Bill 4035 Committee stage Lords

Cyber Security and Resilience (Network and Information Systems) Bill

A Bill to Make provision, including provision amending the Network and Information Systems Regulations 2018, about the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities.

Introduced by
Liz Kendall · Labour · Leicester West
Originating house
Commons
Introduced
12 November 2025
Last updated
16 September 2026

What this bill does

Currently at Committee stage in the Lords.

Expands UK cyber rules to cover more services and gives ministers stronger powers.

This bill is now in its later parliamentary form and would widen the UK’s cyber security rules to cover more organisations, including data centres, managed service providers and some load controllers. It also strengthens incident reporting, customer notification, information sharing, inspections and financial penalties. At the same time, it gives the Secretary of State broader powers to set priorities, make further rules and direct action for national security reasons.

  • Expand the scope of the NIS Regulations to include data centre services, managed services, critical suppliers and large load controllers
  • Create new duties for relevant digital service providers and relevant managed service providers to manage cyber risks, report incidents and notify affected customers
  • Require certain operators of data centre services, digital service providers and managed service providers to register and provide updated information to the Information Commission or competent authorities
  • Allow regulators to gather information, issue guidance, recover costs through charges, impose financial penalties and take enforcement action
  • Give the Secretary of State powers to designate strategic statements, issue a code of practice, require reports on the legislation, and make regulations about cyber security and resilience
  • Allow the Secretary of State to give directions to regulated persons and regulatory authorities where a cyber threat poses a risk to national security, including secrecy requirements in some cases

The stage line is the same Parliament bill record as the heading. The summary is AI-generated and not independently reviewed. Report an error.

Progress

  1. 1st reading · Commons
  2. 2nd reading · Commons
  3. Programme motion · Commons
  4. Money resolution · Commons
  5. Ways and Means resolution · Commons
  6. Carry-over motion · Commons
  7. Committee stage · Commons
  8. Bill reintroduced · Commons
  9. Report stage · Commons
  10. 3rd reading · Commons
  11. 1st reading · Lords
  12. 2nd reading · Lords
  13. Committee stage · Lords
  14. Report stage · Lords