Transport Infrastructure

Transport Infrastructure Cyber Security and Resilience Bill Compliance Guide

Complete guide to Cyber Security and Resilience Bill compliance for Rail Operators, Aviation Providers, Maritime Ports, and Transport Infrastructure. Understand OES obligations under HL Bill 32.

Sector Overview

Transport infrastructure is critical to the UK's economy and daily functioning. Rail networks, airports, ports, and air traffic control systems are essential services that keep the country moving. Under the Cyber Security and Resilience Bill (HL Bill 32), transport infrastructure providers are regulated as Operators of Essential Services (OES) under the NIS Regulations.

Critical National Infrastructure: Transport infrastructure is recognised as critical national infrastructure, making it a high-value target for cyber attacks. The Cyber Security and Resilience Bill (CSRB) strengthens requirements for protecting these systems.

Transport Sectors in Scope

Under the NIS Regulations (as amended by HL Bill 32), the following transport sectors are regulated as essential services:

Rail Transport

Rail operators, network infrastructure, signalling systems, and rail traffic management

Aviation

Airports, air traffic control, air navigation services, and aviation infrastructure

Maritime

Ports, port services, maritime traffic management, and critical maritime infrastructure

You're likely in scope if you operate:
  • Rail networks, signalling systems, or rail traffic management services
  • Airports, air traffic control, or air navigation services
  • Ports, port services, or maritime traffic management
  • Transport infrastructure that meets threshold requirements in Schedule 2 of the NIS Regulations
  • Services that are essential to the economy or day-to-day functioning of society
  • Network and information systems that support critical transport operations

Operator of Essential Services (OES) Identification

Under Part 2, Section 3 of HL Bill 32, Regulation 8 of the NIS Regulations identifies Operators of Essential Services:

Regulation 8(1) applies to a person whether or not the person is established in the United Kingdom. A person may be designated under Regulation 8(3) whether or not the person is established in the United Kingdom.

- HL Bill 32, Part 2, Section 3, Regulation 8(1ZA), (3A)

Key Points:
  • You can be an OES whether or not you're established in the UK, as long as you provide essential services in the UK
  • You may be automatically deemed to be an OES if you meet the threshold requirements in Schedule 2
  • You may be designated as an OES by your designated competent authority if you don't meet automatic thresholds but are considered essential
  • Public electronic communications networks and services are explicitly excluded from OES designation

Security Duties - Regulation 10

As an Operator of Essential Services (OES) in the transport sector, you must comply with security duties under Regulation 10 of the NIS Regulations:

  • Take appropriate and proportionate technical and organisational measures to manage risks posed to the security of network and information systems on which you rely for the provision of the essential service
  • Take appropriate and proportionate measures to prevent and minimise the impact of incidents affecting the security of those network and information systems
  • Have regard to any relevant guidance issued by the designated competent authority
  • Ensure a level of security appropriate to the level of risk you face
  • Manage supply chain risks - you may be designated as a critical supplier if you supply to other regulated organisations

Incident Reporting Requirements - Regulation 11

Under Part 2, Section 15 of HL Bill 32, Regulation 11 sets out strict incident reporting requirements for Operators of Essential Services:

⚠️ Critical Timeline:
24 Hours: Initial notification must be given before the end of 24 hours beginning with the time you first become aware that an OES incident has occurred or is occurring
72 Hours: Full detailed notification must be given before the end of 72 hours beginning with that time
What is an OES Incident?

An incident is an "OES incident" if:

  • The incident has affected or is affecting the operation or security of the network and information systems relied on to provide the essential service
  • The impact of the incident in the United Kingdom or any part of it has been, is or is likely to be significant having regard to factors including: extent of disruption, number of users affected, duration, geographical area, and data confidentiality/authenticity/integrity/availability compromise
Required Information in Full Notification:
  • Your name and the essential service to which the incident relates
  • The time the incident occurred, its duration and whether it is ongoing
  • Information concerning the nature of the incident
  • Where the incident was caused by a separate incident affecting another regulated person: details of that separate incident and of the regulated person
  • Information concerning the impact (including any cross-border impact) which the incident has had, is having or is likely to have
  • Such other information as you consider may assist the designated competent authority in exercising its functions
Reporting Requirements:

Notifications must be in writing, provided in such form and manner as the designated competent authority determines. You must send a copy of the notification to CSIRT (Computer Security Incident Response Team) at the same time as sending it to the designated competent authority.

- HL Bill 32, Part 2, Section 15, Regulation 11

Information Requests & Inspections

Under Part 2, Section 20 of HL Bill 32, Regulation 15 gives designated competent authorities powers to:

  • Require you to give such information or documents as it reasonably requires for exercising its functions
  • Require you to obtain or generate information or documents
  • Require you to collect or retain information that you would not otherwise collect or retain
  • Send information notices whether or not you're established in the UK
  • Request information or documents stored within or outside the United Kingdom
⚠️ Important:

Failure to comply with an information notice is a breach that can result in penalties. You may not be required to give privileged communications (legal advice protected by legal professional privilege). Regulators can inspect your premises, examine documents, test your systems, and interview your staff.

