Security, Resilience & Assurance · United Kingdom
Cyber Security and Resilience (Network and Information Systems) Bill
The UK's post-Brexit update to the NIS Regulations 2018, broadly mirroring the EU's NIS2 while reflecting UK-specific priorities. It expands regulatory scope to managed service providers and data centres, and introduces a new “critical suppliers” designation.
REGULATORDepartment for Science, Innovation & Technology (DSIT) & sector regulators
REGIONUnited Kingdom
EFFECTIVEIntroduced to Parliament 12 November 2025; phased implementation expected 2026–2028
Who it applies to
- Operators of essential services in energy, health, transport, water and digital infrastructure
- Managed service providers and qualifying data centre operators
- Suppliers designated as “critical” to an in-scope organisation's essential service
Key requirements
- Appropriate and proportionate supply chain risk management
- 24-hour initial incident notification, 72-hour detailed reporting
- Alignment with the NCSC's Cyber Assessment Framework outcomes
- Cooperation with expanded regulator information and inspection powers
- Board-level ownership of cyber risk
Maximum penaltyUp to £17 million or 4% of global turnover, plus daily penalties of up to £100,000 for ongoing non-compliance
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates UK Cyber Security & Resilience Bill compliance
Continuous monitoring, evidence and reporting for UK Cyber Security & Resilience Bill — alongside every other framework you need to satisfy.