ComplianceBack to Blog

Cyber Security and Resilience Bill: New Powers to Block Risky Suppliers

Ahead of Lords Committee Stage, the Government has tabled amendments to the Cyber Security and Resilience Bill (CSRB) creating a new 'vendor-related direction' power - letting ministers order essential and digital service providers to stop buying from, restrict, or remove technology from suppliers judged a national security risk. Here is what it does, how it differs from the Huawei-era telecoms powers, and what your supply chain team should do now.

Precursor Security
2 September 2026
7 min read
1,428 words

Precursor Security

Precursor Security is a UK-based penetration testing and offensive security testing company with 24/7 security operations centres. We are CREST certified in both penetration testing and security operations, providing comprehensive cyber security services to help organisations achieve regulatory compliance and enhance their security posture.

Share:

Ahead of Lords Committee Stage, which began on 1 September 2026, the Government tabled a significant package of amendments to the Cyber Security and Resilience Bill (CSRB), now HL Bill 32. The headline change is a new power of "vendor-related direction" that would let ministers order essential and digital service providers to stop buying from, restrict, or rip out equipment supplied by a company judged to be a national security risk. If it survives scrutiny, it is one of the most consequential supply chain provisions in UK cyber law - and it reaches far beyond the sectors most readers will expect.

This post explains what the vendor-direction power does, how it differs from the powers already used to remove Huawei from the UK's 5G networks, who falls in scope, and the practical steps in-scope organisations should take now.

The Government's amendments, introduced by Baroness Lloyd of Effra, the Minister for the Digital Economy, would give a senior minister a discretionary power to issue binding directions in relation to a supplier whose products or services could pose a critical risk to national security. Reporting on the tabled amendments describes three broad things a direction could require an in-scope organisation to do:

  • Stop procuring goods, services or facilities from a named supplier.
  • Restrict or place conditions on how that supplier's products or services are used.
  • Modify, disable or remove equipment or software already installed.

The stated purpose is to let the Government intervene where an essential service provider plans to buy from, or already relies on, "suppliers that could pose a critical national security risk, particularly where they have ties to hostile states who may seek to use products to spy, sabotage systems or cause disruption." In other words, it moves supplier risk from something regulators encourage you to manage into something the state can compel you to act on.

This sits alongside the Bill's existing "designated critical suppliers" regime, under which regulators can designate a supplier whose disruption would significantly affect essential or digital services and impose security duties on it. The vendor-direction power is different in kind: it targets the buyer's use of a supplier, not just the supplier's own conduct, and it is framed around national security rather than routine resilience.

How this differs from the Huawei-era telecoms powers

The model here is not new. It adapts the designated vendor direction regime created by the Telecommunications (Security) Act 2021, which the Government used to require operators to remove Huawei equipment from 5G and full-fibre networks. What is new is the reach - and what has been stripped out.

Under the telecoms regime, ministers had to designate a vendor publicly before issuing a direction against it, and the vendor had to be notified. According to reporting on the CSRB amendments, those transparency safeguards are pared back: a minister would not have to publicly designate a supplier as a security risk before acting, and there would be no duty to send the affected supplier a copy of the order. Instead, the Government would be required to publish only higher-level data about the directions it has imposed, in an annual report to Parliament.

That trade-off - faster, quieter intervention in exchange for less individual transparency - is exactly the kind of point Lords flagged at Second Reading when they warned about the Bill's breadth of delegated powers. Expect it to be one of the most contested elements of Committee and Report Stage.

Who is in scope

The single most important thing to understand is that this is not a telecoms measure. The powers are drafted to reach across the sectors the Bill regulates, including:

If your organisation operates in any of these sectors, a vendor direction is not something that happens to your telecoms carrier - it is something that could land on you, requiring you to change a procurement decision or remove technology you have already deployed, potentially at your own cost and on the Government's timetable. Organisations already tracking the Bill's designated critical supplier duties should treat this as a closely related, and more directive, second front.

The data centre and AI dimension

The amendment package has also drawn attention for how far it could extend into data centres and artificial intelligence. Commentators have characterised part of it as a potential "kill switch" - the ability, in extremis, to require a data centre hosting AI workloads to be shut down or curtailed where it poses a critical threat to national infrastructure or security. The "kill switch" label is press shorthand rather than statutory wording, but the underlying direction: greater state reach over the physical and computational backbone of AI is consistent with the Government's decision to regulate data centres for the first time and to make Ofcom their sole regulator.

It is also notable given that the Bill as introduced was criticised at Second Reading for saying nothing about AI at all. The vendor-direction and data centre provisions are, in effect, the Government's first substantive answer to that criticism, even if they approach AI through the lens of supplier and infrastructure risk rather than model governance.

