Legislative Changes

What's Changing Under the Cyber Security and Resilience Bill?

The UK's new Cyber Security and Resilience Bill (introduced November 2025) is the biggest update to cyber legislation in over a decade. It expands who needs to comply, introduces stricter incident reporting rules, and gives regulators stronger enforcement powers. This guide explains 11 major changes and what they mean for your organisation - in plain English.

What's Changing:

  • Managed Service Providers (MSPs) providing IT support, maintenance, or monitoring are now regulated (small businesses are exempt)
  • Data centres with 1MW+ capacity (or 10MW+ for enterprise-only) are now essential services
  • Large load controllers managing 300MW+ of electrical control are now regulated
  • Suppliers to regulated organisations can be designated as 'critical suppliers' - even small businesses
  • Cloud computing, online marketplaces, and search engines are now 'relevant digital services'
  • Organisations can be regulated whether or not they're based in the UK
  • Public sector organisations may be regulated even if they generate commercial income

Impact:

  • Hundreds of previously unregulated organisations will now need to comply - potentially thousands of new entities
  • Even small suppliers can be designated as 'critical suppliers' if their failure would disrupt essential services
  • You must register with your regulator within 3 months, and update your registration within 7 days of any changes
  • Your registration information will be shared with GCHQ for national security purposes
  • If you're based outside the UK, you must nominate a UK representative within 3 months
  • Government data centres are now regulated (with some security service exceptions)
  • Small businesses remain exempt but must monitor if they grow beyond the thresholds

What You Must Do:

  • Check if you meet the thresholds - calculate your data centre capacity or load control capacity if applicable
  • Assess whether you might be designated as a critical supplier if you supply to regulated organisations
  • Gather registration information now: company details, directors, contact information, and services you provide
  • If you're based outside the UK, identify and prepare a UK representative with full contact details
  • Set up processes to update your registration within 7 days whenever your details change
  • For MSPs: Review your service contracts to confirm if you qualify as a managed service provider
  • For data centres: Calculate your rated IT load to determine if you're above the thresholds

What's Changing:

  • The definition of 'incident' now includes potential impacts, not just actual damage - you must report threats that could cause harm
  • Initial incident notification required within 24 hours, full detailed report within 72 hours to both your regulator and CSIRT
  • Data centre operators face a lower reporting threshold - any incident with significant impact must be reported
  • You must notify affected UK customers as soon as reasonably practicable after reporting to regulators
  • Regulators may require you to publicly disclose incidents if necessary to manage the threat or prevent future incidents
  • Information about your incidents may be shared with other regulated organisations to help prevent similar attacks
  • You must provide annual reports on incidents to the Single Point of Contact by 1 July each year
  • Incidents affecting data confidentiality, system availability, or having significant economic/social impact must be reported

Impact:

  • You need 24/7 monitoring capability - 24 hours is a very tight deadline to detect, assess, and report incidents
  • Failure to report on time can result in penalties up to the greater of £17 million and 4% of your turnover
  • You must notify both your regulator AND CSIRT at the same time - you can't report to one then the other
  • Customer notification adds pressure - you must quickly identify affected UK customers and explain what happened
  • Data centre operators have a lower threshold - any significant impact triggers reporting requirements
  • You may be required to publicly disclose incidents even if you'd prefer to keep them private
  • Details of your incidents may be shared with other organisations to help prevent similar attacks
  • Annual reporting creates an ongoing compliance requirement - you must track and report incidents each year

What You Must Do:

  • Set up 24/7 monitoring and detection systems - you need to spot incidents immediately, not days later
  • Train your team to identify potential threats, not just actual damage - the definition of 'incident' is now broader
  • Assign specific people responsible for reporting with clear escalation procedures and backup contacts
  • Create customer notification templates ready to use - you'll need to explain what happened and why customers are affected
  • Build processes to quickly identify which UK customers are affected after an incident
  • Prepare communication plans for potential public disclosure - you may not have a choice about going public
  • Set up systems to track all incidents for your annual reporting requirement
  • For data centres: Understand you have a lower reporting threshold - any significant impact must be reported
  • Review contracts with suppliers to ensure they can provide incident details within 24 hours
  • Regularly test your incident response procedures to ensure you can meet the 24-hour deadline

