ComplianceBack to Blog

Cyber Security and Resilience Bill: Lords Report Stage on 26 October 2026

Lords Report Stage of the Cyber Security and Resilience Bill is scheduled for 26 October 2026. It is the first chance in the Lords to vote amendments into the Bill. Only 5 of 193 Committee amendments were agreed, and the Government's vendor-related direction powers are still to come. Here is what to expect and what to do now.

Precursor Security
29 September 2026
10 min read
2,192 words

Precursor Security

Precursor Security is a UK-based penetration testing and offensive security testing company with 24/7 security operations centres. We are CREST certified in both penetration testing and security operations, providing comprehensive cyber security services to help organisations achieve regulatory compliance and enhance their security posture.

Share:

The House of Lords will hold Report Stage on the Cyber Security and Resilience Bill on Monday 26 October 2026. This is the first stage of the Bill's Lords passage at which amendments can be put to a vote of the whole House, so it is the most likely point for the Bill's text to change before Royal Assent. The Government is also expected to bring back its package of new vendor-related direction powers over risky technology suppliers, which it tabled for Committee but did not move.

Key takeaways

  • Date: Lords Report Stage of the Cyber Security and Resilience Bill is scheduled for 26 October 2026, according to the UK Parliament stages page. Parliament notes that future dates may be provisional.
  • Bill number: peers will consider HL Bill 49, the reprint of the Bill as amended in Grand Committee, which replaced HL Bill 32.
  • Committee changed little: of 193 amendments tabled for Lords Committee Stage, only 5 were agreed, all of them Government amendments. None was put to a vote.
  • Vendor powers are still to come: the Government tabled more than 60 amendments creating a vendor-related direction power, debated them on 1 September, then did not move them. The minister said she would engage peers on the package "ahead of Report".
  • Nothing changes for compliance on 26 October: Report Stage commences no duties. Royal Assent is expected between late 2026 and spring 2027, with most duties arriving later through secondary legislation.

When is Report Stage for the Cyber Security and Resilience Bill?

Lords Report Stage is scheduled for 26 October 2026. The House of Lords rose for the conference recess on 18 September and returns on 12 October 2026, so peers will have two sitting weeks to table and group amendments before the debate. Any amendments for Report will be published on the Bill's publications page as a marshalled list shortly before the sitting.

Lords Committee Stage finished on 7 September 2026 after three days in Grand Committee, on 1, 3 and 7 September. The Bill was then reprinted as HL Bill 49 (as amended in Grand Committee). You can see how this fits the Bill's full passage on our what the Bill is page.

Why does Report Stage matter more than Committee Stage?

Report Stage matters more because amendments can be pressed to a vote and carried against the Government. Lords Committee Stage on this Bill took place in Grand Committee, a committee room procedure where decisions have to be unanimous. In practice that means amendments can only be probed and withdrawn, not voted through.

The Committee record shows this clearly. Of the 193 amendments tabled:

Outcome at Lords Committee Stage Government amendments Other peers' amendments
Agreed 5 0
Withdrawn after debate 1 20
Not moved 63 104
Total 69 124

Source: UK Parliament, Committee Stage amendments list for the Bill.

At Report Stage the Bill is debated in the main chamber, every member can take part and divisions are allowed. A peer who withdrew an amendment in September can table it again and ask the House to vote on it. That is why 26 October is the most important date for how the Bill's final duties will read.

What did Lords Committee Stage actually change?

The five amendments agreed in Committee were narrow. They are now part of HL Bill 49:

  • Large load controllers (amendments 4 and 5): the new essential service of load control only applies to organisations that carry on activities for "system-balancing purposes", meaning activities that contribute to the balancing, flexibility, security or stability of the electricity system. Read more on our large load controllers page.
  • Incident reporting (amendments 19, 36 and 44): operators of essential services, relevant digital service providers and relevant managed service providers must now consider whether any data relating to the service has been compromised when deciding whether an incident is reportable. Previously the test was only data relating to users of the service.

Everything else, including the AI, Computer Misuse Act and public-sector amendments, left Committee unchanged.

Which amendments are likely to return at Report Stage?

These are the issues peers pressed in Committee and said they would bring back, or where the Government committed to act before Report.

