The House of Lords will hold Report Stage on the Cyber Security and Resilience Bill on Monday 26 October 2026. This is the first stage of the Bill's Lords passage at which amendments can be put to a vote of the whole House, so it is the most likely point for the Bill's text to change before Royal Assent. The Government is also expected to bring back its package of new vendor-related direction powers over risky technology suppliers, which it tabled for Committee but did not move.
Key takeaways
- Date: Lords Report Stage of the Cyber Security and Resilience Bill is scheduled for 26 October 2026, according to the UK Parliament stages page. Parliament notes that future dates may be provisional.
- Bill number: peers will consider HL Bill 49, the reprint of the Bill as amended in Grand Committee, which replaced HL Bill 32.
- Committee changed little: of 193 amendments tabled for Lords Committee Stage, only 5 were agreed, all of them Government amendments. None was put to a vote.
- Vendor powers are still to come: the Government tabled more than 60 amendments creating a vendor-related direction power, debated them on 1 September, then did not move them. The minister said she would engage peers on the package "ahead of Report".
- Nothing changes for compliance on 26 October: Report Stage commences no duties. Royal Assent is expected between late 2026 and spring 2027, with most duties arriving later through secondary legislation.
When is Report Stage for the Cyber Security and Resilience Bill?
Lords Report Stage is scheduled for 26 October 2026. The House of Lords rose for the conference recess on 18 September and returns on 12 October 2026, so peers will have two sitting weeks to table and group amendments before the debate. Any amendments for Report will be published on the Bill's publications page as a marshalled list shortly before the sitting.
Lords Committee Stage finished on 7 September 2026 after three days in Grand Committee, on 1, 3 and 7 September. The Bill was then reprinted as HL Bill 49 (as amended in Grand Committee). You can see how this fits the Bill's full passage on our what the Bill is page.
Why does Report Stage matter more than Committee Stage?
Report Stage matters more because amendments can be pressed to a vote and carried against the Government. Lords Committee Stage on this Bill took place in Grand Committee, a committee room procedure where decisions have to be unanimous. In practice that means amendments can only be probed and withdrawn, not voted through.
The Committee record shows this clearly. Of the 193 amendments tabled:
| Outcome at Lords Committee Stage |
Government amendments |
Other peers' amendments |
| Agreed |
5 |
0 |
| Withdrawn after debate |
1 |
20 |
| Not moved |
63 |
104 |
| Total |
69 |
124 |
Source: UK Parliament, Committee Stage amendments list for the Bill.
At Report Stage the Bill is debated in the main chamber, every member can take part and divisions are allowed. A peer who withdrew an amendment in September can table it again and ask the House to vote on it. That is why 26 October is the most important date for how the Bill's final duties will read.
What did Lords Committee Stage actually change?
The five amendments agreed in Committee were narrow. They are now part of HL Bill 49:
- Large load controllers (amendments 4 and 5): the new essential service of load control only applies to organisations that carry on activities for "system-balancing purposes", meaning activities that contribute to the balancing, flexibility, security or stability of the electricity system. Read more on our large load controllers page.
- Incident reporting (amendments 19, 36 and 44): operators of essential services, relevant digital service providers and relevant managed service providers must now consider whether any data relating to the service has been compromised when deciding whether an incident is reportable. Previously the test was only data relating to users of the service.
Everything else, including the AI, Computer Misuse Act and public-sector amendments, left Committee unchanged.
Which amendments are likely to return at Report Stage?
These are the issues peers pressed in Committee and said they would bring back, or where the Government committed to act before Report.
| Issue |
Led by |
Committee outcome |
Government position |
| Vendor-related direction power |
Government (Baroness Lloyd of Effra) |
Debated 1 September, not moved |
Will engage peers "ahead of Report" |
| Delegated powers (Clauses 37(7) and 40(5)) |
Lord Clement-Jones |
Withdrawn |
Will respond formally to the Delegated Powers Committee ahead of Report |
| Computer Misuse Act review (amendment 164) |
Lord Clement-Jones |
Withdrawn |
Reform to come in the national security Bill announced in the May King's Speech |
| AI products and services in scope (amendment 6) |
Baroness Kidron |
Withdrawn |
Resisted; AI's impact kept "under review" |
| AI "kill switch" (amendment 84) |
Lord Clement-Jones |
Not moved |
Exploring "proportionate containment powers" instead |
| Public bodies, councils and elections in scope (81B-81D) |
Lord Clement-Jones |
Not moved |
Engagement on new sectors offered ahead of Report |
This is the biggest expected change at Report. The Government tabled the package on 24 August 2026. It would let the Secretary of State, or the Chancellor of the Duchy of Lancaster, direct in-scope organisations to restrict, remove or modify goods, services or facilities from a vendor that poses a national security risk. The minister told peers the power would apply "to operators of essential services in the first instance". It would come with procurement guidance, a voluntary referral route into government, and a power to create a mandatory referral scheme later if needed.
Because these amendments were not moved in Committee, they are not yet in the Bill. If the Government re-tables them for Report, peers will be able to vote on them. Our post on new powers to block risky suppliers explains how the power would work.
Lord Clement-Jones's amendment 164 would have required the Secretary of State to review, within 12 months of Royal Assent, whether a statutory defence under section 1 of the Computer Misuse Act 1990 is needed for people carrying on legitimate cyber security activities. The Government said that review would be too narrow, and pointed to the national security Bill announced in the May 2026 King's Speech, which includes measures to update the Computer Misuse Act. Lord Clement-Jones withdrew the amendment, saying he hoped for "more clarity" on the timing of that Bill "between Committee and Report".