What's Changing:

  • Section 25: Secretary of State can designate Statement of Strategic Priorities setting out government priorities, roles/responsibilities, and objectives for regulatory authorities
  • Section 26: Statement requires consultation with regulatory authorities (40 days), parliamentary approval (40-day period), and can be amended within 3 years if significant change occurs
  • Section 27: Regulatory authorities must have regard to Statement and seek to achieve relevant objectives when exercising functions under NIS Regulations, Part 3, and Part 4
  • Section 28: Secretary of State must report annually on how regulatory authorities have complied with duties under Section 27
  • Section 36: Secretary of State can issue Codes of Practice describing recommended measures for compliance with NIS Regulations or regulations under Section 29
  • Section 37: Codes must be laid before Parliament with 40-day approval period before coming into force
  • Section 38: Codes are admissible in evidence and must be taken into account by courts and regulators when determining compliance questions
  • Section 39: Codes can be withdrawn with 40-day notice period
  • Section 29: Secretary of State can make regulations relating to security and resilience of network and information systems used for essential activities
  • Section 30: Regulations can impose requirements on regulated persons (OES, RDSP, RMSP, critical suppliers, or activity-critical supply providers)
  • Section 19: Regulators must issue guidance, with coordination requirements for critical suppliers and consistency with codes of practice
  • Section 19(3ZB), (4B): Regulators must have regard to relevant codes when preparing guidance

Impact:

  • Organisations must have regard to Codes of Practice when determining compliance (Section 38) - failure to follow codes may be evidence of non-compliance
  • Strategic Priorities will guide regulator enforcement decisions (Section 27) - expect enforcement aligned with government priorities
  • Regulations under Section 29 can impose specific security requirements beyond NIS Regulations - requirements can evolve quickly
  • Regulator guidance must be consistent with codes of practice (Section 19) - creates unified compliance framework
  • Annual reporting (Section 28) creates transparency and accountability for regulators
  • Codes can be updated to reflect evolving threats (Section 36) - compliance requirements may change
  • Strategic Priorities can be amended within 3 years if significant change (Section 25(7)) - including after general elections

What You Must Do:

  • Monitor for Statement of Strategic Priorities and Codes of Practice publication - subscribe to government updates
  • Align security measures with codes when issued - codes describe recommended measures for compliance
  • Ensure compliance documentation references relevant codes and demonstrates regard to them
  • Stay informed about regulations made under Section 29 - these can impose new requirements
  • Review annual reports under Section 28 to understand regulator priorities and focus areas
  • Participate in consultations on Strategic Priorities and Codes of Practice (Section 26, 36)
  • Update compliance frameworks when codes are revised or new regulations are made
  • Train staff on relevant codes and ensure they're considered in day-to-day operations

What's Changing:

  • Section 12: Regulation 14H allows designated competent authorities and Information Commission to designate critical suppliers
  • Regulation 14H(1): Designation criteria for suppliers to OES - must supply goods/services directly, rely on network/information systems, and failure must have potential to cause significant disruption to essential services or economy/society
  • Regulation 14H(2): Designation criteria for suppliers to RDSP/RMSP - similar criteria but for relevant digital services or managed services
  • Regulation 14H(3): Regulators must consider whether alternative sources are available when assessing designation
  • Regulation 14H(4): Regulators must consider nature, scale, and duration of potential disruption
  • Regulation 14H(6): Regulators must consider whether risks could be managed through OES/RDSP/RMSP duties or other regulatory functions
  • Regulation 14H(7): Suppliers can be designated whether or not established in UK
  • Regulation 14H(8): Supply includes supply outside UK
  • Regulation 14I: Restrictions - cannot designate person who is already OES/RDSP/RMSP for same service
  • Regulation 14J: Consultation required before designation - must consult other relevant regulators, give written notice with reasons, allow representation period
  • Regulation 14K: Suppliers can request revocation if criteria no longer met - must provide evidence
  • Regulation 14L: Coordination required between regulators for multi-designated suppliers - must coordinate functions and determine who should designate
  • Section 30(3): Regulations under Section 29 can impose requirements on providers of 'activity-critical supplies' (supplies without which essential activities would be at risk)
  • Section 29(6): 'Activity-critical supply' defined as supply of goods/services without which carrying on of essential activity would be at risk of disruption