- HL Bill 32, Part 2, Section 20, Regulation 15

Critical Suppliers in Transport Supply Chain

Under Part 2, Section 12 of HL Bill 32, Regulation 14H allows designation of critical suppliers:

Suppliers to transport infrastructure operators may be designated as critical suppliers if:

  • They supply goods or services directly to an OES (transport operator)
  • They rely on network and information systems for that supply
  • An incident affecting their systems has the potential to cause disruption to the provision of essential services
  • Any such disruption is likely to have a significant impact on the economy or day-to-day functioning of society
  • The OES is unlikely to be able to obtain the goods or services from an alternative source

- HL Bill 32, Part 2, Section 12, Regulation 14H

Penalties for Non-Compliance

Under Part 2, Section 21 of HL Bill 32, Regulation 18 sets out financial penalties for Operators of Essential Services:

Higher Maximum Amount (Serious Failures):

For failures including:

  • Failure to fulfil security duties under regulation 10(1) and (2)
  • Failure to notify an incident under regulation 11(2)
  • Failure to comply with regulation 11(6) and (7) in relation to notification requirements

Maximum: the greater of £17,000,000 and 4% of global turnover

Standard Maximum Amount (Administrative Failures):

For failures including:

  • Failure to comply with regulation 11(8) - sending copy to CSIRT
  • Administrative failures and late notifications

Maximum: the greater of £10,000,000 and 2% of global turnover

- HL Bill 32, Part 2, Section 21, Regulation 18

Benefits of Cyber Security and Resilience Bill Compliance

Operational Benefits
  • Improve resilience and reduce downtime
  • Better incident response capabilities
  • Enhanced security posture
Regulatory & Business Benefits
  • Demonstrate compliance to regulators and stakeholders
  • Reduce risk of financial penalties
  • Build public trust and confidence

Direct References from HL Bill 32

Part 2, Section 3 - Identification of Operators of Essential Services

Regulation 8 identifies OES, including transport infrastructure providers. Regulation 8(1ZA) clarifies that OES identification applies whether or not the person is established in the UK. Regulation 8(3A) allows designation whether or not the person is established in the UK.

HL Bill 32, Part 2, Section 3, Regulation 8

Part 2, Section 15 - Incident Reporting

Regulation 11 requires OES to report incidents within 24 hours (initial notification) and 72 hours (full notification) to the designated competent authority, with a copy to CSIRT simultaneously.

HL Bill 32, Part 2, Section 15, Regulation 11

Part 2, Section 12 - Critical Suppliers

Regulation 14H allows designated competent authorities to designate suppliers to OES as critical suppliers if their failure could disrupt essential services and have significant impact on the economy or day-to-day functioning of society.

HL Bill 32, Part 2, Section 12, Regulation 14H

Part 2, Section 20 - Information Gathering

Regulation 15 gives designated competent authorities power to require OES to provide information or documents, obtain or generate information, and collect or retain information for regulatory purposes. Information notices can be sent to OES whether or not they're established in the UK.

HL Bill 32, Part 2, Section 20, Regulation 15

Part 2, Section 21 - Financial Penalties

Regulation 18 sets maximum penalties: the greater of £17 million and 4% of turnover for serious failures (security duties, incident reporting), and the greater of £10 million and 2% of turnover for standard failures (administrative requirements).

HL Bill 32, Part 2, Section 21, Regulation 18

Frequently Asked Questions

Are transport infrastructure providers regulated under the CSRB?

Transport infrastructure providers operating rail, aviation or maritime services that meet the threshold requirements in Schedule 2 of the NIS Regulations are regulated as Operators of Essential Services under the Cyber Security and Resilience Bill. An operator that does not meet the automatic thresholds may still be designated as an OES by its designated competent authority if it is considered essential.

What are the incident reporting requirements for transport operators?

Transport infrastructure operators must give their designated competent authority an initial notification within 24 hours and a full notification within 72 hours of first becoming aware of an OES incident, under Regulation 11. A copy of each notification must be sent to CSIRT at the same time. Notifications must be in writing and in the form and manner the designated competent authority determines.

Which transport sectors are in scope of the CSRB?

Rail, aviation and maritime are the transport sectors regulated as essential services under the NIS Regulations as amended by HL Bill 32. That covers rail operators, network infrastructure, signalling systems and rail traffic management; airports, air traffic control, air navigation services and aviation infrastructure; and ports, port services, maritime traffic management and critical maritime infrastructure, in each case where the Schedule 2 threshold requirements are met.

Can a transport operator based outside the UK be an Operator of Essential Services?

A transport operator can be an Operator of Essential Services whether or not it is established in the United Kingdom, provided it supplies essential services in the UK. Regulation 8(1ZA) confirms that Regulation 8(1) applies whether or not the person is established here, and Regulation 8(3A) allows designation on the same basis. Public electronic communications networks and services are explicitly excluded from OES designation.

What penalties do transport operators face under the CSRB?

Transport infrastructure operators face a higher maximum penalty of the greater of £17,000,000 and 4% of global turnover, for serious failures such as breaching the Regulation 10 security duties or failing to notify an incident under Regulation 11(2). Administrative failures carry a standard maximum of the greater of £10,000,000 and 2% of global turnover, and include failing to send a copy of a notification to CSIRT under Regulation 11(8) and late notifications.

Need Help with Transport Infrastructure Cyber Security and Resilience Bill Compliance?

Our expert team helps Transport Infrastructure Providers implement and prove compliance with Cyber Security and Resilience Bill requirements.