This matters to any organisation that commissions penetration testing or runs a vulnerability disclosure programme, because it decides how that work is treated in criminal law.
AI scope and the AI "kill switch"
Baroness Kidron's amendment 6, backed by Lord Clement-Jones, Lord Tarassenko and Lord Holmes of Richmond, would have added AI products and services to the digital services the Bill covers. Lord Tarassenko told the Committee there was an "AI-shaped hole in the Bill". The minister, Baroness Lloyd of Effra, replied that the Bill regulates risks to the systems of the organisations it covers, and that the Government will keep AI's impact "under review". The amendment was withdrawn.
Lord Clement-Jones's amendment 84 proposed a last-resort power to shut down an AI model in critical infrastructure, which he called an "emergency kill switch". It was debated but not moved. The Government argued that the Bill's existing direction powers could already require an organisation to "cease using and isolate an AI model". It also said it was examining "proportionate containment powers", including powers "to restrict access to specific AI systems". We cover this debate in detail in our analysis of the AI scope debate at Lords Committee.
Delegated powers and the public sector
The Delegated Powers and Regulatory Reform Committee recommended removing Clause 37(7) and Clause 40(5). These clauses would let ministers amend the Bill's own consultation and reporting requirements by regulations. Lord Clement-Jones said that if the Government does not respond to both recommendations "we will bring this back on Report". The Government said it would respond to the committee formally before Report.
Lord Clement-Jones also tabled amendments 81B to 81D to bring central government, local authorities and electoral infrastructure into scope. They were not moved. The minister offered further engagement "ahead of Report" on which new sectors could be added. See our local councils page for what this means for the public sector.
What happens after Report Stage?
| Step |
What happens |
Expected timing |
| Lords Report Stage |
Whole House debates and votes on amendments |
26 October 2026 |
| Lords Third Reading |
Final tidying amendments in the Lords |
After Report, date not yet set |
| Commons consideration of Lords amendments |
MPs accept or reject each Lords change ("ping-pong" if they disagree) |
After Third Reading |
| Royal Assent |
The Bill becomes an Act |
Expected late 2026 to spring 2027 |
| Commencement |
Most duties switched on by secondary legislation |
Phased, full effect expected around 2028 |
The Bill has been carried over from the 2024-26 session. It cleared the Commons on 16 June 2026 and completed Lords Second Reading on 14 July 2026. For the full journey, see our analysis of the Lords Second Reading and Committee Stage agenda.
What should organisations do before 26 October?
- Scope yourself now. The Bill's core structure has been stable since the Commons: operators of essential services, relevant digital service providers, relevant managed service providers, data centres and designated critical suppliers. None of the amendments expected at Report would change whether most organisations are in scope. Use our key changes summary and the text of the Bill as a starting point.
- Check your incident reporting test. The Committee change means you must consider whether any data relating to your service was compromised, not only your users' data. Build that into your triage runbook alongside the 24-hour initial notification.
- Review supplier risk if you are an operator of an essential service. If the vendor-related direction power is added at Report, operators of essential services could be directed to remove or restrict specific suppliers. Now is the time to map which suppliers support your critical systems.
- Read the Report Stage marshalled list when it is published. It is the only reliable guide to what peers will vote on. Look for re-tabled amendments on delegated powers, the Computer Misuse Act and AI.
- Brief your board on the timeline. Royal Assent is still expected between late 2026 and spring 2027. Organisations that have not yet named an accountable owner or aligned to the NCSC Cyber Assessment Framework have a short runway.
Frequently asked questions
When is Report Stage for the Cyber Security and Resilience Bill?
Lords Report Stage is scheduled for 26 October 2026, according to the UK Parliament stages page for the Bill. It follows Lords Committee Stage, which sat in Grand Committee on 1, 3 and 7 September 2026. Parliament notes that future dates may be provisional.
Is the Cyber Security and Resilience Bill now HL Bill 32 or HL Bill 49?
It is now HL Bill 49. HL Bill 32 was the Bill as brought from the Commons on 17 June 2026. After Lords Committee Stage it was reprinted as HL Bill 49 (as amended in Grand Committee), and that is the text peers will amend at Report Stage.
Can the Lords defeat the Government at Report Stage?
Yes. Unlike Grand Committee, Report Stage takes place in the main chamber and amendments can be pressed to a division. If a majority of peers voting support an amendment, it is added to the Bill against the Government's wishes. MPs can then accept or reject it when the Bill returns to the Commons.
It is expected to be. The Government tabled the package on 24 August 2026 and debated it on 1 September, but did not move the amendments in Committee. The minister said she would engage peers on the package ahead of Report. Until it is agreed, the power is not part of the Bill.
Does anything change for my organisation on 26 October 2026?
No. Report Stage commences no duties. It only settles more of the final wording. Duties will start after Royal Assent, mostly through secondary legislation, with full effect expected around 2028.
When will the Cyber Security and Resilience Bill become law?
After Report Stage the Bill still needs Lords Third Reading and Commons consideration of any Lords amendments. Royal Assent is expected between late 2026 and spring 2027.
Sources
- UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill: stages (Report Stage date, stage history)
- UK Parliament, Committee Stage amendments (amendment numbers, sponsors and outcomes)
- UK Parliament, Bill publications (HL Bill 49, marshalled lists)
- Lords Hansard, Grand Committee debates of 1 September, 3 September and 7 September 2026
- UK Parliament news, Cyber security bill completes Lords committee stage, 8 September 2026
Position as at 30 September 2026. All dates, amendment numbers and outcomes were checked against the UK Parliament Bills site and Lords Hansard on that date. The Report Stage marshalled list had not yet been published.