Issue Led by Committee outcome Government position
Vendor-related direction power Government (Baroness Lloyd of Effra) Debated 1 September, not moved Will engage peers "ahead of Report"
Delegated powers (Clauses 37(7) and 40(5)) Lord Clement-Jones Withdrawn Will respond formally to the Delegated Powers Committee ahead of Report
Computer Misuse Act review (amendment 164) Lord Clement-Jones Withdrawn Reform to come in the national security Bill announced in the May King's Speech
AI products and services in scope (amendment 6) Baroness Kidron Withdrawn Resisted; AI's impact kept "under review"
AI "kill switch" (amendment 84) Lord Clement-Jones Not moved Exploring "proportionate containment powers" instead
Public bodies, councils and elections in scope (81B-81D) Lord Clement-Jones Not moved Engagement on new sectors offered ahead of Report

This is the biggest expected change at Report. The Government tabled the package on 24 August 2026. It would let the Secretary of State, or the Chancellor of the Duchy of Lancaster, direct in-scope organisations to restrict, remove or modify goods, services or facilities from a vendor that poses a national security risk. The minister told peers the power would apply "to operators of essential services in the first instance". It would come with procurement guidance, a voluntary referral route into government, and a power to create a mandatory referral scheme later if needed.

Because these amendments were not moved in Committee, they are not yet in the Bill. If the Government re-tables them for Report, peers will be able to vote on them. Our post on new powers to block risky suppliers explains how the power would work.

Computer Misuse Act reform

Lord Clement-Jones's amendment 164 would have required the Secretary of State to review, within 12 months of Royal Assent, whether a statutory defence under section 1 of the Computer Misuse Act 1990 is needed for people carrying on legitimate cyber security activities. The Government said that review would be too narrow, and pointed to the national security Bill announced in the May 2026 King's Speech, which includes measures to update the Computer Misuse Act. Lord Clement-Jones withdrew the amendment, saying he hoped for "more clarity" on the timing of that Bill "between Committee and Report".

This matters to any organisation that commissions penetration testing or runs a vulnerability disclosure programme, because it decides how that work is treated in criminal law.

AI scope and the AI "kill switch"

Baroness Kidron's amendment 6, backed by Lord Clement-Jones, Lord Tarassenko and Lord Holmes of Richmond, would have added AI products and services to the digital services the Bill covers. Lord Tarassenko told the Committee there was an "AI-shaped hole in the Bill". The minister, Baroness Lloyd of Effra, replied that the Bill regulates risks to the systems of the organisations it covers, and that the Government will keep AI's impact "under review". The amendment was withdrawn.

Lord Clement-Jones's amendment 84 proposed a last-resort power to shut down an AI model in critical infrastructure, which he called an "emergency kill switch". It was debated but not moved. The Government argued that the Bill's existing direction powers could already require an organisation to "cease using and isolate an AI model". It also said it was examining "proportionate containment powers", including powers "to restrict access to specific AI systems". We cover this debate in detail in our analysis of the AI scope debate at Lords Committee.

Delegated powers and the public sector

The Delegated Powers and Regulatory Reform Committee recommended removing Clause 37(7) and Clause 40(5). These clauses would let ministers amend the Bill's own consultation and reporting requirements by regulations. Lord Clement-Jones said that if the Government does not respond to both recommendations "we will bring this back on Report". The Government said it would respond to the committee formally before Report.

Lord Clement-Jones also tabled amendments 81B to 81D to bring central government, local authorities and electoral infrastructure into scope. They were not moved. The minister offered further engagement "ahead of Report" on which new sectors could be added. See our local councils page for what this means for the public sector.

What happens after Report Stage?

Step What happens Expected timing
Lords Report Stage Whole House debates and votes on amendments 26 October 2026
Lords Third Reading Final tidying amendments in the Lords After Report, date not yet set
Commons consideration of Lords amendments MPs accept or reject each Lords change ("ping-pong" if they disagree) After Third Reading
Royal Assent The Bill becomes an Act Expected late 2026 to spring 2027
Commencement Most duties switched on by secondary legislation Phased, full effect expected around 2028

The Bill has been carried over from the 2024-26 session. It cleared the Commons on 16 June 2026 and completed Lords Second Reading on 14 July 2026. For the full journey, see our analysis of the Lords Second Reading and Committee Stage agenda.

What should organisations do before 26 October?

