Lords Complete CSRB Second Reading: Key Themes and Committee Stage on 1 September
The House of Lords completed its Second Reading of HL Bill 32 on 14 July 2026, with Baroness Lloyd of Effra, the Government's Minister for Digital Economy, opening and closing for the Government. No division was called - the Lords gave the legislation cross-party support in principle - but the debate placed five clear themes on the record that will drive amendment activity when Committee Stage begins on 1 September 2026.
This article covers what was said, what the two new Lords committee reports mean, and what organisations in scope should be doing before scrutiny intensifies in the autumn.
What Second Reading Is - and Why the Debate Matters
Second Reading in the House of Lords is a general debate on the principles of a Bill. No amendments are moved at this stage. Its function is to allow Lords to express support for, or reservations about, the legislation's overall approach and to signal the areas they intend to pursue once Committee Stage begins.
Because the Bill arrived from the Commons having passed its Third Reading without a division, the Lords were never likely to reject it. What matters is what they chose to put on the record. Those statements now form the working agenda for Committee Stage, which unlike the Commons process is taken on the floor of the chamber, allowing all Lords to participate and to move amendments.
As our earlier post on the Second Reading anticipated, several themes were already predictable from the Commons passage. The 14 July debate confirmed which of those will be actively pursued.
Theme 1: The Bill Is "Not Nearly Ambitious Enough"
The most prominent criticism came from Lord Clement-Jones, the Liberal Democrat digital spokesperson, who reflected what he described as a cross-bench consensus: the Bill is "not nearly ambitious enough." In a summary published on 17 July, he identified two specific shortcomings.
First, scope. The statutory duties in the Bill apply to a comparatively small population of regulated entities - operators of essential services, qualifying managed service providers, data centres, large load controllers and designated critical suppliers. Central government, public administrations and local authorities are "almost entirely exempt from the Bill's direct statutory duties." Given the volume of sensitive data and critical systems operated by public bodies, Lords are likely to press the Government on why the public sector sits largely outside the main statutory framework.
Second, EU alignment. Lord Clement-Jones argued the Bill represents a missed opportunity to align more closely with the NIS2 Directive, from which the UK diverged after leaving the EU. Organisations operating across both UK and EU jurisdictions would benefit from harmonisation; the divergence is a compliance overhead with no obvious policy rationale.
Theme 2: AI and Cyber-Enabled Fraud Are Absent
Lords raised two significant omissions from the Bill's text.
The Bill does not mention artificial intelligence anywhere in its provisions. The NCSC and Five Eyes partners have already published joint advisories warning that AI is compressing cyber threat timelines, and that 75 per cent of attacks on UK critical infrastructure are state-linked. For a Bill presented as the UK's primary cyber resilience reform, the complete silence on AI-specific risks was noted as incongruous. Lords may seek provisions requiring regulated entities to assess AI-related risks or requiring regulators to publish AI threat guidance.
Cyber-enabled fraud is equally absent. The estimated annual cost to the UK economy runs to billions of pounds. Lords raised the concern that a Bill framed around cyber resilience has nothing to say about the cyber-enabled crime that causes the most direct financial harm to individuals and smaller businesses. Whether this produces a specific amendment or a Government commitment to address fraud through separate legislation remains to be seen at Committee.
Theme 3: Digital Sovereignty and the Transnational Repression Amendment
Baroness Bennett of Manor Castle used the Second Reading to revive the "transnational repression amendment" that was voted down in the Commons before Third Reading. The amendment would prevent the UK from sharing private information with overseas authorities in jurisdictions where the right to a fair trial cannot be guaranteed - a provision aimed specifically at China and Hong Kong.
The Bill's Part 4 confers broad powers on the Secretary of State to issue national security directions, including information-sharing arrangements. Critics, including Hong Kong Watch, argue that without an explicit carve-out those provisions could expose at-risk individuals in the Hong Kong diaspora to serious harm. Baroness Bennett indicated that Lord Alton of Liverpool - a patron of Hong Kong Watch and chair of the Joint Committee on Human Rights - is expected to reintroduce the amendment formally at Committee Stage.
Theme 4: SME Burden and Compliance Proportionality
The Association of British Insurers, Zurich and industry bodies representing smaller managed service providers all submitted briefings to Lords ahead of the Second Reading. A consistent thread was the compliance burden on organisations that sit just above the in-scope threshold but lack the in-house legal and compliance resource of larger firms.
The 24-hour and 72-hour incident reporting obligations attracted particular attention. Meeting the 24-hour initial notification window while simultaneously managing an active incident - before its full scope is understood - is a demanding operational requirement for any organisation without a dedicated security operations centre. The ABI made the additional point that cyber insurance arrangements can have a measurable positive effect on cyber resilience behaviour, and suggested the Bill's framework might usefully acknowledge that.