Impact:

  • You're responsible for ensuring the cyber maturity of vendors and partners throughout supply chains - designation creates direct regulatory obligations
  • Even small suppliers can be designated if their failure impacts national infrastructure - size doesn't matter, impact does
  • Critical suppliers face same regulatory duties as OES/RDSP/RMSP - security measures, incident reporting, inspections, penalties
  • Multi-designation possible - same supplier can be designated by multiple authorities (Regulation 14H(5)) - coordination required
  • Designation can apply to suppliers outside UK (Regulation 14H(7-8)) - international supply chains affected
  • Regulators must coordinate to avoid duplication but can still multi-designate (Regulation 14L)
  • Activity-critical supply requirements under Section 30(3) can impose additional obligations beyond critical supplier designation
  • Consultation process (Regulation 14J) provides opportunity to challenge designation but requires evidence
  • Revocation requests (Regulation 14K) must be supported by evidence that criteria no longer met

What You Must Do:

  • Perform supply chain risk assessments to identify potential critical suppliers - assess whether suppliers rely on network/information systems and impact of failure
  • Create supplier vetting, contract, and monitoring processes - ensure suppliers understand potential designation
  • Understand whether you might be designated as a 'critical supplier' under Regulation 14H - review your customer base and impact of your failure
  • Prepare for consultation process if designated (Regulation 14J) - you'll receive written notice with reasons and have representation period
  • Monitor for 'activity-critical supply' requirements under Section 30(3) - regulations may impose additional obligations
  • Review contracts with suppliers to understand their regulatory status and obligations
  • Establish processes to monitor supplier compliance if they're designated
  • Consider whether alternative suppliers are available - this affects designation likelihood (Regulation 14H(3))
  • If designated, understand coordination requirements if multiple regulators involved (Regulation 14L)
  • Prepare evidence for revocation requests if criteria no longer met (Regulation 14K)

What's Changing:

  • Section 20: Regulation 15 - Powers to require information and documents from regulated persons and others likely to have information (including non-regulated persons)
  • Regulation 15(4-5): Information can be required for establishing designation, deciding on designation/revocation, determining penalties, determining charges
  • Regulation 15(6): Information notices must specify information/documents sought, explain why, specify manner/form, specify time period, include consequences
  • Regulation 15(7): Information notices can be general requests to categories of persons and can be published
  • Regulation 15A(1): Power includes requiring person to obtain, generate, collect, or retain information/documents they wouldn't otherwise have
  • Regulation 15A(3): Powers exercisable in relation to information/documents whether stored within or outside UK
  • Regulation 15A(4-6): Privileged communications protected from disclosure
  • Schedule 1 (Regulation 16): Strengthened inspection powers - on-site inspections, document examination, system testing, interviews, material/equipment examination/removal
  • Regulation 16(4A): Inspector must give notice of consequences before conducting inspection
  • Regulation 16(8A-8B): Privileged communications protected, powers not exercisable outside UK for premises/material/equipment/individuals
  • Section 21: Financial penalties up to the greater of £17,000,000 and 4% of global turnover for serious failures; the greater of £10,000,000 and 2% of turnover for standard failures
  • Section 17: Regulation 20A - Cost recovery through charging schemes - regulators can impose periodic charges
  • Regulation 20B: Charges recoverable as civil debt, with statements of costs and charges required
  • Regulation 20C: Can require charges for specific enforcement actions (excludes appeals and proceedings)
  • Schedule 1 (Regulation 17): Enforcement notices requiring immediate action - applies to OES, RDSP, RMSP, and persons failing to comply with information notices
  • Section 47 (Part 4): Inspection powers for national security directions - similar powers for compliance with directions under Section 43

Impact:

