Universities & Research Institutions

Universities Cyber Security and Resilience Bill Compliance Guide

Complete guide to Cyber Security and Resilience Bill compliance for universities and research institutions. Understand multi-faceted regulatory obligations under HL Bill 32.

Sector Overview

Universities and research institutions are hubs of innovation, managing vast amounts of sensitive research data, student information, and critical computing infrastructure. Under the Cyber Security and Resilience Bill (HL Bill 32), universities may be regulated in multiple ways depending on their activities.

Strategic Importance: The Cyber Security and Resilience Bill (CSRB) recognises the strategic importance of academic institutions - placing certain universities within its regulatory scope based on their research activities and infrastructure.

Why Universities Are In Scope

Universities may be in scope under HL Bill 32 in several ways:

You're likely in scope if your organisation:
  • Provides a service that meets a NIS Schedule 2 sector threshold, such as in energy or transport (universities are not named in Schedule 2)
  • Provides cloud computing services, online marketplaces, or search engines (RDSP under Part 2, Section 7) and is not under public authority oversight, or is under oversight but derives more than half its income commercially
  • Provides managed IT services (RMSP under Part 2, Section 9), subject to the same public authority oversight test
  • Carries on essential activities or provides activity-critical supplies (subject to Part 3 regulations)
  • May be subject to directions for national security purposes (Part 4)
  • Manages research with implications for national resilience or security
  • Operates or supports high-performance computing (HPC) environments
  • Processes sensitive student, staff, or partner data at scale
  • Provides infrastructure to regulated sectors through collaboration
Public Authority Oversight:

Under Part 2, Section 11 of HL Bill 32, public authority oversight is an exemption from RDSP and RMSP status. A university is caught as an RDSP or RMSP only if it is not subject to public authority oversight, or is subject to it and derives more than half its income from commercial activities. A university under oversight earning half or less of its income commercially is outside those categories. The test does not affect OES status.

As Operators of Essential Services (OES)

Universities are not named in NIS Schedule 2. Under the Cyber Security and Resilience Bill a university is an operator of essential services (OES) only where a service it provides meets a Schedule 2 sector threshold, such as in energy or transport.

As an OES, you must:
  • Comply with security duties under Regulation 10
  • Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 11
  • Send a copy of incident notifications to CSIRT
  • Provide information to designated competent authority within 3 months under Regulation 8ZA (if providing data centre services)
  • Comply with information requests and inspections under Regulations 15 and 16
  • Have regard to guidance from your designated competent authority

As Relevant Digital Service Providers (RDSP)

Under Part 2, Section 7 of HL Bill 32, universities providing cloud computing services, online marketplaces, or search engines may be regulated as Relevant Digital Service Providers (RDSPs):

  • Register with the Information Commission within 3 months (Regulation 14)
  • Comply with security duties under Regulation 12
  • Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 12A
  • Notify affected customers as soon as reasonably practicable under Regulation 12C
  • Comply with information requests and inspections

As Relevant Managed Service Providers (RMSP)

Under Part 2, Section 9 of HL Bill 32, universities providing managed IT services may be regulated as Relevant Managed Service Providers (RMSPs):

  • Register with the Information Commission within 3 months (Regulation 14C)
  • Comply with security duties under Regulation 14B
  • Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 14E
  • Notify affected customers as soon as reasonably practicable under Regulation 14G
  • Comply with information requests and inspections

Essential Activities & Activity-Critical Supplies

Under Part 3, Section 24 of HL Bill 32, universities may carry on essential activities or provide activity-critical supplies, subjecting them to additional security and resilience requirements:

  • May be subject to regulations under Section 29 relating to security and resilience of network and information systems
  • May be subject to requirements imposed under Section 30
  • May be subject to enforcement, sanctions, and appeals under Section 31
  • May become subject to financial penalties under future Part 3 regulations, which Section 32(3) caps at the greater of £17,000,000 and 10% of turnover; no such regulations have been made yet
  • Must have regard to codes of practice issued under Section 36

National Security Directions - Part 4

Under Part 4, Section 43 of HL Bill 32, universities may be subject to directions for national security purposes:

  • The Secretary of State may give directions if threats relating to network and information systems pose a risk to national security
  • Directions may impose requirements relating to management of systems, provision of information, or prohibitions on use of goods/services
  • You must comply with directions and may be subject to monitoring, information gathering, and inspections under Sections 45-47
  • Penalties for contravening a direction: up to £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, with daily penalties of up to £100,000 while the contravention continues

- HL Bill 32, Part 4, Sections 43-52

Penalties for Non-Compliance

Universities face penalties depending on how they're regulated:

Part 2 Penalties (OES/RDSP/RMSP):

Higher Maximum: the greater of £17,000,000 and 4% of turnover for security-duty and incident-notification failures

Standard Maximum: the greater of £10,000,000 and 2% of turnover for registration and information failures

Part 3 Penalties (Essential Activities):

Cap on future regulations: the greater of £17,000,000 and 10% of turnover. Part 3 penalties only come into being once regulations under Section 29(1) are made, and none have been.