What the Cyber Security and Resilience Bill means for your supply chain now

Nothing here is in force yet - these are amendments in Committee, and the detail can still change. But the direction of travel is clear enough to act on, and the sensible steps are ones a well-run security function should be taking regardless:

  1. Build a real supplier inventory. You cannot respond to a vendor direction if you do not know where a given supplier's technology sits across your estate, including fourth-party and embedded dependencies. A software bill of materials and an up-to-date asset register are the foundation, and they map directly to Principles A3 and A4 of the NCSC Cyber Assessment Framework - see our CAF readiness guide for the Cyber Security and Resilience Bill.

  2. Assess supplier concentration and origin. Identify single points of dependence and suppliers with ownership or operational ties to higher-risk jurisdictions. This is not about blanket exclusion; it is about knowing your exposure before someone else decides it for you.

  3. Secure your exit and step-in rights. A direction could require you to remove or replace a supplier at short notice. Contracts should give you the commercial and technical ability to do that - exit assistance, data portability, and the right to substitute - rather than locking you in.

  4. Plan for confidentiality. Because a direction may arrive without the supplier being publicly named, you need internal governance to receive, act on and record sensitive instructions without breaching them. Legal, procurement and security should agree that process in advance.

  5. Diversify critical technology. Where feasible, avoid architectures that make one vendor impossible to remove. Designing for substitutability is the most durable hedge against a compelled change.

For a fuller view of how these obligations fit together, see what the Cyber Security and Resilience Bill is, the key changes it makes, and the text and structure of the Bill.

Where this sits in the Bill's timeline

The CSRB cleared all its Commons stages and passed to the House of Lords, where Second Reading was completed on 14 July 2026. Lords Committee Stage began on 1 September 2026, and these vendor-direction amendments are part of the Government's own contribution to that line-by-line scrutiny, alongside opposition and cross-bench amendments on issues such as AI, delegated powers and a review of the Computer Misuse Act 1990 to protect good-faith security researchers. Report Stage and the remaining Lords stages will follow, with Royal Assent still expected in late 2026 and most substantive duties commencing later through secondary legislation, following the Government's implementation consultation, towards 2028.

For the wider set of themes now driving Lords scrutiny, see our companion analysis of the Lords Second Reading and Committee Stage agenda, and for the end-to-end picture our definitive guide to the Cyber Security and Resilience Bill.

Position as at 2 September 2026. The new vendor-related direction powers are drawn from Government amendments tabled ahead of Lords Committee Stage (which began 1 September 2026) and reported by Recorded Future's The Record, Computer Weekly, IT Pro and MLex; the designated vendor precedent is the Telecommunications (Security) Act 2021. Stage dates are confirmed against the UK Parliament bill page for HL Bill 32 (Bill 4035). Amendment detail described here is reported and subject to change in Committee; verify specific clause wording against the Bill's amendment papers before relying on it.

Tags:
Cyber Security and Resilience BillCSRBCSRB compliancevendor directionsdesignated vendorsupply chain securitycritical suppliersnational securityUK legislationHouse of LordsHL Bill 32Lords committee stageBaroness Lloyd of Effradata centresmanaged service providersTelecommunications Security Act 2021AIComputer Misuse Act
Last updated: 2 September 2026
Share:

You Might Also Like

Explore more insights and guidance on the Cyber Security and Resilience Bill.

Precursor Security
22 Jul 2026

Lords Complete Cyber Security and Resilience Bill Second Reading: Key Themes and Committee Stage on 1 September

The Lords gave the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, cross-party support at Second Reading on 14 July 2026 without calling a division - but they put five pointed themes on the record, from the public sector exemption to the Bill's total silence on AI. Committee Stage begins on 1 September, and those themes are the working agenda. Here is what each one means for in-scope organisations.

CSRBcyber security+19 more
Read Article
Precursor Security
28 Jul 2026

The Cyber Security and Resilience Bill Skills Gap: Can UK Firms Resource the New Duties?

A new think-tank report warns the Cyber Security and Resilience Bill (CSRB) risks becoming a "paper tiger" unless the UK's cyber skills shortage is addressed. With 49% of businesses and 58% of government bodies reporting a basic skills gap, the people needed to run 24/72-hour reporting and ongoing risk management may not be there. Here is what in-scope organisations should do about it before the duties commence.

CSRBcyber security+14 more
Read Article
Precursor Security
3 Jul 2026

UK Cyber Breaches Survey 2026: The Cyber Security and Resilience Bill Compliance Gap

DSIT's Cyber Security Breaches Survey 2025/2026 put 43% of UK businesses on the wrong end of a breach. The more revealing numbers sit beneath that headline: only 40% told anyone outside the organisation, and only 25% hold a formal incident response plan. Here is what that gap means once the Cyber Security and Resilience Bill (CSRB) makes 24/72-hour reporting a legal duty.

CSRBcyber security+12 more
Read Article