  • You must be ready to evidence compliance - on demand, including from non-regulated persons (Section 20) - information requests can be published
  • Lack of preparedness could trigger inspections, enforcement notices, or financial penalties - enforcement notices require immediate action
  • Must pay reasonable costs of inspections (Schedule 1, Regulation 16) - can be significant for complex systems
  • Information requests can require generation of new information, not just existing documents (Section 20) - may require new systems/processes
  • Information notices can be given to persons outside UK (Regulation 15A(2)) - international operations affected
  • Inspections can examine, print, copy, or remove documents/information and material/equipment (Regulation 16)
  • Enforcement notices can require steps outside UK (Regulation 17(3ZA))
  • Charging schemes may impose charges not related to functions exercised in relation to you (Regulation 20A(5))
  • Failure to comply with information notice = penalty under Section 21 (Regulation 17(2ZB))

What You Must Do:

  • Build and maintain a clear audit trail (security measures, risk registers, incident logs, compliance documentation) - must be accessible on demand
  • Assign compliance responsibility internally (or to a third party) - ensure someone can respond to information requests
  • Prepare for on-site inspections with document access and system testing capabilities - inspectors can test systems
  • Budget for potential regulatory charges under Section 17 - monitor charging scheme publications
  • Stay engaged with your regulator's guidance and updates (Section 19) - guidance may explain inspection processes
  • Establish processes to generate/collect information that may be required - Regulation 15A(1) allows this
  • Review privileged communication policies - understand what's protected (Regulation 15A(4-6))
  • Prepare for potential publication of information requests if you're in a category (Regulation 15(7))
  • Ensure international operations can comply with information requests (Regulation 15A(3))
  • Test inspection readiness - can you provide documents, access systems, demonstrate compliance quickly?

What's Changing:

  • Section 43: Secretary of State can give directions to regulated persons when security/operational compromise or threat gives rise to national security risk
  • Section 43(3): Directions can require: management of network/information systems, risk reduction/mitigation, information provision, prohibition/restriction on use of goods/services/facilities, prohibition on installation, removal/disablement/modification, appointment of skilled persons, actions in UK/relevant UK waters/outside UK
  • Section 43(5): Directions must specify person, reasons (unless contrary to national security), time of coming into force, reasonable period for compliance
  • Section 43(6): Person must comply with direction
  • Section 43(7): Written approval required before appointing skilled person, must notify Secretary of State after appointment
  • Section 43(11): Secretary of State can require non-disclosure of direction existence/contents
  • Section 44: Compliance with directions takes priority over conflicting regulatory requirements - Secretary of State must notify relevant regulator
  • Section 45: Secretary of State can direct regulatory authorities to monitor compliance with directions and provide reports
  • Section 46: Information gathering powers for Secretary of State and regulatory authorities in relation to directions
  • Section 47: Inspection powers for verifying compliance with directions - can require regulated person to pay costs
  • Section 48-51: Enforcement regime with notifications, confirmation decisions, and penalties of up to £17M for contravening a direction, plus up to £100,000 per day while the contravention continues
  • Section 49(2): Maximum penalties: £17M for contravening a direction, rising to the greater of £17M and 10% of turnover only where regulations under Section 49(5) are in force (none have been made yet); £10M for information/inspection failures
  • Section 52: Enforcement of non-disclosure requirements with penalties up to £10M
  • Section 53: Secretary of State can direct regulatory authorities themselves (cannot direct Ministers, devolved governments, NI departments)
  • Section 54: Directions can be reviewed, varied, or revoked - variation requires consultation unless contrary to national security
  • Section 55: Directions must be laid before Parliament unless contrary to national security (can exclude commercial/security sensitive information)
  • Section 56: Information sharing between Secretary of State, regulatory authorities, GCHQ, UK public authorities, and overseas public authorities for national security purposes

Impact:

