 75 per cent of attacks on UK critical infrastructure are state-linked. For a Bill presented as the UK's primary cyber resilience reform, the complete silence on AI-specific risks was noted as incongruous. Lords may seek provisions requiring regulated entities to assess AI-related risks or requiring regulators to publish AI threat guidance.

Cyber-enabled fraud is equally absent. The estimated annual cost to the UK economy runs to billions of pounds. Lords raised the concern that a Bill framed around cyber resilience has nothing to say about the cyber-enabled crime that causes the most direct financial harm to individuals and smaller businesses. Whether this produces a specific amendment or a Government commitment to address fraud through separate legislation remains to be seen at Committee.

Theme 3: Digital Sovereignty and the Transnational Repression Amendment

Baroness Bennett of Manor Castle used the Second Reading to revive the "transnational repression amendment" that was voted down in the Commons before Third Reading. The amendment would prevent the UK from sharing private information with overseas authorities in jurisdictions where the right to a fair trial cannot be guaranteed - a provision aimed specifically at China and Hong Kong.

The Bill's Part 4 confers broad powers on the Secretary of State to issue national security directions, including information-sharing arrangements. Critics, including Hong Kong Watch, argue that without an explicit carve-out those provisions could expose at-risk individuals in the Hong Kong diaspora to serious harm. Baroness Bennett indicated that Lord Alton of Liverpool - a patron of Hong Kong Watch and chair of the Joint Committee on Human Rights - is expected to reintroduce the amendment formally at Committee Stage.

Theme 4: SME Burden and Compliance Proportionality

The Association of British Insurers, Zurich and industry bodies representing smaller managed service providers all submitted briefings to Lords ahead of the Second Reading. A consistent thread was the compliance burden on organisations that sit just above the in-scope threshold but lack the in-house legal and compliance resource of larger firms.

The 24-hour and 72-hour incident reporting obligations attracted particular attention. Meeting the 24-hour initial notification window while simultaneously managing an active incident - before its full scope is understood - is a demanding operational requirement for any organisation without a dedicated security operations centre. The ABI made the additional point that cyber insurance arrangements can have a measurable positive effect on cyber resilience behaviour, and suggested the Bill's framework might usefully acknowledge that.

These concerns did not coalesce around a single amendment at this stage. But having been placed on the record at Second Reading, the Government will need to address them at Committee.

Theme 5: Bot Traffic and Sector Gaps

The News Media Association submitted a briefing to Lords drawing attention to automated bot traffic, which now accounts for approximately 50 per cent of all internet traffic. Bots distort advertising markets, enable content scraping at scale, and can form part of coordinated disinformation and denial-of-service campaigns. The Association's briefing reflects a broader concern that the Bill's scope boundaries leave parts of the digital ecosystem inadequately protected.

The Committee Reports That Will Shape Scrutiny

Two Lords committee reports are now formally in play alongside the debate. Both will feed directly into Committee Stage proceedings.

The Lords Select Committee on the Constitution published its report on the Bill on 1 July 2026 (3rd Report of Session 2026-27, HL Paper 28). It flagged concern about the breadth of the Secretary of State's powers to make regulations - particularly Clause 29, which enables secondary legislation to manage network and information systems risks. The Committee also noted that the Government has not published a full European Convention on Human Rights memorandum, which it said inhibits parliamentary scrutiny of the Bill.

The Delegated Powers and Regulatory Reform Committee published its Seventh Report of Session 2026-27 (HL Paper 41) on 21 July 2026 - the most recent primary document on the Bill. It examined Clause 40(5), which grants the Secretary of State the power to amend Clause 40 itself by regulations - a Henry VIII power that would allow primary legislation to be altered without a further Act of Parliament. The Committee found this provision to be broader than justified. Its recommendations will be a direct input to Committee Stage amendments on secondary legislation and ministerial powers.

For organisations trying to plan compliance, these reports matter because they may result in the skeletal structure of the Bill being either tightened on the face of the primary legislation, or accompanied by commitments to publish secondary legislation in draft for further scrutiny before it is laid. Either outcome would improve legal certainty around the obligations that will actually apply.

What Happens Next: Committee Stage on 1 September 2026

Committee Stage is confirmed to begin on 1 September 2026. Unlike the Commons, where the Bill was scrutinised by a Public Bill Committee of around twenty MPs, Lords Committee Stage takes place on the floor of the chamber. All Lords may attend and move amendments.

