Praeferre/Frameworks/UK Cyber Security & Resilience Bill
Security, Resilience & Assurance · United Kingdom

Cyber Security and Resilience (Network and Information Systems) Bill

The UK's post-Brexit update to the NIS Regulations 2018, broadly mirroring the EU's NIS2 while reflecting UK-specific priorities. It expands regulatory scope to managed service providers and data centres, and introduces a new “critical suppliers” designation.

REGULATORDepartment for Science, Innovation & Technology (DSIT) & sector regulators REGIONUnited Kingdom EFFECTIVEIntroduced to Parliament 12 November 2025; phased implementation expected 2026–2028

Who it applies to

  • Operators of essential services in energy, health, transport, water and digital infrastructure
  • Managed service providers and qualifying data centre operators
  • Suppliers designated as “critical” to an in-scope organisation's essential service

Key requirements

  • Appropriate and proportionate supply chain risk management
  • 24-hour initial incident notification, 72-hour detailed reporting
  • Alignment with the NCSC's Cyber Assessment Framework outcomes
  • Cooperation with expanded regulator information and inspection powers
  • Board-level ownership of cyber risk

Maximum penaltyUp to £17 million or 4% of global turnover, plus daily penalties of up to £100,000 for ongoing non-compliance

Go to the source

Official resources

Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.

Start your compliance journey

See how Praeferre automates UK Cyber Security & Resilience Bill compliance

Continuous monitoring, evidence and reporting for UK Cyber Security & Resilience Bill — alongside every other framework you need to satisfy.