  • Unprecedented executive power - Secretary of State can require immediate action without primary legislation when national security at risk
  • Directions can override conflicting regulatory requirements (Section 44) - creates potential for conflicting obligations
  • Non-disclosure requirements (Section 43(11)) may prevent you from discussing directions with customers, partners, or even internally
  • Penalties are severe - up to £17M for contravening a direction, plus up to £100,000 per day while the contravention continues, and these Part 4 sanctions are separate from the NIS Regulations regime (Section 49)
  • Inspections can require you to pay costs (Section 47(4)) - can be significant
  • Directions can require actions outside UK (Section 43(3)(h)) - international operations affected
  • Skilled person appointments require written approval (Section 43(7)) - may delay response
  • Directions are laid before Parliament (Section 55) - creates transparency but may expose sensitive information
  • Regulatory authorities can be directed to monitor compliance (Section 45) - creates additional oversight layer
  • Information sharing with GCHQ and overseas authorities (Section 56) - sensitive information may be shared

What You Must Do:

  • Establish processes to receive and respond to directions quickly - directions can require immediate action
  • Understand non-disclosure requirements - you may not be able to discuss directions even internally
  • Prepare for potential conflicts between directions and other regulatory requirements - Section 44 provides priority but creates complexity
  • Budget for potential inspection costs if directed (Section 47(4))
  • Identify potential skilled persons in advance - appointments require approval (Section 43(7))
  • Review contracts to understand obligations if directions require actions affecting third parties
  • Establish information sharing protocols - directions may require information sharing with GCHQ/overseas authorities
  • Monitor Parliament for laid directions (Section 55) - understand what directions are being given
  • Prepare for potential public disclosure - directions are laid before Parliament (with exceptions)
  • Understand appeal rights - directions can be challenged but process may be limited for national security matters

What's Changing:

  • Section 29: Secretary of State can make regulations relating to security and resilience of network and information systems
  • Section 30: Can impose requirements on regulated persons, including activity-critical supplies
  • Section 36: Can issue Codes of Practice (must be laid before Parliament with 40-day approval period)
  • Section 25: Can designate Statement of Strategic Priorities (40-day parliamentary approval)
  • Section 42: Consultation required before making certain regulations, but can be satisfied by pre-commencement consultation

Impact:

  • Requirements can evolve quickly through regulations (Section 29) without primary legislation
  • Codes of Practice can be updated to reflect evolving threats (Section 36)
  • Strategic Priorities can be amended within 3 years if significant change occurs (Section 25(7))
  • Regulations can make different provision for different sectors or circumstances (Section 41)

What You Must Do:

  • Stay informed - subscribe to government updates and monitor Parliament website
  • Monitor regulatory consultation periods (Section 42 requires consultation)
  • Review Codes of Practice when issued (Section 36) and align compliance accordingly
  • Work with a compliance partner who can help interpret legal change and regulations

What's Changing:

  • Section 18: Regulation 6 - NIS enforcement authorities can disclose information to other NIS enforcement authorities, Secretary of State, relevant law-enforcement authorities, CSIRT, UK public authorities
  • Regulation 6(1): Disclosure purposes include: NIS Regulations functions, national security, prevention/detection of crime, investigation of criminal offences, criminal proceedings
  • Regulation 6(3): Persons within paragraph (2) can disclose to NIS enforcement authorities for same purposes
  • Regulation 6(4): Disclosure must be limited to information relevant and proportionate to purpose
  • Regulation 6(5): NIS enforcement authorities can disclose to Secretary of State for reports under Section 40, assessment of security/resilience, policy formulation
  • Regulation 6(7): Can disclose to relevant overseas authorities (authorities in countries outside UK with corresponding functions)
  • Regulation 6A: Onward disclosure restrictions - information disclosed under Regulation 6 must not be further disclosed except in accordance with Regulation 6A
  • Regulation 6A(2): Can disclose to Secretary of State, relevant law-enforcement authorities, CSIRT, UK public authorities for Regulation 6(1) purposes, or with consent
  • Regulation 6A(5): Disclosure doesn't breach obligations of confidence or other restrictions
  • Regulation 6A(6): Doesn't authorise disclosure prohibited by Investigatory Powers Act 2016
  • Regulation 6B: Information Commission can use information obtained under NIS Regulations for facilitating functions under other enactments if necessary and proportionate
  • Section 18(1): Regulation 3(3)(e) amended - competent authorities must send lists to GCHQ (not just SPOC) for facilitating GCHQ functions
  • Section 18(1): Regulation 3(5A) - Lists must be sent to GCHQ within 4 months of Section 18(1) commencement and annually thereafter
  • Section 18(2): Regulation 4(2) amended - SPOC can notify relevant authorities in countries outside UK (not just EU Member States)
  • Section 18(2): Regulation 4(2ZA) - Defines 'relevant' overseas authority as one with corresponding functions
  • Section 18(4): Regulation 7 (Northern Ireland) - Disclosure doesn't breach obligations of confidence, doesn't authorise disclosure prohibited by Investigatory Powers Act 2016
  • Section 56 (Part 4): Information sharing for national security purposes between Secretary of State, regulatory authorities, GCHQ, UK public authorities, overseas public authorities