The consequence is that Committee Stage is slower and more detailed. In bills that leave significant detail to secondary legislation - as this one does - Lords committee scrutiny typically results in either textual amendments that put more of the regulatory architecture into the primary legislation, or Government commitments to publish secondary legislation in draft and conduct further consultation.

The number and diversity of themes placed on record at Second Reading suggest a substantial Committee Stage. If the Lords complete their stages efficiently, Royal Assent in autumn or winter 2026 remains achievable. Extended debate on delegated powers, scope, or the transnational repression amendment could affect that timetable.

What Organisations Should Do Now

For managed service providers, data centre operators, utilities and energy providers and other organisations in scope, the period between now and Committee Stage is the window in which to engage with the legislative process and to advance internal compliance preparation in parallel.

  1. Monitor Committee Stage from 1 September. Amendments tabled will show exactly where the Bill may change. Track which provisions face the most pressure and plan for alternative scenarios - particularly around scope boundaries, reporting thresholds and the secondary legislation that will define specific obligations.

  2. Engage through your trade association. Collective responses to the forthcoming DSIT implementation consultation carry weight. The pre-Second-Reading briefings from ABI, NMA and Zurich demonstrate the value of sector co-ordination in placing issues on the parliamentary record.

  3. Build and test your 24-hour incident notification workflow now. The core reporting obligation is not going to be amended away. Organisations that build and rehearse their notification processes before commencement are in a materially stronger position than those that improvise during an actual incident.

  4. Benchmark against the Cyber Assessment Framework (CAF). The CAF is expected to underpin how regulators assess compliance under the Bill. Aligning to it now reduces the gap that will need to be closed when duties take effect - and demonstrates a proactive approach if a regulator comes calling.

For a complete overview of what the Bill requires, see what is it and what the Bill changes. The full text of HL Bill 32 is available on this site.

This article reflects the position as of 22 July 2026. The Lords Second Reading took place on 14 July 2026 as confirmed by the official Parliament news page and Hansard. Lords Committee Stage on 1 September 2026 was confirmed from the Parliament.uk news release and multiple secondary sources. Lord Clement-Jones's post-debate summary was published on 17 July 2026. The Delegated Powers and Regulatory Reform Committee Seventh Report (HL Paper 41) was published 21 July 2026. For the latest parliamentary position, see bills.parliament.uk/bills/4035.

Tags:
CSRBcyber securityUK legislationcomplianceHouse of LordsHL Bill 32Lords second readingLords committee stageLord Clement-JonesBaroness Lloyd of EffraBaroness BennettLord AltonHenry VIII powersdelegated powersAIdigital sovereigntytransnational repressionmanaged service providersdata centresincident reportingNIS
Last updated: 22 July 2026
Share:

You Might Also Like

Explore more insights and guidance on the Cyber Security and Resilience Bill.

Precursor Security
26 Jun 2026

CSRB Lords Second Reading Scheduled for 14 July 2026

The House of Lords has fixed 14 July 2026 for its Second Reading of HL Bill 32, with a dedicated Lords Library briefing published to accompany the debate. Here is what a Lords Second Reading actually does, the reservations peers are most likely to put on the record, and how the remaining stages shape your compliance timeline.

CSRBcyber security+10 more
Read Article
Precursor Security
3 Jul 2026

UK Cyber Breaches Survey 2026: The CSRB Compliance Gap

DSIT's Cyber Security Breaches Survey 2025/2026 put 43% of UK businesses on the wrong end of a breach. The more revealing numbers sit beneath that headline: only 40% told anyone outside the organisation, and only 25% hold a formal incident response plan. Here is what that gap means once the CSRB's 24/72-hour reporting duty becomes law.

CSRBcyber security+12 more
Read Article
Precursor Security
21 Jun 2026

Cyber Security and Resilience Bill Clears the Commons: Where It Stands in 2026

The Cyber Security and Resilience Bill has cleared every House of Commons stage and passed to the Lords as HL Bill 32. The core architecture survived intact - expanded scope, 24/72-hour reporting, £17m penalties - with one headline change: Ofcom is now the sole regulator for data centres. Here is the confirmed timeline and what to do before Royal Assent, expected late 2026.

CSRBcyber security+12 more
Read Article