  1. Scope yourself now. The Bill's core structure has been stable since the Commons: operators of essential services, relevant digital service providers, relevant managed service providers, data centres and designated critical suppliers. None of the amendments expected at Report would change whether most organisations are in scope. Use our key changes summary and the text of the Bill as a starting point.
  2. Check your incident reporting test. The Committee change means you must consider whether any data relating to your service was compromised, not only your users' data. Build that into your triage runbook alongside the 24-hour initial notification.
  3. Review supplier risk if you are an operator of an essential service. If the vendor-related direction power is added at Report, operators of essential services could be directed to remove or restrict specific suppliers. Now is the time to map which suppliers support your critical systems.
  4. Read the Report Stage marshalled list when it is published. It is the only reliable guide to what peers will vote on. Look for re-tabled amendments on delegated powers, the Computer Misuse Act and AI.
  5. Brief your board on the timeline. Royal Assent is still expected between late 2026 and spring 2027. Organisations that have not yet named an accountable owner or aligned to the NCSC Cyber Assessment Framework have a short runway.

Frequently asked questions

When is Report Stage for the Cyber Security and Resilience Bill?

Lords Report Stage is scheduled for 26 October 2026, according to the UK Parliament stages page for the Bill. It follows Lords Committee Stage, which sat in Grand Committee on 1, 3 and 7 September 2026. Parliament notes that future dates may be provisional.

Is the Cyber Security and Resilience Bill now HL Bill 32 or HL Bill 49?

It is now HL Bill 49. HL Bill 32 was the Bill as brought from the Commons on 17 June 2026. After Lords Committee Stage it was reprinted as HL Bill 49 (as amended in Grand Committee), and that is the text peers will amend at Report Stage.

Can the Lords defeat the Government at Report Stage?

Yes. Unlike Grand Committee, Report Stage takes place in the main chamber and amendments can be pressed to a division. If a majority of peers voting support an amendment, it is added to the Bill against the Government's wishes. MPs can then accept or reject it when the Bill returns to the Commons.

It is expected to be. The Government tabled the package on 24 August 2026 and debated it on 1 September, but did not move the amendments in Committee. The minister said she would engage peers on the package ahead of Report. Until it is agreed, the power is not part of the Bill.

Does anything change for my organisation on 26 October 2026?

No. Report Stage commences no duties. It only settles more of the final wording. Duties will start after Royal Assent, mostly through secondary legislation, with full effect expected around 2028.

When will the Cyber Security and Resilience Bill become law?

After Report Stage the Bill still needs Lords Third Reading and Commons consideration of any Lords amendments. Royal Assent is expected between late 2026 and spring 2027.

Sources

Position as at 30 September 2026. All dates, amendment numbers and outcomes were checked against the UK Parliament Bills site and Lords Hansard on that date. The Report Stage marshalled list had not yet been published.

Tags:
Cyber Security and Resilience BillCyber Security and Resilience Bill 2026Lords Report StageHL Bill 4926 October 2026vendor-related directionsComputer Misuse ActLord Clement-JonesBaroness Kidronincident reportingdelegated powersRoyal AssentUK legislationcompliance
Last updated: 30 September 2026
Share:

You Might Also Like

Explore more insights and guidance on the Cyber Security and Resilience Bill.

Precursor Security
7 Sept 2026

Cyber Security and Resilience Bill: AI Scope at Lords Committee

At Lords Committee Stage this month, the Government rejected calls to pull AI vendors into the Cyber Security and Resilience Bill, now HL Bill 32. The Bill regulates the organisations that use technology to deliver essential and digital services, not the companies that build AI models - so AI risk falls to in-scope entities to manage under their security duties. Here is what was debated in committee, including the rejected AI kill switch, and the steps to take now.

Cyber Security and Resilience Billartificial intelligence+13 more
Read Article
Precursor Security
22 Jul 2026

Lords Complete Cyber Security and Resilience Bill Second Reading: Key Themes and Committee Stage on 1 September

The Lords gave the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, cross-party support at Second Reading on 14 July 2026 without calling a division - but they put five pointed themes on the record, from the public sector exemption to the Bill's total silence on AI. Committee Stage begins on 1 September, and those themes are the working agenda. Here is what each one means for in-scope organisations.

CSRBcyber security+19 more
Read Article
Precursor Security
26 Jun 2026

Cyber Security and Resilience Bill: Lords Second Reading Scheduled for 14 July 2026

The House of Lords has fixed 14 July 2026 for its Second Reading of the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, with a dedicated Lords Library briefing published to accompany the debate. Here is what a Lords Second Reading actually does, the reservations peers are most likely to put on the record, and how the remaining stages shape your compliance timeline.

CSRBcyber security+10 more
Read Article