Impact:

  • GCHQ receives direct access to registers and lists (Section 18(1)) - creates direct intelligence agency oversight
  • Information can be shared with overseas authorities (Regulation 6(7)) - international information sharing expanded
  • Information sharing for national security, crime prevention, and criminal proceedings (Regulation 6(1)) - broad purposes
  • Onward disclosure restrictions (Regulation 6A) - information shared with you may have restrictions on further sharing
  • Information Commission can use NIS information for other functions (Regulation 6B) - cross-functional information use
  • Disclosure doesn't breach obligations of confidence (Regulation 6A(5)) - legal protection for sharing
  • SPOC can notify non-EU countries (Section 18(2)) - post-Brexit expansion of international cooperation
  • Information sharing for policy formulation (Regulation 6(5)) - your information may inform government policy
  • Annual reporting to GCHQ (Section 18(1)) - ongoing intelligence agency access to registers

What You Must Do:

  • Understand what information may be shared - registers, incident reports, compliance information can all be shared
  • Review data protection implications - information sharing may involve personal data
  • Understand onward disclosure restrictions if you receive information (Regulation 6A)
  • Prepare for potential overseas information sharing - your information may be shared internationally
  • Review contracts with third parties - information sharing may affect confidentiality obligations
  • Understand GCHQ access - your registration information goes to GCHQ (Section 18(1))
  • Monitor for information sharing requests - you may be asked to provide information for policy formulation
  • Review information governance policies - ensure they account for regulatory information sharing
  • Understand Investigatory Powers Act 2016 restrictions - some disclosures remain prohibited (Regulation 6A(6))
  • Prepare for potential international information sharing - overseas authorities may receive your information

What's Changing:

  • Section 16: After full notification, must notify affected customers 'as soon as reasonably practicable'
  • Regulation 11C: Applies to data centre operators (OES providing data centre services)
  • Regulation 12C: Applies to Relevant Digital Service Providers (RDSPs)
  • Regulation 14G: Applies to Relevant Managed Service Providers (RMSPs)
  • Must take reasonable steps to identify affected customers in UK
  • Notification must include: nature of incident, why customer is likely to be adversely affected

Impact:

  • This introduces reputational risk and pressure for incident readiness
  • Customers and partners will expect evidence of preparedness
  • Failure to notify customers = penalty under Section 21 (higher band: the greater of £17M and 4% turnover)
  • Must balance transparency with confidentiality requirements

What You Must Do:

  • Create a notification and PR plan aligned with Section 16 requirements
  • Establish processes to identify affected customers quickly
  • Prepare notification templates that explain nature of incident and impact
  • Consider how you'll inform customers while maintaining confidentiality
  • Ensure third-party SLAs include timely reporting and customer alert clauses

What's Changing:

  • Section 17: Regulation 20A allows NIS enforcement authorities to impose periodic charges through charging schemes
  • Charging schemes must specify: functions covered, chargeable periods, amount or calculation method, payment terms
  • Regulation 20B: Charges recoverable as civil debt, with statements of costs and charges
  • Regulation 20C: Can require charges for specific enforcement actions (excludes appeals and proceedings)
  • Section 34 (Part 3): Regulations can provide for regulatory authority cost recovery
  • Charging schemes must be published and consulted on (Regulation 20A(7-8))