These concerns did not coalesce around a single amendment at this stage. But having been placed on the record at Second Reading, the Government will need to address them at Committee.
Theme 5: Bot Traffic and Sector Gaps
The News Media Association submitted a briefing to Lords drawing attention to automated bot traffic, which now accounts for approximately 50 per cent of all internet traffic. Bots distort advertising markets, enable content scraping at scale, and can form part of coordinated disinformation and denial-of-service campaigns. The Association's briefing reflects a broader concern that the Bill's scope boundaries leave parts of the digital ecosystem inadequately protected.
The Committee Reports That Will Shape Scrutiny
Two Lords committee reports are now formally in play alongside the debate. Both will feed directly into Committee Stage proceedings.
The Lords Select Committee on the Constitution published its report on the Bill on 1 July 2026 (3rd Report of Session 2026-27, HL Paper 28). It flagged concern about the breadth of the Secretary of State's powers to make regulations - particularly Clause 29, which enables secondary legislation to manage network and information systems risks. The Committee also noted that the Government has not published a full European Convention on Human Rights memorandum, which it said inhibits parliamentary scrutiny of the Bill.
The Delegated Powers and Regulatory Reform Committee published its Seventh Report of Session 2026-27 (HL Paper 41) on 21 July 2026 - the most recent primary document on the Bill. It examined Clause 40(5), which grants the Secretary of State the power to amend Clause 40 itself by regulations - a Henry VIII power that would allow primary legislation to be altered without a further Act of Parliament. The Committee found this provision to be broader than justified. Its recommendations will be a direct input to Committee Stage amendments on secondary legislation and ministerial powers.
For organisations trying to plan compliance, these reports matter because they may result in the skeletal structure of the Bill being either tightened on the face of the primary legislation, or accompanied by commitments to publish secondary legislation in draft for further scrutiny before it is laid. Either outcome would improve legal certainty around the obligations that will actually apply.
What Happens Next: Committee Stage on 1 September 2026
Committee Stage is confirmed to begin on 1 September 2026. Unlike the Commons, where the Bill was scrutinised by a Public Bill Committee of around twenty MPs, Lords Committee Stage takes place on the floor of the chamber. All Lords may attend and move amendments.
The consequence is that Committee Stage is slower and more detailed. In bills that leave significant detail to secondary legislation - as this one does - Lords committee scrutiny typically results in either textual amendments that put more of the regulatory architecture into the primary legislation, or Government commitments to publish secondary legislation in draft and conduct further consultation.
The number and diversity of themes placed on record at Second Reading suggest a substantial Committee Stage. If the Lords complete their stages efficiently, Royal Assent in autumn or winter 2026 remains achievable. Extended debate on delegated powers, scope, or the transnational repression amendment could affect that timetable.
What Organisations Should Do Now
For managed service providers, data centre operators, utilities and energy providers and other organisations in scope, the period between now and Committee Stage is the window in which to engage with the legislative process and to advance internal compliance preparation in parallel.
-
Monitor Committee Stage from 1 September. Amendments tabled will show exactly where the Bill may change. Track which provisions face the most pressure and plan for alternative scenarios - particularly around scope boundaries, reporting thresholds and the secondary legislation that will define specific obligations.
-
Engage through your trade association. Collective responses to the forthcoming DSIT implementation consultation carry weight. The pre-Second-Reading briefings from ABI, NMA and Zurich demonstrate the value of sector co-ordination in placing issues on the parliamentary record.
-
Build and test your 24-hour incident notification workflow now. The core reporting obligation is not going to be amended away. Organisations that build and rehearse their notification processes before commencement are in a materially stronger position than those that improvise during an actual incident.
-
Benchmark against the Cyber Assessment Framework (CAF). The CAF is expected to underpin how regulators assess compliance under the Bill. Aligning to it now reduces the gap that will need to be closed when duties take effect - and demonstrates a proactive approach if a regulator comes calling.
For a complete overview of what the Bill requires, see what is it and what the Bill changes. The full text of HL Bill 32 is available on this site.
This article reflects the position as of 22 July 2026. The Lords Second Reading took place on 14 July 2026 as confirmed by the official Parliament news page and Hansard. Lords Committee Stage on 1 September 2026 was confirmed from the Parliament.uk news release and multiple secondary sources. Lord Clement-Jones's post-debate summary was published on 17 July 2026. The Delegated Powers and Regulatory Reform Committee Seventh Report (HL Paper 41) was published 21 July 2026. For the latest parliamentary position, see bills.parliament.uk/bills/4035.