Part 4 Penalties (National Security Directions):

Maximum: £17,000,000 for contravening a direction, becoming the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues

- HL Bill 32, Part 2, Section 21; Part 3, Section 32; Part 4, Section 49

Benefits of Cyber Security and Resilience Bill Compliance

Research Protection
  • Protects data and research environments from cyber threats
  • Supports funding, collaboration, and government trust
  • Strengthens cyber maturity across academic networks
Strategic Benefits
  • Futureproofs institutions in a security-driven digital landscape
  • Access to guidance from regulatory authorities
  • Better positioning for government-backed research programmes

Direct References from HL Bill 32

Schedule 2 - Essential Services

Universities are not named in Schedule 2. A university is an operator of essential services (OES) only where a service it provides meets a Schedule 2 sector threshold.

HL Bill 32, Schedule 2

Part 2, Section 11 - Subject to Public Authority Oversight

Regulation 1(3E) defines public authority oversight for the RDSP and RMSP definitions. A university subject to oversight is caught as an RDSP or RMSP only if it derives more than half its income from commercial activities. The test does not affect OES status.

HL Bill 32, Part 2, Section 11, Regulation 1(3E)

Part 3, Section 24 - Essential Activities

Universities may carry on essential activities or provide activity-critical supplies, subjecting them to additional security and resilience requirements under Part 3.

HL Bill 32, Part 3, Section 24

Part 4, Section 43 - Directions for National Security

Universities may be subject to directions for national security purposes if threats relating to network and information systems pose a risk to national security.

HL Bill 32, Part 4, Section 43

Frequently Asked Questions

Are universities regulated under the CSRB?

Universities are not named in NIS Schedule 2 and are not regulated as a category. Under the Cyber Security and Resilience Bill a university is an operator of essential services only where a service it provides meets a Schedule 2 sector threshold, such as in energy or transport. It is a relevant digital or managed service provider only if it provides cloud computing services, online marketplaces, search engines or managed IT services and is either not subject to public authority oversight, or is subject to it but derives more than half its income from commercial activities. Part 3 and Part 4 may also apply.

Are universities regulated if most of their income is commercial?

Commercial income matters only for digital and managed service provider status. Under the Cyber Security and Resilience Bill a university that provides cloud computing, online marketplace, search engine or managed IT services is caught as an RDSP or RMSP only if it is not subject to public authority oversight, or is subject to it and derives more than half its income from commercial activities. A university under oversight that earns half or less of its income commercially is outside those categories. The test does not affect operator of essential services status. Public authority oversight is defined by Regulation 1(3E), inserted by Part 2, Section 11 of HL Bill 32.

What must a university do if it is an Operator of Essential Services?

A university regulated as an Operator of Essential Services must comply with the security duties in Regulation 10, report incidents within 24 hours and 72 hours under Regulation 11, and send a copy of each notification to CSIRT. Where it provides data centre services it must also give information to its designated competent authority within 3 months under Regulation 8ZA. It must comply with information requests and inspections under Regulations 15 and 16 and have regard to guidance from its designated competent authority.

Does high-performance computing bring a university into CSRB scope?

Universities that operate or support high-performance computing (HPC) environments are among those most likely to fall within scope of the Cyber Security and Resilience Bill. Other indicators include managing research with implications for national resilience or security, processing sensitive student, staff or partner data at scale, and providing infrastructure to regulated sectors through collaboration.

What penalties do universities face under the CSRB?

Universities face a higher maximum penalty of the greater of £17,000,000 and 4% of turnover for Part 2 security-duty and incident-notification failures as an OES, RDSP or RMSP, and a standard maximum of the greater of £10,000,000 and 2% of turnover for registration and information failures. Part 3 penalties do not exist yet; when regulations are made, Section 32(3) caps them at the greater of £17,000,000 and 10% of turnover. Contravening a Part 4 national security direction carries a maximum of £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues.

Need Help with University Cyber Security and Resilience Bill Compliance?

Our expert team helps universities and research institutions navigate multi-faceted Cyber Security and Resilience Bill requirements.