Impact:

  • Compliance may come with direct costs: periodic charges, registration fees, enforcement action costs
  • Charges may not relate to functions exercised in relation to the person charged (Regulation 20A(5))
  • Must budget for potential annual or periodic regulatory charges

What You Must Do:

  • Budget for cyber compliance fees - monitor regulator charging scheme publications
  • Track your status with your sector regulator and any charging scheme updates
  • Review charging scheme consultation documents and provide feedback
  • Understand what charges apply to your organisation type

What's Changing:

  • Section 22: Schedule 1 amends Regulation 19A - Appeals to First-tier Tribunal against enforcement notices, penalty notices, and critical supplier designations
  • Schedule 1 (Regulation 19A): Appeals available for: enforcement notices (OES, RDSP, RMSP, information notice failures), penalty notices, critical supplier designations, critical supplier revocations
  • Schedule 1 (Regulation 19A(2B)): Persons can appeal against designation under Regulation 14H, revocation of designation, enforcement notices, penalty notices
  • Schedule 1 (Regulation 19B): First-tier Tribunal can confirm, vary, or withdraw decisions
  • Section 60: Commencement provisions - Part 1, Chapters 1/3/6 of Part 3, Section 40, Part 5 come into force on day Act is passed
  • Section 60(2): Section 18(3-4), Chapter 2 of Part 3, Schedule 2 paragraphs 3/4/13 come into force 2 months after passing
  • Section 60(3): Other provisions come into force on day appointed by Secretary of State by regulations
  • Section 60(5): Section 12 (critical suppliers) must come into force on same day as first regulations under Section 29(1) containing relevant amending provision
  • Section 60(7): Secretary of State can make transitional or saving provision by regulations
  • Schedule 2 (Paragraph 13): Regulations 2 and 3(6) of NIS Regulations (NIS national strategy) continue to have effect until first statement designated under Section 25
  • Section 40: Secretary of State must report at least once every 5 years on operation of NIS Regulations, Part 3, Part 4, and regulations under Part 3
  • Section 40(4): Reports must assess objectives, achievement, appropriateness, whether objectives could be achieved with less onerous provision, and review exercise of powers

Impact:

  • Appeal rights available but limited - can appeal enforcement notices, penalties, and critical supplier designations (Schedule 1)
  • First-tier Tribunal can vary or withdraw decisions (Schedule 1, Regulation 19B) - provides remedy but requires legal action
  • Staggered commencement (Section 60) - some provisions immediate, others delayed - creates uncertainty about when requirements apply
  • Critical supplier designation tied to Section 29 regulations (Section 60(5)) - may delay implementation
  • Transitional provisions (Section 60(7)) - Secretary of State can make saving provisions, may provide grace periods
  • NIS national strategy continues until Strategic Priorities statement (Schedule 2, Paragraph 13) - provides continuity
  • 5-year reporting cycle (Section 40) - creates opportunity for legislative review and potential changes
  • Reports assess whether objectives could be achieved with less onerous provision (Section 40(4)) - may lead to deregulation
  • Appeals require legal representation and costs - can be expensive
  • Commencement dates may be different for different purposes (Section 60(4)) - creates complexity

What You Must Do:

  • Monitor commencement dates - subscribe to government updates for when provisions come into force
  • Understand appeal rights - can appeal enforcement notices, penalties, and critical supplier designations
  • Prepare for potential appeals - may need legal representation for First-tier Tribunal
  • Review transitional provisions when published - may provide grace periods or exemptions
  • Monitor 5-year reports under Section 40 - may indicate future legislative changes
  • Understand that NIS national strategy continues until Strategic Priorities statement - existing guidance remains relevant
  • Prepare for staggered commencement - some requirements may apply before others
  • Review regulations made under Section 60(3) for commencement dates
  • Consider participating in consultations on transitional provisions
  • Budget for potential appeal costs if you receive enforcement notice or penalty

Need help navigating these changes?

Our cyber security compliance experts can help you understand how these changes impact your organisation and build a roadmap for compliance.